What Is the Deadline to Respond to a GDPR Data Access Request?

What Is the Deadline to Respond to a GDPR Data Access Request?
Quick answer: One calendar month from the day you receive the request. You can extend by a further two months if the request is genuinely complex or you have received several from the same person, but you have to tell them inside the original month and explain why. The response is free, and it has to go out even if your answer is that you hold nothing. The clock starts when the request arrives anywhere in your business, not when it reaches the person who handles it.

One Calendar Month, Counted the Simple Way

The deadline is one calendar month, not thirty days. If a shopper emails you on 3 March, the response is due by 3 April. If they email on 31 January, the deadline lands on the last day of February, because there is no 31st.

The standard is actually stricter than the deadline suggests. The rule is to respond without undue delay and in any event within one month. A request you could have answered in three days should not sit for twenty-eight because the calendar allows it.

Weekends and public holidays do not extend anything. If the due date falls on a Sunday or a bank holiday, most authorities accept the next working day, but building your process around that margin is a bad habit.

The response also has to be free. You cannot charge a handling fee, and you cannot make the shopper create an account or use a specific form to exercise the right. A store on OpoShop has to accept a valid request however it arrives, including a reply to a marketing email or a message on social.

The Clock Starts Earlier Than Most Merchants Think

This is where deadlines get missed, and it is almost never because someone ignored a request on purpose.

The clock starts when the request reaches your organisation, through any channel, in any wording. It does not start when it reaches the right inbox. A message sitting unread in a shared support address for eleven days has already used eleven days of your month.

Requests also rarely announce themselves. Shoppers do not write "I am exercising my Article 15 right of access". They write "can you send me everything you have about me" or "what data do you hold on my account". Both are valid requests and both start the clock.

  • Any channel counts: Email, contact form, chat, social message, or a phone call your team takes.
  • Any wording counts: No magic words, no template, no requirement to cite the regulation.
  • Any recipient counts: A request to a customer service agent is a request to the business.
  • Third parties can ask: An authorised representative acting for the shopper can make the request on their behalf.

There is one legitimate pause. If you have reasonable doubts about who is asking, you may request information to verify identity, and the deadline effectively runs from when you receive that confirmation. Use it honestly. Asking a known account holder emailing from the address on file to post a photo of their passport is a delay tactic, and regulators treat it as one.

For a merchant on OpoShop, the cleanest fix is a single intake point that timestamps every request on arrival, so the due date is calculated automatically rather than reconstructed from an email thread later.

Track privacy requests in one place

When You Can Extend, and How to Do It Properly

The two-month extension is real, and it is narrower than merchants hope.

It applies where the request is complex or where the same person has submitted a number of requests. Complexity means genuine difficulty, such as data spread across many systems, or material that needs careful redaction because it involves other people. Being busy is not complexity. Being a small team is not complexity.

The mechanics matter as much as the grounds. You must inform the shopper within the first month that you are extending, and you must explain the reason. An extension you decide on quietly in week five is not an extension. It is a missed deadline.

There is also a separate route for requests that are manifestly unfounded or excessive, usually meaning repetitive. There you can charge a reasonable fee based on administrative cost, or refuse. Both are high bars, both require you to explain your reasoning, and you still have to reply within the month telling the person what you decided and that they can complain to their supervisory authority.

Most ecommerce requests are neither complex nor excessive. A typical OpoShop store holds order history, addresses, email marketing status and some analytics identifiers, which is a fifteen minute export once you know where to look.

What Actually Has to Go Back to the Shopper

The response is more than a data dump, and it is less than everything you have ever touched. Both mistakes are common.

You need to provide a copy of their personal data, plus supporting information: the purposes of processing, the categories of data, who you shared it with, how long you keep it, where it came from if not from them, and their rights to rectification, erasure, restriction, objection and complaint.

The format should be concise, transparent and intelligible. A raw database export with column names like usr_attr_7 does not meet that standard. Plain labels do.

You also have to protect other people. If an order note contains another customer's details, or an internal message names a staff member's personal information, redact it. The right of access is to their data, not to your records wholesale.

Three things you do not have to hand over: your internal commercial analysis that is not personal data, information that would reveal trade secrets or another person's data without justification, and material covered by other legal protections. Redact narrowly and explain that you have done so.

For a typical OpoShop store the finished response runs to a few pages. Account details, an order table, marketing consent status, support history, and a short list of technical identifiers with a sentence each explaining what they are for.

How to Handle a Request Inside the Deadline

A repeatable process turns this from a scramble into a task. The goal is a clear owner, a fixed intake point and a template you are not writing from scratch.

1
Log it the day it arrives
Record the request with its arrival timestamp and calculate the one month due date immediately, before anything else happens.
2
Confirm receipt quickly
Reply within a day or two acknowledging the request and stating the date you will respond by, which prevents most follow-up chasing.
3
Verify identity proportionately
Match the request to the account it concerns, and only ask for extra proof if there is genuine doubt about who is asking.
4
Gather from every system
Pull order and customer records, email marketing status, support tickets, and any analytics or advertising identifiers tied to that person.
5
Send a plain-language response
Deliver the data in a readable format with the required explanations, and keep a copy of what you sent and when.

The three parts that decide whether you hit the deadline are below.

1. Give every request one front door

Requests arriving in four different inboxes is the single biggest cause of missed deadlines for small stores.

Publish one privacy contact route, link it from your footer and your privacy policy, and brief whoever answers support to forward anything that smells like a data request the same day. A store on OpoShop that funnels these into one tracked inbox with automatic due dates removes the entire class of problem.

2. Know your data map before you need it

Write down where customer personal data lives, once, in advance. Orders, customer accounts, email marketing platform, support desk, reviews app, shipping and returns tools, and any analytics or ad platform identifiers you can tie to a person.

That list turns a stressful search into a checklist. Do it on a quiet afternoon rather than on day twenty-five of a live request, and update it whenever you install a new app that stores customer data.

3. Answer in language a shopper can read

Structure the response by category. Account details, orders, marketing preferences, support history, technical identifiers. Under each, the data, then a one line explanation of why you hold it.

Then add the required context: retention periods, who you shared it with, and their other rights including the right to complain to a supervisory authority. Keep a copy of the exact response, because your ability to show you complied depends on it.

Shared Inbox vs Spreadsheet Tracking vs a Tracked Request Queue

How you track these matters more than how you word them, because deadlines are missed through invisibility rather than refusal.

MethodHow deadlines are trackedFailure modeFits
Shared support inboxWhoever notices, if they noticeRequests buried under normal ticketsVery low volume, one person handling support
Manual spreadsheetSomeone logs each request by handDepends entirely on remembering to log itSmall teams with a disciplined routine
Tracked request queueTimestamped on arrival with an automatic due dateVery few, provided intake is routed to itAny store with EU, UK or California traffic

A shared inbox works right up until the week you are busy, which is exactly when a request is most likely to arrive.

A spreadsheet is a real improvement, since it makes deadlines visible. It still relies on a human noticing the request is a request, which is the step that actually fails.

A tracked queue removes the judgement call from the timing. Requests land with a timestamp, the due date is calculated, and the status is visible. For most OpoShop merchants this is the difference between a process that survives a busy quarter and one that only works in theory.

What We Recommend for [OpoShop](https://oposhop.io) Merchants

Assume you will receive these, because privacy-aware shoppers do send them, and a single missed deadline is a complaint you did not need.

Do three things now. Publish one privacy contact route and link it from your footer and privacy policy. Write your data map so you know every system holding customer data. Build a response template with the required explanations already in it.

Then run the process the same way every time. Log the arrival date, acknowledge within two days with a stated response date, verify identity proportionately, gather, redact other people's data, and send in plain language. Keep the sent copy.

If you sell into the EU or UK, treat one month as your hard ceiling and two weeks as your working target. If most of your customers are Californian, note that the equivalent request has a different clock, so track the deadline per request rather than assuming one rule fits all.

Best answer: You have one calendar month from receipt to respond to a GDPR data access request, extendable by two months only for genuinely complex or repeated requests and only if you tell the person inside the first month. Log every request in your OpoShop store the day it arrives, acknowledge within two days, and respond free of charge in plain language.

Set up the intake route once and the deadline stops being something you have to remember.

Set up a privacy request inbox

FAQs

Is the deadline one month or thirty days?

One calendar month. A request received on 10 June is due by 10 July. Where the following month has no matching date, the deadline moves to the last day of that month.

Can I charge for handling a data access request?

No, not for a normal request. The response must be free. You can charge a reasonable administrative fee only where a request is manifestly unfounded or excessive, and you have to explain that decision.

Does the clock pause while I verify identity?

Effectively yes, where you have genuine reason to doubt who is asking. Ask promptly and proportionately, because unnecessary verification steps used to buy time are treated as a delay tactic rather than a pause.

What if I hold no data about the person?

You still have to reply within the month and tell them so. A response confirming you hold nothing, and explaining their right to complain, is a valid answer. Silence is not.

Do I have to include data held by my apps?

Yes, if it is personal data you control. Your email marketing platform, support desk and reviews tool all hold data on behalf of your OpoShop store, so your data map should cover them and your response should include what they hold.

What happens if I miss the deadline?

The shopper can complain to their supervisory authority, which usually starts with a request that you explain your process. Responding late with a clear apology and a corrected process is a far better position than having no process to describe.

Want deadlines tracked automatically instead of remembered? Handle privacy requests where your store already runs.

Never miss a request deadline

Ready to dive in?

Learn more