FAQ
What deadline applies to each request?
UK and EU requests get your default SLA (30 days out of the box); California requests get 45 days. The clock starts at verification.
1 min readLast updated 17 July 2026
What deadline applies to each request?
The clock starts when the requester verifies their email, not when they hit submit. An unverified submission never starts a legal clock, which protects you from junk and typo'd addresses.
From verification:
- UK requests (UK GDPR): your default SLA from Settings. Out of the box that's 30 days, in line with the "one month" the law requires.
- EU requests (EU GDPR): the same default SLA.
- US requests (CCPA/CPRA, California): 45 calendar days, set automatically regardless of your default.
- Somewhere else: no deadline is assumed until your team confirms which regime applies. Requests waiting for that confirmation are flagged. Don't let them sit.
Two things can change a deadline after intake:
- A workflow template with a shorter internal SLA tightens the due date. Templates can never extend the legal deadline.
- An overturned appeal reopens the request with a fresh clock: 45 days for US requests, your default SLA otherwise.
You'll be warned as deadlines approach: requests are flagged at 7 days out, 3 days out, and when overdue, and the daily digest lists what's due. If you genuinely need a legal extension (complex GDPR requests can be extended), agree it with the requester through the message thread and record it. The extension email template exists for exactly this.