Back to the hub

What's the deadline for responding to a DSAR under GDPR versus CCPA?

The GDPR gives one month from receipt under Article 12(3), extendable by two further months where necessary. The CCPA gives 45 days from receipt of a verifiable consumer request under Cal. Civ. Code section 1798.130(a)(2)(A), extendable once by a further 45 days. Both extensions require notifying the requester first.

Applies to: Businesses that receive data subject access requests under both the EU GDPR and the California Consumer Privacy Act and need one intake process that satisfies the shorter of the two clocks.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

If you answer data subject access requests under both regimes, the deadline question comes up early and the two answers are close enough to be confusing. They are not the same number, they do not start the same way, and their extensions work differently.

The GDPR clock: one month, plus two

Article 12(3) sets the rule. The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.

Three details matter. The obligation is "without undue delay and in any event within one month", so one month is a ceiling rather than a target. The extension is up to two further months, giving a three-month maximum, and it is justified by complexity and volume rather than convenience. The notice of extension is due inside the original month, with reasons, so an extension decided in week six is already late.

Article 12(3) also carries a delivery rule: where the data subject makes the request by electronic means, the information shall be provided by electronic means where possible, unless otherwise requested.

Article 12(4) covers the other outcome. If the controller does not take action on the request, it must inform the data subject without delay and at the latest within one month of receipt of the reasons for not taking action. A refusal is not a reason to let the clock run out.

The CCPA clock: 45 days, plus 45

Section 1798.130(a)(2)(A) requires a business to disclose and deliver the required information to a consumer free of charge, correct inaccurate personal information, or delete a consumer's personal information, based on the consumer's request, within 45 days of receiving a verifiable consumer request.

The same paragraph then closes the gap that most businesses try to use. The business shall promptly take steps to determine whether the request is a verifiable consumer request, but this shall not extend the business's duty to disclose and deliver the information, to correct inaccurate personal information, or to delete personal information within 45 days of receipt of the consumer's request. Verification time is inside the 45 days.

The extension is a single one. The time period may be extended once by an additional 45 days when reasonably necessary, provided the consumer is provided notice of the extension within the first 45-day period. That is a 90-day maximum, against the GDPR's three months.

Delivery is prescribed too. The disclosure shall be made in writing and delivered through the consumer's account with the business if the consumer maintains one, or by mail or electronically at the consumer's option if they do not.

Which is actually shorter

One month is shorter than 45 days in every month of the year, so the GDPR deadline binds first whenever both apply. That is the practical answer for a business running one intake process: build to one month and you are inside both.

The maximum lengths invert. Three months under the GDPR is longer than 90 days under the CCPA. A business that plans around worst-case timelines rather than default ones needs to hold both numbers.

The starting points differ in wording but converge in effect. The GDPR runs from receipt of the request. The CCPA's 45 days are expressed from receipt of a verifiable consumer request, but the anti-delay sentence pins the practical start at receipt of the consumer's request. Timestamp on arrival for both.

Building one process for both

Treat the deadline as the easy part and the scope as the hard part. The CCPA's 45-day response period applies to requests to know, delete and correct. The GDPR's one month covers the whole of Articles 15 to 22, which includes access, rectification, erasure, restriction, portability, objection, and automated decision-making. The response content is not interchangeable even where the timing lines up.

If you operate across US states as well, the picture widens again: the state-by-state response deadlines are not uniform, and several states run 45 days with their own extension rules and appeal clocks on top.

Next step

If you are not sure which of these regimes reach your business, the free 2-minute Obligation Scan works out which privacy laws apply and what each one requires of your request process. The US state privacy law hub and the GDPR compliance hub set the rest of the duties in order.

Compliance checklist

  • Timestamp every request on receipt, because both clocks start at receipt rather than at verification or triage.
  • Default your internal target to one month, the shorter of the two, so a single process satisfies both laws.
  • Build the extension notice as a template: the GDPR requires informing the data subject within one month with the reasons for the delay.
  • For CCPA extensions, send notice of the extension within the first 45-day period, which section 1798.130(a)(2)(A) requires.
  • Track the two GDPR paths separately: Article 12(3) for action taken, Article 12(4) for a refusal, which must still go out within one month.
  • Deliver CCPA responses in writing through the consumer's account if they have one, or by mail or electronically at the consumer's option if they do not.

Sources

Last verified: 2026-09-15

Informational, not legal advice.