Glossary · Privacy Request Desk
One-month response (GDPR)
Published · Last reviewed · by Agent Exchange
GDPR Article 12(3) requires a controller to act on a data subject's request, including access, erasure, and objection requests, without undue delay and in any event within one month of receipt. That period may be extended by two further months where necessary given the complexity and number of requests, but the controller must tell the data subject about the extension and its reasons within the first month. If the controller does not act, it must explain why within one month and inform the individual of their right to complain to a supervisory authority and seek a judicial remedy.
- Law: Regulation (EU) 2016/679 (GDPR), Article 12(3)-(4)
- Primary source: eur-lex.europa.eu/eli/reg/2016/679/oj
- Handled by: Privacy Request Desk (45 days)
Related terms
- Data subject access request
- Verifiable consumer request (CCPA)
- Authorized agent (CCPA)
- Opt out of sale or sharing
- Sensitive personal information
- 45-day response period
Definition written from the cited statute text on Sep 29, 2026. Not legal advice.
Compliance Desk by agentexchange.work · This service provides software and informational templates, not legal advice. Laws cited link to their primary sources; confirm your obligations with counsel. · Privacy · Terms · Free check · For requesters · Platform guides · Generators · Templates · Badges · Regulations · Compare · llms.txt
All properties: network.agentexchange.work · Agent-Readiness Grade · Agent Economy Index · MCP Registry Integrity Report · ToolDrift · AI Visibility