What Is the Deadline to Respond to a GDPR Data Access Request?

One Calendar Month, Counted the Simple Way
The deadline is one calendar month, not thirty days. If a shopper emails you on 3 March, the response is due by 3 April. If they email on 31 January, the deadline lands on the last day of February, because there is no 31st.
The standard is actually stricter than the deadline suggests. The rule is to respond without undue delay and in any event within one month. A request you could have answered in three days should not sit for twenty-eight because the calendar allows it.
Weekends and public holidays do not extend anything. If the due date falls on a Sunday or a bank holiday, most authorities accept the next working day, but building your process around that margin is a bad habit.
The response also has to be free. You cannot charge a handling fee, and you cannot make the shopper create an account or use a specific form to exercise the right. A store on OpoShop has to accept a valid request however it arrives, including a reply to a marketing email or a message on social.
The Clock Starts Earlier Than Most Merchants Think
This is where deadlines get missed, and it is almost never because someone ignored a request on purpose.
The clock starts when the request reaches your organisation, through any channel, in any wording. It does not start when it reaches the right inbox. A message sitting unread in a shared support address for eleven days has already used eleven days of your month.
Requests also rarely announce themselves. Shoppers do not write "I am exercising my Article 15 right of access". They write "can you send me everything you have about me" or "what data do you hold on my account". Both are valid requests and both start the clock.
- Any channel counts: Email, contact form, chat, social message, or a phone call your team takes.
- Any wording counts: No magic words, no template, no requirement to cite the regulation.
- Any recipient counts: A request to a customer service agent is a request to the business.
- Third parties can ask: An authorised representative acting for the shopper can make the request on their behalf.
There is one legitimate pause. If you have reasonable doubts about who is asking, you may request information to verify identity, and the deadline effectively runs from when you receive that confirmation. Use it honestly. Asking a known account holder emailing from the address on file to post a photo of their passport is a delay tactic, and regulators treat it as one.
For a merchant on OpoShop, the cleanest fix is a single intake point that timestamps every request on arrival, so the due date is calculated automatically rather than reconstructed from an email thread later.
When You Can Extend, and How to Do It Properly
The two-month extension is real, and it is narrower than merchants hope.
It applies where the request is complex or where the same person has submitted a number of requests. Complexity means genuine difficulty, such as data spread across many systems, or material that needs careful redaction because it involves other people. Being busy is not complexity. Being a small team is not complexity.
The mechanics matter as much as the grounds. You must inform the shopper within the first month that you are extending, and you must explain the reason. An extension you decide on quietly in week five is not an extension. It is a missed deadline.
There is also a separate route for requests that are manifestly unfounded or excessive, usually meaning repetitive. There you can charge a reasonable fee based on administrative cost, or refuse. Both are high bars, both require you to explain your reasoning, and you still have to reply within the month telling the person what you decided and that they can complain to their supervisory authority.
Most ecommerce requests are neither complex nor excessive. A typical OpoShop store holds order history, addresses, email marketing status and some analytics identifiers, which is a fifteen minute export once you know where to look.
What Actually Has to Go Back to the Shopper
The response is more than a data dump, and it is less than everything you have ever touched. Both mistakes are common.
You need to provide a copy of their personal data, plus supporting information: the purposes of processing, the categories of data, who you shared it with, how long you keep it, where it came from if not from them, and their rights to rectification, erasure, restriction, objection and complaint.
The format should be concise, transparent and intelligible. A raw database export with column names like usr_attr_7 does not meet that standard. Plain labels do.
You also have to protect other people. If an order note contains another customer's details, or an internal message names a staff member's personal information, redact it. The right of access is to their data, not to your records wholesale.
Three things you do not have to hand over: your internal commercial analysis that is not personal data, information that would reveal trade secrets or another person's data without justification, and material covered by other legal protections. Redact narrowly and explain that you have done so.
For a typical OpoShop store the finished response runs to a few pages. Account details, an order table, marketing consent status, support history, and a short list of technical identifiers with a sentence each explaining what they are for.
How to Handle a Request Inside the Deadline
A repeatable process turns this from a scramble into a task. The goal is a clear owner, a fixed intake point and a template you are not writing from scratch.
The three parts that decide whether you hit the deadline are below.
1. Give every request one front door
Requests arriving in four different inboxes is the single biggest cause of missed deadlines for small stores.
Publish one privacy contact route, link it from your footer and your privacy policy, and brief whoever answers support to forward anything that smells like a data request the same day. A store on OpoShop that funnels these into one tracked inbox with automatic due dates removes the entire class of problem.
2. Know your data map before you need it
Write down where customer personal data lives, once, in advance. Orders, customer accounts, email marketing platform, support desk, reviews app, shipping and returns tools, and any analytics or ad platform identifiers you can tie to a person.
That list turns a stressful search into a checklist. Do it on a quiet afternoon rather than on day twenty-five of a live request, and update it whenever you install a new app that stores customer data.
3. Answer in language a shopper can read
Structure the response by category. Account details, orders, marketing preferences, support history, technical identifiers. Under each, the data, then a one line explanation of why you hold it.
Then add the required context: retention periods, who you shared it with, and their other rights including the right to complain to a supervisory authority. Keep a copy of the exact response, because your ability to show you complied depends on it.
Shared Inbox vs Spreadsheet Tracking vs a Tracked Request Queue
How you track these matters more than how you word them, because deadlines are missed through invisibility rather than refusal.
| Method | How deadlines are tracked | Failure mode | Fits |
|---|---|---|---|
| Shared support inbox | Whoever notices, if they notice | Requests buried under normal tickets | Very low volume, one person handling support |
| Manual spreadsheet | Someone logs each request by hand | Depends entirely on remembering to log it | Small teams with a disciplined routine |
| Tracked request queue | Timestamped on arrival with an automatic due date | Very few, provided intake is routed to it | Any store with EU, UK or California traffic |
A shared inbox works right up until the week you are busy, which is exactly when a request is most likely to arrive.
A spreadsheet is a real improvement, since it makes deadlines visible. It still relies on a human noticing the request is a request, which is the step that actually fails.
A tracked queue removes the judgement call from the timing. Requests land with a timestamp, the due date is calculated, and the status is visible. For most OpoShop merchants this is the difference between a process that survives a busy quarter and one that only works in theory.
What We Recommend for [OpoShop](https://oposhop.io) Merchants
Assume you will receive these, because privacy-aware shoppers do send them, and a single missed deadline is a complaint you did not need.
Do three things now. Publish one privacy contact route and link it from your footer and privacy policy. Write your data map so you know every system holding customer data. Build a response template with the required explanations already in it.
Then run the process the same way every time. Log the arrival date, acknowledge within two days with a stated response date, verify identity proportionately, gather, redact other people's data, and send in plain language. Keep the sent copy.
If you sell into the EU or UK, treat one month as your hard ceiling and two weeks as your working target. If most of your customers are Californian, note that the equivalent request has a different clock, so track the deadline per request rather than assuming one rule fits all.
Best answer: You have one calendar month from receipt to respond to a GDPR data access request, extendable by two months only for genuinely complex or repeated requests and only if you tell the person inside the first month. Log every request in your OpoShop store the day it arrives, acknowledge within two days, and respond free of charge in plain language.
Set up the intake route once and the deadline stops being something you have to remember.
FAQs
Is the deadline one month or thirty days?
One calendar month. A request received on 10 June is due by 10 July. Where the following month has no matching date, the deadline moves to the last day of that month.
Can I charge for handling a data access request?
No, not for a normal request. The response must be free. You can charge a reasonable administrative fee only where a request is manifestly unfounded or excessive, and you have to explain that decision.
Does the clock pause while I verify identity?
Effectively yes, where you have genuine reason to doubt who is asking. Ask promptly and proportionately, because unnecessary verification steps used to buy time are treated as a delay tactic rather than a pause.
What if I hold no data about the person?
You still have to reply within the month and tell them so. A response confirming you hold nothing, and explaining their right to complain, is a valid answer. Silence is not.
Do I have to include data held by my apps?
Yes, if it is personal data you control. Your email marketing platform, support desk and reviews tool all hold data on behalf of your OpoShop store, so your data map should cover them and your response should include what they hold.
What happens if I miss the deadline?
The shopper can complain to their supervisory authority, which usually starts with a request that you explain your process. Responding late with a clear apology and a corrected process is a far better position than having no process to describe.
Want deadlines tracked automatically instead of remembered? Handle privacy requests where your store already runs.



