← Tools

Axiom Compliance - free tool

DSAR and 72-hour breach deadline calculator

Enter the date a subject access request arrived, or the time you became aware of a personal data breach, and get the UK GDPR deadline.

Subject access request

Extended? complex or numerous requests only

Respond by

Enter the date received

The one-month response deadline appears here.

Personal data breach

Report to the ICO by

Enter when you became aware

The 72-hour report-by time appears here.

Runs entirely in your browser. Nothing you enter is sent anywhere, and the tool never asks who the request or breach concerns.

The one-month clock for a subject access request

Under UK GDPR a person can ask an organisation for a copy of the personal data it holds about them. This is a data subject access request, usually shortened to DSAR or SAR. You must respond without undue delay and at the latest within one month of receiving it.

One month does not mean 30 days. The period runs from the day the request arrives to the same date in the following month. A request received on 3 September is due on 3 October. Where the following month has no such date, the deadline is its last day, so a request received on 31 January is due on 28 February, or 29 February in a leap year. The calculator applies exactly that rule.

Two things can move the date. If the deadline falls on a weekend or a public holiday, guidance from the Information Commissioner's Office (ICO) treats the next working day as the deadline. The calculator tells you when the date is a Saturday or Sunday, but it does not know your public holidays. And the clock may not start on the day of receipt: if you genuinely need proof of identity, the period starts when you receive it, and if you hold a large amount of information and need the person to clarify what they want, the clock is paused until they do.

Because the last day varies between 28 and 31 days after receipt, many organisations adopt a flat 28-day internal target so that nobody has to work it out. There is more on running the whole process in handling a DSAR inside one month.

When you can extend

The deadline can be extended by up to two further months, making three months from receipt, where the request is complex or the person has made a number of requests. Being busy, or short of staff, is not a reason. If you extend, you must tell the person within the first month and explain why. Choose "Yes" under Extended and the calculator shows both the original one-month date and the extended one.

The 72-hour clock for a personal data breach

A personal data breach is a security incident that leads to personal data being lost, destroyed, altered, disclosed or accessed when it should not have been. If a breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.

The clock starts when you are reasonably certain that a breach has happened, not when the investigation is complete. It runs through evenings, weekends and public holidays. The calculator adds 72 hours to the date and time you enter and shows roughly how many hours are left on your own clock.

Three points are easy to miss. You do not need the full picture to report: the information can be given in phases. If you report after 72 hours you must give the reason for the delay. And if the breach is likely to result in a high risk to the people affected, you must also tell them directly, without undue delay. A breach that is unlikely to result in any risk does not need reporting, but the decision and the reasoning should still go in your breach record. The 72-hour breach clock walks through the assessment.

How the calculator counts

Both calculations use plain calendar dates and times, with no time-zone conversion, exactly as a spreadsheet would. The request deadline is the same day of the month one month, or three months, after receipt, capped at the last day of a shorter month. The breach deadline is the same clock time three days later. Days and hours remaining are measured against the date and time on your own device.

Common questions

Does the day of receipt count?

The period starts on the day of receipt, whether or not that is a working day, and ends on the corresponding date in the following month. A request that arrives on a Saturday is due on that same date next month, moved to the next working day if that date is itself a weekend or public holiday.

Does this cover other individual rights requests?

The same one-month period and the same extension apply to requests for rectification, erasure, restriction, portability and objection, so the request calculator works for those too.

Is anything I enter stored?

No. The calculation happens on this page, in your browser. The dates are held in the page address so that you can copy a link to a result. The tool never asks for a name, and the optional reference is used only on your printout.

Run every request and breach against the clock

The Axiom DSAR Log for Excel works out the one-month and extended deadlines for every request, counts the days down and flags anything overdue. The Data Breach Register does the same for the 72-hour reporting clock.

Want new guides and tools as they are published? You can subscribe on the Axiom homepage.

Independent tool notice: this is an original Axiom calculator using original wording, not affiliated with or endorsed by any regulator (including the ICO or the UK Government). References to UK GDPR, the Data Protection Act 2018 and ICO guidance identify the subject matter only.

This tool does date arithmetic. It is not legal advice and it does not decide when a clock started, whether an extension is justified or whether a breach is reportable: those depend on the facts. Check the current ICO guidance and take advice from a suitably qualified professional, such as your data protection officer or a solicitor, where you need it.