What would you do if a customer asked to see every piece of personal data your organisation holds about them? Could you respond confidently within the legal deadline? Or would the request expose gaps in how your business stores and manages personal information?
This is exactly what a Data Subject Access Request (DSAR) demands. It is a legal right that allows individuals to request access to their personal data from any organisation that processes it. Under regulations like GDPR and CCPA, businesses are legally required to fulfil these requests within strict timelines. Failing to do so can result in heavy fines and reputational damage.
This blog covers everything you need to know about a Data Subject Access Request (DSAR), from how it works and who can submit one, to the steps your organisation must take to respond correctly. Whether you are in compliance, legal, IT, or a leadership role, understanding DSARs is no longer optional.
A Data Subject Access Request (DSAR) is a formal right that puts individuals in control of their personal data.
Under GDPR Article 15, every individual has the right to know what personal data an organisation collects about them. This includes the purpose of processing, who the data has been shared with, and how long it will be stored. The CCPA provides similar rights under US state law, allowing California residents to request disclosure of collected personal information.
These laws make it clear that personal data belongs to the individual, not the organisation. A DSAR is the mechanism that enforces this principle. Other regulations, including Brazil’s LGPD, South Africa’s POPIA, and multiple US state privacy laws, also recognise this right in various forms.
Any individual whose personal data is processed by an organisation can submit a DSAR. This includes customers, employees, job applicants, contractors, and even website visitors. In many jurisdictions, a parent or legal guardian can submit a request on behalf of a child. Authorised representatives, such as solicitors, can also file DSARs with proper documentation.
A Data Subject Access Request covers all personal data an organisation holds about the requester. This can include contact details, transaction history, communication records, employment data, health information, and any sensitive personal information linked to the individual. It also includes data shared with third parties and any automated decision-making applied to their profile.
Understanding the DSAR process is essential for any organisation that collects or processes personal data.
A Data Subject Access Request can arrive through any communication channel. This includes email, web forms, phone calls, social media, or even verbal requests. There is no mandatory format. Once received, the organisation must verify the identity of the requester. This step prevents unauthorised access to someone else’s personal data. Verification methods can include asking for a copy of identification or confirming account details.
After verification, the organisation must search across all systems where personal data might exist. This includes CRM platforms, email servers, HR databases, cloud storage, backup systems, and third-party processors. Data fragmentation is one of the biggest challenges at this stage. Many organisations store personal data across dozens of disconnected systems, making a complete search difficult without proper data mapping.
Before sending the data back to the requester, the organisation must review it carefully. If the data contains references to other individuals, those details must be redacted to protect third-party privacy. Legal privilege, trade secrets, or ongoing investigations may also justify withholding certain information. However, any exemptions must be clearly explained to the requester with valid legal reasoning.
Every privacy regulation sets a strict deadline for responding to a Data Subject Access Request, and missing it carries real consequences.
Under GDPR, organisations must respond to a DSAR within one calendar month from the date of receipt. If the request is complex or if the organisation receives a high volume of requests, this can be extended by an additional two months. However, the organisation must inform the requester of the extension and the reason within the first month. Businesses should follow established GDPR best practices to stay prepared for incoming requests.
The California Consumer Privacy Act (CCPA) requires businesses to respond within 45 calendar days. A 45-day extension is available if the business notifies the consumer and provides a valid reason. Businesses must also confirm receipt of the request within 10 business days. Understanding the differences between GDPR vs CCPA helps organisations prepare for requests from different jurisdictions.
Beyond GDPR and CCPA, many other data privacy laws enforce DSAR rights. Brazil’s LGPD requires a response within 15 days. South Africa’s POPIA allows 30 days. US states like Virginia, Colorado, and Connecticut each set their own response windows, typically between 30 and 45 days. Organisations operating across borders must track and comply with each applicable timeline.
Ignoring or mishandling a Data Subject Access Request is not just a compliance gap. It is a business risk with financial and legal consequences.
Under GDPR, failure to comply with a DSAR can attract fines of up to 20 million euros or 4% of global annual turnover, whichever is higher. CCPA violations can cost up to $7,500 per intentional violation. These are not theoretical figures. Regulators have issued substantial GDPR penalties for DSAR failures in recent years, making this a very real financial threat.
Beyond fines, a failed DSAR response damages trust. Customers, employees, and partners expect organisations to handle their data responsibly. When a DSAR complaint reaches a supervisory authority, it often becomes a matter of public record. This can erode confidence in the brand and make customers reluctant to share their data in the future.
Individuals also have the right to seek compensation through the courts if an organisation fails to respond to their DSAR. Under GDPR, data subjects can claim damages for both material and non-material harm. This means the cost of non-compliance extends well beyond regulatory fines. It includes legal fees, settlements, and the operational disruption of defending against claims.
Even well-intentioned organisations struggle with DSARs due to operational and technical hurdles.
A structured approach to DSAR management reduces risk and ensures timely, compliant responses.
Every organisation should have a documented DSAR policy that outlines how requests are received, logged, verified, fulfilled, and closed. This policy should assign clear roles and responsibilities across departments. It should also define escalation paths for complex or high-volume periods. A well-documented policy ensures consistency and accountability in every response.
Knowing where personal data lives is half the battle. Organisations should maintain a comprehensive data inventory that maps every system, database, and third-party processor that handles personal data. Regular audits of this inventory ensure that new systems are included and decommissioned ones are removed. This makes it significantly faster to locate and retrieve data when a DSAR arrives.
DSARs can arrive at any department, not just the legal or compliance team. Frontline staff, HR teams, and customer service agents must all recognise a DSAR and know how to route it correctly. Regular GDPR staff training ensures that requests are not overlooked or mishandled. Training should cover recognition, escalation, and the legal timelines involved.
Manual DSAR fulfilment is time-consuming and error-prone, especially as request volumes continue to grow.
DSAR management tools can automatically log incoming requests, assign them to the appropriate team, and track progress against the legal deadline. This eliminates the risk of requests slipping through the cracks. Automated tracking also creates a complete audit trail, which is valuable evidence of compliance during regulatory inspections.
Automation platforms can connect to multiple data sources and search for personal data across them simultaneously. This drastically reduces the time spent on manual searches. Instead of coordinating across departments, a single platform can pull records from CRMs, HR systems, email archives, and cloud storage in one unified search.
Advanced DSAR tools can flag third-party data within retrieved records and suggest redactions. Some can also generate formatted response packages ready for delivery to the data subject. This reduces human error and speeds up the review process significantly. Handling user consent records alongside DSAR fulfilment ensures a comprehensive and transparent response.
A Data Subject Access Request is just one of several rights that individuals hold under data protection laws.
Organisations should prepare to handle all of these rights, not just DSARs. A comprehensive rights management framework ensures no request type catches the team off guard.
A Data Subject Access Request (DSAR) is a fundamental right that every individual holds under modern privacy laws. For organisations, it is both a legal obligation and an opportunity to demonstrate transparency. Building a clear process, training your teams, and investing in the right tools will turn DSAR compliance from a burden into a competitive advantage. The organisations that handle DSARs well are the ones that earn lasting trust.
Managing Data Subject Access Requests does not have to be a manual, stressful process. Seers helps organisations streamline DSAR fulfilment with automated tracking, centralised data discovery, and built-in compliance tools. Stay audit-ready and respond to every request on time.
START FREE TODAYUnder GDPR, organisations must respond to a Data Subject Access Request within one calendar month. If the request is particularly complex or the organisation is dealing with multiple requests simultaneously, this deadline can be extended by an additional two months. The requester must be informed of any extension within the original one-month period, along with a clear explanation of why the delay is necessary.
Under GDPR, organisations must provide the first copy of personal data free of charge. A reasonable fee can only be charged for additional copies or if the request is manifestly unfounded or excessive. Under CCPA, businesses cannot charge a fee for processing a standard DSAR. The key principle across most regulations is that exercising data rights should not come at a financial cost to the individual.
A DSAR response must include all personal data the organisation holds about the requester. This covers contact details, transaction records, communication logs, employment data, health records, and any profiling or automated decision-making information. The response should also confirm the purposes of processing, the categories of data held, any recipients the data has been shared with, and the intended retention period.
An organisation can refuse a DSAR only under very specific circumstances. Under GDPR, refusal is permitted if the request is manifestly unfounded or excessive, particularly if it is repetitive. The organisation must still respond to the requester, explaining the refusal and their right to lodge a complaint with the supervisory authority. Blanket refusals without valid legal grounds can lead to regulatory enforcement action.
A Data Subject Access Request applies to all personal data, including employee records. Current and former employees have the same rights as customers when it comes to accessing their data. This includes HR files, performance reviews, payroll records, internal communications referencing the employee, and any monitoring data collected during employment. Organisations must be prepared to search employee-related systems alongside customer databases.
When a DSAR response contains references to other individuals, the organisation must redact that third-party information before disclosure. The obligation is to provide the requester’s data without compromising anyone else’s privacy. If the third party consents to disclosure, their data can be included. Organisations should have clear redaction procedures in place to handle these situations efficiently and avoid accidental data breaches.
Under GDPR, if the request is made electronically, the response should be provided in a commonly used electronic format such as PDF or CSV. The data must be presented in a clear, intelligible way that the requester can understand. Organisations should avoid delivering raw database exports or overly technical outputs. The goal is to provide the data in a format that is accessible and meaningful to the individual.
An organisation can ask for the reason behind a DSAR, but the requester is under no obligation to provide one. The right to access personal data is unconditional and does not depend on the individual’s motivation. Requiring a reason as a condition for processing the request would be considered a barrier to exercising data rights and could attract regulatory scrutiny.
Small businesses can manage DSARs effectively by creating a simple, documented process for handling requests. Assigning a single point of contact, maintaining a basic data inventory, and using affordable DSAR management tools can streamline the process. Regular staff awareness sessions ensure everyone knows how to recognise and escalate a request. The key is having a consistent, repeatable workflow rather than a large team.
Rimsha ZafarRimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.
Take our Free Cookie Audit and find out
Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.