GDPR / DSAR Response Deadline
Data subject access request response deadline.
Written and maintained by Paul Clark, Redmoon Software · Rules last verified · Sources
These calculators are for informational purposes only and do not constitute legal, financial, or professional advice.
How the GDPR / DSAR Response Deadline works
The GDPR / DSAR Response Deadline calculator finds the date by which you must respond to a data subject access request under the GDPR. The baseline is "one month" from receipt — but a month is not 30 days, and the calculator applies the rule the regulators actually use.
Under the GDPR the period runs to the corresponding date in the next month, and it can be extended by up to two further months for complex or numerous requests. Getting day zero and the month-boundary handling right is what keeps a response defensibly on time.
Worked example
A request received on 31 January is due by 28 February (29 in a leap year), because there is no 31 February — the deadline lands on the last day of the next month. A request received on 15 March is due 15 April.
Frequently asked questions
Is the DSAR deadline one month or 30 days?
One calendar month, running to the corresponding date in the following month — not a flat 30 days. Where that date does not exist, it falls on the last day of the month.
Can the deadline be extended?
Yes. For complex or multiple requests the period can be extended by up to two further months, provided you tell the requester within the first month and explain why.
When does the clock start?
On the day the request is received. The calculator lets you set that receipt date explicitly so day zero is never in doubt.
The request came in through our support inbox and sat there for a week. When was it due?
One month from the day it was received by the organisation, not from the day the privacy team saw it. A request does not have to use the words "subject access request", cite the GDPR, or arrive through a designated channel — it can be made verbally, to anyone. This is the most common reason a response goes late, and the fix is to log receipt at the point of receipt across every channel a request could arrive through.
Can we stop the clock while we verify who the requester is?
Only where you have reasonable doubts about their identity, and only until you receive what you asked for. It is not a routine step. Demanding identity documents from someone writing in from an authenticated account is hard to justify, and it creates a data-minimisation problem of its own.
What this calculator does not do
A limitation you know about costs far less than one you find after the deadline. These are the specific things this tool cannot work out for you.
- The extension is not automatic. You must tell the requester within the first month that you are extending, and why — the calculator shows the date, not the notification obligation that unlocks it.
- It does not decide whether a request is manifestly unfounded or excessive, which is the other route to refusing or charging for it.
- UK GDPR runs the same one-month clock but is administered separately by the ICO; the date is the same, the regulator is not.
Where these rules come from
The periods this calculator applies are taken from the primary sources below rather than from secondary summaries. Verify against them before relying on a date that matters.
- Regulation (EU) 2016/679 (GDPR), Article 12(3)
One month to respond, extendable by two further months where the request is complex or numerous.
- EDPB guidance on data subject rights — access
How supervisory authorities read "without undue delay" and the calendar-month calculation.