Insight

What is a DSAR? 2026 Guide

Insight Published 16 min read
DSAR (Data Subject Access Request) concept showing personal data, identity information, addresses, passport and driving license details in a digital privacy interface.

A DSAR rarely announces itself. The deadline begins on the day it arrives, not when the right team notices. Klarna found this out from Sweden’s regulator. Although the request was clear, it was put into the wrong inbox; the clock was set in motion, and the matter ended with a public reprimand.

Most guides omit the two factors that cause companies problems: what constitutes a request and where the data is actually located. This one includes both and then moves through the legal requirements under GDPR and CCPA, how to respond step by step, when identity verification or refusal is justified, which systems and browser-based third-party data flows must be checked, what happens when a DSAR is ignored or answered inaccurately, and how MELURNA helps teams monitor those external data paths continuously.

Key takeaways

  • A DSAR is a legally enforceable request to know what personal data an organization holds about you, anchored in GDPR Article 15 and CCPA Section 1798.110.
  • A request is valid without legal language, without a form, and without a reason. Train the inboxes where requests actually arrive.
  • GDPR gives you one calendar month, extendable by two months with notice. CCPA gives you 45 days, extendable by 45. Verification does not extend either clock.
  • Verification must be proportionate; refusal is limited to manifestly unfounded or excessive requests with reasons, and responses are free by default.
  • The response must name recipients. A truthful recipient’s answer includes what your website sends from the browser to third parties: the layer most DSAR searches miss.
  • Ignoring a DSAR escalates from regulator complaints to fines, court orders, and, in the UK, criminal liability.

What is a DSAR (data subject access request)?

A DSAR is a request that exercises the “right of access”: an individual’s legal right to see the personal data an organization holds about them. 

The right comes from Article 15 of the EU’s General Data Protection Regulation (GDPR). US privacy laws created equivalents under different names. California’s CCPA calls it a “request to know.”

The person making the request is the “data subject.” The organization that decides why and how the data is processed (the one that owes the response) is the “controller” in GDPR terms, or the “business” in CCPA terms.

DSAR vs DSR vs SAR vs VCR: the term map

The privacy industry uses at least four acronyms for overlapping ideas:

TermStands forWhat does it actually mean
DSARData subject access requestA request to access personal data is one specific right
DSRData subject requestThe umbrella term: access, deletion, correction, portability, opt-out requests
SARSubject access requestThe UK term for a DSAR, same right, same rules
VCRVerifiable consumer requestCalifornia’s version: a request whose requester has been identity-verified under CCPA rules

The siblings in the DSR family (deletion, correction, portability, and opt-out of sale or sharing) follow different rules and clocks, and we cover them in our CCPA guide. This guide is about the access request: the one that forces you to actually find and produce the data.


What must a DSAR response include?

When someone requests access to their personal data, the request is still valid even if they do not use the term DSAR. Under GDPR Article 15(1), when a person makes an access request, the response confirms whether you process the person’s data and, if so, provides a copy of the data plus eight categories of information about the processing. Under CCPA Section 1798.110(a), the response covers the categories of information, sources, purposes, third parties, and the specific pieces of information collected.

The GDPR’s eight categories, with what each one means in practice:

GDPR requirement (Art. 15(1))What does it mean in practice?Where does it typically live?
(a) Purposes of the processingWhy do you hold the dataPrivacy notice, records of processing
(b) Categories of personal dataWhat kinds of data do you holdData inventory
(c) Recipients or categories of recipientsTo whom the data has been or will be disclosedVendor list, data inventory, browser-layer data map
(d) Retention period or criteriaHow long do you keep it, or how do you decideRetention schedule
(e) Rights to rectification, erasure, restriction, objectionA reminder of the person’s other rightsPrivacy notice
(f) Right to complain to a supervisory authorityWhere the person can escalatePrivacy notice
(g) Source of the data, if not collected from the personWhere did you get itData inventory
(h) Automated decision-making, including profilingLogic, significance, and consequences of any automated decisionsInternal documentation

The CCPA’s list is similar in spirit: categories of personal information collected, categories of sources, the business or commercial purpose, categories of third parties to whom it is disclosed, and the specific pieces collected about that person. The lookback is the preceding 12 months. Since January 1, 2023, a request can reach back beyond 12 months unless doing so is impossible or would involve disproportionate effort, and only for personal information collected on or after January 1, 2022.

The format is also very specific: under the GDPR, a copy requested electronically must be provided in a widely used electronic format. Under the CCPA, the particular items have to be given in a format that is easy to use and machine-readable, insofar as technically feasible. In neither case are you required to hand over internal databases or entire documents since a DSAR pertains only to the individual’s data and not to all the documents in which their name occurs.

There are two main limits. GDPR Article 15(4) says you cannot share copies that would harm the rights or freedoms of others, so you should redact third-party information. CCPA Section 1798.130(a)(8) limits access requests to two per consumer every 12 months.


How long do you have to respond to a DSAR?

Under GDPR, you have one calendar month to respond after receiving a DSAR. If the request is complex or covers a lot of data, you can extend this by two more months, but you must tell the person within the first month. Under CCPA, you have 45 days from when you receive the request, and you can extend this once by another 45 days if you give notice. In both cases, the clock starts when you get the request, not after you finish verifying the person’s identity.

LawStandard deadlineExtensionNotifying the requester
GDPR (Article 12(3))One month+2 months for complex or numerous requestsWithin one month of receipt, with reasons
UK GDPR (same structure)One calendar month+2 months for complex or numerous requestsWithin one month of receipt, with reasons
CCPA (Section 1798.130(a)(2))45 days+45 days when reasonably necessaryWithin the first 45 days, with notice

Two timing details catch organizations out. A period of “one month” under the GDPR refers to a calendar month. The ICO specifies that if a request is received on the 3rd of September, it is due on the 3rd of October, not thirty days later. Although some people attempt to extend the deadline by counting days rather than months, this is not correct.

The time you spend verifying someone’s identity does not count toward your response deadline. Although you are required to carry out the verification promptly under the CCPA, this does not reduce the 45 days you have to respond to the request. Similarly, under the GDPR, the identity checks must be carried out within the same one-month period, and you remain responsible if the verification takes too long.

CCPA also requires you to confirm receipt of the request within 10 business days, as set out in the regulations (11 CCR Section 7021). Even if you do not have any data on the person, you still need to respond within the deadline. Telling them you hold no personal data counts as a response.


Can you verify, refuse, or charge for a DSAR?

You can verify identity, but each DSAR must be assessed on a case-by-case basis before deciding whether to seek further verification, refuse the request, or charge a fee, and those steps are only justified in certain circumstances. Verification must be reasonable. You can only refuse if the request is clearly unfounded or excessive, and you must be able to prove it. Fees are only allowed in these rare cases.

Verification

GDPR Article 12(6) lets you request additional information to confirm the data subject’s identity where you have reasonable doubts. The CCPA standard is “reasonable in light of the nature of the personal information requested.” CCPA Section 1798.130(a)(2) bars requiring someone to create an account just to make a request, and if they already have an account with you, you can use it. For requests involving sensitive personal information, stronger authentication may be appropriate. Weak checks can disclose personal data to the wrong person.

If you collect more personal data than necessary just to verify a privacy request, that is a violation. Honda learned of this when the CPPA ruled against them in March 2025. Honda asked consumers for too much personal information to verify their identities, even when it was not needed.

Refusal

According to the GDPR, you are allowed to refuse to act only if a request is clearly unfounded or excessive, including cases involving multiple requests when they are clearly repetitive. The procedure is laid down in Article 12(4): you must inform the person of this within one month, provide them with the reasons, and notify them of their right to complain to a supervisory authority as well as to pursue judicial remedies; any refusal must also match the standard under the relevant law that applies to the request. 

The burden of proof sits on the controller. Note what is not a ground: the person’s motive. A DSAR does not require a reason. The CCPA’s built-in limits are the twice-per-12-month cap and the statute’s own scope limits.

Fees

It is free by default. Under GDPR Article 12(5), a reasonable fee based on administrative costs may be charged only if the request is clearly unfounded or excessive, and under Article 15(3), a reasonable fee may be charged for additional copies. Under CCPA Section 1798.130(a)(2), the responses to access and portability requests must be given free of charge.


How do you handle a DSAR step by step?

A DSAR response is a sequence of eight steps, and the deadline is anchored at the first step.

  1. Log the request and begin the clock. Note the date, the channel, and the applicable law. That determines your deadline. If a request remains untraced in an inbox, then the deadline is considered to have started.
  2. Acknowledge the request and confirm you have received it; for requests under the CCPA, this is a legal requirement with a deadline of ten business days.
  3. Verify identity proportionately. Match the verification effort to the sensitivity of the data. Do not collect new personal data just to verify.
  4. Clarify the scope if needed. GDPR Article 12(3) lets you ask the person to specify what they’re looking for when you process a large quantity of their data. You may ask. You cannot force them to narrow the request, and asking does not stop the clock.
  5. Check all the systems that could have the person’s data. This covers the CRM, HR systems, email, support tickets, databases, and other systems mentioned in the following section.
  6. Review the data and remove any information about third parties, as required by GDPR Article 15(4). Internal documents that mention the person are not automatically in scope.
  7. Deliver securely, in a usable format. Electronic requests get electronic delivery. A secure system beats an emailed spreadsheet full of personal data.
  8. Record everything. What was requested, when, what you searched, what you sent, and why you redacted or refused anything. If a regulator or a court asks later, this file is your defense.
DSAR response workflow showing eight steps for handling data subject access requests, from logging and identity verification to data search, redaction, secure delivery, and recordkeeping under GDPR and CCPA.

Who is responsible for the DSAR process?

If you have a Data Protection Officer, they should oversee DSAR handling, though GDPR only requires a DPO for some organizations. Regardless, the function needs an owner (typically legal, compliance, or security) with a named escalation path. Klarna is what unclear ownership looks like: the request existed, nobody owned it, and four years passed.


Where does personal data actually live? 

A complete DSAR search must cover every place a person’s personal data could be held, even what your website sends from a visitor’s browser to third parties. Most searches stop at internal systems, which is not enough.

Both laws require that you identify the recipients. 

  • As stated in GDPR Article 15(1)(c), you must give the names of the recipients or the categories of recipients to whom the data has been sent or will be sent.
  • Under CCPA Section 1798.110(a)(4), you must list the categories of third parties to whom the information is disclosed. The term “recipients” includes anyone to whom the data flows, not merely vendors with whom you have deliberately integrated.

In all the competitor guides that we looked at, the standard DSAR search list is nothing other than a version of the same five systems: CRM, HR platform, email, support tickets, and marketing database. That list is not incorrect; it is just incomplete.

The lists are based on the assumption that personal data exists only within the systems that you manage. However, most websites load third-party scripts like analytics tags, ad pixels, session replay tools, chat widgets, and consent managers. These scripts are able to send personal data directly from the visitor’s browser to ad companies and analytics providers, and that browser-side data collection can include granular data points such as identifiers, browsing behavior, and, in some cases, the contents of forms. This data will not appear in your server logs and will never reach your database.

When a DSAR request asks for the requested data, including the categories of personal data collected about an individual and the categories of third parties to whom that data was disclosed, then that browser-layer process is included in a truthful response with the relevant information. We already wrote separately about how this silent transmission amounts to a data leak and when it becomes a privacy incident.

DSAR search map showing two data layers: internal systems such as CRM, HR, email, support tickets, databases and cloud storage, plus browser data including analytics tags, ad pixels, session replay and chat widgets.

This means your search needs a two-layer data map. The first layer covers the systems you manage, each with an owner and a data inventory. The second layer covers the browser: which pages load which third-party endpoints, what specific data each one gets, and which platform it belongs to. Without this second layer, your answers about data recipients are just guesses.


What happens if you ignore a DSAR?

If you ignore a DSAR, you will be subjected to four stages, getting worse over time: the individual raises a complaint with a regulator, the regulator then investigates and imposes a fine, the individual takes you to court, and in some jurisdictions, people can face criminal liability.

Regulatory complaints and fines

California Consumer Privacy Act (CCPA) compliance and fines

Under CCPA, the California Privacy Protection Agency can impose administrative fines of up to $2,500 ($2,663 inflation-adjusted) per violation, or $7,500 ($7,988 inflation-adjusted) per intentional violation or violations involving minors, under Section 1798.155. These rights sit within broader data privacy laws and privacy regulations, and similar access rights to DSARs exist in multiple jurisdictions worldwide; in California, the California Privacy Rights Act expands the CCPA framework relevant to these requests, including the right to opt out of sharing personal information for targeted advertising purposes. “Per violation” is where the math gets serious: in the Honda decision, the CPPA tallied violations across 153 consumers and settled for $632,500.

General Data Protection Regulation (GDPR) compliance and fines

Under GDPR, infringements of the data subject rights in Articles 12 through 22 fall into the highest fining tier: up to €20 million or 4 percent of total worldwide annual turnover, whichever is higher, under Article 83(5)(b). The UK’s cap under the UK GDPR is £17.5 million or 4 percent of global turnover.

Fines are not the only tool regulators use. The ICO also gives public reprimands when organizations mishandle access rights. In February 2025, Glasgow City Council and the City of Edinburgh Council were reprimanded after leaving access requests unanswered for years. The ICO also noted that SARs to Scottish local authorities rose by 67 percent between 2021 and 2024. A reprimand costs nothing on paper and a great deal in reputation.

Court

A person can seek a court order compelling disclosure, and courts can award compensation for non-compliance. An ignored DSAR also tends to surface in other litigation because access requests are often the first step a person takes before suing over something else. Your DSAR file becomes evidence of how you treat people’s rights.

Criminal liability

In the UK, blocking, erasing, or concealing records to avoid disclosing them is a criminal offense under section 173 of the Data Protection Act 2018. 

In September 2025, the ICO announced that a care home director was found guilty after ignoring a subject access request made by a daughter with lasting power of attorney for her father. He was fined £1,100 and ordered to pay £5,440 in costs. The pattern across these cases is the same: none of the organizations were punished for holding data. They were punished for how they handled the request.


How MELURNA helps with DSARs

MELURNA covers the part of the DSAR search that internal inventories cannot reach: what your website sends from visitors’ browsers to third parties.

We continuously monitor your site’s client-side data flows: which third-party endpoints load on which pages, what data each one receives, and which platform it belongs to. 

When a DSAR arrives, that map feeds the two answers most organizations struggle to give truthfully: the categories of recipients under GDPR Article 15(1)(c) and the categories of third parties under CCPA Section 1798.110(a)(4). This also strengthens your data inventory, so the search step starts from evidence instead of guesswork.

We do not handle the request itself. Verification, deadlines, redaction, and delivery stay with your team and your processes. What changes is that the browser layer of your search stops being a blind spot.

Next steps


FAQs

What is the difference between a DSAR and a DSR (Data Subject Rights)? 

A DSAR is one type of data subject request: the access request. DSR is the umbrella term that also covers erasure, rectification, portability, restriction, and objection.

How long does a company have to respond to a DSAR? 

One calendar month under GDPR and UK GDPR, extendable by two months for complex requests if the person is notified within the first month. Forty-five days under CCPA, extendable once by 45 days with notice. The clock starts on receipt.

Can a company refuse a DSAR? 

Only in narrow circumstances. Under GDPR, a request can be refused if it is manifestly unfounded or excessive, and the controller bears the burden of proof. The person must be told within one month, with reasons and their right to complain. Suspecting the person’s motive is not a ground for refusal.

Can you charge a fee for a DSAR? 

Almost never. GDPR allows a reasonable administrative fee only for manifestly unfounded or excessive requests and for further copies. CCPA requires access and portability responses to be provided free of charge.

What if we have no data on the requester? 

You still respond within the deadline even if you hold none of the requested data, confirming that you hold no personal data about them. GDPR Article 15 requires confirmation of whether any personal data involved in the request is processed either way, and if none is held, there is no data summary to provide. Silence is non-compliance even when the honest answer is “nothing.”

Does a DSAR require the requester to prove identity? 

You may ask for additional information to confirm identity where you have reasonable doubts, but verification must be proportionate to the sensitivity of the data. Over-verification is itself an enforcement target. California’s first major CCPA penalty included allegations of excessive verification demands.


DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.


Reference

Cite this page

Dany Mirza. “What is a DSAR? 2026 Guide.” Melurna, September 10, 2026. https://www.melurna.com/blog/what-is-a-dsar/