What Is a Data Subject Access Request, and What It Actually Gets You

  • WeThePurple
  • Rights
  • 8 min read

A DSAR is a legal right to be told what an organisation holds about you. It is free, it has a deadline, and it works far better than the deletion request most people send instead. What to ask for, what they may withhold, and what to do when the deadline passes.

Most people who want a company to stop holding their data send a deletion request. It is the wrong first move, and the reason is practical rather than legal: you cannot ask for the deletion of something you cannot name. An organisation that receives a vague deletion request will delete the account you know about and keep everything you did not.

A data subject access request asks a different question: tell me everything you hold about me, and where you got it. In the EU and the UK it is a right under Article 15 of the GDPR. In California it is the right to know under the CCPA and CPRA. The wording differs, the mechanism is the same.

It is free, it does not require a lawyer, and it does not require you to explain why you want it. That last point matters, because organisations sometimes ask, and you are not obliged to answer.

What you are entitled to receive

A hand posting a plain white envelope with a stamp into one of a row of grey metal apartment letterboxes, several of the slots below it still holding mail.
A hand posting a plain white envelope with a stamp into one of a row of grey metal apartment letterboxes, several of the slots below it still holding mail.

What you are entitled to receive goes well beyond a copy of your profile. The categories of personal data held, the purposes of processing, who it has been disclosed to, where it came from if not from you, how long it will be kept, and whether it feeds automated decision making. In practice the list of recipients is the part that surprises people, because it names the data brokers and advertising partners nobody told them about.

The deadline is one month under the GDPR, extendable by two further months for complex requests, and the extension itself has to be communicated within the first month. Under the CCPA it is 45 days, extendable to 90. An organisation that simply goes quiet is not exercising an extension, it is missing a deadline.

How to send it, and what they can ask of you

Send it in writing and keep proof. Email to the data protection officer or privacy address works, and a request made in any form is legally valid, but a request you cannot prove you sent is a request you cannot escalate. State plainly that you are making a subject access request under Article 15 GDPR or the applicable law, and give enough detail for them to find you: the email address on the account, a customer number, the approximate period.

  • Free, no reason required, no lawyer needed
  • One month under the GDPR, 45 days under the CCPA, extensions must be announced
  • Ask for categories, purposes, recipients, source, retention period and automated decisions
  • Identity checks are legitimate; demands far beyond what the account required are not
  • Access first, deletion second: you cannot delete what you cannot name

They may ask you to prove who you are, and that is legitimate. Handing your data to whoever asks would be the opposite of privacy. What is not legitimate is demanding far more identification than the account itself required. If you opened the account with an email address, a passport scan is disproportionate, and you can say so.

Refusals, deadlines and escalation

What they may lawfully withhold is narrower than most refusals suggest. Data about other people, material covered by legal privilege, and information whose disclosure would prejudice an investigation. A refusal has to be reasoned and specific. « Commercially confidential » applied to your own contact history is not a reason, it is a hope that you will not press.

When the deadline passes, escalate rather than resend. A complaint to the supervisory authority costs nothing: the CNIL in France, the ICO in the UK, the relevant state authority elsewhere in the EU, the California Privacy Protection Agency in California. Complaints are handled routinely and an organisation that ignored you will usually answer the regulator.

**When the deadline passes, escalate rather than resend.** A complaint to the supervisory authority costs nothing: the CNIL in France, the ICO in the UK, the relevant state authority elsewhere in the EU, the California Privacy Protection Agency in California. Complaints are handled routinely and an organisation that ignored you will usually answer the regulator.

- WeThePurple

The order that works, and the limit

The sequence that works is access first, then correction or deletion, because the response tells you exactly what to name in the second request. Sending them in the other order is how people end up believing their data was deleted when only the visible part was.

One honest caveat: a DSAR tells you what one organisation holds, not what exists about you. Each company must be asked separately, and the ones profiting most from your data are the ones you have never heard of. That is a structural limit of the right, not a failure of your request, and it is why the data broker route is a separate exercise.

Related