Reference guide

How long do you have to respond to a data request?

GDPR, CCPA/CPRA and DPDP all give people the right to ask what data you hold, correct it, or delete it — and each law sets its own clock for how fast you have to respond.

Last checked 26 August 2026 · This is a general guide, not legal advice — confirm your specific obligations with a lawyer, especially if you handle sensitive data or operate in a regulated industry.

Last reviewed: 26 August 2026

LawDeadlineExtensionApplies to
GDPR (EU/UK)1 month (~30 days)+2 months, if complexEU/UK residents' data
CCPA/CPRA (California)45 days+45 days, if neededCalifornia residents' data
DPDP (India)No fixed day-count — publish your own process72-hour breach notice to affected individuals is fixedData of individuals in India

GDPR — one month, extendable

Under Article 12(3) of the GDPR, a controller must respond to a data subject's request "without undue delay and in any event within one month of receipt." If the request is complex, or you've received a high volume of requests from the same person, you can extend by a further two months — but you have to tell the requester you're extending, and why, within that first month. You can't decide silently to take longer.

"One month" is generally read as running to the same date in the following calendar month (a request received on the 5th is due by the 5th of the next month), not a flat 30 days — worth knowing if you're tracking this by hand, since it can be 28-31 days depending on the month.

CCPA/CPRA — 45 days, extendable

California's law gives you 45 days from receipt to respond (Cal. Civ. Code §1798.130). You can take another 45 days when reasonably necessary, but — same rule as GDPR — you must notify the consumer of the extension and the reason for it within the original 45-day window.

DPDP — India's law, deliberately not overstated here

India's Digital Personal Data Protection Act, 2023 (enacted 11 August 2023) gives individuals rights to access, correct, and erase their data, and to escalate unresolved grievances to a Grievance Officer and ultimately the Data Protection Board of India. The DPDP Rules, 2025 were notified on 14 November 2025 — that's the date the framework actually became operational, not just the 2023 Act sitting on paper.

What's live now versus later, as of this review:

On the specific question this page is about — how many days you have to respond to a request — DPDP does not set one single statutory day-count for the request itself the way GDPR (1 month) and CCPA (45 days) do. The Rules put the responsibility on each Data Fiduciary (business) to publish its own process and timeline for access, correction and erasure requests. Rule 14(3) does set a numeric cap, but on a different, narrower thing: if a data principal is unhappy with how their request was handled and raises a grievance, the Fiduciary's own published grievance-redressal mechanism must resolve that grievance within a period it sets itself, not exceeding 90 days. That cap applies to the grievance process, not to the original request. Treat 30 days as DSAR Desk's own internal working default for the request itself, for tracking purposes only — it is not a legal deadline DPDP hands you, and you should publish and follow your own stated process rather than relying on our default.

Source: Press Information Bureau, "DPDP Rules, 2025 Notified" (Government of India, 17 November 2025). Gazette notification reported as G.S.R. 846(E) by secondary legal trackers — verify against the official e-Gazette copy if the exact number matters for your own filing.

When does the clock actually start? Generally from the day you receive a valid, identifiable request — not from when you finish verifying who's asking. If you need more information to confirm identity, GDPR lets that pause the clock, but you should ask for it promptly rather than let a request sit unanswered while you decide whether to act.

How to actually respond, step by step

  1. Log it immediately. The single most common failure mode isn't refusing a request — it's losing track of one in an inbox. Timestamp it the moment it arrives.
  2. Verify identity proportionately. Enough to be confident you're not handing someone else's data to the wrong person, without demanding more than necessary — asking for a full ID scan for a simple "what's my email on file" request is usually overkill.
  3. Confirm what's actually being asked. Access, correction, deletion, and opt-out requests need different responses — don't default to deletion when someone asked to see their data.
  4. Pull the data from wherever it actually lives — your database, your CRM, your email tool, any third-party processor acting on your behalf. This is usually the slowest step and the reason deadlines get missed, so start it early.
  5. Respond inside the deadline, even if the answer is "we found nothing" or "we can't verify who you are" — silence is the worst outcome, not a neutral one.
  6. Keep a record of what was asked, when, and what you did — if a regulator or the requester ever follows up, "we don't remember" is not a good position to be in.

What happens if you miss it

Consequences vary by jurisdiction and regulator, and can range from a complaint escalated to a data protection authority to financial penalties in serious or repeated cases. For most small businesses, the more immediate risk is relational, not regulatory — a customer whose deletion request goes unanswered for weeks rarely lets it go quietly, and it's exactly the kind of thing that ends up as a public complaint.

Tracking these by hand in an inbox is how deadlines get missed. DSAR Desk gives you one link for requests to come in through, with the deadline calculated automatically the moment they land.

Try DSAR Desk — free for up to 3 requests/month

Add this calculator to your own site

Free to embed, no sign-up required. Drop it in a help center article, a privacy page, or a blog post about data requests — it's a live, self-contained widget, not a screenshot.

<iframe src="https://dsar.klairlabs.com/embed.html" style="width:100%;max-width:420px;height:300px;border:1px solid #E2E4E9;border-radius:12px" loading="lazy" title="Data request deadline calculator"></iframe>
<p style="font-size:12px;color:#5B6472;margin-top:6px">Deadline calculator by <a href="https://dsar.klairlabs.com/" target="_blank" rel="noopener">DSAR Desk</a></p>

Questions

How many days do I have to respond to a GDPR data request?

One month (roughly 30 days) from receipt of the request, under Article 12(3) of the GDPR. If the request is complex or you've received a high volume of requests, you can extend by up to two further months — but you must tell the requester within the first month that you're extending, and explain why.

How many days do I have to respond to a CCPA request?

45 days from receipt, under the CCPA/CPRA (Cal. Civ. Code §1798.130). You can extend by another 45 days when reasonably necessary, but you must notify the consumer of the extension and the reason within the initial 45-day period.

What's the deadline under India's DPDP Act?

India's DPDP Rules, 2025 were notified on 14 November 2025 (PIB, 17 Nov 2025). The Data Protection Board's provisions took effect immediately; most other duties phase in over 18 months to 13 May 2027, and Consent Manager registration is expected to open around November 2026. A breach must be reported to affected individuals within 72 hours — that part is fixed. But DPDP does not set one statutory day-count for the request itself the way GDPR and CCPA do — you publish and follow your own process. Rule 14(3) does cap a related but different thing at 90 days: if a data principal raises a grievance about how their request was handled, your own grievance-redressal mechanism must resolve it within a period you set, not exceeding 90 days — that cap is on the grievance process, not the original request. Treat 30 days as DSAR Desk's own internal default for the request itself, not a legal deadline, and don't rely on this as a substitute for legal advice.

When does the deadline clock actually start?

Generally from the day you receive a valid, identifiable request — not from when you finish verifying the requester's identity. Under GDPR specifically, if you need additional information to confirm identity, the clock can pause until you receive it, but you should ask for that information promptly rather than sitting on the request.

What happens if I miss the deadline?

Consequences vary by jurisdiction and regulator, and can range from a complaint escalated to a data protection authority to financial penalties in serious or repeated cases. The bigger practical risk for most small businesses is reputational and relational — a customer whose deletion request goes unanswered rarely stays quiet about it.