Data Subject Access Request (DSAR)
Abbreviation: DSAR
Pronunciation: DAY-tuh SUB-jekt AK-sess rih-KWEST (D-S-A-R)
Also known as: DSAR
Definition
A Data Subject Access Request (DSAR) is a request by an individual for confirmation of whether an organization processes their personal data and for access to that data and required contextual information. It is an exercise of a data-protection right, not a general demand for every document mentioning the person or for another person’s confidential information. Handling requires identity verification proportionate to risk, request logging, scope clarification, data discovery, redaction, exemption analysis, secure delivery, deadline tracking, and evidence explaining searches, decisions, extensions, and refusals.
Overview
A Data Subject Access Request (DSAR) is a request by an individual for confirmation of whether an organization processes their personal data and for access to that data and required contextual information. The control exists to protect personal and sensitive data while enabling lawful access, analysis, security, and business use under defined rights and governance. It is an exercise of a data-protection right, not a general demand for every document mentioning the person or for another person’s confidential information. It should be interpreted alongside Data Loss Prevention (DLP) because the concepts can affect the same decision without representing the same control, event, or risk.
The workflow identifies data, purpose, legal basis, owner, location, recipients, retention, access, and risk before applying minimization, protection, monitoring, response, and deletion controls. Decisions should consider individual rights, security needs, contractual duties, and the risk of revealing another person’s data. In this context, handling requires identity verification proportionate to risk, request logging, scope clarification, data discovery, redaction, exemption analysis, secure delivery, deadline tracking, and evidence explaining searches, decisions, extensions, and refusals.
It should connect the term to Auditability where that relationship changes access, transaction treatment, investigation, communication, or recovery.
Records should preserve data inventories, classifications, requests, identity checks, searches, disclosures, redactions, approvals, access events, incidents, exceptions, retention actions, and the rationale for decisions. Evidence itself should be minimized and protected.
Useful measures include sensitive-data coverage, unauthorized disclosures, request completion time, overdue requests, false-positive alerts, excessive access, retention exceptions, incident impact, and verified deletion or remediation.
The relationship with Business Verification should be documented where it affects residual risk or control ownership.
Key Takeaway
Handling requires identity verification proportionate to risk, request logging, scope clarification, data discovery, redaction, exemption analysis, secure delivery, deadline tracking, and evidence explaining searches, decisions, extensions, and refusals.
Sources
- General Data Protection Regulation, Regulation (EU) 2016/679 — European Union (2026-08-03)
- Guidelines 01/2022 on Data Subject Rights – Right of Access — European Data Protection Board (2026-08-03)
- Right of Access Guidance — Information Commissioner’s Office (2026-08-03)