What is Data Subject Access Request?
Definition
A Data Subject Access Request (DSAR) is a formal request made by an individual to an organization asking what personal data is held about them, how it is processed, and to whom it has been disclosed. Under GDPR, organizations must respond within 30 days.
In Depth
DSARs are a cornerstone of data subject rights under GDPR and similar privacy regulations. When an individual submits a DSAR, the organization must provide a copy of all personal data being processed, the purposes of processing, the categories of data involved, recipients or categories of recipients, retention periods, and the source of data if not collected directly from the individual. Organizations must also inform data subjects of their rights to rectification, erasure, restriction of processing, and the right to lodge a complaint with a supervisory authority. Handling DSARs efficiently requires knowing where personal data resides across all systems — a challenge for organizations with fragmented data architectures. Best practices include implementing a DSAR intake portal, maintaining a data inventory or Record of Processing Activities (ROPA), automating data discovery across databases and SaaS tools, and training customer-facing staff to recognize and escalate DSARs appropriately.
Related Frameworks
Related Terms
GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union that governs how personal data of EU residents is collected, processed, stored, and transferred. It became enforceable on May 25, 2018, and applies to any organization worldwide that processes EU resident data.
Privacy Policy
A privacy policy is a public-facing legal document that describes how an organization collects, uses, shares, and protects personal information. It must be transparent, accurate, and compliant with applicable privacy laws in all jurisdictions where the organization operates.
Data Processing Agreement
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor that specifies the terms for processing personal data. Under GDPR Article 28, a DPA is mandatory whenever a controller engages a processor.
Privacy Impact Assessment
A Privacy Impact Assessment (PIA), known as a Data Protection Impact Assessment (DPIA) under GDPR, is a systematic process for evaluating how a proposed project or system will affect individual privacy. It identifies privacy risks and recommends mitigations.
Generate compliance docs with PoliWriter
Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.
Get Started Free