Skip to main content

Understanding DSAR response timelines

Know how long you have to respond to Data Subject Access Requests (DSARs) under GDPR.

Updated over 3 weeks ago

1️⃣ What Is a DSAR?

A Data Subject Access Request (DSAR) is when an individual asks to access, correct, delete, or restrict their personal data.
Under Articles 12–15 of the GDPR, your business must respond within a defined timeframe — even if the request seems simple or informal.


2️⃣ Standard Response Timeline

Action

Timeframe

Details

Acknowledge receipt

Within 7 days

Confirm that you’ve received the request and, if needed, ask for ID verification.

Provide full response

Within 1 month

Send the requested data or confirm the action taken (e.g., rectification or erasure).

Extension (if needed)

+ 1 month (maximum 2 months total)

Only allowed for complex or multiple requests. You must inform the requester within the first month.

💡 Tip: The one-month period starts on the day you receive the request, not when you verify identity — so act quickly.


3️⃣ When You Can Extend or Refuse

You can extend or decline a DSAR only when:

  • The request is manifestly unfounded or excessive, or

  • Responding would affect another person’s rights.

If you refuse or delay:

  • Inform the requester within one month,

  • Explain the reason, and

  • Tell them they can complain to the relevant Data Protection Authority.


4️⃣ How Euverify Helps You Stay on Time

When a DSAR arrives via your Secure Request Portal, Euverify:

  • Automatically logs the received date

  • Calculates and displays your response deadline

  • Sends email reminders before the one-month expiry

  • Keeps a timeline record of actions for audit purposes


✅ Summary

Requirement

Timeline

Acknowledge receipt

7 days

Full response

1 month

Possible extension

+ 1 month (for complex cases)

Notify of refusal or delay

Within 1 month

Did this answer your question?