Every right in Chapter III of the Regulation arrives at a software company as a message: a user asks what the company holds about them, a former employee asks for a copy, a customer's end user asks to be erased. Article 12 sets the procedure for all of them, and its paragraph 3 sets the clock: information on action taken on a request under Articles 15 to 22 is provided without undue delay and in any event within one month of receipt. This article reads Article 12 and Article 15 against the catalogue StandardOS keeps of the Regulation, where the row for Article 12(3) carries the month as a clock, and against the free page that computes the deadline and writes the answer.

The month: from receipt, by the period rule

The period runs from receipt, which is the day the request reached the company through any of the channels it offers, not the day someone read it. A period expressed in months ends with the expiry of the day of the last month that bears the same date as the day it started, or the last day of that month where there is none: the rule of Regulation (EEC, Euratom) No 1182/71, which the European Data Protection Board applies to Article 12(3) in its guidelines on the right of access. A request received on 31 January is therefore answered by 28 February, or 29 in a leap year; one received on the 13th of any month by the 13th of the next. The page computes the date by that rule and does not move a deadline that falls on a weekend, because the safe reading is to answer earlier, not later. Article 12(1) adds the form: in writing or by other means, including electronic means, and orally only where the data subject asks for it and their identity is proven; Article 15(3) adds that a request made electronically is answered in a commonly used electronic form unless the data subject asks otherwise.

The two further months, and the notice inside the first

Article 12(3), second sentence, allows the period to be extended by two further months where necessary, taking into account the complexity and number of the requests. The extension is not a second month granted by silence: the controller informs the data subject of the extension and its reasons within one month of receipt, so the first deadline survives as the day of that notice, and only the substance moves to the third month. A company that receives a single access request from one user cannot honestly call it complex; the extension is for the company that receives hundreds after a breach, or one request that spans years of records across several systems. The page keeps both dates apart: the day the notice was due and the day the answer is.

Refusal, fee and identity: the three other paragraphs

Article 12(4) covers the company that will not act on the request: it informs the data subject without delay and at the latest within one month of receipt of the reasons, and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy. Silence is not a refusal; a refusal is a letter with reasons, on the same clock. Article 12(5) makes the answer free of charge; only a manifestly unfounded or excessive request, in particular because of its repetitive character, allows the company to charge a reasonable fee based on administrative costs or to refuse to act, and the company bears the burden of demonstrating that character. A second request a year later is not repetitive; the same request every week is. Article 12(6) lets the company request additional information to confirm the identity of the person asking where it has reasonable doubts, which is the case for a request from an unknown address about a named account and not the case for a request sent from the account itself; the question does not stop the clock, and a company that asks for a passport copy from every requester has created a processing of its own it will have to justify.

The access answer: a copy and eight pieces of information

Article 15(1) gives the data subject the right to obtain confirmation as to whether or not personal data concerning them are being processed and, where they are, access to the data and eight pieces of information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient, in particular in third countries or international organisations; (d) where possible, the envisaged period of storage or the criteria used to determine it; (e) the existence of the rights to rectification, erasure, restriction and objection; (f) the right to lodge a complaint with a supervisory authority; (g) where the data are not collected from the data subject, any available information as to their source; (h) the existence of automated decision-making, including profiling, under Article 22(1) and (4), with meaningful information about the logic involved and the significance and envisaged consequences for the data subject. Article 15(3) adds the copy of the personal data undergoing processing, further copies at a reasonable fee, and the electronic form; Article 15(4) keeps the copy from adversely affecting the rights and freedoms of others, which is why a copy of a support ticket is redacted of the agent's private notes about a third person and not of the agent's answers. For a software company, seven of the eight are already written: they are the columns of the record of processing, and (h) is either "none" or the description the product's own documentation gives of the model that scores, ranks or decides.

The processor's part, and the standard's

A company that hosts its customers' data receives requests it must not answer: the data subject is the customer's, and the customer is the controller. Article 28(3)(e) has the processor assist the controller, by appropriate technical and organisational measures and insofar as possible, in responding to requests for exercising the data subject's rights, which is the term the processor terms page writes and the export, search and deletion functions the product has to have. ISO/IEC 27701:2025 puts the same duties in Table A.1 as controls on access, correction and erasure, on the copy of PII and on handling requests, each of which the catalogue reads against Article 12(3) and (4), so a certified system carries the month as a procedure with a record behind it, not as a memory.

What to do with it

Log every request on the day it arrives, in one place, with the right it exercises: that record is the start of the clock and the evidence the authority asks for first. Compute the deadline by the period rule and write the notice of extension or of refusal on the first date, never after it. Answer access requests from the record of processing and add the copy from the product; answer erasure and rectification requests and then tell each recipient of the data under Article 19. The request clock does the arithmetic and the writing; the breach clock sits beside it for the request that turns out to describe a breach, and the duties determination says which of the other duties the same company carries.