What Is a DSAR? Data Subject Access Requests Explained
A DSAR lets a person see the data you hold on them. Here is what one is, which laws require it, and how it differs from a DSR.
7 min read
A data subject access request (DSAR) is a request from an individual to see the personal data an organization holds about them. It is one of the core rights in modern privacy law, and for most companies it is the request that arrives most often.
What a DSAR Is
At its narrowest, a DSAR is the right of access: a person asks what data you have on them, and you provide a copy along with context such as why you hold it and who you share it with. In everyday use the term is often stretched to cover the wider set of privacy rights, which is where the DSAR-versus-DSR distinction below comes in.
Which Laws Require It
- GDPR grants access, rectification, erasure, restriction, portability, and objection rights across the EU and UK.
- CCPA/CPRA grants California residents the right to know, delete, correct, and opt out of sale or sharing.
- The wider US state patchwork (Virginia, Colorado, and twenty-plus others) grants a similar set, with variations in scope and deadline.
If you process data on residents of any of these places, you are in scope regardless of where your company is based.
DSAR vs DSR
You will see both terms. A DSR, or data subject request, is the umbrella: any exercise of a privacy right, including deletion, correction, portability, and objection. A DSAR is specifically the access request. Treating access as one workflow inside a broader requests system keeps you from building a silo per right.
How to Respond Without a Fire Drill
Most DSAR failures are really data-mapping failures: you cannot hand over, correct, or delete data you cannot locate. The teams that handle requests calmly have three things in place before the first one arrives: a current map of where personal data lives, an intake form with identity verification, and a defined owner and clock for each request.
How Concord Fits
Concord Privacy pairs configurable request forms and identity verification with data mapping, so an incoming request routes to the systems that actually hold the data. The response becomes a tracked workflow rather than an all-hands search.