Compliance

DSAR Deadline Calculator

Calculate the response deadline for a data subject access request under GDPR, UK GDPR, CCPA, LGPD, PIPL and other regimes, including whether an extension applies and how the clock is counted.

Last reviewed by the Radiatus Cloud team

Deadlines appear here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

The clock starts on receipt, not on recognition

The most common way organisations miss a response deadline is by starting the count when the request reaches the privacy team rather than when it reached the organisation. Under the GDPR the period runs from receipt of the request, which means the day a support agent read it in a shared inbox, not the day it was escalated. An identity verification step does not stop the clock either, though a genuine and proportionate request for identification can pause it under some regimes.

Calendar days, months, and business days are all used

The regimes do not agree on how to count. The GDPR uses one month, which under Regulation 1182/71 means the same numbered day of the following month, rolling forward to the next working day if it falls on a weekend or public holiday, and to the last day of the month when that number does not exist. The CCPA uses 45 calendar days. Others use business days. Applying the wrong counting rule to the right period produces a date that is wrong by several days, which is more than enough to matter.

Extensions are conditional and must be communicated

The GDPR permits a two-month extension for complex or numerous requests, but only if the data subject is told within the original month, together with the reasons. An extension taken silently is a missed deadline. The CCPA similarly allows a 45-day extension with notice. This tool shows both the base deadline and the extended one, and the date by which the extension notice itself must be sent, because that intermediate date is the one usually forgotten.

Related tools

Frequently Asked Questions

When does the deadline start running?

From receipt by the organisation, not by the privacy team. A request read in a shared support inbox has been received, even if it was escalated a week later.

How is "one month" counted under the GDPR?

As the same numbered day of the following month, per Regulation 1182/71. If that day does not exist, the period ends on the last day of the month, and if it falls on a weekend or public holiday it rolls to the next working day.

Does verifying identity pause the clock?

Under some regimes a genuine and proportionate identity request can pause it, but the pause is not automatic and does not apply merely because verification is in progress internally. Treat the original date as the deadline unless you have a documented basis to pause.

When must an extension be notified?

Within the original period, together with the reasons for it. An extension taken without telling the data subject inside the first month is simply a missed deadline.

Is this legal advice?

No. It applies the counting rules published in each regime to the dates you enter. Whether a particular request qualifies for an extension, or which law applies, is a legal question this tool cannot answer.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter the date the request was received and select the applicable law.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.