GDPR DSAR Response Time: How Long Do You Have?

Table of Contents

If your business processes personal data covered by the General Data Protection Regulation, knowing exactly how long you have to respond to a data subject access request is not optional knowledge. Missing the response window can trigger regulatory penalties, and the deadline starts running the moment a request lands in your inbox, not when you get around to reviewing it.

Given the complexity of some DSARs, fulfilling a request within the required window can be genuinely difficult. Whether your business is new to handling DSARs or looking to tighten up an existing process, this guide walks through exactly what the GDPR requires, how the CCPA and its 2023 amendment under the CPRA compare, and what it actually takes to respond on time.

We will cover the specific response deadlines under both frameworks, where the CPRA changed the rules businesses were used to under the original CCPA, practical ways to shorten your response time, and what happens if you miss the deadline.

Let’s get into it.

Key Takeaways

The GDPR requires a response to any DSAR within one calendar month of receipt, extendable by up to two additional months for complex or numerous requests. The CCPA, as amended by the CPRA, requires a response within 45 days, with one 45-day extension available when reasonably necessary, for a maximum of 90 days.

The CPRA did not change the CCPA’s response timeline, but it did change what businesses are responding to. It added the right to correct inaccurate personal information and the right to limit the use of sensitive personal information, both of which businesses must be able to fulfill within the same deadline as an access or deletion request, and it removed the original 12-month lookback limit on the right to know for data collected on or after January 1, 2022.

On average, businesses with a functioning process take about two weeks to respond to a DSAR. Response time is most affected by how fragmented your data is across systems, how much manual labor the request requires, and how long final legal review takes.

You can meaningfully shorten DSAR response time by streamlining internal workflows, using dedicated DSAR software, training staff on the current requirements, and working with compliance specialists like Captain Compliance.

GDPR DSAR Response Time

GDPR DSAR Response Time (1).jpg

Article 12 of the GDPR requires that any organization receiving a data subject access request under Article 15 respond without undue delay, and in any event no later than one month after receiving it, a period that can be extended by up to two additional months where necessary, taking into account the complexity and number of requests.

The calendar month begins on the day your business receives the request, not the day you begin processing it. The UK’s Information Commissioner’s Office publishes detailed guidance on how to calculate this deadline correctly.

For example, a request received on April 15 must be fulfilled by midnight on May 15.

If the corresponding date doesn’t exist in the following month, for example a request received on March 31, the deadline falls on the last day of the following month instead, so you would have until April 30 at midnight.

If the calculated deadline lands on a weekend or public holiday, your business has until the next working day. A request received on November 25, for instance, would ordinarily fall due on December 25, so the deadline shifts to the next business day.

The ICO permits an extension of up to two additional months under a few specific circumstances:

The request is complex and genuinely requires more time to fulfill

You need to request additional information from the data subject to locate their data

You need to verify the data subject’s identity before proceeding. (In this case, the one-month clock does not start until identity is confirmed.)

If your business falls under the CCPA rather than the GDPR, the timeline is different, and it’s worth understanding exactly how the CPRA amendments changed what that timeline actually covers.

CCPA vs. CPRA: What Changed for DSAR Response Times

The California Privacy Rights Act took effect operationally on January 1, 2023, amending the original CCPA rather than replacing it. Businesses often ask whether the CPRA changed the response deadline. It didn’t. What it changed was the scope of what businesses now have to be able to respond to within that same deadline.

The response window stayed the same. Businesses subject to the CCPA/CPRA must still respond to a verifiable consumer request within 45 days of receipt, with one permissible 45-day extension when reasonably necessary, for a combined maximum of 90 days. Consumers must be notified of an extension, and the reason for it, within the initial 45-day period.

The scope of requests expanded. The original CCPA gave consumers the right to know, delete, and opt out of sale. The CPRA added the right to correct inaccurate personal information and the right to limit the use and disclosure of sensitive personal information, a new data category the CPRA itself created (covering things like precise geolocation, government ID numbers, and health data, among others). Both of these newer rights carry the same 45-day response requirement as an access or deletion request.

The lookback period changed. Under the original CCPA, businesses could limit a right-to-know response to the 12 months preceding the request. The CPRA removed that cap for personal information collected on or after January 1, 2022, meaning a request received today can require your business to produce records going back further than the old 12-month standard allowed, unless your business has proactively adopted the narrower disclosure option the CPRA still permits in certain cases.

Enforcement changed too. The original CCPA was enforced solely by the California Attorney General. The CPRA created the California Privacy Protection Agency, a dedicated regulator with its own investigative and enforcement authority, running alongside continued AG enforcement. That matters for DSAR compliance specifically, because the CPPA has made operational compliance, including timely request fulfillment, an active area of review rather than a rarely enforced statutory requirement.

The practical takeaway: if your DSAR process was built for the original 2020 version of the CCPA, it is very likely missing the correction and limitation workflows the CPRA requires, and may still be capping disclosures at 12 months when the law no longer allows it.

How Long Does a DSAR Take to Respond to?

How to Shorten the Amount of Time Needed to Respond to a DSAR.png

Actual response time varies widely, but businesses with a mature DSAR process typically fulfill a request in about two weeks, well inside both the GDPR and CCPA/CPRA deadlines. A number of factors determine where a given request falls on that spectrum.

The amount of searching a request requires depends heavily on the data subject, how much personal information your business holds on them, and how many systems that information is scattered across.

Here are the factors that most influence how long a response actually takes:

Data Spread Across Multiple Platforms

Most businesses don’t hold a given data subject’s personal information in one place. It typically lives across a mix of physical records and digital systems, and different categories of data are frequently accessible only through separate tools or platforms that don’t talk to each other.

Locating everything relevant to a single request takes time, and the more categories of data a request touches, the longer that process runs.

Staff Labor Needed

Beyond fragmented data, the people responsible for fulfilling the request are usually stretched thin. It is not unusual for a single DSAR to involve dozens of internal emails and attachments before it’s ready to send.

At many businesses, this responsibility sits with a single data protection officer or compliance lead. Without a dedicated team or budget behind that role, the process can consume a disproportionate amount of time relative to the deadline available.

The last major factor is legal review of the compiled response before it goes out. Most businesses treat this as a standard part of good data practice, not an optional step.

This review is where personal information unrelated to the requester gets redacted or anonymized, and it’s the final check that the response actually satisfies what the applicable law requires, whether that’s the GDPR’s access obligations or the CCPA/CPRA’s expanded set of consumer rights.

Don’t want to manage this process in-house? Captain Compliance can handle it for you. Contact us for a free consultation to see how we keep your business’s data subject requests on schedule.

How to Shorten the Amount of Time Needed to Respond to a DSAR

Data subjects can submit a request at any time, and the deadlines that follow don’t bend for a business that isn’t prepared. Building an efficient response process ahead of time is the difference between a routine two-week turnaround and a scramble against the clock.

Here are the practices that make the biggest difference in response efficiency:

Streamline Internal Processes

The best place to start is optimizing how your business processes a request end to end, before the volume of requests forces the issue.

Set up a clear, documented system for locating and compiling a data subject’s personal information the moment a request comes in.

Standard operating procedures for every department that might hold relevant data, paired with clear escalation channels between departments, remove most of the friction that slows a response down.

Use DSAR Software

Dedicated DSAR software is one of the highest-leverage investments a business can make here, since it automates the discovery and compilation work that otherwise falls entirely on staff. The right platform depends on your business’s specific data footprint, but the time savings scale with the volume of requests you handle.

It also gives your business a concrete way to demonstrate a functioning privacy program, which matters increasingly as regulators like the CPPA treat operational compliance as an active enforcement priority rather than a paperwork exercise.

Employee Training

Training every department that touches DSAR fulfillment, not just your compliance team, on the current requirements under both the GDPR and the CPRA-amended CCPA closes a lot of the gaps that slow requests down. Employees who understand what a correction request or a limitation request actually requires respond faster and make fewer mistakes than those working from an outdated understanding of the CCPA alone.

Collaboration with Compliance Experts

Selecting the right DSAR software and building an effective training program is easier with outside expertise. Captain Compliance offers a full suite of compliance services and brings deep, hands-on experience helping businesses build DSAR processes that hold up under both GDPR and CPRA requirements.

We help businesses implement response protocols and training that reduce turnaround time while keeping every request, including the newer correction and limitation rights under the CPRA, fully compliant.

Consequences of Not Responding to a DSAR in Time

Consequences of Not Responding to a DSAR in Time.jpg

Under the GDPR, regulators can issue fines of up to €20 million or 4% of global annual turnover, whichever is greater, for the most serious violations. Less severe violations are typically capped at €10 million or 2% of annual turnover.

The CCPA, as amended by the CPRA, uses a different structure entirely. The California Privacy Protection Agency and the Attorney General can pursue administrative fines on a per-violation basis. Fines run up to $2,500 per violation, or up to $7,500 per violation where the violation is intentional or involves the personal information of a consumer known to be under 16. Because DSAR fulfillment failures are typically assessed per affected consumer, these amounts can compound quickly across even a modest volume of missed requests.

Beyond regulatory fines, a data subject whose request goes unanswered without valid justification can pursue legal action directly. Civil claims of this kind are not subject to the same statutory caps as regulatory fines and can, in some circumstances, result in penalties well beyond what a regulator would have assessed.

Frequently Asked Questions (FAQs)

What is the GDPR DSAR process?

Under the GDPR, data subjects have the right to access, correct, or request deletion of personal data your business holds about them. They submit a data subject access request, and your business must respond with the requested information within one calendar month of receipt.

Learn which DSAR software is best here!

Can a DSAR be refused?

As a data controller, you may refuse or charge a reasonable fee for a request you can demonstrate is manifestly unfounded or excessive, including requests that are unreasonably repetitive. The GDPR does not define a bright-line test for this, so refusals should be well-documented and applied cautiously.

Get in touch with us for help resolving difficult requests!

Does my business have to respond to DSARs?

If your business qualifies as a controller or processor under the GDPR, or as a business under the CCPA/CPRA, you are legally required to fulfill valid data subject requests within the applicable deadline.

Find out if your business is under the scope of the GDPR here.

What happens if you don’t respond to a DSAR?

Under the GDPR, failing to respond can result in fines of up to €20 million or 4% of global annual turnover, whichever is greater. Under the CCPA/CPRA, unfulfilled requests can draw administrative fines of up to $7,500 per violation, assessed by the CPPA or the Attorney General.

Use our GDPR compliance checklist to avoid these significant fines!

How do I respond to a DSAR?

Compile all personal information covered by the request, verify the requester’s identity, and deliver it securely through the channel agreed with the consumer. Under both the GDPR and the CPRA-amended CCPA, the response must be transparent, complete, and delivered within the applicable statutory window.

Find out how to respond to DSARs here!

Did the CPRA change the DSAR deadline under the CCPA?

No. The 45-day response window, with one available 45-day extension, remains unchanged. What changed is the scope of rights that deadline now covers, including the right to correct and the right to limit use of sensitive personal information, along with the removal of the original 12-month lookback cap for data collected on or after January 1, 2022.

How Can Captain Compliance Help You?

Your business is legally required to respond to data subject access requests within one calendar month under the GDPR, or within 45 days (extendable to 90) under the CCPA as amended by the CPRA. Extensions exist for a reason, but a fast, well-documented response is always the safer position.

Our team at Captain Compliance helps businesses build DSAR processes that hold up under GDPR, CCPA, and CPRA requirements alike, reducing response time while avoiding the fines that come with falling behind.

Get in touch with us today for a complimentary consultation to learn how you can ensure your business’s compliance with all relevant regulations.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.