What is a DSAR?
What does a DSAR cover?
Is there a difference between DSAR and SAR?
DSAR under GDPR
The GDPR applies to any organization, regardless of its location, that collects and processes the personal data of people in the EU.
The right of access is one of the nine rights the data subjects have under GDPR.
Recital 63 states that the data subjects have the right to access their personal data collected by an organization. They must be able to easily exercise this right to be aware of and to verify if the data is being processed lawfully. The right extends to health data as well.
Art. 15 lists down the information related to personal data a data subject has the right to have access to:
- The purpose of processing the data
- The categories of personal data collected
- The recipients with whom the personal data has been or will be shared with
- How long the data will be stored
- Information or awareness about other data subject rights — the right to rectification, right to delete, right to restrict processing, and the right to object to the processing of personal data
- Information about the right of data subjects to file a complaint with their supervisory authority
- The source of personal data, if it was not directly collected from the data subject
- The existence, significance, and consequences of processing personal data through automated decision-making and user profiling
- In case there is cross-country data transfer, the appropriate safety measures taken to secure the data
The organizations are liable to provide a copy of the personal data in a commonly used electronic form if requested. They may charge a reasonable fee for further copies.
The GDPR recommends organizations ‘-’ have a secure system that gives the data subject direct access to their personal data. However, while providing the copy, you have to ensure that it will not interfere with the rights and freedom of other data subjects. In case there is a request for accessing a large quantity of information, you can request the data subject to specify the information they require. You can refuse a data access request only after careful consideration, and you must specify your reason to them
DSAR under CPRA
A applies to any for-profit entity that does business in California, that collects and processes Californian consumers’ personal information, and that satisfies at least one of the following:
- Has annual gross revenues of over 25 million dollars
- Annually buys, receives, sells, or shares, alone or in combination, the personal information of 100,000 or more consumers, households, or devices for commercial purposes
- Derives 50% or more of its annual revenues from selling personal information
Like GDPR, the CPRA also grants its data subjects or consumers (Californians) the right to access personal information. It gives them the right to request access to the personal information the organizations have on the consumers.
Under CPRA, a consumer can request a business that collects personal information about consumers access to the following information:
- The categories of personal information the business has collected
- The specific pieces of personal information the business has collected
- The categories of sources of personal information it has collected
- The categories of personal information the business has sold or disclosed
- The business or commercial purpose for collecting or selling personal information
- The categories of third parties the business has sold or disclosed the personal information
A business must have two or more designated methods for the data subjects to submit their data access requests. These methods include a toll-free number, a website address, and an email address.
How long do you have to respond to a DSAR?
The ideal DSAR response time an organization must take depends on the applicable data privacy law.
For GDPR, you have to respond to a data access request within a month of receiving it. There must be a legitimate reason behind any delay in response. In case there are numerous requests, or if they are complex, you can take an additional two months to respond and specify the reason for the extension.
The CPRA response time for DSAR is 45 days from the day of receiving the request to respond. The 45 days include the time required to verify the request. If you need additional information from the data subjects, you can take another 45 days.
Can you refuse a DSAR?
Under GDPR, you can refuse to comply with a data access request under certain circumstances, such as
- (Manifestly unfounded) If it is found to be made with the intention of harassing the employers of the organization or purely for gaining favor from you in exchange for withdrawing the request.
- (Excessive) If there are repeated requests made without a legitimate reason.
- If sharing the requested information interrupts the rights and freedom of other data subjects.
Under CPRA, your business does not require to oblige with the DSAR if:
- You cannot verify the identity of the data subject.
- It does not maintain personal information in an accessible format.
- The purpose of storing personal information is solely a legal obligation.
- It does not sell or use personal information for commercial purposes.
- If the requested information is a consumer’s government-issued identification numbers, bank account details, medical data, account password, or other security-related data, or unique biometric data.
Can you charge a fee for DSAR?
How do you handle a DSAR?
We have already seen what information data subjects can request to access. However, it remains a question of how you are going to respond to such a request. Is there a standard DSAR template or a DSAR form?
Well, the truth is there isn’t any.
Yes, you do not have to follow a specific format to handle or respond to a DSAR. You can set your template or process that is meticulous and easy for the data subjects to exercise the right.
The major steps you can follow to handle a DSAR are:
Data request verification
Identity verification
Perhaps, the most important step.
An insightful experiment by James Pavur, University of Oxford-based researcher, highlights the need for robust identity checks. Pavur sent DSARs to 150 organizations pretending to be his girlfriend, using a fake email address. The results showed:
- Only 84 organizations responded at all
- 39% initiated further ID checks
- 24% complied without verifying identity
- 16% had weak verification processes

Data verification
Send data




![Consentement aux cookies du RGPD: Exemples & comment se conformer [Directives par pays]](https://assets.cookieyes.com/gdpr_cookie_consent_9b2f29afaf.png)

