Data Subject Access Request
A Data Subject Access Request (DSAR) is a request an individual makes to an organization to obtain a copy of the personal data that organization holds about them. It is a way for people to see how and why their information is being used and to check that the organization is handling it lawfully. In the UK, anyone can make such a request directly, without needing a solicitor.
A Data Subject Access Request is the mechanism by which a data subject exercises the right of access to personal data held by a controller. Under the UK GDPR, as explained in ICO guidance, this right generally entitles the individual to confirmation of whether their personal data is being processed, access to that data, and supplementary information about the purposes and lawfulness of the processing. The DSAR is directed to the organization acting as controller rather than to a regulator, and organizations must be able to recognize such a request even where it is not labeled formally. The precise scope, applicable time limits, permissible exemptions, and any grounds for refusal or charging depend on the governing legal instrument and jurisdiction; equivalent access rights exist under other regimes (for example the EU GDPR and certain US state privacy laws), but their specific conditions differ. This entry describes the concept qualitatively; readers should verify procedural requirements, deadlines, and exemptions against the current authoritative text applicable to their jurisdiction, and application to particular circumstances requires professional judgment.
Why it matters
The DSAR operationalizes one of the most fundamental data protection rights: the ability of individuals to see what personal data an organization holds about them and to understand how and why it is being used. For data subjects, it is a practical tool for verifying that an organization is handling their information lawfully. Because, under the UK GDPR as explained in ICO guidance, anyone can make such a request directly and without engaging a solicitor, the mechanism lowers the barrier to individuals exercising oversight over their own data.
For organizations, DSARs carry operational and compliance significance because a request need not be labeled formally to be valid. ICO guidance makes clear that organizations must be able to recognize a subject access request even when it is not framed in legal terms or does not use the phrase 'subject access request.' This means front-line staff, customer service teams, and complaint-handling functions can all be points at which a valid request arrives, and failure to recognize and act on one may expose the organization to compliance risk under the applicable regime.
Because equivalent access rights exist under other frameworks, such as the EU GDPR and certain US state privacy laws, organizations operating across jurisdictions cannot assume a single uniform process will satisfy every regime. The specific conditions, scope, and procedural obligations differ, so the significance of a DSAR — and the correct response to it — is fact-specific and depends on the governing legal instrument. Readers should verify procedural requirements against the current authoritative text applicable to their jurisdiction.
Who it's relevant to
Inside DSAR
Common questions
Answers to the questions practitioners most commonly ask about DSAR.

