Deadline guide · 8 min read

DSAR deadline: what the one-month clock means in practice

The short answer: act without undue delay and generally within one month. The useful answer is an operating plan that protects review time, records any extension and never confuses Trace’s 24-hour preparation target with the legal deadline.

How long do you have to respond to a DSAR?

Under GDPR Article 12, a controller must act on an access request without undue delay and at the latest within one month of receipt. Where requests are complex or numerous, that period may be extended by two further months, provided the requester is informed of the reasons within the first month.

The direct answer

What is the GDPR deadline for a DSAR?

GDPR Article 12(3) says the controller must provide information on action taken on a request under Articles 15 to 22 without undue delay and in any event within one month of receiving the request. Where necessary, that period may be extended by two further months, taking account of the complexity and number of requests. If the controller extends, it must inform the individual within one month of receipt and give reasons for the delay.

Read the exact wording in Article 12 GDPR and the European Data Protection Board’s deadline explanation. The EDPB also notes that “one month” is not simply a fixed 30-day period.

Do not translate “one month” into “30 days” by default. Calendar calculation and any applicable national procedural rules should be checked for the case. Your workflow should store the received timestamp, calculated target and person who verified it.

Does acknowledgement stop the clock?

An acknowledgement is useful operationally, but Article 12 does not turn it into a replacement deadline. The case should continue moving while scope, identity and sources are clarified. If a timing issue may affect the legal calculation, route it to qualified review rather than silently shifting the target.

Is an extension automatic for a difficult stack?

No. The Article 12 wording makes the extension conditional on necessity, taking account of complexity and number of requests, and requires timely notice with reasons. Six internal systems do not create a blanket extension rule. Record the facts and the authorised decision.

Build review time in

An internal deadline plan.

The statutory limit is the outer framework, not the day to begin assembling the response. Set earlier operational targets and keep them visible in the case.

RECEIPT / SAME DAY

Preserve and route

Record the original request, channel, timestamp, requester details and accountable case owner. Do not wait for a perfect classification.

TRIAGE / EARLY

Confirm right, identity and scope

Identify what is being exercised, whether there is reasonable identity doubt and which entities or products are implicated.

DISCOVERY / EARLY

Freeze the source map

List systems, identifiers, owners, access paths and known gaps while there is still time to escalate missing sources.

ASSEMBLY / BUFFERED

Retrieve and normalise

Collect evidence with provenance. Preserve enough buffer for incomplete exports, re-runs and cross-system reconciliation.

REVIEW / PROTECTED

Reserve human judgement

Give the authorised reviewer time for third-party information, applicable limitations, response language and secure delivery.

DELIVERY / RECORDED

Respond and evidence

Record what was sent, when, through which channel, under whose approval and what case data is retained.

If more time may be necessary

The extension needs its own evidence.

A controlled case should not show only a new date. It should record:

  • the facts creating complexity or the relevant number of requests;
  • the person authorised to decide on the extension;
  • the original receipt time and the first-month notification target;
  • the reasons communicated to the individual;
  • the delivery channel and evidence of the notice; and
  • the revised target and remaining operational milestones.

This record supports review. It does not itself make the extension valid; that remains a legal conclusion for the controller.

What if the organisation will not act?

Article 12(4) requires the controller to inform the individual without delay and at the latest within one month of receipt about the reasons for not taking action and the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy. The exact response should receive qualified review.

Trace product truth

Twenty-four hours and one month are different clocks.

Trace proposes to prepare a review-ready pack within 24 hours for an accepted, in-scope pilot request after required access is available. It does not promise that every request can be legally completed in 24 hours.

The pack target covers operational preparation: classification, identity state, source inventory, available evidence, response draft, open decisions and event timeline. Authorised human review, identity follow-up, source outages, legal questions and customer approval may take longer.

Before a live pilot, the start condition, supported sources, reviewer capacity and exceptions must be agreed in writing.

Official EU references

Sources used for legal statements.

Editorial method: legal statements are paraphrased from official EU materials. Operational recommendations are Trace commentary and should be adapted with qualified legal and security review.

A controlled first request

Protect review time before the deadline becomes urgent.

Trace’s proposed concierge pilot starts with the source map, case owner and one accepted request. No live personal data should be sent through the public application.