Guide

What Is a DSAR? Handling Data Subject Requests Under GDPR

A data subject access request lets anyone ask what personal data you hold on them. Here's what DSARs actually require, the 30-day clock, and how to handle one without dedicated tooling.

Published June 8, 2026·Last updated August 18, 2026

A DSAR, data subject access request, is one of the more concrete, actionable parts of GDPR: a formal request from an individual asking what personal data you hold on them, and often what you do with it. Unlike broader compliance questions, this one has a clear trigger (someone actually asks) and a clear clock (you have a defined window to respond).

What visitors can actually ask for

Under GDPR, individuals have several distinct rights that a DSAR can invoke:

  • Access, what personal data you hold about them, and details of how it’s processed.
  • Rectification, correcting inaccurate data.
  • Erasure, deleting their data (“right to be forgotten”), subject to some exceptions (legal retention obligations, for example).
  • Portability, receiving their data in a structured, machine-readable format.
  • Restriction, limiting how their data is processed, without necessarily deleting it.
  • Objection, objecting to certain processing, particularly direct marketing.

A single request might invoke more than one of these, “send me what you have on me and delete it after” is a common combined ask.

The 30-day clock

You generally have one month from receiving a valid request to respond, extendable by up to two further months for complex or numerous requests, with the individual notified of the extension and the reason within the original month. The clock starts when the request is received, not when you’ve verified the requester’s identity, though verification is a legitimate step before fulfilling the request, especially for sensitive data.

How a DSAR usually arrives, and why that’s a problem

Requests don’t always arrive labeled “DSAR.” A support email saying “what information do you have about me” or “please delete my account and everything tied to it” is a DSAR, whether or not the sender uses the term. This is the most common practical failure point: the request gets treated as a routine support ticket and the response clock quietly expires because nobody recognized what it was.

Our recommendation

Usercentrics

A consent platform doesn't replace a DSAR process, but Usercentrics' consent logs give you a documented record of what a visitor agreed to, useful context when a data subject request comes in and you need to reconstruct their history quickly.

Try Usercentrics

Handling a DSAR without dedicated tooling

At small scale, you don’t need specialized software to handle this correctly:

  1. Have a clear internal process: who receives these requests, how identity gets verified, and who has authority to pull and send the data.
  2. Know where your data actually lives. This is where the data inventory step from our compliance checklist pays off directly, you can’t respond to a DSAR quickly if you don’t know which systems hold the person’s data.
  3. Verify identity reasonably, proportional to the sensitivity of the data, don’t demand excessive verification for a simple newsletter unsubscribe-and-delete request, but do verify before sending detailed account data.
  4. Document what you did and when, in case the request or your response is ever questioned later.

The bottom line

DSARs are one of the more procedural, checklist-able parts of GDPR compliance. The main risk isn’t legal complexity, it’s an untrained team member not recognizing a request for what it is and letting the clock run out unnoticed.

This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.