DSAR full form is Data Subject Access Request. Learn what people can ask for, response deadlines under GDPR and CCPA, fees, ID checks, exemptions and how to respond step by step.
The full form of DSAR is Data Subject Access Request. A DSAR is a request from an individual asking an organization to confirm whether it processes their personal data and, if so, to give them a copy of that data and details of how it is used. The right to make a DSAR comes from Article 15 of the GDPR, and similar rights exist under the UK GDPR, the California CCPA/CPRA and most other privacy laws.
| Term | Full form | Meaning |
|---|---|---|
| DSAR | Data Subject Access Request | A request to access your personal data. The most common name in the EU and US. |
| SAR | Subject Access Request | The same request. The usual name in the UK, used by the ICO. |
| DSR | Data Subject Request (or Data Subject Rights request) | Any request to exercise a privacy right: access, deletion, correction, portability, restriction or objection. A DSAR is one type of DSR. |
| Right to know | CCPA/CPRA term | The Californian equivalent of a DSAR. |
Under Article 15 of the GDPR, a person has the right to receive:
A DSAR covers all personal data, not just data in a customer database. That includes emails, chat logs, support tickets, CRM notes, call recordings, CCTV footage, log files, and online identifiers such as cookie IDs and consent records.
The Court of Justice of the EU has confirmed that people are entitled to know the identity of the specific recipients of their data, not just categories, where possible (Österreichische Post, C-154/21, 2023). It has also held that the "copy" must be a faithful and understandable reproduction of the data, which can mean providing extracts of documents or whole documents where that is needed to understand the data (C-487/21, 2023).
| Law | Deadline | Extension |
|---|---|---|
| EU GDPR | Without undue delay and within one month of receipt | Up to two further months for complex or numerous requests, if you tell the person within the first month and explain why |
| UK GDPR | One month | Up to two further months for complex requests |
| California CCPA/CPRA | 45 calendar days | A further 45 days when reasonably necessary, with notice to the consumer |
| Other US state laws (Virginia, Colorado, Connecticut, Texas and others) | 45 days | A further 45 days when reasonably necessary |
| Brazil LGPD | 15 days for a complete statement | None stated |
Under the GDPR, the clock starts when you receive the request. If you need to verify the person's identity, many regulators, including the ICO, treat the deadline as starting once you have what you need to confirm it.
No, in most cases. Under the GDPR, the first copy must be free. You can charge a reasonable fee based on administrative costs only if a request is manifestly unfounded or excessive, or if the person asks for further copies. Under the CCPA, businesses cannot charge for responding to right-to-know requests, although they do not have to answer more than two in a 12-month period from the same consumer.
Under the GDPR, a DSAR does not need a special form or specific wording, and it does not need to mention the GDPR or use the words "subject access request". A request can be made:
You can offer a preferred channel, such as an online form, but you cannot refuse a valid request because it came through a different one. Staff who deal with customers should be trained to recognise a DSAR and pass it on quickly.
Under the CCPA, businesses must offer at least two methods for submitting requests, including a toll-free number. Businesses that operate only online and have a direct relationship with the consumer can offer an email address instead of a phone number.
If you refuse, you must tell the person without undue delay and within the deadline, explain why, and inform them of their right to complain to a supervisory authority and to seek a judicial remedy.
Individuals can use a short letter or email like this:
Subject: Data Subject Access Request
Dear Data Protection Officer,
Under Article 15 of the GDPR, I request confirmation of whether you process my personal data and, if so, a copy of that data, together with the information listed in Article 15(1), including the purposes, recipients, retention period and source of the data.
Name: [your full name]
Email or account ID: [the email or account you used]
Other details that may help locate my data: [for example, customer number or dates]
Please respond within one month of receiving this request.
Yours sincerely,
[your name]
Failing to respond properly to DSARs is one of the most common reasons people complain to supervisory authorities. Infringing data subject rights falls under the higher tier of GDPR fines, up to €20 million or 4% of global annual turnover.
DSARs increasingly ask about website tracking: which cookies were set, whether the person consented, and which ad tech vendors received their data. Online identifiers such as cookie IDs and device IDs are personal data under the GDPR. A consent management platform that stores consent records with timestamps, banner versions and choices makes it much easier to answer these questions and to show that consent was valid.
UniConsent's Privacy Portal gives you one place to receive and manage data subject requests:
DSAR stands for Data Subject Access Request, a request from an individual to access the personal data an organization holds about them.
Under the GDPR and UK GDPR, you must respond within one month, extendable by two further months for complex or numerous requests. Under the CCPA and most US state privacy laws, you have 45 days, extendable by another 45 days.
Not normally. The first copy must be free. Under the GDPR, you can charge a reasonable fee only for manifestly unfounded or excessive requests or for additional copies.
No. Under the GDPR, a DSAR can be made verbally, by email, through social media or through a web form, and it does not need to use any particular wording.
Yes, if you have reasonable doubts about the person's identity. Ask only for what is proportionate to confirm who they are.
A DSAR is a request to access personal data. A DSR, or data subject request, covers any privacy right, including deletion, correction, portability, restriction and objection.
The person can complain to a supervisory authority or go to court. Regulators can order you to respond and issue fines of up to €20 million or 4% of global annual turnover for infringing data subject rights.
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up