Obtainer
Use case

GDPR Compliance Software for Data Subject Access Requests and the One-Month Deadline

A GDPR data subject access request starts a one-month clock, and the manual scramble across your systems is where teams lose time and miss things. Obtainer is GDPR compliance software that finds where the personal data lives, compiles it into one reviewable manifest, and drafts a deadline-safe response you redact and approve.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

GDPR gives a person the right to request a copy of the personal data an organization holds about them, and you generally must respond within one month. Obtainer is GDPR compliance software built for that request: it intakes the DSAR, finds where the person's data lives across your systems, compiles it into a single source-system manifest, drafts a deadline-safe response from templates, and tracks the one-month deadline so it does not slip. Nothing is disclosed automatically; every response passes a human redaction-and-approval gate, so you stay in control of what is disclosed. Obtainer helps you comply. It is not legal advice, so the legal calls, exemptions, identity verification, and any refusal stay with your team. It is self-serve from $49/mo, focused on DSAR fulfillment rather than a full governance suite.

// THE FIT

Why it fits

Privacy, DPO, and legal teams handling GDPR access requests who want to compile the data, draft the response, and track the one-month deadline in one place, self-serve.

Track the one-month clock

Obtainer records when each request arrives and tracks the GDPR one-month deadline per request, which reduces the risk of a response slipping past the date.

One manifest across systems

Instead of a scramble through inboxes and databases, the personal data is compiled into one source-system manifest you can review before anything goes out.

You approve every disclosure

A human redaction-and-approval gate sits in front of the response. Obtainer helps you comply; it is not legal advice, and you stay in control of what is disclosed.

// FAQ

Questions

Common questions about this

What is GDPR compliance software?

GDPR compliance software is tooling that helps an organization meet its obligations under the General Data Protection Regulation. The category is broad, covering consent banners, records of processing, breach registers, and vendor assessments. Obtainer covers one part of it deliberately: fulfilling data subject requests. It intakes the request, finds where the person's data lives, compiles a manifest, drafts the response, and tracks the one-month clock, with a human approving anything that goes out.

How long do you have to respond to a GDPR data subject access request?

One month from receipt of the request. You can extend by up to two further months where the request is complex or where you have received a number of requests from the same person, but you must tell the data subject about the extension and the reason within the first month. The clock generally starts when you receive the request, not when you finish verifying identity, though the deadline can pause while you seek the information you reasonably need to confirm who the person is.

Can you charge a fee for a subject access request?

Usually no. Article 12(5) says you must provide the information free of charge. You may charge a reasonable fee based on administrative costs, or refuse to act, where a request is manifestly unfounded or excessive, in particular because it is repetitive, and you may charge a reasonable fee for further copies beyond the first. The burden of showing a request is manifestly unfounded or excessive sits with you, so this is a narrow exception rather than a routine option.

Can you refuse a GDPR data subject access request?

In limited circumstances, yes. A request that is manifestly unfounded or excessive can be refused, and Article 15(4) says the right to obtain a copy must not adversely affect the rights and freedoms of others, which is why third-party data is usually redacted rather than released. Member state law adds further restrictions. When you refuse you must tell the person without delay and at the latest within one month, explain why, and inform them of their right to complain to a supervisory authority and to a judicial remedy. Obtainer helps you comply; the refusal decision itself is a legal call for your team.

What happens if you miss the GDPR one-month deadline?

A late response is itself an infringement of Article 12(3), and supervisory authorities do issue reprimands, orders, and fines for it. Infringements of the data subject rights in Articles 12 to 22 fall in the higher tier under Article 83(5), up to 20 million euros or 4 percent of total worldwide annual turnover, whichever is higher, though a single late response typically draws a corrective order rather than a headline fine. The practical risk is a complaint that puts your whole request process under review.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.