What is DSAR management? A guide to handling data subject requests

DSAR management is the structured workflow for receiving, validating, fulfilling and recording data subject requests – access, deletion, portability, correction, objection and similar rights.
Quick answer

DSAR management is the structured workflow for receiving, validating, fulfilling and recording data subject access requests and similar rights – including deletion, portability, correction and objection. Most regulations require a response within 30 days, with audit-grade evidence of how the request was handled and what was disclosed.

What a DSAR is

A Data Subject Access Request (DSAR) is a formal request by an individual to exercise their rights under a privacy regulation. The most common request is for access – what data does the organisation hold about me, why and where did it come from. But DSAR is often used as shorthand for the broader set of rights: deletion, rectification, portability, restriction, objection, and rights related to automated decision-making.

Which rights are covered

  • Right of access – receive a copy of the personal data being processed
  • Right to rectification – correct inaccurate or incomplete data
  • Right to erasure (‘right to be forgotten’) – delete data under defined conditions
  • Right to restriction – pause processing in defined circumstances
  • Right to data portability – receive data in a structured, commonly used format
  • Right to object – to processing based on legitimate interests, direct marketing or research
  • Rights related to automated decisions – including profiling with legal or similarly significant effects

Timeframes and obligations

Under GDPR, the response window is one month from receipt, extendable by two further months for complex or numerous requests (the data subject must be informed within the original month). POPIA requires a ‘reasonable time’; the South African regulator interprets this as 30 days. CCPA gives 45 days, extendable by 45 more. Most regulations require the response to be free of charge for the first request; subsequent or manifestly unfounded requests may attract a reasonable fee.

The DSAR workflow

Intake

Through a portal, dedicated email address, or other channel disclosed in the privacy notice. The request is logged and acknowledged.

Identity verification

Proportionate to risk. Don’t over-verify – asking for excessive ID is itself a privacy concern. A matched email, name and date-of-birth typically suffices for low-risk requests.

Scope and lawful basis review

What rights are being exercised? Over what data? Are there exemptions (legal professional privilege, ongoing investigations, third-party data)?

Internal data collection

Tasks are assigned to system owners and departments. Data is gathered, deduplicated and reviewed.

Redaction and packaging

Third-party personal data is redacted. The response pack is assembled – usually a PDF or structured download.

Response delivery and resolution record

The data subject receives the response. The full workflow, decisions and evidence are retained for audit.

Identity verification

The most common failure mode in DSAR handling is over-verification – asking the requester for excessive documentation (passport scans, utility bills, signed declarations) for what should be a straightforward request. The regulator’s guidance is consistent: verification should be proportionate to the sensitivity of the data and the risk of unauthorised disclosure. Match the verification effort to the request, not to a one-size-fits-all template.

Redaction and exemptions

Personal data of third parties (other employees mentioned in an HR file, customers in a CRM note) generally needs to be redacted unless the third party has consented to disclosure or it is reasonable to disclose without consent. Other exemptions vary by regulation – legal professional privilege, regulatory functions, research and statistical purposes, and crime prevention are common ones.

Common challenges

  • Volume during disputes – disgruntled employees and customers often submit broad DSARs as part of a dispute
  • Scope creep – vague requests like ‘all my data’ that require negotiation to scope
  • Third-party data in unstructured stores (email threads, Slack, file shares)
  • Backup and archive data – generally not in scope of immediate retrieval, but disclosure obligations apply
  • Subject access requests routed through legal proceedings – these often have separate rules

How PrivIQ approaches DSAR management

PrivIQ provides structured intake (portal or email), internal task assignment, evidence collection, redaction workflow and a resolution record that satisfies regulator-facing audit needs. Requests link back to the ROPA and data map so scope can be assessed from a single source of truth.

Key takeaways
  • DSAR is shorthand for the full set of data-subject rights, not just access.
  • Response windows are tight – one month under GDPR, similar in POPIA and CCPA.
  • Verification should be proportionate to risk. Over-verification is itself a regulator concern.
  • Volume spikes during employment and consumer disputes. Plan capacity accordingly.
PrivIQ

PrivIQ helps organisations and consultants put this into practice — with policies, controls, evidence, tasks, registers and reporting that survive audit.

Frequently asked questions

More on Privacy Compliance.

Who can submit a DSAR?

Any individual whose personal data you process – employees, customers, prospects, suppliers, members of the public who interacted with you. Authorised representatives (lawyers, family members with appropriate authority) can submit on their behalf.

Can I charge a fee for a DSAR?

Under GDPR, the first request is free. A reasonable fee is permitted for manifestly unfounded or excessive requests, or for additional copies. The fee must reflect actual administrative cost.

What if a request is vexatious or manifestly unfounded?

You can refuse or charge a fee – but you must document the reasoning and the bar is high. Repeated requests with the same scope, requests clearly intended to disrupt, and requests made in bad faith may qualify. Annoyance or inconvenience does not.

Do I need to provide data from backups?

Generally, no – backup tapes and archives are typically out of scope for immediate disclosure if they are inaccessible in the ordinary course of business. But you must disclose the existence of such backups and the retention applied.

How long do I have to respond?

Under GDPR, one month from receipt, extendable by two further months for complex or numerous requests (the data subject must be informed of the extension within the original month). POPIA: 30 days. CCPA: 45 days, extendable by 45.

Put this into practice.

Book a meeting, watch a self-guided walkthrough or take the free assessment to see where your programme stands.