What Is a Data Subject Access Request (DSAR)? A Complete Guide for Businesses

Summarise on:
Charu Pel

Charu Pel

Published:

A Data Subject Access Request (DSAR) is a request from an individual asking an organization to confirm whether it processes their personal data and, where applicable, provide access to that data and information about how it is used, shared, and retained. DSAR is primarily an access-right term; correction, erasure, consent withdrawal, and grievance requests are related but legally distinct rights.

For Indian businesses, the closest DPDP concept is a Data Principal request. Sections 11 to 14 of the Digital Personal Data Protection Act, 2023 cover access, correction and erasure, grievance redressal, and nomination. As of 3 August 2026, these rights provisions are scheduled to commence on 13 May 2027, so organizations should use the transition period to build secure intake, identity verification, data discovery, approval, response, and audit-evidence workflows.

What Is a Data Subject Access Request (DSAR)?

A Data Subject Access Request is a formal request through which an individual asks an organization for access to personal data relating to them. It may require the organization to confirm whether the data is being processed, provide a copy or summary of the relevant personal data, and explain important details about the processing.

What Does DSAR Stand For?

DSAR stands for Data Subject Access Request. The term is widely associated with the GDPR right of access. In the United Kingdom, the shorter term Subject Access Request or SAR is also commonly used.

What Can an Access Request Cover?

  • Confirmation of whether personal data is being processed
  • A copy or summary of personal data relating to the requester
  • The purposes for which the data is processed
  • The categories of personal data involved
  • Recipients or categories of recipients receiving the data
  • Available information about the source of the data
  • Retention information where required by the applicable law
  • Information about relevant automated decision-making where applicable

For the statutory wording, refer to GDPR Article 15 and the Digital Personal Data Protection Act, 2023.

DSAR vs DSR vs SAR vs Data Principal Request: What Is the Difference?

These terms are related, but they should not be used as exact legal synonyms in every jurisdiction.

  • DSAR: A Data Subject Access Request focused on access to personal data and processing information
  • SAR: A shorter term for Subject Access Request, commonly used in the United Kingdom
  • DSR: A broader Data Subject Request that may include access, correction, deletion, objection, restriction, or portability depending on the law
  • Data Principal request: The DPDP-aligned term for a request made by an individual exercising rights under India’s privacy framework

For SEO, businesses may use the familiar term DSAR in the page title. Inside the article and operational workflow, however, it is better to distinguish an access request from correction, erasure, consent withdrawal, grievance, and nomination requests.

Is a DSAR a Right Under the DPDP Act, 2023?

The DPDP Act does not use DSAR as its primary statutory label. It gives a Data Principal separate rights relating to access, correction and erasure, grievance redressal, and nomination.

Relevant DPDP Rights

  • Section 11: Right to access information about personal data
  • Section 12: Right to correction, completion, updating, and erasure of personal data
  • Section 13: Right of grievance redressal
  • Section 14: Right to nominate another individual in specified circumstances

Under Section 11, a qualifying access request may require a Data Fiduciary to provide a summary of the personal data being processed, a summary of processing activities, and details of other Data Fiduciaries and Data Processors with whom the personal data has been shared, subject to the Act’s conditions and exceptions.

Correction and erasure should be handled as separate request types. An erasure request may not require deletion where retaining the data remains necessary for the specified purpose or for compliance with applicable law.

Read also: Data Fiduciary Obligations Under the DPDP Act.

When Do DPDP Data Principal Rights Take Effect?

As of 3 August 2026, Sections 11 to 14 of the DPDP Act are scheduled to commence on 13 May 2027, which is eighteen months after 13 November 2025. Businesses should therefore treat 2026 as a readiness period rather than waiting until the commencement date to design their rights-management process.

What Rule 14 Requires Businesses to Prepare

  • Publish a clear method through which Data Principals can exercise their rights
  • State the identifiers required to locate and identify the requester in the organization’s systems
  • Provide an accessible grievance redressal mechanism
  • Publish a reasonable grievance response period that does not exceed ninety days
  • Implement appropriate technical and organizational measures to support the process

The ninety-day period relates to grievance redressal. It should not be presented as a universal response deadline for every access, correction, or erasure request. Organizations should map the specific law that applies and establish stricter internal service-level targets where appropriate.

Who Can Submit a DSAR Request?

A DSAR is normally submitted by the individual to whom the personal data relates. Depending on the applicable law and the circumstances, an authorized representative, parent, lawful guardian, or nominated person may also act on the individual’s behalf.

Common Requesters

  • Customers and account holders
  • Employees, former employees, and job applicants
  • Website and mobile-app users
  • Patients, students, members, or policyholders
  • Vendors, contractors, and business contacts
  • Parents or lawful guardians acting where permitted
  • Authorized representatives with valid proof of authority

Businesses should not assume that every request will arrive through a privacy portal. A valid request may be received by email, support ticket, webform, letter, telephone call, branch office, HR team, or customer-service channel, depending on the applicable law.

What Information Is Included in a DSAR Response?

The exact response depends on the applicable privacy law, the request scope, the organization’s role, and any lawful restrictions. A complete response should answer the individual’s request without disclosing information that belongs to another person or is protected from disclosure.

Typical DSAR Response Components

  • Confirmation of whether the organization processes the requester’s personal data
  • The personal data or an intelligible copy of the data within scope
  • Purposes and categories of processing
  • Relevant recipient or data-sharing information
  • Retention information where required
  • Source information where the data was not collected directly from the individual
  • An explanation of redactions, withheld material, or actions not taken where required
  • Information about complaint, grievance, or appeal options under the applicable law

A DSAR is a right to personal data, not automatically a right to every complete document in which the person’s name appears. Teams must identify the personal data within records, review the rights of others, and apply lawful redactions before disclosure.

How Long Does a Business Have to Respond to a DSAR?

There is no single global DSAR deadline. The response period depends on the privacy law governing the request.

GDPR Response Timeline

Under the GDPR, the controller must communicate the action taken without undue delay and generally within one month of receiving the request. The period may be extended by two additional months when necessary because of complexity or the number of requests, but the individual must be informed of the extension and reasons within the first month.

DPDP Response Timeline

The final DPDP framework requires organizations to publish the means for exercising rights and a grievance response period not exceeding ninety days. This ninety-day period is not a blanket deadline for every Data Principal access, correction, or erasure request. Businesses should configure request-specific internal SLAs and update them when regulatory guidance or sector-specific requirements apply.

Recommended Internal SLA Controls

  • Record the legal deadline when the request is received
  • Track identity-verification and clarification dependencies separately
  • Set internal due dates earlier than the statutory deadline
  • Escalate overdue tasks to privacy, legal, security, and business owners
  • Document any lawful extension, pause, rejection, or partial response

What Is the DSAR Process for Businesses?

A reliable DSAR process converts an individual’s request into a controlled case with ownership, deadlines, evidence, approvals, and secure delivery.

Step-by-Step DSAR Workflow

  1. Capture the request from the privacy portal, email, support, HR, branch, or another intake channel
  2. Create a case record and calculate the applicable legal and internal deadlines
  3. Classify the request as access, correction, erasure, consent withdrawal, grievance, nomination, or another right
  4. Acknowledge receipt and explain any information needed to process the request
  5. Verify the requester’s identity and the authority of any representative using proportionate checks
  6. Clarify the scope only where necessary, without creating avoidable delay or limiting a valid request
  7. Search relevant systems, repositories, processors, archives, and business functions
  8. Review the results for relevance, duplication, third-party information, privilege, legal holds, and lawful restrictions
  9. Prepare the response or execute the approved correction, erasure, restriction, or other action
  10. Obtain required privacy, legal, security, HR, or business approval
  11. Deliver the response through a secure and accessible channel
  12. Close the case with a complete audit trail, evidence of action, and lessons for process improvement

The most difficult part is usually not writing the response. It is locating complete and accurate personal data across fragmented systems while preventing unauthorized disclosure.

Read also: Grievance Redressal Under DPDP.

How Should a Business Verify Identity for a DSAR?

Identity verification protects the requester from having their personal data disclosed to an unauthorized person. The verification method should be proportionate to the sensitivity of the data, the risk of impersonation, and the organization’s existing relationship with the requester.

Proportionate Verification Methods

  • Authenticated login to an existing customer or employee account
  • One-time password or verified-email confirmation
  • Matching an existing customer, employee, application, or account identifier
  • Knowledge-based checks using information already held by the organization
  • Additional evidence only where reasonable doubt remains
  • Proof of authority where a representative submits the request

Organizations should avoid collecting excessive identity documents merely to process a rights request. Verification evidence should be protected, access-controlled, retained only as necessary, and recorded in the case audit trail.

Where Should a Business Search for Personal Data?

A defensible search should cover the systems that are reasonably likely to contain personal data within the request scope. A data inventory and processing map make this search faster, more consistent, and easier to evidence.

Common Data Sources

  • Customer relationship management and core business systems
  • Human resources, payroll, recruitment, and performance systems
  • Email, chat, collaboration, and ticketing platforms
  • Cloud storage, shared drives, documents, PDFs, and scanned files
  • Websites, mobile applications, analytics, and consent records
  • Call recordings, CCTV, branch, help-desk, and customer-service records
  • Data warehouses, data lakes, archives, and reporting platforms
  • Third-party processors, SaaS providers, and outsourced service partners
  • Backups where restoration or retrieval is reasonably required by the applicable law and process

GRC³ Data Discovery supports the identification of personal data across structured and unstructured sources, helping teams reduce blind spots during rights-request fulfilment.

Can a Company Refuse a DSAR Request?

A company should not reject a request simply because it is inconvenient, broad, or operationally difficult. However, an organization may withhold information, limit disclosure, retain data, charge a permitted fee, or refuse action where the applicable law provides a valid basis.

Issues Requiring Legal Review

  • The identity of the requester cannot be verified
  • The requester has not shown authority to act for another individual
  • Disclosure would adversely affect the rights and freedoms of another person
  • The material is protected by legal professional privilege or another lawful restriction
  • The request is manifestly unfounded or excessive under a law that recognizes that ground
  • The data must be retained to satisfy a legal obligation, legal hold, or specified purpose
  • A statutory exemption or law-enforcement restriction applies

Any refusal or partial response should be documented, approved by the appropriate legal or privacy owner, explained to the requester where required, and linked to the relevant legal basis.

What Are the Most Common DSAR Management Challenges?

DSAR failures usually result from weak data visibility, unclear ownership, inconsistent intake, and manual coordination rather than from a lack of policy wording.

  • Requests arriving through channels that employees do not recognize
  • Personal data scattered across structured and unstructured systems
  • No reliable data inventory, ROPA, or system-owner directory
  • Inconsistent identity verification and representative validation
  • Unclear ownership between privacy, legal, HR, IT, security, and business teams
  • Manual collection, deduplication, review, and redaction of large data sets
  • Slow responses from processors and third-party service providers
  • Missed deadlines because tasks and dependencies are tracked in spreadsheets or email
  • Incomplete evidence of searches, approvals, actions, and secure delivery
  • Failure to apply correction or erasure consistently across connected systems

A request that cannot be completed without emergency searches and repeated follow-ups is a warning that the organization’s wider privacy governance needs improvement.

What Is a Practical DSAR Compliance Checklist?

Businesses can use the following checklist to test whether their DSAR and Data Principal rights process is operationally ready.

  • Publish clear rights-request and grievance channels
  • Train customer service, HR, support, sales, branch, and operations teams to recognize requests
  • Define request types, legal bases, deadlines, extensions, and escalation rules
  • Use secure and proportionate identity verification
  • Maintain a current data inventory, ROPA, system-owner list, and processor register
  • Assign named owners for search, review, approval, execution, and communication
  • Create standard acknowledgement, clarification, extension, response, and refusal templates
  • Apply legal-review, redaction, privilege, third-party, retention, and legal-hold controls
  • Use secure response delivery and access logging
  • Track corrections, erasures, and withdrawals through downstream systems and processors
  • Retain audit-ready evidence of every material decision and action
  • Monitor request volume, ageing, overdue cases, cycle time, rework, and complaint trends
  • Test the workflow with sample requests before the legal commencement date

What DSAR Records Should a Business Keep for Audit Evidence?

A complete case record should show what the organization received, how it interpreted the request, what systems it searched, what decisions it made, what action it completed, and when the response was securely delivered.

Recommended Evidence

  • Original request and intake channel
  • Request type, jurisdiction, applicable law, and deadline calculation
  • Acknowledgement and correspondence with the requester
  • Identity and representative-verification outcome
  • Scope, search terms, systems, custodians, processors, and date ranges searched
  • Task assignments, reminders, escalations, and completion timestamps
  • Data collected, deduplicated, reviewed, redacted, withheld, corrected, or erased
  • Legal, privacy, security, HR, or business approvals
  • Reasoning for extensions, exemptions, partial disclosures, retention, or refusal
  • Response package, delivery method, delivery confirmation, and access logs
  • Evidence that downstream processors and connected systems completed required actions
  • Closure notes, lessons learned, and linked grievance or appeal records

How Do DSAR Software and Automation Help Businesses?

DSAR software helps organizations manage the complete request lifecycle through centralized intake, identity checks, workflow routing, data discovery, SLA monitoring, approvals, response delivery, and audit reporting.

Capabilities to Look For

  • Configurable request types and multilingual privacy forms
  • Identity verification and representative-authority checks
  • Automated deadline calculation, reminders, and escalation
  • Role-based routing across privacy, legal, HR, IT, security, and business teams
  • Personal data discovery across structured and unstructured sources
  • Processor and third-party task management
  • Review, deduplication, redaction, and approval controls
  • Correction, erasure, consent-withdrawal, and grievance workflows
  • Secure response delivery and requester communications
  • Immutable activity history and audit-ready evidence
  • Dashboards for volume, ageing, SLA performance, bottlenecks, and trends
  • APIs and integrations with CRM, HRMS, ticketing, consent, and data systems

Automation should support human review rather than blindly disclose or delete personal data. High-risk decisions, exemptions, redactions, legal retention, and third-party information still require accountable oversight.

How Can GRC³ Support DSAR and Data Principal Rights Management?

GRC³ helps organizations centralize Data Principal requests and manage access, correction, erasure, consent withdrawal, and grievance workflows through one auditable privacy-operations environment.

GRC³ Rights Management Capabilities

  • Centralized request intake through forms, APIs, and internal channels
  • Configurable request types, owners, workflows, approvals, and SLA timelines
  • Identity verification, case routing, reminders, and escalation controls
  • Personal data discovery across relevant systems and sources
  • Cross-functional tasks for legal, privacy, IT, HR, security, vendors, and processors
  • Correction, erasure, consent-withdrawal, and grievance execution tracking
  • Complete lifecycle history, audit logs, and evidence for compliance reporting
  • Dashboards for request status, ageing, overdue cases, and operational performance

Explore GRC³ Data Privacy and Rights Management to see how your organization can manage Data Principal requests with centralized workflows, SLA tracking, data discovery, and audit-ready evidence.

You can also request a GRC³ demo for a walkthrough aligned to your DSAR, DPDP, data discovery, consent, and privacy-operations requirements.

Conclusion

A Data Subject Access Request is more than a privacy inbox task. It tests whether an organization can identify the requester, understand the legal right being exercised, locate personal data across systems, protect the rights of others, complete approved actions, meet the applicable deadline, and prove what it did.

Businesses preparing for India’s DPDP rights provisions should build separate but connected workflows for access, correction, erasure, consent withdrawal, grievance redressal, and nomination. Strong data discovery, clear ownership, secure identity verification, SLA-driven case management, processor coordination, and complete audit evidence will make the process faster, safer, and more defensible.

Frequently Asked Questions About DSARs

A DSAR is a request from an individual asking an organization to show what personal data it processes about them and provide the information required by the applicable privacy law.