GDPR Compliance Software for Data Subject Access Requests and the One-Month Deadline
A GDPR data subject access request starts a one-month clock, and the manual scramble across your systems is where teams lose time and miss things. Obtainer is GDPR compliance software that finds where the personal data lives, compiles it into one reviewable manifest, and drafts a deadline-safe response you redact and approve.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
General Data Protection Regulation compliance turns on a right you have to service rather than a document you file. The GDPR gives a person the right to request a copy of the personal data an organization holds about them, and you generally must respond within one month. Obtainer is GDPR compliance software built for that request: it intakes the DSAR, finds where the person's data lives across your systems, compiles it into a single source-system manifest, drafts a deadline-safe response from templates, and tracks the one-month deadline so it does not slip. Nothing is disclosed automatically; every response passes a human redaction-and-approval gate, so you stay in control of what is disclosed. Obtainer helps you comply. It is not legal advice, so the legal calls, exemptions, identity verification, and any refusal stay with your team. It is self-serve from a planned $49/mo, focused on DSAR fulfillment rather than a full governance suite.
Last updated August 2026
Why it fits
Privacy, DPO, and legal teams handling GDPR access requests who want to compile the data, draft the response, and track the one-month deadline in one place, self-serve.
Track the one-month clock
Obtainer records when each request arrives and tracks the GDPR one-month deadline per request, which reduces the risk of a response slipping past the date.
One manifest across systems
Instead of a scramble through inboxes and databases, the personal data is compiled into one source-system manifest you can review before anything goes out.
You approve every disclosure
A human redaction-and-approval gate sits in front of the response. Obtainer helps you comply; it is not legal advice, and you stay in control of what is disclosed.
More use cases
Related features
Questions
Common questions about this
What is GDPR compliance software?
GDPR compliance software is tooling that helps an organization meet its obligations under the General Data Protection Regulation. The category is broad, covering consent banners, records of processing, breach registers, and vendor assessments. Obtainer covers one part of it deliberately: fulfilling data subject requests. It intakes the request, finds where the person's data lives, compiles a manifest, drafts the response, and tracks the one-month clock, with a human approving anything that goes out.
How long do you have to respond to a GDPR data subject access request?
One month from receipt of the request. You can extend by up to two further months where the request is complex or where you have received a number of requests from the same person, but you must tell the data subject about the extension and the reason within the first month. The clock generally starts when you receive the request, not when you finish verifying identity, though the deadline can pause while you seek the information you reasonably need to confirm who the person is.
Can you charge a fee for a subject access request?
Usually no. Article 12(5) says you must provide the information free of charge. You may charge a reasonable fee based on administrative costs, or refuse to act, where a request is manifestly unfounded or excessive, in particular because it is repetitive, and you may charge a reasonable fee for further copies beyond the first. The burden of showing a request is manifestly unfounded or excessive sits with you, so this is a narrow exception rather than a routine option.
Can you refuse a GDPR data subject access request?
In limited circumstances, yes. A request that is manifestly unfounded or excessive can be refused, and Article 15(4) says the right to obtain a copy must not adversely affect the rights and freedoms of others, which is why third-party data is usually redacted rather than released. Member state law adds further restrictions. When you refuse you must tell the person without delay and at the latest within one month, explain why, and inform them of their right to complain to a supervisory authority and to a judicial remedy. Obtainer helps you comply; the refusal decision itself is a legal call for your team.
What happens if you miss the GDPR one-month deadline?
A late response is itself an infringement of Article 12(3), and supervisory authorities do issue reprimands, orders, and fines for it. Infringements of the data subject rights in Articles 12 to 22 fall in the higher tier under Article 83(5), up to 20 million euros or 4 percent of total worldwide annual turnover, whichever is higher, though a single late response typically draws a corrective order rather than a headline fine. The practical risk is a complaint that puts your whole request process under review.
Does the GDPR apply to US companies?
Often, and having no office, server or entity in Europe does not settle it. Article 3(2) extends the GDPR to a controller or processor not established in the Union where the processing relates to either the offering of goods or services to data subjects in the Union, irrespective of whether payment is required, or the monitoring of their behaviour as far as that behaviour takes place within the Union. The first limb catches a US company that prices in euros, ships to the EU, or otherwise targets European customers. The second catches analytics, ad pixels and behavioral profiling of visitors located in the EU, which is why a purely US business with a public website can still be in scope. Merely being reachable from Europe is not enough on its own; the test is whether you are targeting or tracking people there.
Do I need an EU representative under the GDPR?
If Article 3(2) brings you into scope, Article 27(1) requires you to designate a representative in the Union in writing, and Article 27(3) says that representative must be established in a Member State where your data subjects are. There are two exemptions. Article 27(2)(a) covers processing that is occasional, does not include large-scale processing of the special categories of data in Article 9(1) or of criminal conviction data, and is unlikely to result in a risk to the rights and freedoms of individuals. Article 27(2)(b) covers public authorities. Most US companies doing ongoing EU business fall outside both. The representative is the contact point for supervisory authorities and for data subjects, so publish the details in your privacy notice, and note that appointing one does not shift your own liability.
What counts as personal data in a subject access request?
More than most US teams assume, because the operative definition is Article 4(1), not the American security term PII. Personal data is any information relating to an identified or identifiable natural person, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person physical, physiological, genetic, mental, economic, cultural or social identity. Online identifiers are named explicitly, so cookie IDs, device identifiers and IP addresses are in scope where they can be linked to a person, and so are derived records such as scores and segments. Pseudonymized data still counts; only genuinely anonymous data falls out. Our guide to what PII is and where it stops covers the gap in detail.
Does the GDPR require a data processing agreement?
Yes. Article 28(3) requires a written contract, or another legal act, whenever a processor handles personal data on a controller's behalf, and Article 28(9) confirms electronic form counts. The contract must set out the subject matter and duration of the processing, its nature and purpose, the type of personal data and the categories of data subjects, and bind the processor to eight duties: process only on documented instructions, keep authorized personnel under confidentiality, apply Article 32 security, control subprocessors under Article 28(2) and (4), assist with data subject rights requests, assist with the Articles 32 to 36 obligations, delete or return the data at the end of the service, and make available what is needed to demonstrate compliance and allow audits. Article 28(4) also keeps the original processor fully liable if a subprocessor fails.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.