Key takeaways
- A DSAR must be answered within one month of receipt. You can extend by two further months, but only if you tell the requester within that first month and give reasons (Art. 12(3) GDPR).
- The response includes a copy of the personal data, not a list of data categories. The CJEU defined "copy" in 2023 as a faithful and intelligible reproduction, extending to whole documents where that is indispensable for the person to exercise their rights (C-487/21, 4 May 2023).
- You must name the actual recipients of the data, not just categories of recipient, wherever identifying them is possible (C-154/21, 12 January 2023).
- Since 19 March 2026, even a first-time request can be excessive under Art. 12(5) where the controller proves abusive intent, such as artificially creating the conditions needed to obtain a benefit under the Regulation. The same judgment confirms that Art. 82 gives a right to compensation for a breach of the right of access (C-526/24).
- Breaches of data subject rights fall in the higher fining tier of Art. 83(5): up to EUR 20 million or 4 percent of worldwide annual turnover, whichever is higher.
What is a DSAR under the GDPR?
A DSAR, or data subject access request, is a person asking whether and how you process their personal data. Article 15 gives them two entitlements in one: confirmation plus eight mandatory pieces of information under paragraph 1, and a copy of the data itself under paragraph 3. You will see the same thing called a subject access request, a SAR, a right of access request, or a data subject request. Legally they are all the same thing.
The right of access is one of the data subject rights in Articles 15 to 22, and in practice it is by far the most exercised. Our complete guide to the GDPR covers the other rights and the wider obligations they sit alongside.
The eight items under paragraph 1 are where responses most often fall short. They are the purposes of processing, the categories of personal data, the recipients, the envisaged retention period or the criteria for setting it, notice of the rights to rectification, erasure, restriction, and objection, the right to lodge a complaint with a supervisory authority, the source of the data where it was not collected from the person, and the existence of automated decision-making. Miss one and the response is incomplete. Where data is transferred to a third country, Art. 15(2) adds notice of the appropriate safeguards under Art. 46.
One misconception is worth clearing up first. The requester does not have to give a reason, use a form, or say the word "DSAR." "I want to know what you hold about me" in an ordinary support email triggers the same obligations and the same clock as a solicitor's letter. That is exactly why requests sit unnoticed in inboxes whose owners were never trained to recognize one.
The DSAR deadline, and when you can extend it
The clock starts on receipt, not on identity verification, and not on the day the right team hears about it. Art. 12(3) also says "without undue delay," so one month is the ceiling, not the target.
The extension is the part teams get wrong. It is not a quiet buffer you reach for once the month has run out. If you notice on day 35 that the search is taking longer, the extension is already gone and you are simply late. The notice has to go out inside the first month; it has to give reasons, and "this is taking a lot of effort" on its own will not carry it.
Identity verification is the second trap. Where you have reasonable doubts, Art. 12(6) lets you ask for more information, and you should, because releasing data to the wrong person is itself a reportable breach. What that request does not do is automatically restart the month. So ask on the day the request lands, not in week three. Ask only for what you actually need, too: a full-resolution ID document is disproportionate when the person is already logged into a verified account.
How far does the right of access reach?
The scope of Article 15 is no longer an open question. The Court of Justice settled it across six judgments between 2023 and 2026, and several of them contradict what internal process documents still say.
Two consequences follow. First, a response that lists data categories does not satisfy Article 15, and has not since CRIF. Sending a table headed "master data, contract data, communications data" answers the request in form and fails it in substance. Second, the recipient list is where most organizations come unstuck, because it assumes you already know which processors received this particular person's data. Without a current record of processing activities that question has no answer; finding personal data across the systems your teams actually use is covered in our guide to data discovery for GDPR compliance.
The DSAR process in six steps
Order matters here. Start searching before identity is settled and you risk creating a breach rather than answering a request.
The timings describe a plausible run, not measured turnaround times.
Step 5 is the effort driver nobody budgets for. Konstantin Steger, Senior Privacy Expert at Kertos, describes the case he meets regularly in practice:
That is manual work, and in cases like this it outweighs the rest of the request put together.
Which is what makes step 3 worth more than it looks. You are allowed to ask what the person is actually after. If they want their order history rather than eight years of mailbox, the request changes by an order of magnitude. Asking is good practice rather than a delaying tactic, as long as it happens at the start and not on day 28.
Access and erasure: what retention obligations change
An access request rarely arrives alone. An erasure request under Article 17 often follows, and neither is recognized as a formal request in the inbox. How the individual data subject rights under the GDPR fit together is set out in our guide.
It is the second half of that pair that organizations run into, for a reason that has nothing to do with data protection at first glance. The same emails you have just gathered for the access response are often ones you are not permitted to delete.
The mechanism is the same in every member state; only the periods and the statutes differ. Germany is a useful worked example because the categories are unusually explicit.
The accounting voucher period was cut from ten years to eight by the Fourth Bureaucracy Relief Act with effect from 1 January 2025. The six years for business letters did not change.
Legally, Art. 17(3)(b) resolves the conflict: the erasure obligation falls away to the extent that processing is necessary for compliance with a legal obligation, as the text of the Regulation puts it. In practice that does not mean "request refused." It means you erase what you are permitted to erase and restrict the rest to the retention purpose alone. You have to explain both to the person, citing the provision the obligation comes from.
None of this touches the access request itself. Retention obligations block erasure, not disclosure; data you must keep for six years is data you must also disclose for six years.
When you can refuse or charge for a DSAR
Art. 12(5) gives you two options where a request is manifestly unfounded or excessive, in particular because it repeats: charge a reasonable fee, or refuse to act. Proving that the condition is met is expressly your job.
This is where the most significant recent shift sits. After the CJEU's judgment of 26 October 2023 (C-307/22), the accepted reading was that the requester's motive is irrelevant. On 19 March 2026, in C-526/24 (Brillen Rottler), the Court refined that: even a first request can be excessive where the controller demonstrates that it does not serve the purpose of Article 15, namely becoming aware of and verifying the processing, but instead serves to prepare a compensation claim under Article 82. A pattern of serial requests to different controllers each followed by a demand for payment can support that showing.
Do not read this as a license. The burden stays entirely with you, motive alone is not enough, and the threshold is high. The more effective response to a request that looks like the opening move in a dispute is still the unglamorous one: answer on time, in full, and politely. Where the answer is timely and complete, the second breach that such claims are usually built on simply is not there.
Konstantin Steger frames that as a stance rather than a technique:
What a mishandled DSAR costs
Access requests are not an administrative sideshow. They fall under Art. 83(5)(b), which is the higher tier: up to EUR 20 million or 4 percent of worldwide annual turnover, whichever is greater.
Enforcement is more instructive than the ceiling. In September 2025, the North Rhine-Westphalia supervisory authority fined a German recruitment agency more than EUR 35,000 for ignoring access requests under Article 15 and erasure requests under Article 17, confirming deletion to people and then continuing to contact them, and failing to cooperate with the authority.
The second cost line is compensation under Article 82, and national courts are actively shaping it. Germany's Federal Court of Justice held on 18 November 2024 (VI ZR 10/24) that loss of control over personal data is itself compensable non-material damage, with no seriousness threshold, and indicated an order of magnitude around EUR 100 for bare loss of control. Small per claim, and the reason mass claims are viable. Whether a late or incomplete access response by itself supports a claim is not settled: the same court referred exactly that question to the CJEU on 6 May 2025 (VI ZR 53/23), where it is pending as C-416/25. Until that lands, do not assume a missed deadline is consequence-free.
For scale, an EY survey of more than 500 financial services professionals published in March 2023 found that 60 percent of data protection and compliance leaders saw DSARs rise in 2022, and 46 percent were still handling them manually. One sector and one survey year rather than a current market picture, but the direction is clear enough.
A written policy does not stand in for the process, including one that was generated.
DSAR automation: what it takes off you, and what it does not
The bottleneck in DSAR handling is rarely the legal call. It is step 4, working out where this one person's data actually sits. That is the part DSAR automation is worth buying, and the part it genuinely solves.
Kertos runs the request as a single process: intake with the clock started automatically, identity verification, and collection across connected systems. By Kertos's own figures, more than 500,000 data subject requests have been handled through it. The DSAR management page shows how that works in practice.
Customers tend to single out how far the process runs without anyone touching it:
The recipient list that Art. 15(1)(c) turns on comes from the same data as your record of processing activities, which is why the two obligations are hard to separate. A RoPA refreshed once a year will hand you last year's recipients when a request arrives; the privacy management system keeps both on one live data set instead.
What automation does not do is decide. Whether a passage is the requester's data or a colleague's, whether a request is genuinely excessive, and how a refusal has to be reasoned so it survives a complaint are judgment calls. Where nobody internally can make them, Kertos supplies an external data protection officer who does.
To see how long a DSAR would actually take across your systems, book a call.
Frequently asked questions
How long do you have to respond to a DSAR?
One month from receipt of the request. Where the request is particularly complex, or where you have received a high number at once, you can extend by two further months, but you must tell the requester within the first month and explain why. Miss that notice and the extension is not valid, which leaves you simply late.
Can you refuse a subject access request?
Only where it is manifestly unfounded or excessive under Art. 12(5), and you carry the burden of proving it. Since the CJEU's judgment of 19 March 2026 (C-526/24), even a first request can qualify if you can show it was made to prepare a compensation claim rather than to verify the processing. The bar is high, and suspicion on its own is not enough.
Do you have to provide a copy of the data or just a list of categories?
A copy. The CJEU held on 4 May 2023 (C-487/21) that "copy" means a faithful and intelligible reproduction of the personal data, which can extend to extracts from documents or entire documents where that is indispensable for the person to exercise their rights. Listing data categories does not satisfy Art. 15(3).
Is there a fee for a subject access request?
Not for the first copy, and the requester's motive makes no difference to that (C-307/22, 26 October 2023). For further copies of the same data you may charge a reasonable fee based on administrative costs under Art. 15(3). Charging for the first response is not permitted.
Do you have to name the recipients of the data?
Yes, where identifying them is possible. On 12 January 2023 (C-154/21) the CJEU held that the data subject is entitled to the actual identity of the recipients. You may fall back on categories of recipient only where those recipients cannot be identified, or where the request is manifestly unfounded or excessive.
Do you have to erase the data if an erasure request follows the DSAR?
Not always. Art. 17(3)(b) removes the erasure obligation to the extent that a legal obligation requires you to retain the data. With emails that is common: under German law, customer correspondence is regularly classified as a business letter and has to be kept for six years (section 257(4) HGB, section 147(3) AO), while an invoice sent by email counts as an accounting voucher and runs to eight. Periods differ by member state, so check the ones that apply to you. Erase what you are permitted to erase, restrict the rest to the retention purpose, and tell the person which provision the obligation comes from. The retention obligation does not affect the Article 15 response.





