DSAR Requirements by State: Response Deadlines, Rights, and Penalties

Compare DSAR response deadlines, consumer rights, identity verification, and penalties across all 19 US state privacy laws plus GDPR and UK GDPR.

Last updated: 2026-02-08

When someone submits a data subject access request, your response deadline and obligations depend on where they live. Nineteen US states now have comprehensive privacy laws with DSAR requirements, plus the EU's GDPR and the UK GDPR. Each has different deadlines, consumer rights, and penalties for non-compliance.

This page gives you the quick-reference view. Click any jurisdiction for the full DSAR requirements breakdown.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Consult a qualified attorney for guidance specific to your business.

DSAR Response Deadlines and Penalties

JurisdictionLawResponse DeadlineExtensionMax PenaltyCure Period
CaliforniaCCPA/CPRA45 days+45 days$7,500/violationNone
VirginiaVCDPA45 days+45 days$7,500/violation30 days
ColoradoCPA45 days+45 days$20,000/violationExpired
ConnecticutCTDPA45 days+45 days$5,000/violationExpired
UtahUCPA45 days+45 days$7,500/violation30 days (permanent)
OregonOCPA45 days+45 days$7,500/violationExpired
TexasTDPSA45 days+45 days$7,500/violationExpired
MontanaMTCDPA45 days+45 days$7,500/violation60 days (exp. Apr 2026)
DelawareDPDPA45 days+45 days$10,000/violationExpired
IowaICDPA90 daysNone$7,500/violation90 days (permanent)
NebraskaNDPA30 days+30 days$7,500/violation30 days (permanent)
New HampshireNHPA45 days+45 days$10,000/violationExpired
New JerseyNJDPA45 days+45 days$10K/$20K per violation30 days (exp. Jul 2026)
TennesseeTIPA45 days+45 days$7,500/violation60 days (exp. Jul 2027)
MinnesotaMCDPA45 days+45 days$7,500/violation30 days (exp. Jul 2026)
MarylandMODPA45 days+15 days only$10K/$25K per violation60 days (exp. Apr 2027)
IndianaINCDPA45 days+45 days$7,500/violation30 days (exp. Jan 2028)
KentuckyKCDPA45 days+45 days$7,500/violation30 days
Rhode IslandRIDTPPA45 days+45 days$10,000/violation30 days (exp. Jan 2027)
GDPR (EU)GDPR30 days+2 monthsEUR 20M or 4% revenueNone
UK GDPRUK GDPR30 days+2 monthsGBP 17.5M or 4% revenueNone

Key Patterns

Response deadlines: Most US states give you 45 days. Iowa is the most generous at 90 days. Nebraska is the tightest US state at 30 days. GDPR and UK GDPR are 30 days.

Extensions: Most states allow a 45-day extension. Maryland only allows 15 days. Iowa allows no extension at all. GDPR allows 2 months.

Cure periods: Many states had cure periods that have now expired. Utah, Iowa, and Nebraska have permanent cure periods. GDPR and California have no cure period.

Private right of action: Only California (for data breaches) and GDPR/UK GDPR allow individuals to sue directly. All other US state laws are enforced only by the Attorney General.

Consumer Rights by Jurisdiction

Not every state grants the same DSAR rights. Most grant access, deletion, and portability. Correction and profiling opt-out vary.

RightMost US StatesIowa/UtahGDPR/UK GDPR
AccessYesYesYes
CorrectionYesNoYes
DeletionYesYesYes
PortabilityYesYesYes
Opt out of saleYesYesYes
Opt out of targeted advertisingYesYesN/A (consent model)
Opt out of profilingYesNoYes
Appeal denied requestsYesNoVia DPA complaint

Identity Verification

Every jurisdiction requires identity verification before fulfilling a DSAR, but none prescribe a specific method. See our DSAR identity verification guide for practical approaches.

For full privacy law coverage of each jurisdiction, see boringgovernance.com.

Related Guides