Data Subject Access Request
Data Subject Access Request (DSAR) is a formal request from an individual to see, correct, port, or delete the personal data an organization holds about them, with regulated response timeframes.
Also known as: DSAR, subject access request, privacy request
Data Subject Access Request (DSAR) is a formal request made by an individual exercising their privacy rights to access, correct, port, or delete the personal information an organization holds about them. Privacy regulations including GDPR, CCPA, and UK GDPR grant these rights and set the response windows organizations must meet. For marketing operations, DSARs are where privacy policy stops being abstract and starts requiring the data inventory to actually work.
What A Data Subject Access Request Means
A Data Subject Access Request is a request initiated by the individual the data is about, asking the organization to take a specified action against the personal data it holds. The actions vary by jurisdiction but typically include the right to access (a copy of the data), the right to rectification (correction), the right to erasure (deletion), the right to portability (a structured export), and the right to object to specific processing. Response windows are also set in regulation — typically 30 days under GDPR, 45 under CCPA — with limited extensions. The request can come from any channel and must be authenticated to confirm the person is who they claim to be.
How A Data Subject Access Request Works
In practice, fulfilling a Data Subject Access Request means locating an individual’s data across every system that holds it — CRM, marketing automation, analytics, support tools, advertising platforms, warehouse — then taking the action the request specifies. Authentication confirms identity, a search runs across systems, the results are assembled, the action is performed, and the response is delivered to the requester. Mature organizations route DSARs through a privacy portal and run them through a documented workflow with ownership at each step. The work is much easier when data inventories are current; it becomes punishing when personal data is scattered and undocumented.
Common Pitfalls and Misconceptions
A common misconception is that Data Subject Access Requests are purely a legal department concern. Legal owns the policy, but marketing operations is often where the personal data actually lives, so MOps has to provide the infrastructure. Teams underestimate the volume that arrives once privacy notices direct users to a clear request channel, and they end up handling DSARs as scrambles instead of as a process. Another trap is treating deletion as record hiding rather than actual erasure; backups, exports, and replicated systems often retain data after the primary record is deleted, leaving the organization technically non-compliant. Identity verification is also routinely sloppy, either too lax (releasing data to the wrong person) or too strict.
Data Subject Access Request in Practice
The teams that fulfill Data Subject Access Requests reliably treat each request as a system test of their data inventory. Every DSAR validates that personal data lives where the inventory says it does, that retrieval works as documented, and that deletion actually deletes. Teams that handle DSARs as one-off scrambles never close the gap between policy and reality. The mature approach uses DSAR volume and turnaround time as leading indicators of compliance readiness: handling a request in days proves the infrastructure works when it matters, while missed deadlines signal that policy and operations have drifted apart. Investing in the DSAR workflow pays dividends across every privacy obligation.
Common questions.
What rights does a DSAR cover?
Why does marketing operations need to be involved?
How can a team prepare to handle DSARs?
Is there a deadline to respond to a DSAR?
What makes DSARs difficult to fulfill?
What is the timeline to respond to a DSAR under GDPR?
Are DSARs free for individuals to submit?
Related Terms
More from MarTech & Operations.
Let’s Talk
Let’s talk about what your next quarter could look like.
Tell us what you’re working on. A senior practitioner reads it, not an SDR queue, and replies, usually within one business day.
- Reviewed personally, not routed through a queue.
- A conversation about what you’re actually working on, not a generic pitch.
- No pressure, just a chance to talk it through.