7.1 Data Subject Access Requests & Consent/Rights Processes

Key Takeaways

  • A Data Subject Access Request (DSAR) is the individual's mechanism to exercise rights of access, deletion, rectification, portability, restriction, objection, and consent withdrawal against a controller
  • GDPR Article 12(3) requires controllers to respond 'without undue delay and at the latest within one month' of receipt, extendable by two further months for complex or numerous requests with notice within the first month
  • CCPA/CPRA gives businesses 45 days to respond to verifiable consumer requests, with a single 45-day extension permitted when reasonably necessary
  • Identity verification must be proportionate to the sensitivity of the data and the risk of unauthorized disclosure — over-collection of ID for verification can itself become a privacy violation
  • Consent is a lifecycle, not a one-time event: collect → record → manage → honor withdrawal → delete, and withdrawal must be as easy as giving consent
Last updated: August 2026

What a DSAR Is and Why It Matters

A Data Subject Access Request (DSAR) — sometimes called a subject access request (SAR) or, under the California Consumer Privacy Act (CCPA), a verifiable consumer request — is the individual's formal mechanism to exercise one or more of their statutory privacy rights against an organization that processes their personal data. Under the CIPM Body of Knowledge (BoK competency VI.A), privacy managers must ensure the organization can receive, verify, fulfill, and document these requests consistently and within statutory deadlines.

The privacy notice and internal privacy policies must transparently articulate the data subject's rights and the means of exercising them. A notice that lists rights but omits how to invoke them, or sets an internal contact address the organization does not actually monitor, is a transparency defect that regulators routinely cite.

The Rights Most Commonly Invoked

  • Access — confirmation that data is processed plus a copy of it (GDPR Art. 15; CCPA 'know' categories and specific pieces)
  • Rectification / Correction — fixing inaccurate or incomplete data (GDPR Art. 16; CCPA right to correct)
  • Erasure / Deletion — removal of data under defined conditions (GDPR Art. 17; CCPA right to delete)
  • Restriction — limiting processing pending verification or contestation (GDPR Art. 18)
  • Portability — receiving data in a structured, commonly used, machine-readable format (GDPR Art. 20)
  • Objection — stopping processing for direct marketing or certain other grounds (GDPR Art. 21)
  • Withdrawal of consent — retracting consent at any time, as easily as it was given (GDPR Art. 7(3))
  • Opt-out of sale or sharing — preventing the transfer of personal information for monetary or other valuable consideration (CCPA)
  • Complaint — the right to lodge a complaint with a supervisory authority (GDPR Art. 77)

The DSAR Workflow

A defensible DSAR process follows a repeatable workflow. Each stage should generate an audit record so the organization can demonstrate accountability (GDPR Art. 5(2) — the principle of accountability).

StageKey ActivityOperational Notes
1. IntakeCapture the request through any channel the organization offers (web form, email, call center, in person).Do not require a specific form. GDPR Art. 12(2) says controllers must facilitate requests; refusing a request because it was 'not on the right form' is a violation.
2. Acknowledge & LogConfirm receipt, open a ticket, assign an owner, and start the statutory clock.The GDPR clock starts on receipt, not on completion of internal triage.
3. Identity VerificationConfirm the requester is the data subject or their authorized agent, using proportionate means.For sensitive data, stronger verification (e.g., identity document check) is justified; for low-risk data, matching on name + account number may suffice. Do not retain the verification artifact longer than necessary.
4. Search & LocateIdentify all systems holding the individual's data — CRM, HRIS, backups, email, shared drives, third-party processors, legacy systems.Scope creep and missed systems are the two most common DSAR defects. Maintain a data map / RoPA (Record of Processing Activities, GDPR Art. 30) to make this stage reliable.
5. Review & RedactReview located data for third-party rights, legal privilege, trade secrets, and applicable exemptions before production.Redacting other individuals' personal data is required under GDPR Art. 15(4) and CCPA's business-purpose exemptions.
6. Produce & RespondDeliver the response in a concise, transparent, intelligible, and easily accessible form (GDPR Art. 12(1)). Close the ticket and record the outcome.Provide the information free of charge for the first copy under GDPR; CCPA requires free responses to consumers.

Timelines and Extensions

RegimeBase DeadlineExtensionTrigger to Start Clock
GDPR1 month from receiptUp to 2 further months for complex or numerous requests; must inform the requester of the extension and reasons within the first month (Art. 12(3))Receipt of the request (not completion of verification)
CCPA/CPRA45 daysOne 45-day extension when reasonably necessary; must inform the consumer of the reasons and the new deadlineReceipt of a verifiable consumer request
HIPAA right of access30 daysOne 30-day extension with written reasonReceipt of request (45 CFR 164.524(b)(2))

Fees, Exemptions, and Refusal Grounds

Under GDPR, the first copy is free (Art. 15(3)); a reasonable fee may be charged for further copies based on administrative cost, and requests that are 'manifestly unfounded or excessive, especially because of their repetitive character' may be refused or a reasonable fee charged (Art. 12(5)). Controllers may also refuse to act where compliance would adversely affect the rights and freedoms of others, or where an exemption applies (e.g., legal professional privilege, public security).

Under CCPA, businesses may not charge a fee for responding to consumer requests, but may charge a reasonable fee (calculated on a per-request basis) for costs of verifying the consumer and delivering the information if the requests are 'manifestly unfounded' in nature.

The Consent Lifecycle

For organizations that rely on consent as a lawful basis (GDPR Art. 6(1)(a)) or as a valid opt-in for sensitive data (CCPA's right to limit use of sensitive personal information), consent is not a checkbox captured once at sign-up. It is a managed lifecycle:

graph LR
    A["1. Collect<br/>consent at point<br/>of data collection"] --> B["2. Record<br/>what, when, how,<br/>version of notice"]
    B --> C["3. Manage<br/>keep consent<br/>current as purposes evolve"]
    C --> D["4. Honor<br/>withdrawal as<br/>easily as given"]
    D --> E["5. Delete<br/>or stop processing<br/>unless another basis applies"]
    style A fill:#1e3a5f,color:#fff
    style B fill:#2d5a87,color:#fff
    style C fill:#c9a227,color:#1e3a5f
    style D fill:#2d5a87,color:#fff
    style E fill:#1e3a5f,color:#fff

GDPR Article 7(3) is explicit: the data subject shall have the right to withdraw consent at any time, and it shall be as easy to withdraw as to give consent. A withdrawal flow that is buried three menus deep while the opt-in was a single prominent checkbox is non-compliant, even if the data is ultimately deleted.

Consent and Rights — Operational Comparison

Right / ActionController ObligationCommon Operational Pitfall
AccessProvide a copy plus processing detailsOver-redacting so the requester cannot tell what was withheld
RectificationCorrect inaccurate data without undue delay; notify recipients (Art. 19)Fixing the source system but leaving stale copies in data warehouses or processor systems
ErasureDelete unless an exemption (legal obligation, freedom of expression, public interest) appliesRestoring data from backup tapes after the production deletion, without a backup-deletion procedure
Objection to direct marketingStop processing for marketing 'at the latest at the time of the next communication'Leaving the contact in a marketing suppression list that itself is used for analytics
Withdrawal of consentStop consent-based processing; keep only what another lawful basis requiresTreating withdrawal as a full deletion request when another basis (e.g., contract) still applies
ComplaintAcknowledge; provide DPA contact details in the privacy noticeFailing to log complaints and trend them for program improvement

Worked Scenario

A European customer emails a retailer's general support mailbox: 'I want a copy of all the data you hold on me, and I want to withdraw my consent for marketing.' The mailbox is monitored by a tier-1 agent who has received DSAR training.

Correct handling: The agent logs the request that same day in the privacy request system, sends an acknowledgement, and routes the ticket to the privacy team. The privacy team verifies identity using a proportionate check (matching the email to the account and asking the customer to confirm the last order total — a low-friction, sufficient check because the data to be released is low-sensitivity account data, not financial or health records). The team searches the CRM, marketing platform, order system, and ticketing system using the data map, redacts other customers' personal data from email excerpts, and produces a single consolidated response within 28 days. Separately, the marketing-consent withdrawal is actioned the same week — the customer is moved to a suppression list and removed from the active marketing audience on the email service provider, with the withdrawal timestamp recorded against the consent record.

What would be wrong: Telling the customer they must re-submit on a special web form; demanding a passport scan for a low-risk account-access request (over-collection); deleting the customer's order history when only marketing consent was withdrawn (over-broad action — the order data is needed for contract performance and tax obligations); or letting the 30-day GDPR clock run while waiting for the marketing team to confirm the suppression.

Test Your Knowledge

A controller receives a GDPR access request on May 1. The request is complex, spanning multiple legacy systems and third-party processors. What is the latest date the controller may respond, and what notice obligation applies?

A
B
C
D
Test Your Knowledge

A consumer submits a CCPA deletion request to a business. The business verifies identity, deletes the production data, but the customer's record is later restored from a nightly backup. What is the most accurate characterization?

A
B
C
D