Data Subject Access Request

Data Subject Access Request (DSAR) is a formal request from an individual to see, correct, port, or delete the personal data an organization holds about them, with regulated response timeframes.

Also known as: DSAR, subject access request, privacy request

Data Subject Access Request (DSAR) is a formal request made by an individual exercising their privacy rights to access, correct, port, or delete the personal information an organization holds about them. Privacy regulations including GDPR, CCPA, and UK GDPR grant these rights and set the response windows organizations must meet. For marketing operations, DSARs are where privacy policy stops being abstract and starts requiring the data inventory to actually work.

What A Data Subject Access Request Means

A Data Subject Access Request is a request initiated by the individual the data is about, asking the organization to take a specified action against the personal data it holds. The actions vary by jurisdiction but typically include the right to access (a copy of the data), the right to rectification (correction), the right to erasure (deletion), the right to portability (a structured export), and the right to object to specific processing. Response windows are also set in regulation — typically 30 days under GDPR, 45 under CCPA — with limited extensions. The request can come from any channel and must be authenticated to confirm the person is who they claim to be.

How A Data Subject Access Request Works

In practice, fulfilling a Data Subject Access Request means locating an individual's data across every system that holds it — CRM, marketing automation, analytics, support tools, advertising platforms, warehouse — then taking the action the request specifies. Authentication confirms identity, a search runs across systems, the results are assembled, the action is performed, and the response is delivered to the requester. Mature organizations route DSARs through a privacy portal and run them through a documented workflow with ownership at each step. The work is much easier when data inventories are current; it becomes punishing when personal data is scattered and undocumented.

Common Pitfalls and Misconceptions

A common misconception is that Data Subject Access Requests are purely a legal department concern. Legal owns the policy, but marketing operations is often where the personal data actually lives, so MOps has to provide the infrastructure. Teams underestimate the volume that arrives once privacy notices direct users to a clear request channel, and they end up handling DSARs as scrambles instead of as a process. Another trap is treating deletion as record hiding rather than actual erasure; backups, exports, and replicated systems often retain data after the primary record is deleted, leaving the organization technically non-compliant. Identity verification is also routinely sloppy, either too lax (releasing data to the wrong person) or too strict.

Data Subject Access Request in Practice

The teams that fulfill Data Subject Access Requests reliably treat each request as a system test of their data inventory. Every DSAR validates that personal data lives where the inventory says it does, that retrieval works as documented, and that deletion actually deletes. Teams that handle DSARs as one-off scrambles never close the gap between policy and reality. The mature approach uses DSAR volume and turnaround time as leading indicators of compliance readiness: handling a request in days proves the infrastructure works when it matters, while missed deadlines signal that policy and operations have drifted apart. Investing in the DSAR workflow pays dividends across every privacy obligation.

Back to the glossary
Data Subject Access Request

Frequently asked questions

  • What rights does a DSAR cover?

    Depending on the applicable regulation, individuals may request access to their data, correction of inaccuracies, deletion, a portable copy, or restrictions on processing. The exact rights and how they apply vary by law and jurisdiction.

  • Why does marketing operations need to be involved?

    Personal data often lives in marketing systems like the CRM and automation platform. MOps usually does the practical work of finding and acting on that data, even though legal or privacy teams own the overall policy.

  • How can a team prepare to handle DSARs?

    Maintaining a data inventory that documents what personal data is held and where, keeping systems organized, and defining a clear fulfillment process all make DSARs faster and more accurate to handle.

  • Is there a deadline to respond to a DSAR?

    Yes. Privacy regulations typically require a response within a defined period, such as a number of days from receipt. Missing the deadline can create compliance exposure, so timely processes matter.

  • What makes DSARs difficult to fulfill?

    Scattered, duplicated, or undocumented personal data is the main challenge. If a person's data exists in many systems with no clear inventory, finding and acting on all of it accurately becomes slow and error-prone.

  • What is the timeline to respond to a DSAR under GDPR?

    GDPR generally requires a response within one month of receipt, extendable by two months for complex cases with notification to the data subject. Other regulations have similar but distinct timelines. Missing the deadline creates compliance exposure, so teams need workflows that reliably meet the response window.

  • Are DSARs free for individuals to submit?

    Generally yes, though regulations allow charging for manifestly unfounded, excessive, or repetitive requests. The first request is almost always free. Organizations cannot use cost as a barrier, so the operational process has to be designed to absorb DSAR volume without per-request friction.