How Long Do You Have to Respond to a DSAR? GDPR Deadlines Explained
The GDPR DSAR deadline is one month — but the clock can pause, and complex requests can be extended. Here's exactly how the timing works, with regulator references.
Missing a Data Subject Access Request deadline is one of the most common — and most avoidable — GDPR failures. The rules are not complicated, but they have a few details that trip organisations up. Here’s exactly how the timing works.
The short answer: one month
Under Article 12(3) of the GDPR, you must respond to an access request without undue delay and at the latest within one month of receipt. The Irish Data Protection Commission and the UK ICO both confirm this one-month baseline (Irish DPC, ICO).
“One month” generally means the corresponding calendar date in the following month. If there’s no corresponding date (for example, a request received on 31 January), the deadline is the last day of the next month.
When the clock can be extended
You can extend the deadline by a further two months — giving you three months in total — where the request is complex or you have received a number of requests from the individual (Article 12(3)).
But there are conditions:
- You must tell the requester about the extension within the first month.
- You must explain why the extension is necessary.
- Complexity must be genuine — high volume alone isn’t automatically “complex.”
The EDPB Guidelines 01/2022 on the right of access set out the structured steps controllers should follow, including how to handle complex requests.
When the clock can pause (“stop the clock”)
There are two situations where the one-month period does not start, or pauses, until you receive what you need:
Identity verification. Where you have reasonable doubts about the requester’s identity, Article 12(6) lets you ask for additional information to confirm it. The ICO’s guidance explains that the timescale does not begin until you have received that information — though you should request it promptly (ICO — right of access).
Clarification. Where you process a large amount of information about the individual, you may ask them to clarify the scope of their request. The clock can pause while you reasonably wait for that clarification.
You cannot use these to stall. Requests for ID or clarification must be genuine, prompt, and proportionate.
Free of charge — with narrow exceptions
Access requests must normally be handled free of charge (Article 12(5)). You may only charge a reasonable fee, or refuse, where a request is manifestly unfounded or excessive — and the burden is on you to demonstrate that it is.
Why deadlines slip — and how to stop it
In practice, deadlines are missed for mundane reasons: the request landed in a shared inbox and wasn’t logged, no one calculated the due date, the search took longer than expected, or the extension notice was sent too late. Every one of these is a process problem, not a legal grey area.
A structured DSAR process fixes them by making the timeline visible and automatic.
How SAR Portal keeps you on time
SAR Portal is a controller-side DSAR management platform that builds the statutory timeline into every case:
- The clock starts on receipt. Each case records its received date, so the one-month period is anchored to a fact, not a guess.
- The due date is calculated for you and shown on the case, so nothing relies on someone remembering to count.
- Extensions are tracked — the platform records when an extension was applied so you can evidence that you notified the requester in time.
- Identity verification is captured on the case (email OTP, portal token, manual review, ID document, or knowledge-based), giving you a clear record of when and how the clock legitimately paused.
- The full audit trail records each key action with a default seven-year retention, so you can prove you met the deadline if you’re ever challenged.
See how the workflow fits together on our How It Works page.
Frequently asked questions
Is the DSAR deadline 30 days or one calendar month? It’s one calendar month, not a fixed 30 days. The deadline is the corresponding date in the next month.
Can I always take three months? No. Three months is only available for genuinely complex requests or where you’ve received a number of requests, and only if you notify the requester within the first month and explain why.
Does asking for ID reset the clock? Where you have reasonable doubts about identity, the period doesn’t run until you receive the information you reasonably need — but you must ask promptly and proportionately.
Related guides:
- Received a GDPR Data Access Request? — What you must do in one month
- What Happens If You Ignore a DSAR? — The consequences
- GDPR DSAR Response Checklist — Step-by-step checklist
Never miss a DSAR deadline again. SAR Portal calculates and tracks every due date for you. Start a free trial or see how it works.
Sources
- EDPB — Guidelines 01/2022 on the right of access
- Irish Data Protection Commission — The Right of Access
- UK ICO — Right of access guidance
Ready to simplify your DSAR process?
SAR Portal automates GDPR compliance with AI-powered redaction, deadline tracking, and audit trails.
Related Articles
Are DSAR Portals Good or Bad? The Real Question Is Who Controls the Process
Not all DSAR portals are the same. Learn the difference between third-party …
GDPR Data Residency: Why Where Your DSAR Data Is Hosted Matters
DSAR responses are full of sensitive personal data. Where that data is hosted — …
DSAR Identity Verification: How to Verify a Requester Without Breaching GDPR
Verifying a DSAR requester's identity protects against data breaches — but …