Glossary Terms

Data Subject Access Request (DSAR)

A request by a person to obtain access to personal data and information about how it is being processed.
On this page

What is a data subject access request?

A data subject access request, commonly called a DSAR or subject access request, is a request by an individual to obtain access to personal data about them and information about how that data is processed. Depending on the applicable law, the response may include purposes, categories, recipients, retention, sources, rights and information about automated decision-making.

A DSAR is not limited to information stored in a customer profile. Relevant data may appear in emails, support tickets, human-resources systems, documents, logs, recordings, collaboration tools, archives and vendor platforms.

How is a DSAR handled?

The organisation should capture the request, confirm the applicable right and verify identity proportionately. It may clarify scope when the request is broad, but should not create unnecessary barriers. A case owner coordinates searches across systems and business teams.

Collected material should be reviewed for relevance, duplication, legal privilege, confidentiality and the personal data of other people. Redaction or another balancing method may be needed before information is delivered securely.

Why are access requests operationally difficult?

Data may be fragmented, duplicated or stored in unstructured formats. Different systems use different identifiers, and business owners may not understand what needs to be searched. Large exports can also reveal another person’s information or technical data that requires explanation.

A current data inventory, defined search procedures and trained response teams reduce delay and inconsistency. Organisations should preserve evidence of searches, decisions, approvals and delivery.

What should a DSAR response include?

The response should be understandable and provided in the required format. Raw technical exports may need context so that the person can understand the information. The organisation should explain any information withheld and provide complaint or escalation routes where required.

Deadlines, permitted extensions and fees vary by jurisdiction. Requests should therefore be logged immediately and monitored through a controlled workflow.

Frequently asked questions

Does a person need to use the term DSAR?

No. Any communication that clearly asks for access to personal data may qualify, regardless of the wording or channel.

Can identity documents always be requested?

No. Verification should be proportionate. Excessive collection can create additional privacy risk when identity is already reasonably established.

Must every email mentioning the person be provided?

Not automatically. The organisation must identify personal data and consider scope, relevance, exemptions and the rights of others.

Can a DSAR be refused?

Some laws permit refusal or limitation in specific circumstances, such as manifestly unfounded or excessive requests, but the reasoning should be carefully documented.

How should the response be delivered?

It should be secure, accessible and in the required format, with clear instructions and protection against disclosure to the wrong person.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.