Guide

Can You Charge a Fee for a DSAR? What GDPR and CCPA Allow

Both GDPR and CCPA default to free data subject requests. Here's the narrow set of circumstances where a fee or refusal is actually justified, and how to document it if you go that route.

Published August 15, 2026·Last updated August 15, 2026

The default answer, under both GDPR and CCPA/CPRA, is no: the first request in a given period has to be handled free of charge. But both frameworks carve out a narrow exception for requests that are excessive or clearly unfounded, and it’s worth knowing exactly where that line sits before assuming you can charge.

The GDPR standard

Article 12 requires the first copy of personal data to be provided free of charge. A “manifestly unfounded or excessive” request, particularly one that’s repetitive, can be met with either a reasonable fee covering administrative cost, or a refusal, but the burden is on you to demonstrate why the request meets that bar. Simply being time-consuming to fulfill doesn’t qualify, “excessive” generally refers to the nature or frequency of the request, not the size of your organization’s data footprint.

The CCPA/CPRA standard

Consumers are entitled to two free requests within any 12-month period for most request types. Beyond that, or for a request that’s demonstrably unfounded or excessive, a business may charge a reasonable fee based on the administrative cost of providing the information, or decline to act, again with the reasoning documented.

What actually qualifies as “excessive”

In practice, this bar is higher than it might feel in the moment:

  • Excessive: the same individual submitting near-identical requests weekly with no new purpose, or a request explicitly designed to be disruptive rather than to obtain information.
  • Not excessive: a request that’s simply large in scope, or inconvenient to fulfill because your data is spread across several systems. Operational difficulty on your end isn’t a valid basis for a fee.

If you do charge or decline

  1. Document the specific reason the request met the excessive or unfounded threshold, not just that it was inconvenient.
  2. Communicate the decision within the response window, don’t let the deadline lapse silently while you decide.
  3. Offer the fee amount and basis clearly if charging, tied to actual administrative cost, not an arbitrary number.
Our recommendation

Enzuzo

Most requests never reach the excessive threshold, they're routine and should be free. Enzuzo's data subject request handling is built around that default, so fulfillment doesn't create a temptation to treat every request as a cost center.

Try Enzuzo

The reputational cost of charging

Even where a fee is technically defensible, charging for a routine-seeming request is one of the more visible ways a business signals it isn’t taking privacy rights seriously. Regulators, and requesters who escalate to a regulator, tend to scrutinize fee decisions closely. For most small and mid-size businesses, the operational cost of fulfilling a request for free is lower than the risk of a disputed fee turning into a complaint.

The bottom line

Free is the default, and stays the default for the overwhelming majority of requests you’ll receive. Reach for a fee or refusal only when a request clearly meets the excessive or unfounded bar, and be prepared to explain that decision in writing if asked.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.