What is a DSAR?
short answer
A DSAR — data subject access request — is a formal request from an individual asking an organization to disclose the personal data it holds about them, and often to correct, delete, or stop sharing it. Under the GDPR the response deadline is one month; under California's CCPA/CPRA it is 45 days, extendable once with notice. There is no required format: an email that makes the request clear is usually enough to start the clock.
What a DSAR actually asks for
The name says access, but in practice a DSAR is a family of requests:
- Access — what do you hold about me, and where did it come from?
- Portability — give it to me in a usable, machine-readable format
- Correction — this is wrong, fix it
- Deletion — remove it
- Opt out — stop selling or sharing it
Different laws bundle these differently, but most organizations handle them through one intake process.
The clock
| Framework | Deadline | Extension |
|---|---|---|
| GDPR | 1 month | +2 months for complex requests, with notice |
| CCPA / CPRA (California) | 45 days | +45 days with notice |
| Most other US state laws | 45 days | Commonly +45 days |
The clock starts when the request is received, not when it reaches the right team. A request sent to a general support address counts. This is precisely where organizations fail: the deadline runs while an email sits in a queue nobody routes.
What can and cannot be refused
A request can generally be refused or narrowed when:
- The requester’s identity cannot be verified — and personal data must never be handed to someone who has not shown they are the person
- The request is manifestly unfounded or excessive, particularly if repetitive
- Answering would reveal another person’s personal data
- A specific exemption applies, such as legal claims or a regulatory retention duty
It generally cannot be refused because it is inconvenient, because the data is scattered across systems, or because you would rather not.
Making one, as a consumer
- Write to the company’s privacy contact. Check the privacy policy; most list an address or a form.
- Say what you want plainly. “Please provide all personal data you hold about me, its sources, and any third parties you have shared it with.”
- Give them enough to identify you — and no more. An account email is usually sufficient; a scan of your passport usually is not.
- Note the date. That is when the clock started.
- Escalate if ignored. Your state attorney general, or the relevant data protection authority, accepts complaints about unanswered requests.
Handling one, as a business
Organizations that struggle with DSARs share one trait: they cannot quickly answer where personal data lives.
- Maintain a data inventory. Everything else depends on it.
- Publish one intake route, then route internally to a named owner with a deadline attached.
- Verify proportionately. Demanding excessive identification is itself a compliance problem.
- Record what you sent and when. If a request escalates, that record is the entire defense.
- Include third parties. “Who did you share it with” is part of the request and the part most responses quietly omit.
A DSAR is a test of your data map, not of your legal team. Organizations that know where things live answer in days.
people also ask this as
- What is a data subject access request?
- How do I request my data from a company?
- How long does a company have to respond to a DSAR?
- Can a company refuse a DSAR?
keep reading
Last updated August 2026. This is general information, not legal advice — privacy law changes often and turns on specifics. For your own situation, talk to counsel.