DSAR Lite
← Blog
GDPRDSARArticle 15CCPAprivacy compliance

What Actually Counts as a DSAR? A GDPR Article 15 Guide for Small Teams

September 6, 2026 · DSAR Lite

A customer emails support: "Can you tell me what data you have on me?" A former employee asks HR to "send everything in my file." A website visitor replies to a marketing email with "stop contacting me and delete my info."

Are these all data subject access requests? Two of them are. The third is a mix of two different rights. Most small teams can't tell the difference in the moment — and under GDPR Article 15, that ambiguity is exactly what turns a routine email into a missed deadline.

The one-sentence definition

Article 15 of the GDPR gives any individual the right to obtain confirmation of whether an organization is processing their personal data, and if so, access to that data plus a defined set of details: the purposes of processing, the categories of data involved, who it's been shared with, how long it will be kept, and where it came from. The UK ICO's guidance on the right of access is the clearest plain-language walkthrough of what that means in practice, and it's worth bookmarking even if you're a US-based team — most state privacy laws borrow the same structure.

The catch: nowhere does the law require the word "DSAR," a specific form, or even the phrase "data protection." A request just has to make clear that someone wants to know what personal data you hold about them. That's it.

What counts as a DSAR (even when it doesn't look like one)

  • "What information do you have about me?" — the textbook case, and the easiest to spot.
  • "Send me a copy of my file" — from an employee, a former employee, or a job applicant. HR requests are DSARs just as much as customer ones.
  • A support ticket that includes "under GDPR, I'd like to know what you're storing on me" — the moment the legal basis is invoked, the clock starts, regardless of which inbox it landed in.
  • A vague complaint that turns into a data question — "why am I still getting emails, what did you sign me up with?" often contains an implicit access request even without the word "data."

What doesn't count as a DSAR

  • "Delete my account" on its own is an erasure request (Article 17), not an access request — a related but separate right, with its own timeline.
  • "Unsubscribe me" is a marketing opt-out, generally handled outside the DSAR workflow entirely (though it can trigger one if the person also asks what data is held).
  • "Why was my loan application rejected?" may be a request about automated decision-making (Article 22) layered on top of an access request — it needs both answered, not just one.
  • Internal audits or a regulator's own inquiry aren't DSARs — those follow separate compliance and investigation processes.

The distinction matters because each of these rights carries its own deadline and its own required response — treating them all as the same ticket type is how teams miss the parts of a request that don't say "access" in the subject line.

DSAR vs. subject access request vs. CCPA "right to know" — same idea, different clocks

"DSAR" and "subject access request" (SAR) are the same thing — DSAR is the more common shorthand in GDPR-adjacent conversation, SAR is the term UK guidance tends to use. Both map to Article 15 in the EU/UK.

In the US, the closest equivalent is the CCPA "right to know", and the mechanics diverge in ways that matter operationally:

GDPR Article 15 (EU/UK) CCPA "right to know" (California)
Response deadline 1 month, extendable to 3 for complex requests 45 days, extendable to 90
Verification standard "Reasonable" — context-dependent Explicit two-factor verification for sensitive data
Fee Generally free (fee allowed only for "manifestly unfounded or excessive" repeat requests) Free, twice per 12-month period
Format "Commonly used electronic form" if requested electronically Portable, readily usable format

If you serve both EU and California residents — which most SaaS companies with a website do — you're not tracking one deadline. You're tracking two overlapping ones, on two different clocks, with two different verification bars. Our last post covered why 20 more US states now layer their own versions on top of this, each with its own thresholds and cure periods.

Why this is a spreadsheet problem until it isn't

For a five-person team getting one DSAR a quarter, a shared doc with a due-date column is a perfectly reasonable system. The failure mode isn't complexity — it's volume and drift. The moment two requests land in the same week, from different jurisdictions, with different deadlines and different intake channels (one from a support ticket, one from a reply-to-marketing email, one from HR), a spreadsheet stops being a system and starts being a liability with a due-date column.

That's the gap between "we have a DSAR process" and "we have a DSAR process we can actually produce evidence of" — and evidence is what regulators ask for first, not intentions.

You don't need an enterprise privacy platform to close that gap

Platforms built for enterprise privacy teams — the DataGrails, Transcends, Kettles, and Mimecasts of the world — are built for organizations with dedicated privacy engineering staff, hundreds of internal systems to map, and procurement processes that assume a six-figure annual contract. That's the right tool for that job. It's a lot of tool for a team fielding a handful of requests a month.

DSAR Lite exists for the gap in between "spreadsheet" and "enterprise platform": deadline tracking that calculates the right clock automatically, letter templates by jurisdiction, and an Article 30 processing-activity record — without the implementation project. Plans start at $29/month for small teams, with a 14-day trial on every tier.

The practical checklist

  1. Write down your intake channels. Support inbox, HR inbox, a reply-to-marketing address, a contact form — anywhere a person could plausibly ask "what data do you have on me?" is a channel that needs someone watching it for DSAR language.
  2. Separate the rights. A request to "delete and tell me what you have" is two rights, two deadlines, one ticket.
  3. Track the clock, not the calendar. GDPR gives you a month; some US states give you 45 days; others 15 for consent revocation. The deadline that matters is the one attached to that specific request's jurisdiction.
  4. Keep proof, not just responses. Date received, applicable deadline, what was sent, and when — the same documentation our fines post flagged as what regulators actually check first.

DSAR Lite is a DSAR and Article 30 tracking tool built for small privacy and compliance teams — not a substitute for legal advice. Start a 14-day trial or see how it works.