Skip to content
Redmoon Date Calculators

← Blog

The GDPR DSAR Deadline: "One Month" Is Trickier Than It Sounds

5 min read complianceGDPRprivacy

When a data subject access request (DSAR) lands, the GDPR gives you "one month" to respond. It sounds generous and unambiguous. It is neither — and treating it as "30 days from whenever I noticed it" is how organisations quietly miss a statutory deadline.

A month is not 30 days

The period runs to the corresponding date in the next month. A request received on 15 March is due on 15 April. A request received on 31 January is due on 28 February (or the 29th in a leap year), because there is no 31 February — so it falls on the last day of the month. Counting a flat 30 days gives the wrong answer in either direction depending on the month.

Day zero is the day of receipt

The clock starts the day the request is received, not the day it reaches the right team or the day someone triages it. Internal routing delays eat into your month without extending it, so log the receipt date the moment a request arrives in any channel — email, post, web form, or a passing comment to staff.

You can buy two more months — if you act early

For requests that are complex or numerous, the period can be extended by up to two further months. The catch: you must tell the requester about the extension, and why, within the first month. Miss that window and you have lost the extension, not just the time.

Fix the dates first

The GDPR / DSAR Response Deadline calculator takes the receipt date and returns the one-month deadline using the corresponding-date rule, so day zero and the month boundary are never in doubt. Decide on any extension well before the first month runs out.

General information, not legal advice. Confirm specifics against the GDPR and your supervisory authority’s guidance.

Send feedback

We read every message. Tell us what could be better or what you love.