/ Articles /
Legal
/

How to Handle a DSAR Request

Mar 31, 2026
6
Min Read
Who should read this?

Startup founders, small business owners, HR managers, and compliance officers in companies processing EU personal data under GDPR, especially those handling employee or customer DSARs.

They'll learn a practical step-by-step process to respond efficiently, avoid fines and investigations, and build internal procedures for future requests.

Key Takeaways

  • DSARs must be responded to within one calendar month; extensions possible for complex cases with notification.
  • Search emails, CRM, HR systems, Slack, paper files, and other reasonable locations for personal data.
  • Redact third-party data, legal privilege, and certain investigative info; always document decisions.
  • Follow steps: log request, verify ID if needed, search, review/redact, compile response, send securely.
  • Non-compliance risks DPC complaints, reprimands, fines up to €20M or 4% turnover, plus reputational damage.

Frequently Asked Questions

What is a data subject access request?

A data subject access request (DSAR) is a formal request from an individual for a copy of all personal data you hold about them and how it is used, per Article 15 of the GDPR. It doesn't need specific wording; phrases like 'show me my data' trigger it, starting the response clock immediately. (52 words)

Who can make a DSAR?

Any individual whose personal data you process as a controller, including current/former employees, customers, prospective employees, contractors, and some third parties. No explanation of reason is required, and you can't refuse based on adversarial motives like disputes. (47 words)

What is the deadline for responding to a DSAR?

You must respond within one calendar month from receipt, e.g., request on March 3 due by April 3. For complex cases, extend by two months but notify within the first month with reasons. Late responses breach GDPR and risk DPC action. (50 words)

What must you search for a DSAR?

Search all reasonable locations: emails, CRM, HR/payroll software, project tools like Jira, accounting, Slack/Teams, paper files, backups. Proportionate efforts required; document exclusions if burdensome. Not exhaustive forensics, but cover obvious spots. (41 words)

Can you redact information in a DSAR response?

Yes, redact third-party personal data, legal privilege communications, info prejudicing investigations, or non-personal data. Document reasons for each. Redact minimally; if it makes document meaningless, consider alternatives to protect others. (42 words)

Explore our other topics