Comparison

DSAR Response Timelines by Law: GDPR, CCPA/CPRA, and More

How long you have to respond to a data subject request under each major privacy law, and when the clock can be extended.

7 min read

The clock on a data subject request starts when you receive it, and different laws give you different amounts of time. Miss a deadline and you have a compliance problem, so the response window is one of the first things to get right. Here are the deadlines under the major laws, and when they can be extended.

Deadlines at a Glance

LawDeadline to respondExtension
GDPR (EU/UK)1 monthUp to 2 additional months for complex or numerous requests
CCPA/CPRA (California)45 daysUp to 45 additional days when reasonably necessary
Virginia (VCDPA)45 daysUp to 45 additional days
Colorado (CPA)45 daysUp to 45 additional days
Most other US state laws45 daysTypically up to 45 additional days

Always confirm the current deadline for the specific law that applies; the table is a working guide, not legal advice, and details vary.

How the Clock Works

Two things trip teams up. First, the clock usually starts when the request arrives, not when you finish verifying identity, so verification delays eat into your window. Second, an extension is not automatic: most laws require you to notify the person that you are extending, and why, within the original window. A silent extension is a missed deadline.

Why Timelines Are Really a Data-Mapping Problem

You cannot respond in 30 or 45 days to a request whose data you cannot find. Teams that hit deadlines comfortably are the ones that already know where personal data lives before a request arrives. The deadline is fixed; your ability to meet it is decided months earlier by how well you have mapped your systems.

How Concord Fits

Concord Privacy pairs request intake and identity verification with data mapping, so an incoming request routes to the systems that hold the data and progresses as a tracked workflow with the clock visible, rather than an email thread you hope finishes in time.

Get Started

Run Your Privacy Program on One Platform

Concord brings consent, privacy requests, data mapping, and policy management together, so a rights request is a workflow, not a fire drill.