Guide

How to Respond to a DSAR: Templates and a Sample Response Letter

A structured way to acknowledge, verify, and respond to a data subject access request, plus a sample response letter you can adapt for your own process.

Published August 12, 2026·Last updated August 12, 2026

Once you’ve recognized a message as a data subject access request, the actual response follows a fairly predictable shape. Having a template ready means the person handling it doesn’t have to draft language from scratch under deadline pressure, and reduces the chance of missing a required element.

The three stages of a response

  1. Acknowledge quickly. Confirm receipt within a few days, even if the full response takes longer. This starts building a record that you’re handling the request in good faith and gives you a chance to flag identity verification steps early.
  2. Verify identity proportionally. Don’t over-collect for a low-sensitivity request, but do confirm the requester is who they claim to be before sending account-level data.
  3. Respond within the statutory window, generally one month under GDPR (extendable up to two further months for complex requests, with notice), and CCPA/CPRA’s 45-day window (extendable by another 45 days with notice).

Sample acknowledgment email

Subject: We’ve received your data request

Hi [Name],

Thanks for reaching out. We’ve received your request regarding the personal data we hold about you, and we’re treating it as a formal data subject request under [GDPR / CCPA].

To process this securely, we need to verify your identity. Could you confirm the email address associated with your account, and reply from that address?

We’ll respond in full within [30 / 45] days of your original request. If we need more time, we’ll let you know before that window closes and explain why.

[Your name / team]

Sample fulfillment email

Subject: Your data request, response

Hi [Name],

Here’s what we found in response to your request:

  • Data we hold: [summary or attached export]
  • Where it came from: [e.g., account signup, newsletter opt-in, purchase history]
  • Who we share it with: [e.g., payment processor, email platform, analytics provider]
  • Action taken: [e.g., “we’ve deleted the records you asked us to remove” or “attached is a copy of your data in CSV format”]

If anything here looks incomplete or you have follow-up questions, reply to this email and we’ll address it.

[Your name / team]

Our recommendation

Enzuzo

Templates handle the writing, but you still need to know what data exists and where. Enzuzo bundles data subject request handling with its consent platform, so the systems generating consent records and the process fulfilling requests aren't disconnected.

Try Enzuzo

What to avoid

  • Don’t send raw database exports. Format the response for a person to read, not a developer debugging a table.
  • Don’t ignore partial requests. “Just delete my newsletter subscription” is narrower in scope than a full access request, respond to what was actually asked.
  • Don’t skip the paper trail. Keep a copy of the request and your response, even after it’s resolved.

The bottom line

A DSAR response doesn’t need to be legally elaborate, it needs to be accurate, timely, and documented. A reusable template for acknowledgment and fulfillment removes most of the friction that causes deadlines to slip.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.