DSAR Deadline Calculator
Calculate the response deadline for a data subject access request under GDPR, UK GDPR, CCPA, LGPD, PIPL and other regimes, including whether an extension applies and how the clock is counted.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
The clock starts on receipt, not on recognition
The most common way organisations miss a response deadline is by starting the count when the request reaches the privacy team rather than when it reached the organisation. Under the GDPR the period runs from receipt of the request, which means the day a support agent read it in a shared inbox, not the day it was escalated. An identity verification step does not stop the clock either, though a genuine and proportionate request for identification can pause it under some regimes.
Calendar days, months, and business days are all used
The regimes do not agree on how to count. The GDPR uses one month, which under Regulation 1182/71 means the same numbered day of the following month, rolling forward to the next working day if it falls on a weekend or public holiday, and to the last day of the month when that number does not exist. The CCPA uses 45 calendar days. Others use business days. Applying the wrong counting rule to the right period produces a date that is wrong by several days, which is more than enough to matter.
Extensions are conditional and must be communicated
The GDPR permits a two-month extension for complex or numerous requests, but only if the data subject is told within the original month, together with the reasons. An extension taken silently is a missed deadline. The CCPA similarly allows a 45-day extension with notice. This tool shows both the base deadline and the extended one, and the date by which the extension notice itself must be sent, because that intermediate date is the one usually forgotten.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
When does the deadline start running?
From receipt by the organisation, not by the privacy team. A request read in a shared support inbox has been received, even if it was escalated a week later.
How is "one month" counted under the GDPR?
As the same numbered day of the following month, per Regulation 1182/71. If that day does not exist, the period ends on the last day of the month, and if it falls on a weekend or public holiday it rolls to the next working day.
Does verifying identity pause the clock?
Under some regimes a genuine and proportionate identity request can pause it, but the pause is not automatic and does not apply merely because verification is in progress internally. Treat the original date as the deadline unless you have a documented basis to pause.
When must an extension be notified?
Within the original period, together with the reasons for it. An extension taken without telling the data subject inside the first month is simply a missed deadline.
Is this legal advice?
No. It applies the counting rules published in each regime to the dates you enter. Whether a particular request qualifies for an extension, or which law applies, is a legal question this tool cannot answer.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter the date the request was received and select the applicable law.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.