The controller must respond within one month of the relevant time, which is the latest of receipt of the request, receipt of identity information asked for under Article 12(6), and payment of any fee. The period may be extended by two further months for complex or numerous requests by notice to the data subject given within the first month and stating the reasons. For an access request, where the controller reasonably needs more information to identify the information or processing sought (for example because it holds a large amount about the person), it may ask for it and the time until the answer arrives does not count. Requests received before 5 February 2026 keep the earlier time limits.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.