Quick Answer: A Data Subject Access Request (DSAR) is a formal request made by an individual to find out what personal data an organisation holds about them, how it’s being used, and who it’s been shared with. Under UK GDPR and EU GDPR, organisations must respond within one calendar month — free of charge in most cases. DSARs are a legal right, not a courtesy.
Key Takeaways
- A DSAR gives individuals the legal right to access their own personal data held by any organisation.
- Under UK GDPR and EU GDPR, organisations have one calendar month to respond (extendable to three months in complex cases).
- Responding to a DSAR is free in the vast majority of cases.
- Organisations can refuse a DSAR, but only on specific, legally defined grounds.
- Ignoring a DSAR can trigger ICO enforcement action and significant fines.
- DSARs can be submitted in any format — there’s no required template or magic phrase.
- US privacy rights vary by state; there is no single federal equivalent to GDPR’s DSAR right.
- Businesses should have a clear internal DSAR process before a request lands — not after.
What Exactly is a Data Subject Access Request (DSAR) — and Why Would You Need One?
A Data Subject Access Request (DSAR) is a written request from an individual — the “data subject” — asking an organisation to confirm whether it holds personal data about them and, if so, to provide a copy of that data. It’s a right enshrined in Article 15 of both the UK GDPR and EU GDPR.
Why would someone need one? The reasons are more varied than you might think:
- Employees checking what their employer holds on them during a dispute or redundancy process.
- Customers wanting to see what a company knows about their purchasing behaviour or communications history.
- Individuals checking whether a financial institution or insurer has data that may have affected a decision made about them.
- Patients reviewing medical records held by a healthcare provider.
For businesses, understanding what a DSAR is matters because you’re almost certainly going to receive one. The ICO reported a significant year-on-year rise in DSAR-related complaints throughout the early 2020s — and that trend hasn’t reversed. Having a clear process in place before a request arrives is the difference between a smooth response and a compliance headache.
If you’re still getting to grips with the broader framework, our guide on what GDPR means and its impact on data protection is a good place to start.
Who Should File a DSAR — and Who Probably Doesn’t Need One?
Any individual whose personal data is processed by an organisation can submit a DSAR. That’s the legal answer. The practical answer is slightly more nuanced.
You probably should file a DSAR if:
- You’re in an employment dispute and want to see what HR records exist about you.
- You’ve been refused credit and want to understand what data influenced that decision.
- You suspect a company is using your data in ways you didn’t agree to.
- You want to check whether an organisation still holds data you’d like deleted.
You probably don’t need a DSAR if:
- You simply want to unsubscribe from a mailing list (that’s a different right — the right to object).
- You want data corrected (that’s a rectification request under Article 16).
- You want your data deleted entirely (that’s a right to erasure, or “right to be forgotten”).
DSARs are specifically about access — seeing what’s held. Other rights exist alongside them. Knowing the difference saves time for everyone.
How Do You Submit a Data Subject Access Request to a Company?
There’s no official form, no required wording, and no special template needed. A DSAR can be made verbally or in writing — by email, letter, or even via a social media message. The moment someone clearly asks to see their personal data, the clock starts ticking.
That said, a clear, written request works best. Here’s what to include:
- Your full name and any other identifiers the organisation might use (account number, employee ID, email address).
- A clear statement that you’re making a Subject Access Request under UK GDPR (or EU GDPR if applicable).
- The specific data you’re looking for, if you want to narrow the scope — though you’re entitled to everything if you don’t specify.
- Proof of identity, if the organisation asks for it (they’re allowed to verify who you are before releasing data).
Common mistake: Being vague. A request that says “send me everything” is valid, but it can result in an overwhelming data dump. If you’re looking for something specific — say, all emails mentioning your name from a particular period — say so. You’ll get more useful results.
What Information Can You Get From a DSAR About Your Personal Data?
A DSAR entitles you to a copy of your personal data and supplementary information about how it’s being used. This goes well beyond a simple printout.
Under Article 15 of UK GDPR, you’re entitled to:
| What You Can Request | What That Means in Practice |
|---|---|
| A copy of your personal data | Emails, records, notes, files — anything containing your personal information |
| The purposes of processing | Why the organisation is using your data |
| Categories of data held | What types of data (health, financial, behavioural, etc.) |
| Recipients or categories of recipients | Who your data has been shared with |
| Retention periods | How long they plan to keep it |
| The source of the data | Where they got it from, if not directly from you |
| Automated decision-making info | Whether decisions about you are made by algorithms |
What you won’t get: data about other people, legally privileged information, or data that falls under specific exemptions (more on those below).
How Long Does a Company Have to Respond to a DSAR?
Organisations must respond within one calendar month of receiving the request. Not 30 business days. One calendar month from the date the request was received.
In complex or high-volume cases, this can be extended by a further two months — but the organisation must tell you within the first month that they’re extending the deadline and explain why.
What counts as “receiving” the request? The clock starts when the organisation receives the request, even if they haven’t yet verified your identity. If they ask for ID verification, the clock pauses until you provide it — but only if the request was genuinely unclear about who was asking.
Missing this deadline is one of the most common reasons organisations receive ICO complaints. It’s also one of the most avoidable. If your business doesn’t have a DSAR log and a response workflow, that’s worth fixing today. Our GDPR compliance audit guide walks through exactly this kind of process gap.
Are DSARs Free — or Do Companies Charge a Fee?
In almost all cases, responding to a DSAR is free. UK GDPR and EU GDPR both establish this as the default position.
The exception: if a request is “manifestly unfounded or excessive” — particularly if it’s repetitive — an organisation can either charge a “reasonable fee” to cover administrative costs or refuse to respond. Both options require the organisation to justify their decision, and the bar is deliberately high.
What organisations cannot do: charge a blanket admin fee for every DSAR, or use cost as a reason to delay. The ICO has been clear on this. If a company tries to charge you without good reason, that’s worth flagging.
Can a Company Legally Deny Your DSAR?
Yes — but only in specific circumstances. Organisations can refuse a DSAR (or withhold certain information within a response) if:
- The request is manifestly unfounded or excessive — for example, someone submitting multiple identical requests in quick succession with no clear purpose.
- An exemption applies — UK GDPR and the Data Protection Act 2018 include exemptions for things like legal professional privilege, crime prevention, national security, and certain management information.
- The data relates to third parties — if releasing the data would reveal personal information about someone else who hasn’t consented, that information can be redacted.
If an organisation refuses, they must tell you why within the one-month deadline. They must also tell you about your right to complain to the ICO. A refusal without explanation is itself a breach.
What Happens if a Company Ignores Your Data Subject Access Request?
Ignoring a DSAR is a serious compliance failure. Here’s what can follow:
- ICO complaint: You can report the organisation to the Information Commissioner’s Office. The ICO investigates and can compel the organisation to respond.
- Enforcement action: The ICO has powers to issue enforcement notices, reprimand letters, and — in serious cases — financial penalties.
- Fines: Under UK GDPR, fines for data protection breaches can reach £17.5 million or 4% of global annual turnover, whichever is higher. DSAR failures contribute to enforcement decisions. See our breakdown of GDPR fines and penalties for the full picture.
- Reputational damage: Enforcement decisions are published. Being named in an ICO ruling isn’t good for customer trust.
For businesses, the message is simple: respond on time, every time.
What’s the Difference Between a DSAR in Europe Versus the US?
This is where things diverge significantly. In the UK and EU, the right to access your personal data is a universal legal right under GDPR — it applies to every individual, every organisation, every sector.
In the US, there’s no single federal equivalent. Privacy rights are fragmented across state laws:
- California has the California Consumer Privacy Act (CCPA), which gives residents the right to know what data is collected and to request deletion.
- Virginia, Colorado, Connecticut, Texas and others have passed their own state-level privacy laws with similar (but not identical) access rights.
- Most US states still have no comprehensive consumer privacy law.
For UK and EU businesses, this matters when dealing with US-based vendors or transferring data internationally. For US companies serving UK or EU customers, GDPR applies to you regardless of where you’re based. Our article on whether GDPR affects US companies covers this in detail.
The key difference: in the UK and EU, the right is automatic and universal. In the US, it depends on your state and the type of organisation involved.
For a deeper look at how UK and EU rules compare to each other, see our EU GDPR vs UK GDPR comparison.
What Are Common Mistakes People Make When Filing a DSAR?
Filing a DSAR is straightforward — but a few missteps can slow things down or reduce the quality of the response.
Mistake 1: Not identifying yourself clearly. If the organisation can’t verify who you are, they’re entitled to ask for proof of identity before responding. This pauses the clock, but it also delays you getting your data.
Mistake 2: Being too vague. “Send me everything” is valid, but if you’re looking for something specific, say so. A targeted request gets a more useful response.
Mistake 3: Using the wrong channel. Some organisations have a dedicated DSAR form or privacy team. Using the general customer service inbox can cause delays. Check the company’s privacy policy for the right contact.
Mistake 4: Confusing a DSAR with other rights. If you want data deleted, that’s a right to erasure. If you want it corrected, that’s rectification. A DSAR is specifically about access.
Mistake 5: Not keeping a copy. Always keep a record of when and how you submitted your request. If you need to escalate to the ICO, you’ll need evidence.
Are There Privacy Laws That Protect Your DSAR Rights?
Yes — and they’re enforceable. In the UK, your right to submit a DSAR is protected by:
- UK GDPR (retained from EU GDPR post-Brexit, now part of UK law)
- The Data Protection Act 2018 (which supplements UK GDPR and includes sector-specific provisions)
- The Data Use and Access Act 2025 — the UK’s significant update to its data protection framework, which introduced some changes to how DSARs are handled in practice. Our complete guide to the Data Use and Access Act 2025 explains what’s changed.
In the EU, Article 15 of the EU GDPR remains the governing provision, enforced by national data protection authorities across member states.
The ICO (Information Commissioner’s Office) is the UK’s supervisory authority. They handle complaints, conduct investigations, and issue enforcement action when organisations fail to comply.
How Detailed Should Your DSAR Be to Get Good Results?
The short answer: specific enough to be useful, but you don’t need to write an essay.
A well-crafted DSAR includes:
- Your full name and contact details
- Any reference numbers or identifiers the organisation uses for you
- The specific types of data or time periods you’re interested in (if relevant)
- A clear statement that this is a Subject Access Request under UK GDPR
You don’t need legal language. You don’t need to cite specific articles. You just need to be clear about what you’re asking for and who you are.
If you’re a DPO or business owner building a DSAR response process, consider whether your organisation has a Data Protection Officer in place — or whether an outsourced DPO service might be the right fit for handling requests like these efficiently.
DSAR Response Checklist for Organisations
Use this as a quick reference when a DSAR lands in your inbox:
- [ ] Log the request with date received
- [ ] Verify the identity of the requester (if genuinely unclear)
- [ ] Confirm receipt to the requester within a few days
- [ ] Search all relevant systems (email, CRM, HR systems, paper files)
- [ ] Review data for third-party information that needs redacting
- [ ] Check whether any exemptions apply
- [ ] Compile the response — include supplementary information (purposes, recipients, retention periods)
- [ ] Respond within one calendar month of receipt
- [ ] If extending, notify the requester within the first month with reasons
- [ ] Document the process for your records
Frequently Asked Questions
Q: Can I make a DSAR on behalf of someone else?
Yes, with their written authorisation. Parents can make DSARs on behalf of young children. Solicitors can act on behalf of clients. The organisation may ask for proof of authority before responding.
Q: Does a DSAR have to be in writing?
No. A verbal request is valid. However, putting it in writing creates a clear record and makes it easier to escalate if the organisation doesn’t respond.
Q: Can an organisation ask me why I’m making a DSAR?
They can ask, but you’re not obliged to explain. The right to access your data doesn’t depend on having a reason. However, providing context can sometimes help the organisation locate the right data faster.
Q: What if the organisation says they don’t hold any data about me?
That’s a valid response — as long as it’s true. If you have reason to believe they do hold data and are refusing to disclose it, you can complain to the ICO.
Q: Can an employee make a DSAR about their employer?
Absolutely. Employee DSARs are among the most common. Employers must respond like any other data controller — within one month, free of charge, with all relevant personal data.
Q: What’s the difference between a DSAR and a Freedom of Information request?
A DSAR is about your own personal data. A Freedom of Information (FOI) request is about information held by public authorities — it’s not personal to you. Different rules apply.
Q: Can I make multiple DSARs to the same organisation?
Yes, but if requests become repetitive without good reason, the organisation may be entitled to refuse or charge a fee for subsequent requests.
Q: What if I’m unhappy with the response I receive?
You can ask the organisation to review their response. If you’re still unsatisfied, you can complain to the ICO at ico.org.uk. The ICO will investigate and can require the organisation to take action.
Q: Do charities and small businesses have to respond to DSARs?
Yes. DSAR obligations apply to all organisations that process personal data — regardless of size, sector, or profit status.
Q: How long does the ICO take to investigate a DSAR complaint?
This varies. The ICO prioritises cases based on risk and impact. Some complaints are resolved within weeks; others take several months. Keeping records of your original request and any correspondence speeds things up.
Conclusion: What to Do Next
Understanding what a Data Subject Access Request (DSAR) is — and how to handle one — is non-negotiable in 2026. Whether you’re an individual wanting to know what a company holds about you, or a business owner making sure your processes are watertight, the fundamentals are the same: DSARs are a legal right, the deadlines are firm, and the consequences of getting it wrong are real.
If you’re an individual: Know your rights. Submit your request in writing, keep a copy, and don’t hesitate to escalate to the ICO if you don’t get a response.
If you’re a business or DPO: Build your DSAR process now, not when a request arrives. Train your team, log every request, and respond on time. A GDPR compliance audit is a practical way to check whether your current processes would hold up under scrutiny.
Data protection compliance isn’t about fear — it’s about being the kind of organisation people can trust with their information. DSARs are one of the clearest ways individuals can hold you to that standard.
DSAR Deadline Calculator
Enter the date a Subject Access Request was received to calculate your legal response deadlines under UK GDPR.
Based on UK GDPR Article 12(3). The one-month period is calculated from the day after receipt. For complex requests, you must notify the data subject of the extension within the first month. This tool is for guidance only and does not constitute legal advice.

