1️⃣ What Is a DSAR?
A Data Subject Access Request (DSAR) is when an individual asks to access, correct, delete, or restrict their personal data.
Under Articles 12–15 of the GDPR, your business must respond within a defined timeframe — even if the request seems simple or informal.
2️⃣ Standard Response Timeline
Action | Timeframe | Details |
Acknowledge receipt | Within 7 days | Confirm that you’ve received the request and, if needed, ask for ID verification. |
Provide full response | Within 1 month | Send the requested data or confirm the action taken (e.g., rectification or erasure). |
Extension (if needed) | + 1 month (maximum 2 months total) | Only allowed for complex or multiple requests. You must inform the requester within the first month. |
💡 Tip: The one-month period starts on the day you receive the request, not when you verify identity — so act quickly.
3️⃣ When You Can Extend or Refuse
You can extend or decline a DSAR only when:
The request is manifestly unfounded or excessive, or
Responding would affect another person’s rights.
If you refuse or delay:
Inform the requester within one month,
Explain the reason, and
Tell them they can complain to the relevant Data Protection Authority.
4️⃣ How Euverify Helps You Stay on Time
When a DSAR arrives via your Secure Request Portal, Euverify:
Automatically logs the received date
Calculates and displays your response deadline
Sends email reminders before the one-month expiry
Keeps a timeline record of actions for audit purposes
✅ Summary
Requirement | Timeline |
Acknowledge receipt | 7 days |
Full response | 1 month |
Possible extension | + 1 month (for complex cases) |
Notify of refusal or delay | Within 1 month |
