What is a data subject request?
A data subject request, or DSR, is a request through which an individual exercises a privacy right. It is a broader category than an access request and can include deletion, correction, portability, restriction, objection, withdrawal of consent and rights relating to automated decision-making.
The rights available depend on the applicable law, the organisation’s role, the processing purpose and any relevant exceptions. A request may arrive through a web form, email, telephone, social media, customer support or an employee channel and does not need to use formal legal language.
How are DSRs managed?
A reliable workflow identifies the requester, applicable jurisdiction, right, deadline and systems involved. Identity should be verified proportionately, and the case should be assigned to an owner. Business, IT, legal, privacy and vendor teams may need to coordinate actions.
The organisation should maintain evidence of searches, deletion, correction, objections, communications and decisions. Automated workflows can help, but human review remains important for exceptions, complex identities and competing rights.
Why do DSR programmes fail?
Common problems include incomplete data inventories, unclear ownership, inconsistent identifiers, manual spreadsheets and failure to involve processors. A request may be marked complete in one system while copies remain in downstream tools, archives or marketing platforms.
Teams may also confuse different rights. A deletion request does not always require immediate removal of every record, and an objection may require assessment of the lawful basis and compelling grounds. Clear procedures help avoid both over-deletion and unjustified refusal.
How should performance be measured?
Useful metrics include volume, response time, overdue cases, request type, verification issues, systems searched, exceptions and complaints. Metrics should support improvement rather than encourage rushed responses that overlook accuracy or security.
Repeated requests about the same product or data use can reveal transparency or process problems that should be corrected at the source.
Frequently asked questions
Is a DSAR the same as a DSR?
A DSAR is a type of DSR focused on access. DSR is the broader term covering multiple privacy rights.
Can an authorised agent submit a request?
Some laws allow it, subject to appropriate evidence of authority and verification of the person represented.
Do processors handle DSRs?
Processors normally assist the controller under contract, while the controller remains responsible for assessing and responding.
Can records be retained after a deletion request?
Sometimes, where a legal obligation, defence of claims or another valid exception applies. Retained data should be limited and restricted.
Should organisations provide one request channel?
Required channels vary, but staff across all customer and employee channels should recognise and promptly route requests.



