DSAR Full Form: Data Subject Access Request

DSAR full form is Data Subject Access Request. Learn what people can ask for, response deadlines under GDPR and CCPA, fees, ID checks, exemptions and how to respond step by step.

DSAR Full Form: What Is a Data Subject Access Request?

The full form of DSAR is Data Subject Access Request. A DSAR is a request from an individual asking an organization to confirm whether it processes their personal data and, if so, to give them a copy of that data and details of how it is used. The right to make a DSAR comes from Article 15 of the GDPR, and similar rights exist under the UK GDPR, the California CCPA/CPRA and most other privacy laws.

DSAR, SAR and DSR: What Is the Difference?

TermFull formMeaning
DSARData Subject Access RequestA request to access your personal data. The most common name in the EU and US.
SARSubject Access RequestThe same request. The usual name in the UK, used by the ICO.
DSRData Subject Request (or Data Subject Rights request)Any request to exercise a privacy right: access, deletion, correction, portability, restriction or objection. A DSAR is one type of DSR.
Right to knowCCPA/CPRA termThe Californian equivalent of a DSAR.

What Can People Ask For in a DSAR?

Under Article 15 of the GDPR, a person has the right to receive:

  1. Confirmation of whether you process their personal data
  2. A copy of the personal data you hold about them
  3. The purposes of the processing
  4. The categories of personal data concerned
  5. The recipients or categories of recipients, including those in other countries
  6. How long the data will be kept, or the criteria used to decide that
  7. Their rights to correction, deletion, restriction and objection
  8. Their right to complain to a supervisory authority
  9. Where the data came from, if it was not collected from them
  10. Whether automated decision-making or profiling is used, the logic involved and its likely consequences
  11. The safeguards used for transfers outside the EEA

A DSAR covers all personal data, not just data in a customer database. That includes emails, chat logs, support tickets, CRM notes, call recordings, CCTV footage, log files, and online identifiers such as cookie IDs and consent records.

The Court of Justice of the EU has confirmed that people are entitled to know the identity of the specific recipients of their data, not just categories, where possible (Österreichische Post, C-154/21, 2023). It has also held that the "copy" must be a faithful and understandable reproduction of the data, which can mean providing extracts of documents or whole documents where that is needed to understand the data (C-487/21, 2023).

How Long Do You Have to Respond to a DSAR?

LawDeadlineExtension
EU GDPRWithout undue delay and within one month of receiptUp to two further months for complex or numerous requests, if you tell the person within the first month and explain why
UK GDPROne monthUp to two further months for complex requests
California CCPA/CPRA45 calendar daysA further 45 days when reasonably necessary, with notice to the consumer
Other US state laws (Virginia, Colorado, Connecticut, Texas and others)45 daysA further 45 days when reasonably necessary
Brazil LGPD15 days for a complete statementNone stated

Under the GDPR, the clock starts when you receive the request. If you need to verify the person's identity, many regulators, including the ICO, treat the deadline as starting once you have what you need to confirm it.

Can You Charge a Fee for a DSAR?

No, in most cases. Under the GDPR, the first copy must be free. You can charge a reasonable fee based on administrative costs only if a request is manifestly unfounded or excessive, or if the person asks for further copies. Under the CCPA, businesses cannot charge for responding to right-to-know requests, although they do not have to answer more than two in a 12-month period from the same consumer.

How Can a DSAR Be Made?

Under the GDPR, a DSAR does not need a special form or specific wording, and it does not need to mention the GDPR or use the words "subject access request". A request can be made:

  • By email or letter
  • Through a web form or privacy portal
  • Verbally, by phone or in person
  • Through social media or live chat
  • By someone acting on the person's behalf, such as a lawyer or a parent, with proof of authority

You can offer a preferred channel, such as an online form, but you cannot refuse a valid request because it came through a different one. Staff who deal with customers should be trained to recognise a DSAR and pass it on quickly.

Under the CCPA, businesses must offer at least two methods for submitting requests, including a toll-free number. Businesses that operate only online and have a direct relationship with the consumer can offer an email address instead of a phone number.

How to Respond to a DSAR: Step by Step

  1. Log the request. Record the date received, the channel, the requester and the deadline.
  2. Verify identity. Ask only for the information you need to be reasonably sure the person is who they say they are. Do not ask for more personal data than necessary.
  3. Clarify the scope if needed. If you process a large amount of data about the person, you can ask them to specify what they want, but the deadline does not stop while you wait.
  4. Search your systems. Use your data map and records of processing to find personal data across databases, email, file storage, CRM, support, marketing, analytics and vendor systems.
  5. Collect and review. Gather the data and remove anything that is not about the requester.
  6. Redact where needed. Protect other people's personal data and apply any legal exemptions, such as legal privilege.
  7. Respond. Send the data and the Article 15 information in a clear, concise format. If the request was made electronically, reply in a commonly used electronic format unless the person asks otherwise.
  8. Keep a record. Document what you searched, what you sent, what you withheld and why, and when you responded.

When Can You Refuse a DSAR?

  • The request is manifestly unfounded, for example it is made only to cause disruption, with no real intention to access the data.
  • The request is manifestly excessive, for example it repeats a recent request without a reasonable gap.
  • Providing the data would adversely affect the rights and freedoms of others, in which case you redact rather than refuse outright where possible.
  • A national law exemption applies, such as legal professional privilege or crime prevention.
  • You cannot verify the person's identity after reasonable efforts.

If you refuse, you must tell the person without undue delay and within the deadline, explain why, and inform them of their right to complain to a supervisory authority and to seek a judicial remedy.

Sample DSAR Request Letter

Individuals can use a short letter or email like this:

Subject: Data Subject Access Request

Dear Data Protection Officer,

Under Article 15 of the GDPR, I request confirmation of whether you process my personal data and, if so, a copy of that data, together with the information listed in Article 15(1), including the purposes, recipients, retention period and source of the data.

Name: [your full name]

Email or account ID: [the email or account you used]

Other details that may help locate my data: [for example, customer number or dates]

Please respond within one month of receiving this request.

Yours sincerely,

[your name]

Common DSAR Mistakes

  • Missing the deadline because the request was not recognised or was sent to the wrong team
  • Asking for excessive ID, such as a passport copy when an email confirmation would be enough
  • Searching only the main database and missing email, support tools, logs and vendor systems
  • Sending another person's data because it was not redacted
  • Providing raw exports that the person cannot understand
  • Not keeping a record of the response

Failing to respond properly to DSARs is one of the most common reasons people complain to supervisory authorities. Infringing data subject rights falls under the higher tier of GDPR fines, up to €20 million or 4% of global annual turnover.

DSARs and Cookie Consent Records

DSARs increasingly ask about website tracking: which cookies were set, whether the person consented, and which ad tech vendors received their data. Online identifiers such as cookie IDs and device IDs are personal data under the GDPR. A consent management platform that stores consent records with timestamps, banner versions and choices makes it much easier to answer these questions and to show that consent was valid.

How UniConsent Helps You Manage DSARs

UniConsent's Privacy Portal gives you one place to receive and manage data subject requests:

  • A branded privacy portal on your own domain, such as privacy.yourcompany.com, with your logo and colours
  • Structured workflows for access, deletion, correction and opt-out requests, with SLA tracking
  • Per-region deadlines for the GDPR, UK GDPR, CCPA/CPRA and US state privacy laws, with alerts before they expire
  • An audit trail that logs every action with timestamps
  • A request form or full portal you can embed on any page with a single snippet
  • A preference center that combines cookie consent, marketing opt-ins and communication preferences
  • Consent records from the UniConsent CMP to answer questions about cookie consent

Frequently Asked Questions

What is the full form of DSAR?

DSAR stands for Data Subject Access Request, a request from an individual to access the personal data an organization holds about them.

How long do I have to respond to a DSAR?

Under the GDPR and UK GDPR, you must respond within one month, extendable by two further months for complex or numerous requests. Under the CCPA and most US state privacy laws, you have 45 days, extendable by another 45 days.

Can I charge for a DSAR?

Not normally. The first copy must be free. Under the GDPR, you can charge a reasonable fee only for manifestly unfounded or excessive requests or for additional copies.

Does a DSAR have to be in writing?

No. Under the GDPR, a DSAR can be made verbally, by email, through social media or through a web form, and it does not need to use any particular wording.

Can I ask for ID before responding to a DSAR?

Yes, if you have reasonable doubts about the person's identity. Ask only for what is proportionate to confirm who they are.

What is the difference between a DSAR and a DSR?

A DSAR is a request to access personal data. A DSR, or data subject request, covers any privacy right, including deletion, correction, portability, restriction and objection.

What happens if I ignore a DSAR?

The person can complain to a supervisory authority or go to court. Regulators can order you to respond and issue fines of up to €20 million or 4% of global annual turnover for infringing data subject rights.

Further Reading

UniConsent Consent Manager for GDPR Compliance

  • Cookies scan and disclosing
  • JavaScript tags blocking and cookies blocking
  • Google Consent Mode v2 support
  • Certified IAB CMP
  • One-tag Implementation
  • Multiple languages support
  • Easy self-serve solution
  • Learn more from GDPR Compliance Guide

Microsoft certified CMP - UniConsent CMPIAB certified CMP - UniConsent CMPIAB TCF V2 certified CMP - UniConsent CMPIAB TCF Canada certified consent manager - UniConsent CMPGoogle-certified CMP Gold tire - UniConsent CMPGoogle-certified CMP partner

Comply With Global Privacy Regulations

Trusted by 5000+ of global publishers and marketers
  • sej
  • football365
  • sharethrough
  • districtm
  • pf1
  • tower cast

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up