Privacy & Data Protection

Data Subject Access Request (DSAR): A Practical Guide

Standarity Editorial Team·GDPR and CCPA privacy practitioners
··7 min read

A data subject access request, or DSAR, is a request from an individual to see the personal data an organisation holds about them and to learn how it is being used. Under GDPR Article 15 this is the right of access; under the CCPA and CPRA it is the right to know. Responding correctly is a legal obligation.

What a DSAR entitles the requester to

GDPR Article 15 gives individuals the right to confirmation of whether their data is being processed and, if so, a copy of that data plus supporting information: the purposes of processing, the categories of data, the recipients, the retention period, and their rights to rectification, erasure, and to lodge a complaint. The CCPA right to know is narrower in scope but similar in spirit, covering the categories and specific pieces of personal information collected, the sources, the business purpose, and the third parties with whom it is shared.

A DSAR can arrive by any channel: an email, a web form, a phone call, or even a social media message. There is no prescribed format, which is one reason organisations need a clear intake process. Our GDPR implementation guide and our CCPA vs GDPR comparison both cover how the access right differs across the two regimes.

Response deadlines: GDPR and CCPA

The clock starts when you receive the request, so identifying a DSAR quickly is critical. The two headline regimes set different windows.

  • GDPR Article 12: respond without undue delay and within one month of receipt
  • GDPR extension: extendable by two further months for complex or numerous requests, with the requester informed of the extension and the reason within the first month
  • CCPA and CPRA: respond within 45 days, extendable by a further 45 days when reasonably necessary
  • In both regimes the response is generally provided free of charge

DSARs are a real operational cost. Manual processing is widely benchmarked at around USD 1,524 per request, with the redaction step alone accounting for 40 to 60 percent of that cost. Many organisations report double-digit annual growth in DSAR volume, which is why tooling and a repeatable workflow matter.

How to handle a DSAR step by step

A consistent workflow keeps you inside the deadline and out of the two most common failure modes: missing data and disclosing someone else data by accident.

  • Log the request and record the date received so the deadline clock is unambiguous
  • Verify the identity of the requester using the least intrusive method sufficient, without collecting more data than necessary
  • Locate the personal data across every system, including email, backups, CRM, and unstructured stores
  • Redact third-party personal data and any information that would reveal another individual identity
  • Apply any lawful exemptions and document why each was relied on
  • Deliver the response in a concise, transparent, intelligible, and accessible form, usually electronically

What can be withheld, and exemptions

The right of access is strong but not absolute. You must not disclose personal data about other people, so third-party data must be redacted unless those individuals consent or it is reasonable to disclose without consent. Data protection law also provides exemptions where responding would reveal information about another individual, prejudice legal privilege, or interfere with the prevention or detection of crime, among others.

A request can be refused only on two narrow grounds: where it is manifestly unfounded or manifestly excessive. Inconvenience or the effort involved is not a lawful reason to refuse. Critically, GDPR Article 12(5) places the burden of proof on the controller to demonstrate that a request meets one of those thresholds, so refusals must be documented carefully.

Fees

The default position under GDPR Article 12(5) is that the response is free. A reasonable fee based on administrative cost may be charged only where a request is manifestly unfounded or excessive, or for additional copies of the same data. Treating fees as an exception rather than a norm keeps you aligned with regulator expectations.

Common pitfalls and how tooling helps

The most damaging DSAR mistakes are incomplete searches that miss data in backups or shadow systems, and incomplete redaction that leaks third-party personal data. Disclosing another person data because a document was not properly redacted can itself be a separate breach for each affected individual.

  • Missing the deadline because the request was not recognised as a DSAR on arrival
  • Over-collecting identity verification data and creating new privacy risk
  • Manual redaction errors that expose third-party names or contact details
  • Failing to document the reasoning behind exemptions or refusals

Purpose-built DSAR tooling addresses these by automating intake, data discovery across connected systems, and bulk redaction, while producing an audit trail of every decision. The goal is not to remove human judgement but to make the routine steps fast and consistent so your team can focus on the genuinely difficult exemption calls.

Frequently Asked Questions

How long do you have to respond to a DSAR?

Under GDPR you must respond without undue delay and within one month of receipt, extendable by two further months for complex or numerous requests. Under the CCPA and CPRA the deadline is 45 days, extendable by a further 45 days. Informing the requester of any extension within the initial window is mandatory.

Can you charge a fee for a DSAR?

Generally no. GDPR Article 12(5) requires responses to be provided free of charge. A reasonable fee based on administrative cost may be charged only where the request is manifestly unfounded or excessive, or for additional copies of the same information. The controller must justify any fee it applies.

Can you refuse a data subject access request?

A DSAR can be refused only if it is manifestly unfounded or manifestly excessive; those are the only two lawful grounds. Inconvenience or the resources required is not a valid reason. Under Article 12(5) the burden of proof sits with the controller to demonstrate that the request meets one of those thresholds.

Do you have to redact third-party data in a DSAR response?

Yes. You must not disclose personal data about other individuals, so third-party information must be redacted unless those people consent or it is reasonable to disclose without consent. Incomplete redaction that exposes another person data can be treated as a separate breach for each affected individual.

What is the difference between a GDPR DSAR and a CCPA right to know?

Both let individuals see the personal data an organisation holds, but the scope and deadlines differ. GDPR Article 15 requires a one-month response and covers a broad set of supporting information. The CCPA right to know allows 45 days, focuses on categories and specific pieces of information collected and shared, and applies to defined businesses in California.

What counts as a valid DSAR?

Any request from an individual for access to their own personal data counts, regardless of format or channel. It does not need to mention the law or use the term DSAR, and it can arrive by email, web form, phone, or social media. This is why a clear intake and recognition process is essential to avoid missing the deadline.

Explore Courses on Udemy

Intermediate

Implement GDPR Step by Step with Templates

Intermediate

Implement CCPA (California Consumer Privacy Act) Step by Step

Intermediate

ISO/IEC 27701: Implement Privacy Management Step by Step