Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Data Subject Rights

Data Subject Access Request

Also known as: DSAR, Subject Access Request, SAR, right of access request
Simply put

A Data Subject Access Request (DSAR) is a request an individual makes to an organization to obtain a copy of the personal data that organization holds about them. It is a way for people to see how and why their information is being used and to check that the organization is handling it lawfully. In the UK, anyone can make such a request directly, without needing a solicitor.

Formal definition

A Data Subject Access Request is the mechanism by which a data subject exercises the right of access to personal data held by a controller. Under the UK GDPR, as explained in ICO guidance, this right generally entitles the individual to confirmation of whether their personal data is being processed, access to that data, and supplementary information about the purposes and lawfulness of the processing. The DSAR is directed to the organization acting as controller rather than to a regulator, and organizations must be able to recognize such a request even where it is not labeled formally. The precise scope, applicable time limits, permissible exemptions, and any grounds for refusal or charging depend on the governing legal instrument and jurisdiction; equivalent access rights exist under other regimes (for example the EU GDPR and certain US state privacy laws), but their specific conditions differ. This entry describes the concept qualitatively; readers should verify procedural requirements, deadlines, and exemptions against the current authoritative text applicable to their jurisdiction, and application to particular circumstances requires professional judgment.

Why it matters

The DSAR operationalizes one of the most fundamental data protection rights: the ability of individuals to see what personal data an organization holds about them and to understand how and why it is being used. For data subjects, it is a practical tool for verifying that an organization is handling their information lawfully. Because, under the UK GDPR as explained in ICO guidance, anyone can make such a request directly and without engaging a solicitor, the mechanism lowers the barrier to individuals exercising oversight over their own data.

For organizations, DSARs carry operational and compliance significance because a request need not be labeled formally to be valid. ICO guidance makes clear that organizations must be able to recognize a subject access request even when it is not framed in legal terms or does not use the phrase 'subject access request.' This means front-line staff, customer service teams, and complaint-handling functions can all be points at which a valid request arrives, and failure to recognize and act on one may expose the organization to compliance risk under the applicable regime.

Because equivalent access rights exist under other frameworks, such as the EU GDPR and certain US state privacy laws, organizations operating across jurisdictions cannot assume a single uniform process will satisfy every regime. The specific conditions, scope, and procedural obligations differ, so the significance of a DSAR — and the correct response to it — is fact-specific and depends on the governing legal instrument. Readers should verify procedural requirements against the current authoritative text applicable to their jurisdiction.

Who it's relevant to

Data protection officers and privacy teams
These roles typically own the process for recognizing, logging, and responding to DSARs. Because a valid request need not be formally labeled, privacy teams generally need procedures that allow requests arriving through any channel to be identified and routed correctly, and they must apply the scope, time limits, and exemptions of the governing regime. Where an organization operates across the UK, EU, and US state law regimes, teams should account for differing conditions rather than assuming one process fits all.
Front-line and customer-facing staff
Because a subject access request may arrive informally and without legal phrasing, staff who handle customer contact, complaints, or general correspondence are often the first to receive one. Their ability to recognize a request and escalate it is relevant to the organization's compliance, since an unrecognized request may go unaddressed.
Individuals exercising their rights
Data subjects use the DSAR to obtain a copy of the personal data an organization holds about them and to understand how and why it is being used. Under the UK GDPR as explained in ICO guidance, anyone can make such a request directly, without needing a solicitor. Equivalent rights exist under other regimes such as the EU GDPR and certain US state privacy laws, though the specific conditions differ by jurisdiction.
Legal and compliance counsel
Because scope, applicable time limits, permissible exemptions, and grounds for refusal or charging depend on the governing legal instrument and jurisdiction, counsel are relevant where a request raises questions of interpretation, competing rights, or cross-border application. Determining how a DSAR should be handled in a particular situation requires professional judgment and verification against the current authoritative text.

Inside DSAR

Right of Access
A DSAR is the mechanism by which an individual (the data subject) exercises the right to obtain confirmation of whether their personal data is being processed and, where it is, access to that data. Under the EU and UK GDPR this right is generally established in the provisions governing access; readers should verify the specific article and wording against the current official text.
Scope of Information Provided
A valid response typically includes a copy of the personal data undergoing processing together with supplementary information such as the purposes of processing, the categories of data concerned, recipients or categories of recipients, retention periods where possible, and the existence of related data subject rights. The precise content required depends on the applicable law and the facts of the request.
Identity Verification
Before responding, the organization generally may take reasonable steps to confirm the requester's identity, particularly where there is doubt, to avoid disclosing personal data to an unauthorized party. Verification must be proportionate and should not be used as an obstruction tactic.
Response Timeframe
DSARs are generally subject to a defined statutory response period, which may be extendable in certain circumstances (for example where requests are complex or numerous). Exact time limits and extension conditions differ by jurisdiction and should be checked against the current authoritative text rather than assumed.
Exemptions and Limitations
Access may be restricted where providing the data would adversely affect the rights and freedoms of others, or where a recognized exemption applies. The availability and scope of exemptions are jurisdiction-specific and fact-dependent.
Fees and Repetitive Requests
In most cases a DSAR must be handled without charge, though a reasonable fee or refusal may be permitted for requests that are manifestly unfounded or excessive. Whether a particular request qualifies is a judgment that must be justified and documented.

Common questions

Answers to the questions practitioners most commonly ask about DSAR.

Does a data subject access request always have to be fulfilled free of charge?
Not in every case. Under the GDPR, controllers generally must respond to a DSAR without charge, but they may in certain circumstances charge a reasonable fee based on administrative costs, or refuse to act, where a request is manifestly unfounded or excessive, for example because it is repetitive. The threshold for treating a request this way is high, and the controller bears the burden of demonstrating that the request meets it. Other jurisdictions handle fees differently, so verify the applicable rule against the current official text. This is a general description, not advice for a specific situation.
Is a DSAR the same thing as a request to delete or correct personal data?
No. A DSAR—the right of access—is generally the right to obtain confirmation of whether personal data is being processed and, where it is, to receive a copy of that data along with certain supplementary information. It is a distinct right from erasure (the so-called right to be forgotten), rectification, restriction, portability, and objection, each of which has its own conditions and exceptions under the applicable law. A single incoming request may in practice invoke more than one right, but the access right should not be conflated with the others. Confirm how each right is framed in the relevant regulation, as details differ across jurisdictions.
How should an organization verify the identity of someone making a DSAR?
Verification is generally expected to be proportionate to the sensitivity of the data and the risk of disclosure to the wrong person, rather than a fixed procedure. Requesting more identification than necessary can itself raise data minimization concerns. Where the controller has reasonable doubts about the requester's identity, it may generally ask for additional information to confirm it, and in some frameworks the response timeline may pause until identity is established. Because practice and interpretation vary, organizations should document their verification approach and check it against current regulatory guidance in the relevant jurisdiction. Application to a specific case requires professional judgment.
What is the typical timeframe for responding to a DSAR, and can it be extended?
Response deadlines are set by the applicable law and differ across jurisdictions, so the specific number of days should be verified against the current official text rather than assumed. Several regimes provide for a standard response period with the possibility of an extension where a request is complex or where numerous requests have been received, subject to informing the requester of the extension and the reasons for it within the initial period. Because the exact durations and conditions are jurisdiction-specific and subject to amendment, confirm them against the authoritative source that governs your organization.
How should third-party personal data appearing in the requested records be handled?
Responding to a DSAR often involves data that also identifies other individuals, and the right of access generally should not adversely affect the rights and freedoms of those third parties. Common approaches include redacting or otherwise not disclosing information relating to other people where doing so is appropriate, unless those individuals have consented or it is otherwise reasonable to disclose. Balancing these interests is fact-specific and can be contentious, so organizations typically document the reasoning behind each redaction decision. This is an informational description, and the correct handling in a particular matter depends on the applicable rules and professional judgment.
Can a controller refuse or limit a DSAR, and on what basis?
In limited and specific circumstances, yes. Applicable law generally provides exemptions or grounds to refuse or restrict access—for example where a request is manifestly unfounded or excessive, or where disclosure would infringe the rights of others—and some sectors or contexts carry their own carve-outs. Any refusal or limitation typically must be justified, communicated to the requester with reasons, and accompanied by information about avenues to complain or seek a remedy. The precise grounds and their scope vary by jurisdiction and are subject to evolving interpretation, so verify them against the governing text and current guidance.

Common misconceptions

A DSAR and a broader compliance obligation are the same thing, so satisfying one means an organization is compliant overall.
A DSAR is a specific data subject right addressing access to one's own personal data. Handling DSARs correctly is only one component of a wider compliance program; it does not by itself demonstrate overall compliance with a given data protection regime.
DSAR rules are uniform worldwide, so one process satisfies every jurisdiction.
Access rights, response timeframes, permissible exemptions, and fee rules differ across jurisdictions such as the EU, the United Kingdom, and various U.S. frameworks. An organization subject to more than one regime generally must account for those differences and should verify each against the applicable current text.
An organization must always fulfil a DSAR in full and without charge, with no ability to refuse.
While requests are generally handled free of charge, exemptions, limitations protecting the rights of others, and provisions for manifestly unfounded or excessive requests may permit partial disclosure, a reasonable fee, or refusal. Any such decision is fact-specific and should be justified and documented.

Best practices

Establish a documented intake and tracking procedure so that DSARs are recognized promptly and logged against the applicable response deadline, including any conditions under which the period may be extended.
Apply proportionate identity verification before disclosure, ensuring the steps taken confirm the requester without becoming an unjustified barrier to a legitimate request.
Confirm which jurisdiction's rules apply to each request, and maintain distinct handling where an organization is subject to more than one data protection regime rather than assuming a single uniform process suffices.
Assess and document any exemptions, third-party data considerations, or grounds for treating a request as manifestly unfounded or excessive, recording the reasoning for each decision.
Provide, alongside a copy of the personal data, the supplementary information the applicable law generally requires, and keep an internal record of what was disclosed and when.
Review DSAR procedures against the latest authoritative text of the relevant regulation, since access rights, timeframes, and related requirements are periodically amended and enforcement practice may diverge from the wording of the law.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide