About this tool
Manage data-access requests with their deadlines, responses and supporting evidence.
DSAR Request Tracker takes a plain list of data subject access requests — one per line as ID, date received, deadline in days, status and owner — and calculates each due date and how many days are left or overdue against a review date you set. Requests marked completed or closed stop the clock; everything else is counted as open and, if the due date has passed, flagged as overdue with the number of days. Privacy teams get a queue view with the countdown already done instead of a spreadsheet of dates they have to subtract by hand.
Open DSAR Request Tracker on AltFTool — it loads instantly in your browser.
Paste your queue into the Requests box, one line per request as ID | received date | deadline days | status | owner.
Set the Review date the countdown is measured from, or load the 'Example queue' preset to see the expected format.
Read the ID, Received, Due, Status, Owner and Clock table, where every open row shows days left or days overdue.
The deadline days column is set per line, so requests under different regimes or with granted extensions sit in the same queue with correct due dates.
Late requests show the exact number of days past due, which is the number a regulator or an escalation will ask for.
A line with an unparseable received date is reported as an invalid date rather than being given a plausible-looking deadline.
Under GDPR and UK GDPR the response is due without undue delay and within one month of receipt, extendable by a further two months where the request is complex or numerous, provided you tell the person within the first month. Under California's CCPA/CPRA the deadline is 45 days, extendable once by another 45.
Whatever applies to that request. The default is 30 days, which approximates the GDPR one-month clock; enter 90 for a GDPR request where you have granted the full two-month extension, or 45 for a CCPA request.
From the date the request was received, which is the date you enter in the second column. Time spent verifying the requester's identity does not reset that clock under GDPR, although the response period can pause until you have the information you reasonably need to identify them.
No, the calculation runs in your browser on the text you paste and nothing is submitted. It is a deadline calculator rather than a compliance record, so keep the authoritative log in your own case system and check obligations with your DPO or privacy counsel.