PrivacyCache← All articles
GDPR

How to Calculate GDPR DSAR Response Deadlines

6 min read
A privacy officer reviewing an access-request deadline calendar

When a data subject submits a request under the GDPR, the clock starts ticking. You have one calendar month to respond — not 30 days, not 28 days, but one calendar month from the day after receipt. Getting this wrong is one of the most common compliance failures, and it accounts for a significant share of complaints filed with supervisory authorities.

The Basic Rule: One Calendar Month

Article 12(3) of the GDPR states that the controller shall provide information on action taken "without undue delay and in any event within one month of receipt of the request."

This means:

The "corresponding date" rule is where most miscalculations happen. You count to the same date in the following month — not by adding 30 or 31 days. When that date doesn't exist (there is no February 31), the deadline is the last day of the shorter month. Get into the habit of thinking in dates, not day counts, and a whole class of errors disappears.

What Counts as "Receipt"?

The clock does not wait for the request to reach the right desk. A DSAR is "received" the moment it arrives anywhere in your organisation, through any channel, in the hands of any employee. A request typed into a live-chat window, mentioned to a support agent, or emailed to a general info@ inbox counts from that moment — not from the day it was finally forwarded to your privacy team.

This is why intake matters as much as processing. If a request sits unrecognised in a shared mailbox for ten days, you have not gained ten days — you have lost them. Train front-line staff to recognise and escalate requests immediately, and log the true date of first contact.

When Can You Extend the Deadline?

The GDPR allows a two-month extension (for a total of three months) when requests are "complex or numerous." However, you must:

  1. Notify the data subject within the first month that you need more time
  2. Explain why the extension is necessary
  3. Document your reasoning — regulators will scrutinize vague justifications

Simply being busy or under-resourced is not a valid reason for extension. The complexity must relate to the request itself — for example, if the data subject's information is spread across dozens of interconnected systems.

Common Mistakes That Trigger Complaints

1. Counting From the Wrong Day

The clock starts the day after receipt, not on the day of receipt. If you receive a DSAR on March 1, day one of your countdown is March 2.

2. Ignoring Identity Verification Time

You may request identity verification before processing a DSAR. However, the deadline clock does not pause during verification. If verification takes two weeks, you have only two weeks left to fulfill the request.

3. Missing Verbal Requests

Under the GDPR, data subjects can make requests verbally — by phone, in person, or through customer service. If your organization only accepts written DSARs, you may be creating compliance risk.

4. Treating All Requests the Same

Different request types may have different processing requirements. An access request (Article 15) typically requires searching all systems, while a deletion request (Article 17) may require coordination with third-party processors.

5. Asking for Clarification to Buy Time

Where you process a large quantity of information about someone, Article 12 lets you ask the data subject to specify what they are looking for. But treat this narrowly. Asking for clarification does not automatically reset the clock, and regulators view "clarification" used as a delaying tactic dimly. Only genuinely ambiguous, high-volume requests justify it — and even then, you should keep working the request in parallel rather than pausing on it.

Manifestly Unfounded or Excessive Requests

Article 12(5) gives you a narrow release valve. Where a request is "manifestly unfounded or excessive" — for instance, repetitive requests submitted purely to disrupt — you may either charge a reasonable fee or refuse to act. Two cautions apply:

Refusing a request you cannot defend is riskier than answering it. When in doubt, respond.

How Different Jurisdictions Compare

While the GDPR provides one calendar month, other privacy laws have different deadlines:

Law Deadline Extension
GDPR (EU) 1 calendar month +2 months
UK GDPR 1 calendar month +2 months
CCPA (California) 45 calendar days +45 days
VCDPA (Virginia) 45 calendar days +45 days
CPA (Colorado) 45 calendar days +15 days

For organizations operating across multiple jurisdictions, tracking these varying deadlines manually is a recipe for missed deadlines and regulatory exposure. Each law also counts its clock differently — calendar days versus business days, from receipt versus from verification — so a single internal "just respond within a month" rule quietly breaks the moment a request lands under a different regime. For a full breakdown, see our DSAR response deadlines by jurisdiction comparison.

Not sure of a specific deadline? Our free DSAR Deadline Calculator works out the exact due date for a request — accounting for the corresponding-date rule, weekends, and public holidays — so you are not counting on your fingers under pressure.

Proving You Met the Deadline

Calculating the deadline correctly is step one. Proving you met it is step two. Regulators don't just ask whether you responded on time — they ask for evidence:

Without timestamped, tamper-proof records, your compliance assertion is just a claim. With cryptographic evidence capture, it becomes verifiable proof.

Key Takeaways

  1. One calendar month from the day after receipt — not 30 days
  2. Extensions require notification within the first month
  3. Identity verification does not pause the deadline clock
  4. Verbal requests count under the GDPR
  5. Document everything — regulators want evidence, not promises

Getting DSAR deadlines right is foundational to privacy compliance. But tracking deadlines across jurisdictions, capturing evidence, and generating audit-ready reports shouldn't require spreadsheets and calendar reminders.

Stay ahead of privacy regulations

Get compliance insights delivered to your inbox — new regulations, enforcement actions, and practical tips.

We respect your privacy. Privacy Policy

Related articles

Professional choosing between a payment card and a two-option consent screen on a laptop in a café
GDPR6 min read

Consent or Pay: Are 'Pay-or-Okay' Cookie Walls Legal in 2026?

Are 'pay-or-okay' cookie walls legal under GDPR in 2026? What the EDPB opinion on consent-or-pay models means for your site.

Contract files, encrypted drive, and cable crossing a relief map between Europe and North America
GDPR7 min read

International Data Transfers Under GDPR: The 2026 Guide to DPF, SCCs, and TIAs

How EU data transfers really work in 2026: the Data Privacy Framework, SCCs, transfer impact assessments, and where the real GDPR risk sits.

Analytics dashboard, EU data map, and consent gate for GDPR-compliant tracking
GDPR6 min read

Google Analytics and GDPR in 2026: Is GA4 Legal in the EU?

Is Google Analytics 4 legal under GDPR in 2026? Where GA4 stands after the EU-US Data Privacy Framework, what still creates risk, and how to check.

Track real GDPR enforcement actions

Monitor fines from 30+ European data protection authorities. Understand what violations get penalized and benchmark your risk.

Browse Enforcement Actions