DSAR
A DSAR (Data Subject Access Request) is a formal request by an individual to access, correct, or delete personal data held about them. Learn GDPR requirements, response timelines, and what fulfilment operationally requires.
What is a Data Subject Access Request (DSAR)?
A Data Subject Access Request, commonly called a DSAR, is a formal request made by an individual to exercise their legal rights over personal data held about them. Under GDPR and equivalent frameworks including CCPA and DPDP, individuals have the right to know what data an organisation holds, to receive a copy of it, to have inaccuracies corrected, and in specific circumstances to have it deleted. A DSAR is the formal mechanism through which any of those rights are invoked.
Organisations receiving a valid DSAR have a legal obligation to respond. The clock starts on receipt.
How DSAR fulfilment works
A DSAR triggers a defined process with a regulatory deadline attached. Under GDPR, organisations have one calendar month to respond. That timeline is not extendable unless the request is complex or the individual has submitted multiple requests simultaneously, in which case an additional two months is available with notification to the requester.
Four steps define the response process.
Identity verification. The organisation must confirm the requester is who they claim to be. This protects both the organisation and third parties whose data might otherwise be disclosed. The verification method must be proportionate: asking for a driving licence to confirm an email address customer relationship is excessive. But basic confirmation that the request comes from the person whose data is sought is always required.
Data search across all systems. This is where most DSAR responses fail. The obligation covers all personal data held about the individual, across every system where it exists. Not just the primary CRM or customer database. The analytics warehouse. The email marketing platform. The development database seeded from production three months ago. The daily backup snapshot. The SaaS integration that synced customer records to a business intelligence tool. Each copy is in scope. Finding them all is the operational challenge.
Compilation and review. The located data must be compiled into a coherent response. Third-party data and information subject to exemptions must be identified and either redacted or withheld with explanation. The response format must be accessible and intelligible.
Response delivery within deadline. The response must be delivered within the statutory timeframe at no charge. Under GDPR, manifestly unfounded or excessive requests can be refused or charged for, but organisations bear the burden of demonstrating the request meets that threshold.
DSAR vs right to erasure: the distinction
A DSAR and a right to erasure request are different rights under the same framework. Both are exercised by individuals. Both require organisational action within a deadline. But they produce different outcomes.
Dimension | DSAR (Right to Access) | Right to Erasure |
|---|---|---|
What the individual receives | A copy of their personal data | Deletion of their personal data |
Organisational obligation | Find, compile, and provide data | Find and delete data from all systems |
Applicable conditions | Generally unconditional | Subject to exemptions (legal obligation, legitimate interest etc.) |
Complexity | Compilation and redaction | Cross-system deletion propagation |
GDPR article | Article 15 | Article 17 |
Both rights share the same foundational operational requirement: finding all personal data associated with the individual across all systems. That requirement doesn't change with the type of request. What changes is what happens to the data once found.
Why DSAR fulfilment is operationally harder than it looks
Most organisations have a process for handling DSARs from their primary systems. A customer submits a request. The CRM team pulls the record. The support team pulls the ticket history. The response goes out.
That process covers perhaps 40% of the actual data. The rest is harder.
Consider what a typical enterprise data estate actually contains about a customer. A record in the production CRM. A copy in the analytics data warehouse, replicated by an ETL pipeline running nightly. Another copy in a BI tool the marketing team uses. A row in a development database that a data scientist built from a production export six months ago, still running on a shared cloud instance. Several backup snapshots from various dates. A record in the email marketing platform synced via API. A reference in the customer support platform, the billing system, and the order management database.
A DSAR response that covers the CRM and the support platform but misses the rest isn't legally complete. It's a partial response to a legal obligation. If the supervisory authority investigates, or if the individual knows their data is held in systems not covered by the response, the incomplete response becomes a compliance failure.
That gap exists because most organisations' data inventories don't reflect the full reality of their data estate. Manual inventories capture what system owners documented. They don't capture the analytics copies, developer exports, SaaS integrations, and orphaned backups that accumulate continuously.
DSAR requirements under GDPR, DPDP, and CCPA
All three frameworks create individual data rights that generate DSAR-equivalent processes, but with different specifics.
GDPR (EU) grants data subjects the right to access, correct, erase, restrict processing of, and port their personal data. Responses required within one month. Organisations must respond free of charge. Failure to respond or incomplete responses can be escalated to the relevant supervisory authority.
DPDP (India) grants Data Principals the right to access information about personal data being processed, the right to correction and erasure, and the right to grievance redressal. DPDP's erasure right is particularly significant operationally because it applies to all copies of data across all systems, including those held by Data Processors on behalf of the Data Fiduciary.
CCPA (California) grants consumers the right to know what personal information is collected, to request deletion, and to correct inaccurate information. Businesses must respond to access requests within 45 days, extendable by a further 45 days with notice.
