Deadline guide · 8 min read
DSAR deadline: what the one-month clock means in practice
The short answer: act without undue delay and generally within one month. The useful answer is an operating plan that protects review time, records any extension and never confuses Trace’s 24-hour preparation target with the legal deadline.
How long do you have to respond to a DSAR?
Under GDPR Article 12, a controller must act on an access request without undue delay and at the latest within one month of receipt. Where requests are complex or numerous, that period may be extended by two further months, provided the requester is informed of the reasons within the first month.
The direct answer
What is the GDPR deadline for a DSAR?
GDPR Article 12(3) says the controller must provide information on action taken on a request under Articles 15 to 22 without undue delay and in any event within one month of receiving the request. Where necessary, that period may be extended by two further months, taking account of the complexity and number of requests. If the controller extends, it must inform the individual within one month of receipt and give reasons for the delay.
Read the exact wording in Article 12 GDPR and the European Data Protection Board’s deadline explanation. The EDPB also notes that “one month” is not simply a fixed 30-day period.
Do not translate “one month” into “30 days” by default. Calendar calculation and any applicable national procedural rules should be checked for the case. Your workflow should store the received timestamp, calculated target and person who verified it.
Does acknowledgement stop the clock?
An acknowledgement is useful operationally, but Article 12 does not turn it into a replacement deadline. The case should continue moving while scope, identity and sources are clarified. If a timing issue may affect the legal calculation, route it to qualified review rather than silently shifting the target.
Is an extension automatic for a difficult stack?
No. The Article 12 wording makes the extension conditional on necessity, taking account of complexity and number of requests, and requires timely notice with reasons. Six internal systems do not create a blanket extension rule. Record the facts and the authorised decision.
Build review time in
An internal deadline plan.
The statutory limit is the outer framework, not the day to begin assembling the response. Set earlier operational targets and keep them visible in the case.
Preserve and route
Record the original request, channel, timestamp, requester details and accountable case owner. Do not wait for a perfect classification.
Confirm right, identity and scope
Identify what is being exercised, whether there is reasonable identity doubt and which entities or products are implicated.
Freeze the source map
List systems, identifiers, owners, access paths and known gaps while there is still time to escalate missing sources.
Retrieve and normalise
Collect evidence with provenance. Preserve enough buffer for incomplete exports, re-runs and cross-system reconciliation.
Reserve human judgement
Give the authorised reviewer time for third-party information, applicable limitations, response language and secure delivery.
Respond and evidence
Record what was sent, when, through which channel, under whose approval and what case data is retained.
If more time may be necessary
The extension needs its own evidence.
A controlled case should not show only a new date. It should record:
- the facts creating complexity or the relevant number of requests;
- the person authorised to decide on the extension;
- the original receipt time and the first-month notification target;
- the reasons communicated to the individual;
- the delivery channel and evidence of the notice; and
- the revised target and remaining operational milestones.
This record supports review. It does not itself make the extension valid; that remains a legal conclusion for the controller.
What if the organisation will not act?
Article 12(4) requires the controller to inform the individual without delay and at the latest within one month of receipt about the reasons for not taking action and the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy. The exact response should receive qualified review.
Trace product truth
Twenty-four hours and one month are different clocks.
Trace proposes to prepare a review-ready pack within 24 hours for an accepted, in-scope pilot request after required access is available. It does not promise that every request can be legally completed in 24 hours.
The pack target covers operational preparation: classification, identity state, source inventory, available evidence, response draft, open decisions and event timeline. Authorised human review, identity follow-up, source outages, legal questions and customer approval may take longer.
Before a live pilot, the start condition, supported sources, reviewer capacity and exceptions must be agreed in writing.
Official EU references
Sources used for legal statements.
- EUR-Lex — Regulation (EU) 2016/679, Article 12
- European Data Protection Board — How long do I have to respond to an access request?
- European Commission — Dealing with requests to exercise data-protection rights
Editorial method: legal statements are paraphrased from official EU materials. Operational recommendations are Trace commentary and should be adapted with qualified legal and security review.