Blog
Manage Data Subject Access Requests (DSARs)
DSARs can be a resource-intensive task for businesses who aren’t prepared. We explain what organisations can do to make them as easy as possible.


In a nutshell, a data subject access request – or DSAR for short – is when someone asks an organisation for a copy of all personal data they hold about them, and then that organisation provides it in a clear and structured way. In addition to the data itself, DSARs allow a data subject (like you or me) to find out things like what the organisation is doing with the data, who they’re sharing it with, how long its held on to for, where they got it from, and so on. On the surface it sounds like it could be a simple task, but finding, collecting and providing this information can be an extremely time-consuming and resource-hungry exercise for busines\ses who aren’t prepared.
DSARs (also sometimes called just SARs) are first on the list of data subjects’ rights in the GDPR, and for a good reason. Being able to see the data that businesses hold about us and what they do with the data, is fundamental to the aims and objectives of the GDPR – although it’s not actually new to the GDPR. DSARs were a part of the old Data Protection Act (1998) too, only previously it came with a fee of £10 and timeframe of 40 days. Under the GDPR however, legitimate requests must be free and there’s a strict one month deadline.
The ICO’s website clarifies this as follows: “You must comply with a SAR without undue delay and at the latest within one month of receiving the request. You can extend the time to respond by a further two months if the request is complex or you have received a number of requests from the individual, eg other types of requests relating to individuals' rights.”
Articles 12 and 15 of the GDPR are the primary ones dealing with DSARs, and between them they ensure a data subject can request and be given a copy of their data in a way that’s transparent, lawful, accessible and fair.
DSARs could come in any form: email, letter, phone, or social media . It could even come as part of a phone call with a separate department, such as customer services. Businesses need to be prepared to record and respond to DSAR requests however they arise. In addition to the technical challenge this presents, staff need to be trained and prepared for the DSAR process.
As we’ve discovered, businesses who are fully GDPR compliant will have a much easier time facilitating DSARs, as a good deal of the legwork (such as finding out the ‘what when where why who and how’ of data) will have been done already. For business who aren’t GDPR compliant, I recommend addressing that as a matter of priority. Internal GDPR expertise is often thin on the ground in many organisations, but that doesn’t mean that help isn’t available. Bulletproof’s outsourced DPO service and excellent GDPR training schemes are both great resources to help get your DSAR process embedded and tested with minimal cost.
Finally, my top tip for organisations receiving a DSAR is to stop and try to reach out to the person making the request. Try to understand the purpose of their request, their personal aims, to see if you can provide them with the information they want outside of the DSAR framework. Afterall, the best way to facilitate a complex DSAR is to make it not a DSAR in the first place..
Share your challenge with us and we’ll help you find the right level of support for your business.















