When can a controller extend a DSAR response?
Article 12(3) requires the controller to provide information on action taken without undue delay and in any event within one month of receiving the request. The controller may extend that period by two further months only where necessary, taking into account the complexity and number of requests.
The extension is not automatic. The controller must tell the data subject within one month of receipt that it is extending the response period and must give the reasons for the delay.
- Record the date the request was received and the first one-month response deadline.
- Identify the concrete complexity or request volume that makes the extension necessary.
- Send the extension notice within the first month, with reasons for the delay.
- Do not extend merely because a processor or internal team is slow to retrieve information.
Can an EU GDPR deadline be extended because the request is complex?
Yes, but only under Article 12(3). The controller may extend by up to two further months where necessary because of the complexity and number of requests, and it must notify the data subject within one month of receiving the with the reasons for the delay.
Article 12(3) sets the one-month DSAR response period and the two-month extension rule.
EDPB access-right guidance explains that access must be fulfilled as soon as possible and that extension depends on complexity and number of requests.