Guide

DSAR vs DSR: What's the Difference

A DSAR is the access-specific request; a DSR is the umbrella covering deletion, correction, portability, and objection. Here is how they relate and why it matters operationally.

6 min read

You will see both terms, often used interchangeably. They are related but not identical. A DSR (data subject request) is the umbrella term for any exercise of a privacy right. A DSAR (data subject access request) is one specific kind of DSR: the request to access the data you hold. Every DSAR is a DSR; not every DSR is a DSAR.

DSR: The Umbrella

A data subject request is any request from an individual to exercise a right the law gives them over their personal data. Depending on the jurisdiction, that includes:

  • Access: see the data you hold about them (the DSAR).
  • Deletion or erasure: have their data removed.
  • Correction or rectification: fix inaccurate data.
  • Portability: receive their data in a portable format.
  • Objection or opt-out: stop certain processing, such as sale or targeted advertising.

DSAR: The Access Request

The DSAR is the access-specific request, and it is usually the most common one. The person wants to know what data you have, often along with context: why you hold it, where it came from, and who you share it with. Because access is where most requests start, "DSAR" became the everyday shorthand for the whole category, which is why the terms blur together.

Why the Distinction Matters Operationally

Treating access as one workflow inside a broader requests system, rather than building a separate process per right, saves you from duplicating effort. The hard part of every DSR is the same: locating the person's data across your systems. Once you can find it, access, deletion, correction, and portability are different actions on the same located data. Build for the umbrella, and the specific rights become variations rather than separate projects.

How Concord Fits

Concord Privacy handles privacy requests as a single configurable workflow: an intake form, identity verification, and routing to the systems that actually hold the data, whether the request is for access, deletion, or correction. You build one process, not one per right.

Get Started

Run Your Privacy Program on One Platform

Concord brings consent, privacy requests, data mapping, and policy management together, so a rights request is a workflow, not a fire drill.