CCSP Legal, Risk, and Compliance Practice Question
A company using a SaaS application for HR management receives a data subject access request (DSAR) under GDPR from an employee. The cloud provider is the data processor. The company as data controller must respond within what timeframe?
⚠ Common exam trap
CCSP often tests the confusion between GDPR timelines: 72 hours for breach notification, one month for DSAR response, and other jurisdictions' deadlines like 45 or 90 days; candidates must distinguish the specific obligation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
One month
Under GDPR Article 12(3), the data controller must respond to a data subject access request (DSAR) without undue delay and in any event within one month of receipt of the request. This one-month period can be extended by two further months for complex requests, but the baseline deadline is one month. The cloud provider as processor must assist the controller, but the controller bears the legal obligation to respond within that timeframe.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
One month
Why this is correct
Under GDPR Article 12(3), the controller must respond to a data subject access request without undue delay and in any event within one month of receipt, extendable by two further months for complex requests. The processor's role does not alter this controller deadline.
- ✗
90 days
Why it's wrong here
GDPR Article 12(3) sets one month, extendable by two further months for complex requests, so 90 days exceeds the statutory window. The figure is tempting because many other privacy regimes, such as certain US state laws, do permit 45- or 90-day response periods, making it familiar to practitioners.
- ✗
45 days
Why it's wrong here
GDPR Article 12(3) requires response within one month, extendable by two months for complex or numerous requests, so 45 days is not the baseline. The figure is tempting because several US state privacy laws and other frameworks do specify 45 days, but that is not the GDPR default.
- ✗
72 hours
Why it's wrong here
GDPR requires controllers to answer DSARs within one month, extendable by two. Seventy-two hours is the breach notification deadline to the supervisory authority under Article 33, so it applies when reporting a personal data breach, not when fulfilling an employee's access request.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.