Last updated: 26 September 2026
Quick answer: The DSAR response time is one month under the EU GDPR and UK GDPR, extendable by two further months for complex or numerous requests. In the US, the CCPA allows 45 calendar days plus a 45-day extension, most other state privacy laws follow a similar 45-day model, and HIPAA gives covered entities 30 days plus one 30-day extension.
Data subject access requests arrive by email, web form, chat and sometimes a letter to the CEO. Whatever the channel, the clock starts running when the request lands, and a missed deadline gives the individual grounds to complain to the regulator.
If you are new to access requests, start with our explainer on what a DSAR is. This guide compares DSAR response time rules in the EU, the UK and the US, explains when you can extend or pause the clock, and gives you a worked example and a process checklist. It is written for DPOs and privacy teams handling requests across more than one jurisdiction.
DSAR response time at a glance: EU vs UK vs US
The core deadline is one month in Europe and 45 days under most US state privacy laws, but the rules for extensions, acknowledgements and pauses differ. The table summarises the main regimes.
| Regime | Standard deadline | Extension | Other timing rules |
|---|---|---|---|
| EU GDPR | Without undue delay and within one month of receipt | Up to two further months, for complexity or number of requests | Tell the individual about any extension, with reasons, within the first month |
| UK GDPR | Without undue delay and within one month of receipt | Up to two further months if complex or you receive a number of requests | Clock can pause while you seek clarification; starts once requested ID or fee is received |
| California (CCPA) | 45 calendar days | Additional 45 calendar days with notice and explanation | Confirm receipt within 10 business days; opt-out requests within 15 business days |
| Virginia (VCDPA) | 45 days | 45 additional days when reasonably necessary | Appeal decisions within 60 days |
| HIPAA (health data) | 30 days | One extension of up to 30 days, with written notice | Applies to covered entities and protected health information |
What is the DSAR response time under the EU GDPR?
Under the EU GDPR you must respond without undue delay and in any event within one month of receipt of the request. The one-month limit is a maximum, not a target.
Article 12(3) of the General Data Protection Regulation sets the deadline for acting on requests under Articles 15 to 22, which covers access as well as rectification, erasure, restriction, portability and objection. The same article allows an extension of two further months where necessary, taking into account the complexity and number of requests. You must tell the individual about the extension, and the reasons for the delay, within one month of receiving the request.
If you decide not to act on a request, Article 12(4) requires you to tell the individual without delay, and at the latest within one month, why you are not taking action and that they can complain to a supervisory authority or seek a judicial remedy.
The EDPB Guidelines 01/2022 on the right of access confirm that the date the controller receives the request triggers the one-month period as a rule, and that requests for extra identification information should not unnecessarily delay the response.
Common mistake: treating the two-month extension as automatic. It is only available where the request is genuinely complex or you have received a number of requests, and you must explain why within the first month.
How does the UK handle DSAR deadlines?
The UK GDPR keeps the same one-month limit and two-month extension, but UK guidance is more explicit about when the clock starts and pauses. The Information Commissioner’s Office (ICO) is the regulator to follow.
The ICO’s guide to subject access says you must respond without undue delay and within one month of receipt. Key points include:
- Identity and fees: if you need information to confirm identity, or a fee where one is allowed, the time limit does not start until you receive it.
- Clarification: if you ask for clarification, the one-month limit pauses on the day you ask and resumes the day after you receive it.
- Extensions: you may extend by up to a further two months if the request is complex or you receive a number of requests, and you must tell the person and explain why within one month.
- Searches: you must make a reasonable and proportionate search, but you do not need to carry out searches that are unreasonable or disproportionate.
The Data (Use and Access) Act 2025, which received Royal Assent in June 2025, has put these points on a statutory footing. Section 78, which confirms that individuals are only entitled to information found through a reasonable and proportionate search, came into force at Royal Assent and is treated as having come into force on 1 January 2024. Most of the Act’s other data protection changes, including the statutory stop-the-clock rule, took effect on 5 February 2026, and the ICO updated its subject access guidance in July 2026 to reflect them. Since 19 June 2026, controllers have also needed a process for handling data protection complaints, including acknowledging them within 30 days.
In practice: only pause the clock when you genuinely need clarification to find the information, for example because you hold a large amount of data about the person. Asking for clarification by default is likely to be challenged.
What are the DSAR response times in the US?
There is no single US federal access right for consumer data. Deadlines come from state privacy laws and from sector rules such as HIPAA.
California: CCPA
The California Attorney General’s CCPA guidance says businesses must respond to requests to know and delete within 45 calendar days, and may extend by another 45 days (90 days in total) if they notify the consumer. The CCPA regulations add that businesses must confirm receipt of a request to delete, correct or know within 10 business days and explain how they will process it. Requests to opt out of sale or sharing must be handled as soon as feasibly possible and within 15 business days.
Other state privacy laws
Many state comprehensive privacy laws follow a similar model. Virginia’s Consumer Data Protection Act, for example, requires controllers to respond within 45 days of receipt, allows a 45-day extension when reasonably necessary, and requires a written response to an appeal within 60 days (Va. Code 59.1-577). Always check the specific state law, because appeal rights and verification rules vary.
Health data: HIPAA
Under the HIPAA Privacy Rule, 45 CFR 164.524 requires covered entities to act on a request for access no later than 30 days after receipt. If they cannot, they may extend once by up to 30 days, provided they give the individual a written statement of the reasons and the expected completion date within the original 30 days.
If you handle requests in several states, a single workflow with configurable deadlines is far easier than tracking each law separately. Start your 14-day free trial to see how jurisdiction-specific timers work in practice.
Worked example: calculating the deadline
Suppose a customer who lives in France, another in the UK and a third in California each submit an access request on 10 March.
| Scenario | Initial deadline | If extended |
|---|---|---|
| EU GDPR, no ID check needed | 10 April | 10 June, if you notify the extension and reasons by 10 April |
| UK GDPR, ID requested and received on 15 March | 15 April, as the clock starts when ID is received | 15 June, if justified and notified within the first month |
| CCPA, request to know | Receipt confirmed within 10 business days; response 45 calendar days after receipt, on 24 April | 90 days after receipt, on 8 June, with notice to the consumer |
Month-end dates and public holidays can shift deadlines, so agree an internal calculation rule with your legal team and apply it consistently. Many teams simply set an internal target well inside the legal limit.
How to meet DSAR deadlines every time
Deadlines are easiest to lose at intake and search, not at the final response. This checklist covers the steps that make the biggest difference.
- Log every request on the day it arrives, whichever channel it comes through, and record the jurisdiction.
- Train front-line staff to recognise requests that do not use the words “subject access request”.
- Verify identity proportionately and quickly, asking only for what you need.
- Map where personal data lives so searches are fast. Your GDPR compliance records of processing are a good starting point.
- Set automatic reminders for acknowledgement, extension notice and final deadlines per jurisdiction.
- Review third-party data and exemptions before disclosure, and document redaction decisions.
- Keep an audit trail of every step, so you can demonstrate compliance if a complaint follows.
A dedicated data subject and consumer request management workflow brings these steps together. For US-specific requirements, see our overview of CCPA compliance, and for pitfalls that often lead to complaints, read our article on common mistakes in GDPR compliance.
Key takeaways
- EU and UK GDPR: one month, extendable by two further months with reasons given within the first month.
- UK guidance lets you pause the clock for genuine clarification and starts it once requested ID or fees are received.
- CCPA: confirm within 10 business days and respond within 45 calendar days, extendable by 45 days.
- HIPAA: 30 days with one 30-day extension for access to protected health information.
- Fast intake, data mapping and jurisdiction-aware reminders prevent most missed deadlines.
Frequently asked questions
When does the DSAR clock start?
Under the EU and UK GDPR, the clock generally starts on the day you receive the request. In the UK, if you reasonably need information to confirm identity, or a permitted fee, the time limit starts when you receive it. Under the CCPA, the 45-day period runs from receipt of the request, regardless of the time needed to verify it.
Can I extend the DSAR deadline because my team is busy?
No. Under the EU and UK GDPR, an extension is only allowed where necessary because the request is complex or you have received a number of requests from the individual. Staff shortages or holidays are not valid reasons. You must tell the individual about the extension and explain why within the first month.
Does the DSAR response time include weekends?
Yes. The GDPR deadline is expressed in months, and the CCPA response deadline is in calendar days, so weekends count. The CCPA acknowledgement deadline of 10 business days and the opt-out deadline of 15 business days are exceptions. Where a deadline falls on a weekend or public holiday, follow your regulator’s guidance and your agreed internal rule.
What happens if we miss a DSAR deadline?
The individual can complain to the supervisory authority, such as the ICO in the UK or a national data protection authority in the EU, and may seek a court remedy. Regulators can issue reprimands, orders and fines. In the US, state attorneys general and, in California, the California Privacy Protection Agency can enforce the CCPA.
Do the same deadlines apply to deletion and correction requests?
Under the EU and UK GDPR, the one-month limit in Article 12(3) applies to all data subject rights under Articles 15 to 22, including erasure and rectification. Under the CCPA, the 45-day deadline applies to requests to know, delete and correct, while opt-out requests have a shorter 15 business day limit.
Conclusion: build one process, many clocks
The DSAR response time differs between the EU, the UK and US states, but the work behind a good response is the same: fast intake, proportionate verification, efficient searches and a clear audit trail. Build one process, attach the right deadline to each jurisdiction and track it from the moment a request arrives. Enactia’s AI-powered GRC platform supports this across GDPR, UK GDPR, CCPA and other privacy laws.
To discuss your DSAR process, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
