Obtainer
Blog / Deadlines 9 min read

Missed DSAR Deadline: What Happens and How to Recover

Last updated July 2026 · Obtainer

Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

If you miss a DSAR deadline, the request does not go away and the obligation does not lapse. The late response itself becomes the violation. Under the GDPR that is an infringement of Article 12(3), which sits in the higher penalty tier and gives the person a right to complain to a supervisory authority. Under US state law it is a violation the attorney general can pursue for a civil penalty, up to $7,500 per violation in most states, $20,000 in Colorado, and $50,000 in Florida. What actually happens in the majority of cases is more mundane than a fine: the person complains, the regulator asks how your request process works, and one late response turns into a review of all of them.

The part teams underestimate is that the safety nets are closing. Most of the cure periods that once let a business fix a first mistake before an enforcement action have now expired, and the ones that remain have to be earned within a fixed number of days. This is a walk-through of what a missed deadline actually triggers, what regulators have fined companies for in 2025 and 2026, and what to do if you are already past the date.

What counts as missing a DSAR deadline

The clock starts when the request arrives, not when someone recognizes it as a request. That single fact causes most of the misses. A GDPR access request is valid however it is made, including verbally and to any part of the organization, so a message in a support queue that says "send me everything you have on me" started your one month even if it sat unread for three weeks. US state laws let you designate submission methods, which helps, but a request through a designated channel that nobody monitors is still a request received.

You are late if any of the following is true:

  • The response went out after the statutory window and you never sent a valid extension notice inside the original period.
  • You sent an extension notice after the first window closed. The notice has to land inside the original 45 days, or one month under the GDPR, to be effective.
  • Under the CCPA, you failed to confirm receipt of the request within 10 business days, which is a separate obligation from the substantive 45-day response.
  • You responded on time but the response was incomplete, and the complete answer arrived after the deadline.
  • You denied the request on time but never told the person how to appeal, in a state that requires an appeal process.

Consequences by regime

RegimeDeadlineWhat a late response exposes you toWho enforces
GDPR1 month, +2 with noticeInfringement of Article 12(3). Article 83(5) upper tier, up to 20 million euros or 4 percent of worldwide annual turnover. Reprimands and compliance orders are far more common than fines for a single miss.Supervisory authority, plus a right to a judicial remedy
CCPA / CPRA (California)45 days, +45; receipt confirmed in 10 business daysAdministrative fine of $2,663 per violation, or $7,988 if intentional or involving a consumer known to be under 16. These are the inflation-adjusted 2026 amounts, not the $2,500 and $7,500 printed in the statute.California Attorney General and the CPPA, independently
Colorado45 days, +45Up to $20,000 per violation under the Colorado Consumer Protection Act. Cure period ended January 1, 2025.Colorado Attorney General
Florida45 days, +15 onlyUp to $50,000 per violation, tripling to $150,000 where the violation involves a known child, a failure to delete or correct, or continued sale after an opt-out.Florida Department of Legal Affairs
Connecticut45 days, +45Up to $5,000 per willful violation, the lowest headline figure among the state laws. No cure period.Connecticut Attorney General
New Jersey45 days, +45$10,000 for a first violation, $20,000 for subsequent ones. The cure period sunset on July 15, 2026.New Jersey Division of Consumer Affairs
Iowa90 days, +45, the longest window in the countryUp to $7,500 per violation, after a permanent 90-day cure period. Iowa grants no right to correct and no profiling opt-out.Iowa Attorney General, exclusively
Most other states45 days, +45Up to $7,500 per violation. Virginia, Texas, Utah, Tennessee, and Iowa still give you a cure window first.State attorney general, exclusively

Two things are worth pulling out of that table. First, no US state privacy law gives a consumer the right to sue you over a late response. California's private right of action exists, but it is limited to certain data breaches, at $107 to $799 per consumer per incident, and it does not reach request handling. So the realistic downstream of a missed deadline in the US is a regulator, not a plaintiff. Second, the penalties are stated per violation, and regulators count violations per affected consumer. A process that is late for one person is a small problem. A process that is late for everyone is the same problem multiplied by your request volume, and that arithmetic is what turns a backlog into a headline number.

What regulators have actually enforced

Very few public enforcement actions are purely about lateness. What the record shows is that request-handling failures, including friction that makes a request effectively impossible to complete, are exactly where California's two regulators have been spending their attention. These are worth reading as a description of what a regulator looks at once it starts examining your process.

ActionAmountRegulator, dateWhat the request process got wrong
Honda$632,500CPPA, March 2025Required excessive personal detail to process opt-out requests, imposed unlawful confirmation requirements on authorized agents, ran an asymmetric cookie banner, and did not apply Global Privacy Control signals to known account holders.
Todd Snyder$345,178CPPA, May 2025A cookie banner that failed for 40 days and blocked opt-outs, a demand for photo identification on every privacy request including opt-outs that require no verification, and one undifferentiated form for all request types.
Healthline$1,550,000California Attorney General, July 2025Continued sharing data after opt-out requests and Global Privacy Control signals, missing contract terms with advertising partners, and a purpose-limitation failure. The largest CCPA settlement to date.
Disney$2,750,000California Attorney General, February 2026Children's data and advertising practices.
PlayOn Sports$1,100,000CPPA, March 2026Consumer rights and opt-out handling failures.
Ford Motor Company$375,703CPPA, March 2026Consumer rights request handling.

The pattern across all six is that the regulator did not need to prove harm to a single consumer. It looked at the mechanism, found that the mechanism did not work as required, and counted. Over-verification shows up twice, which is a useful warning for teams whose instinct after a scare is to add identity checks: demanding a photo ID for a request that does not require verification is itself a violation, not a precaution.

Where you still get a warning first

A cure period is a statutory grace window: the attorney general has to notify you of an alleged violation and give you a set number of days to fix it before filing. If you fix it and confirm in writing, no action follows. In 2023 nearly every state had one. In 2026 most are gone.

Still permanent: Virginia (30 days), Texas (30 days), Utah (30 days), Tennessee (60 days), Iowa (90 days, the longest in the country), plus Nebraska, Indiana, and Kentucky. Expired or sunset: Colorado (ended January 1, 2025), Connecticut, Delaware (January 1, 2026), Oregon (January 1, 2026), Montana, Minnesota (January 31, 2026), and New Jersey (July 15, 2026). Rhode Island and New Hampshire never had one. Florida's is discretionary rather than guaranteed, at 45 days, and it does not apply at all where a known child is involved. Our state privacy law cure periods breakdown has the full twenty-state table with the expiration dates.

The practical reading: if you operate in more than a handful of states, plan on having no warning. The states where you would most want a grace period, the large-population ones, are mostly the states that no longer offer it.

What to do if you are already past the deadline

Being late is a fact you cannot change. How you handle the next 48 hours materially changes the outcome, because both regulators and complainants respond very differently to a company that self-corrects than to one that goes quiet.

  1. Respond now, even partially. A partial response with a clear account of what is still outstanding and when it will arrive is better than continued silence. The obligation persists; the clock having expired does not discharge it.
  2. Do not backdate an extension notice. An extension is only valid if the notice went out inside the original window. Sending one now does not repair the miss, and a fabricated date turns a process failure into a credibility problem.
  3. Write down what happened. Record when the request arrived, through which channel, when it was recognized, what caused the delay, and when the response went out. If a regulator asks later, this record is the difference between an isolated error and an apparent pattern.
  4. Check whether it is one request or a category. If the request was missed because it landed in an unmonitored inbox, other requests are probably sitting in the same place. Search the mailbox for the previous six months before you conclude it was a one-off.
  5. Fix the intake, not just this request. If a cure period does apply, the attorney general will want evidence the underlying problem is fixed, not that one person eventually got an answer.
  6. Tell the person about the appeal route if you denied anything. Most state laws require a conspicuous appeal process, and omitting it is a separate violation from the late response. The rules differ by state, and how the data subject request appeal works covers the deadlines and the one state that has no appeal right at all.

Why deadlines get missed, and how to stop it

In the teams we see, missed deadlines almost never come from the legal analysis being hard. They come from three operational failures.

The request was not recognized as a request

Requests do not arrive labeled. They land in support tickets, in replies to marketing emails, in a message to a salesperson, and in whatever address the person could find on your site. If privacy@, legal@, support@, and the contact form are not all being watched in one place, a request will sit somewhere for weeks while its clock runs. Front-line staff need one instruction they can follow without judgment: anything that reads like a person asking about their own data goes to the privacy queue the same day.

Nobody knew where the data lived

The gather is the slow part. A person's data sits in the production database, the warehouse copy, the CRM, the ticketing tool, the email platform, billing, and however many vendors received an export. Every one of those needs a search, and every search depends on somebody who owns that system having time this week. Gartner has costed a manually fulfilled request at roughly $1,400 to $1,524, and almost all of that is these hours. Our guide to the cost to fulfill a DSAR breaks the figure down step by step.

There was no single clock

A queue tracked in a spreadsheet ages quietly. Nobody notices day 44 until it is day 46. Every request needs the receipt date stamped on arrival and the applicable deadline calculated from it, which also means knowing which law applies, since Florida gives you 60 days maximum where Colorado gives you 90. The data subject request deadlines by state table has each one.

Obtainer is built around those three failure points. It intakes the request and stamps the arrival date, finds where the person's data lives across your systems, compiles it into one reviewable manifest with the source system on each item, drafts a deadline-safe response, and tracks the statutory clock per request. A human redacts and approves before anything is disclosed or erased, so nothing goes out automatically. Obtainer helps you comply. It is not legal advice, so exemptions, refusals, and the disclosure decision stay with your team. Start with DSAR automation or the privacy team workflow.

Frequently asked questions

What happens if you miss a DSAR deadline?

The late response becomes the violation, and the obligation to answer continues. Under the GDPR it is an infringement of Article 12(3), which the person can complain about to a supervisory authority and which sits in the upper penalty tier. Under US state law it is a civil violation the attorney general can pursue, up to $7,500 per violation in most states. In practice a single miss usually draws a complaint and questions about your process rather than an immediate fine.

Can you be fined for a late DSAR response?

Yes, though a fine for one late response alone is uncommon. GDPR infringements of the data subject rights provisions carry a theoretical maximum of 20 million euros or 4 percent of worldwide annual turnover, and supervisory authorities more often issue reprimands and compliance orders. In the US, California's inflation-adjusted penalties are $2,663 per violation and $7,988 if intentional, and most other states cap at $7,500. Because penalties are counted per violation, a systemic delay across many requests is what produces large numbers.

Can a person sue you for missing a DSAR deadline in the US?

No. None of the comprehensive US state privacy laws create a private right of action for request-handling failures. California has a limited private right of action, but it applies only to specific data breaches caused by a failure to maintain reasonable security, with statutory damages of $107 to $799 per consumer per incident. Enforcement of a late response rests with the state attorney general, and in California also with the CPPA.

Can you extend a DSAR deadline after it has expired?

No. An extension is only valid if you notify the person inside the original window and give the reason. Under the GDPR that means within one month, and under US state laws within the initial 45 days. Once the original period has passed there is nothing left to extend, and sending a late extension notice does not cure the miss. Respond as completely as you can, explain what is outstanding, and give a firm date.

Does the DSAR clock stop while you verify identity?

Not in the way most teams hope. Under the GDPR the deadline runs from receipt of the request, though where you have reasonable doubts about identity you may ask for the information necessary to confirm it, and the period is generally treated as pausing until you receive it. Under the CCPA verification is expected to happen inside the 45 days, not alongside a paused clock. Either way the safe assumption is that verification is part of your window, not an extension of it. Demanding more identification than you need is itself an enforcement risk.

What is the first thing to do when you realize a request is overdue?

Respond, even if the response is partial, and say plainly what is still coming and when. Then record when the request actually arrived, how it was missed, and what you are changing so it does not recur. Then check whether the same failure has caught other requests, since a missed request is usually a symptom of an intake gap rather than a one-time slip. Regulators treat a documented self-correction very differently from a silent backlog.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.