Cybersecurity 101back-iconWhat is Data subject access request (DSAR)?

What is Data subject access request (DSAR)?

A data subject access request (DSAR) is a request from an individual asking an organization to confirm whether it processes their personal data and to provide access to that data. It is a core privacy right under laws such as the GDPR and appears in similar forms under other privacy regulations.

In simple terms, a DSAR lets a person ask, “What personal information do you hold about me, why do you use it, who has access to it, and can I get a copy?”

What information can a DSAR include?

A DSAR usually covers more than a raw data export. Depending on the applicable privacy law, the response may need to explain:

  • The categories of personal data being processed
  • The purpose of collecting or using the data
  • The source of the data, if it was not collected directly
  • Recipients or categories of recipients who received the data
  • How long the data is stored, or how retention is decided
  • The individual’s related rights, such as correction or deletion

Personal data can include names, contact details, device identifiers, employee records, customer support logs, location data, account activity, and other information linked to an identifiable person.

Why data subject access request (DSAR) matters

A DSAR is important because it turns privacy from a policy statement into an operational obligation. Organizations must be able to locate personal data across systems, verify the requester’s identity, review whether any exemptions apply, and respond within the required timeline.

For security and privacy teams, DSAR handling also reveals how well data is classified, governed, and controlled. If personal data is scattered across unmanaged devices, shadow IT tools, or poorly documented systems, responding accurately becomes difficult.

DSAR requirement Business impact
Find relevant personal data Requires visibility across apps, endpoints, and repositories
Protect third-party data Responses may need redaction before disclosure
Meet response timelines Needs repeatable workflows and clear ownership

How organizations should prepare

Organizations should maintain accurate data inventories, define DSAR intake procedures, and train teams to recognize access requests even when they are not labeled formally. Identity verification should be proportionate, and responses should avoid exposing another person’s data.

Endpoint and device management can support DSAR readiness by improving visibility into where business data resides. Solutions like Hexnode can help organizations enforce security policies, manage work devices, and reduce uncontrolled data exposure across endpoints.

FAQs

No. A DSAR is mainly about access to personal data. Deletion, correction, restriction, and objection are separate privacy rights, though a DSAR may lead a person to exercise them later.

In some cases, yes. An organization may refuse or limit a response if the request is excessive, unfounded, or conflicts with legal obligations, security needs, or another person’s privacy rights.