Glossary · Compliance concepts

What is Data Subject Access Request?

Also known as: DSAR, Subject Access Request, SAR, Data principal request

A Data Subject Access Request (DSAR) is a request by an individual to exercise their rights over their personal data - most commonly to access a copy of the data an organization holds about them, but also to correct, delete, or port it. Privacy laws such as GDPR and India's DPDP Act give individuals these rights and set deadlines for organizations to respond.

Key takeaways

  • A DSAR is how individuals exercise data rights: access, correction, erasure, and portability.
  • GDPR generally requires a response within one month; other laws set their own deadlines.
  • Organizations must verify the requester's identity before disclosing personal data.
  • Handling DSARs at scale requires knowing where personal data lives across systems and vendors.
  • A repeatable DSAR workflow is itself evidence of privacy-program maturity.

How do organizations handle DSARs?

Under GDPR and comparable laws like the DPDP Act, organizations must have a process to receive requests, verify the requester's identity, locate the relevant personal data across systems and processors, and respond within the statutory deadline - one month under GDPR, extendable in limited cases.

Because personal data is often scattered across SaaS tools and sub-processors, a documented data map and a standard DSAR runbook are essential to respond accurately and on time.

Frequently asked questions

How long do I have to respond to a DSAR?
Under GDPR, generally one month from receipt, extendable by two further months for complex or numerous requests. Other regimes, such as India's DPDP Act, set their own timelines.
Can I charge for a DSAR?
Under GDPR, DSARs are usually free, though a reasonable fee or refusal is permitted for manifestly unfounded or excessive requests.
Do I have to verify the requester's identity?
Yes. You must take reasonable steps to confirm the requester is the data subject (or an authorized representative) before disclosing personal data, to avoid unauthorized disclosure.

Authoritative sources

← Back to the glossary