DSAR Deadline Tracking: Never Miss a GDPR or CCPA Statutory Clock
Every DSAR comes with a statutory clock, and the penalty for missing it is real. Obtainer tracks the GDPR one-month and CCPA 45-day deadlines on every request, so you see each due date coming and reduce the risk of one slipping past unnoticed.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
DSAR deadline tracking is keeping a live countdown on each data subject access request against the statutory time limit, which under GDPR is one month from a valid request and under CCPA is 45 days. Missing that deadline exposes the organization to complaints and regulatory penalties, so knowing where each clock stands matters. Obtainer starts the correct GDPR or CCPA countdown when a request becomes valid and shows it on every request, so your team sees what is due and when at a glance. This helps you meet deadlines and reduces the risk of missing one, but it does not guarantee compliance, because responding on time still depends on your team doing the work. Obtainer helps you comply. It is not legal advice, and judgments like whether the clock can be extended stay with your team. It is self-serve DSAR fulfillment from $49/mo, not a six-figure governance suite. One thing worth knowing before you build a process around a single number: the 45-day figure is the common case, not a universal rule. Of the 20 US states with a comprehensive consumer privacy law in effect, 18 use 45 days with one 45-day extension. Iowa gives 90 days with a 45-day extension, the longest window in the country at 135 days. Florida gives 45 days with only a 15-day extension, the tightest at 60. The GDPR runs on one calendar month, extendable by two further months for complex or numerous requests. And a covered entity answering a HIPAA right of access request has 30 days with a single 30-day extension, which is why a health system can have two different clocks running on two requests from the same person in the same week.
Last updated July 2026
What you get
Deadline tracking, built for privacy, legal, and ops teams
The right clock, automatically
Obtainer applies the GDPR one-month or CCPA 45-day limit to each request, so you are tracking against the correct statutory window, including the state exceptions that are not 45 days.
See due dates coming
A live countdown on every request means a deadline is far less likely to arrive as a surprise.
Prioritize what is due
Requests sort by how close they are to their deadline, so your team works the most time-sensitive one first.
Honest about the limit
Tracking reduces the risk of missing a deadline, it does not promise you never will, because the work still sits with your team.
How it works
From an intake request to a ready-to-review response in four steps
Validate the request
Once the requester is verified and the request is valid, Obtainer knows when the statutory clock starts.
Start the correct clock
Obtainer applies the GDPR one-month or CCPA 45-day deadline and begins the countdown.
Watch the countdown
Every request shows its time remaining, so your team can see and prioritize what is due.
Respond in time
Your team completes review and approval before the clock runs out. Obtainer helps you comply. It is not legal advice.
Frequently asked
Questions teams ask about deadline tracking
How long do you have to respond to a DSAR?
The GDPR gives you one calendar month from a valid request. That extends by up to two further months for complex or numerous requests, provided you tell the person why within the first month. The CCPA gives a business 45 calendar days, extendable by another 45 with notice, so 90 days at the outside.
When does the DSAR deadline start?
The clock starts the day you receive a valid request, not when you get around to it. Under the GDPR, time spent verifying the requester comes out of the one month, so verify quickly. If the request is unclear, you can ask for clarification, and in some cases that pauses the clock until the person responds.
Can you extend a DSAR deadline?
Yes, within limits. The GDPR allows a two-month extension for requests that are complex or come in large numbers, but you must notify the requester of the extension and the reason within the first month. The CCPA allows one 45-day extension with notice. An extension is not automatic, so document why the request qualifies.
What happens if you miss a DSAR deadline?
A missed deadline exposes the organization to complaints to the regulator and, under the GDPR, potential fines. It also erodes trust and invites scrutiny of your wider privacy program. Tracking every clock reduces the risk of missing one, but responding on time still depends on your team doing the work, so treat each due date as firm.
Is the DSAR deadline 45 days in every state?
No, and building a process on that assumption is a common mistake. Eighteen of the 20 states with a comprehensive privacy law in effect use 45 days plus a 45-day extension. Iowa allows 90 days plus 45, the longest in the country. Florida allows 45 days plus only 15, the shortest at a 60-day ceiling. Since rights attach to where the consumer lives rather than where you are, a national business needs the tightest applicable clock on each request, not an average.
How long does a covered entity have to answer a HIPAA request for medical records?
Thirty days from receipt, under 45 CFR 164.524, with one extension of up to 30 more days that requires a written statement of the reason and the date you will act, sent inside the original 30 days. That is materially tighter than the state privacy laws, and it runs on a separate track: a health system in a data-level exemption state such as California or Colorado can owe a 30-day HIPAA response and a 45-day state response about different data belonging to the same person.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.