Data Protection

DSAR: How to Handle a Subject Access Request Under the GDPR

What you have to hand over, what you must keep despite an erasure request, and where the process breaks in practice.

Author
Dr. Kilian Schmidt
Date
9.7.2025
Updated on
22.8.2026
DSAR: How to Handle a Subject Access Request Under the GDPR

Key takeaways

  • A DSAR must be answered within one month of receipt. You can extend by two further months, but only if you tell the requester within that first month and give reasons (Art. 12(3) GDPR).
  • The response includes a copy of the personal data, not a list of data categories. The CJEU defined "copy" in 2023 as a faithful and intelligible reproduction, extending to whole documents where that is indispensable for the person to exercise their rights (C-487/21, 4 May 2023).
  • You must name the actual recipients of the data, not just categories of recipient, wherever identifying them is possible (C-154/21, 12 January 2023).
  • Since 19 March 2026, even a first-time request can be excessive under Art. 12(5) where the controller proves abusive intent, such as artificially creating the conditions needed to obtain a benefit under the Regulation. The same judgment confirms that Art. 82 gives a right to compensation for a breach of the right of access (C-526/24).
  • Breaches of data subject rights fall in the higher fining tier of Art. 83(5): up to EUR 20 million or 4 percent of worldwide annual turnover, whichever is higher.

What is a DSAR under the GDPR?

A DSAR, or data subject access request, is a person asking whether and how you process their personal data. Article 15 gives them two entitlements in one: confirmation plus eight mandatory pieces of information under paragraph 1, and a copy of the data itself under paragraph 3. You will see the same thing called a subject access request, a SAR, a right of access request, or a data subject request. Legally they are all the same thing.

The right of access is one of the data subject rights in Articles 15 to 22, and in practice it is by far the most exercised. Our complete guide to the GDPR covers the other rights and the wider obligations they sit alongside.

The eight items under paragraph 1 are where responses most often fall short. They are the purposes of processing, the categories of personal data, the recipients, the envisaged retention period or the criteria for setting it, notice of the rights to rectification, erasure, restriction, and objection, the right to lodge a complaint with a supervisory authority, the source of the data where it was not collected from the person, and the existence of automated decision-making. Miss one and the response is incomplete. Where data is transferred to a third country, Art. 15(2) adds notice of the appropriate safeguards under Art. 46.

One misconception is worth clearing up first. The requester does not have to give a reason, use a form, or say the word "DSAR." "I want to know what you hold about me" in an ordinary support email triggers the same obligations and the same clock as a solicitor's letter. That is exactly why requests sit unnoticed in inboxes whose owners were never trained to recognize one.

The DSAR deadline, and when you can extend it

The clock starts on receipt, not on identity verification, and not on the day the right team hears about it. Art. 12(3) also says "without undue delay," so one month is the ceiling, not the target.

Event Deadline Legal basis
Respond to the request Without undue delay, at most one month from receipt Art. 12(3) first sentence
Notify the requester of an extension, with reasons Within the first month Art. 12(3) third sentence
Maximum extension, for complex or numerous requests Two further months, so three in total Art. 12(3) second sentence
Notify the requester if you take no action, with complaint and remedy routes Within one month Art. 12(4)
Ask for more information where you have reasonable doubts about identity No separate deadline, and it does not automatically pause the month Art. 12(6)

The extension is the part teams get wrong. It is not a quiet buffer you reach for once the month has run out. If you notice on day 35 that the search is taking longer, the extension is already gone and you are simply late. The notice has to go out inside the first month; it has to give reasons, and "this is taking a lot of effort" on its own will not carry it.

Identity verification is the second trap. Where you have reasonable doubts, Art. 12(6) lets you ask for more information, and you should, because releasing data to the wrong person is itself a reportable breach. What that request does not do is automatically restart the month. So ask on the day the request lands, not in week three. Ask only for what you actually need, too: a full-resolution ID document is disproportionate when the person is already logged into a verified account.

How far does the right of access reach?

The scope of Article 15 is no longer an open question. The Court of Justice settled it across six judgments between 2023 and 2026, and several of them contradict what internal process documents still say.

Case Date What the Court held
C-154/21, Österreichische Post 12 Jan 2023 You must name the actual recipients, not just categories. Categories suffice only where identification is impossible or the request is manifestly unfounded or excessive.
C-487/21, CRIF 4 May 2023 "Copy" means a faithful and intelligible reproduction of the data. Extracts or entire documents must be provided where that is indispensable for the person to exercise their rights effectively.
C-579/21, Pankki S 22 Jun 2023 Log data about consultations, meaning the dates and purposes, is covered. The identity of the employees who accessed the data generally is not, since they act under the controller's authority. The exception is where that information is indispensable for the person to exercise their rights, with the employees' own rights taken into account.
C-307/22, FT v DW 26 Oct 2023 The first copy is free regardless of the requester's motive. Member States may not shift the cost onto the data subject to protect the controller's economic interests.
C-203/22, Dun & Bradstreet Austria 27 Feb 2025 Under Art. 15(1)(h), "meaningful information about the logic involved" in automated decision-making must be concrete and comprehensible to the person. Trade secrecy does not justify a blanket refusal; disclosure then goes to the authority or the court, which weighs the interests.
C-526/24, Brillen Rottler 19 Mar 2026 Even a first request can be excessive where the controller proves it was not made to become aware of and verify the processing, but to manufacture a compensation claim.

Two consequences follow. First, a response that lists data categories does not satisfy Article 15, and has not since CRIF. Sending a table headed "master data, contract data, communications data" answers the request in form and fails it in substance. Second, the recipient list is where most organizations come unstuck, because it assumes you already know which processors received this particular person's data. Without a current record of processing activities that question has no answer; finding personal data across the systems your teams actually use is covered in our guide to data discovery for GDPR compliance.

The DSAR process in six steps

Order matters here. Start searching before identity is settled and you risk creating a breach rather than answering a request.

Step What to do Timing, illustrative
1. Log it Record the date of receipt, start the clock, assign an owner centrally Day 1
2. Verify identity Only where you have reasonable doubts, using the least intrusive method that works Days 1 to 3
3. Clarify scope Where the request is open-ended, ask politely what the person is actually looking for Days 2 to 5
4. Collect the data Every system and every processor, not just the CRM and the ticketing tool Days 3 to 15
5. Protect third parties Redact other people's data, Art. 15(4) Days 10 to 25
6. Respond and record The copy, the eight mandatory items, the complaint route, and a filed audit trail By day 30

The timings describe a plausible run, not measured turnaround times.

Step 5 is the effort driver nobody budgets for. Konstantin Steger, Senior Privacy Expert at Kertos, describes the case he meets regularly in practice:

"You get cases like the former employee who has left the company and then asks for all the personal data processed over an employment relationship of, say, more than ten years. It gets interesting once you start with the email provider and have to ask yourself: do I now have to provide every email this person ever sent or received? Some of those emails will also contain other people's personal data. That will be the normal case. It starts with the people who were copied in, but it also covers emails that discuss other people. You have confidentiality obligations toward those other people too, so you would have to redact the passages concerned."

Konstantin Steger, Senior Privacy Expert at Kertos, translated from German

That is manual work, and in cases like this it outweighs the rest of the request put together.

Which is what makes step 3 worth more than it looks. You are allowed to ask what the person is actually after. If they want their order history rather than eight years of mailbox, the request changes by an order of magnitude. Asking is good practice rather than a delaying tactic, as long as it happens at the start and not on day 28.

Access and erasure: what retention obligations change

An access request rarely arrives alone. An erasure request under Article 17 often follows, and neither is recognized as a formal request in the inbox. How the individual data subject rights under the GDPR fit together is set out in our guide.

"The access request is often made in combination with an erasure request that follows afterwards. That is why it matters to establish what is actually being asked for. Many companies do not even understand that they are dealing with an access request under the GDPR; it ends up in the wastebasket, and then you have a problem."

Konstantin Steger, Senior Privacy Expert at Kertos, translated from German

It is the second half of that pair that organizations run into, for a reason that has nothing to do with data protection at first glance. The same emails you have just gathered for the access response are often ones you are not permitted to delete.

"With emails you have to ask yourself: is this subject to retention obligations? In Germany those come in particular from the Fiscal Code or the Commercial Code. Emails are often customer communication, so legally they could potentially be classified as business letters. Those have to be kept for six years anyway. Which means you would not be allowed to delete them at all."

Konstantin Steger, Senior Privacy Expert at Kertos, translated from German

The mechanism is the same in every member state; only the periods and the statutes differ. Germany is a useful worked example because the categories are unusually explicit.

Record Retention period Legal basis
Business letters sent and received, which regularly covers customer correspondence by email 6 years Section 257(1) nos. 2 and 3, (4) HGB; section 147(1) nos. 2 and 3, (3) AO
Accounting vouchers, such as an invoice sent by email 8 years Section 257(1) no. 4, (4) HGB; section 147(1) no. 4, (3) AO
Commercial books, inventories, annual financial statements 10 years Section 257(1) no. 1, (4) HGB; section 147(1) no. 1, (3) AO

The accounting voucher period was cut from ten years to eight by the Fourth Bureaucracy Relief Act with effect from 1 January 2025. The six years for business letters did not change.

Legally, Art. 17(3)(b) resolves the conflict: the erasure obligation falls away to the extent that processing is necessary for compliance with a legal obligation, as the text of the Regulation puts it. In practice that does not mean "request refused." It means you erase what you are permitted to erase and restrict the rest to the retention purpose alone. You have to explain both to the person, citing the provision the obligation comes from.

None of this touches the access request itself. Retention obligations block erasure, not disclosure; data you must keep for six years is data you must also disclose for six years.

When you can refuse or charge for a DSAR

Art. 12(5) gives you two options where a request is manifestly unfounded or excessive, in particular because it repeats: charge a reasonable fee, or refuse to act. Proving that the condition is met is expressly your job.

This is where the most significant recent shift sits. After the CJEU's judgment of 26 October 2023 (C-307/22), the accepted reading was that the requester's motive is irrelevant. On 19 March 2026, in C-526/24 (Brillen Rottler), the Court refined that: even a first request can be excessive where the controller demonstrates that it does not serve the purpose of Article 15, namely becoming aware of and verifying the processing, but instead serves to prepare a compensation claim under Article 82. A pattern of serial requests to different controllers each followed by a demand for payment can support that showing.

Do not read this as a license. The burden stays entirely with you, motive alone is not enough, and the threshold is high. The more effective response to a request that looks like the opening move in a dispute is still the unglamorous one: answer on time, in full, and politely. Where the answer is timely and complete, the second breach that such claims are usually built on simply is not there.

Konstantin Steger frames that as a stance rather than a technique:

"My credo is: as you call into the forest, so it echoes back. You should deal with the person transparently and politely. If you do not try to play it down, but instead ask again what exactly this is about, you can also de-escalate requests that were heading for a fight."

Konstantin Steger, Senior Privacy Expert at Kertos, translated from German

What a mishandled DSAR costs

Access requests are not an administrative sideshow. They fall under Art. 83(5)(b), which is the higher tier: up to EUR 20 million or 4 percent of worldwide annual turnover, whichever is greater.

Enforcement is more instructive than the ceiling. In September 2025, the North Rhine-Westphalia supervisory authority fined a German recruitment agency more than EUR 35,000 for ignoring access requests under Article 15 and erasure requests under Article 17, confirming deletion to people and then continuing to contact them, and failing to cooperate with the authority.

The second cost line is compensation under Article 82, and national courts are actively shaping it. Germany's Federal Court of Justice held on 18 November 2024 (VI ZR 10/24) that loss of control over personal data is itself compensable non-material damage, with no seriousness threshold, and indicated an order of magnitude around EUR 100 for bare loss of control. Small per claim, and the reason mass claims are viable. Whether a late or incomplete access response by itself supports a claim is not settled: the same court referred exactly that question to the CJEU on 6 May 2025 (VI ZR 53/23), where it is pending as C-416/25. Until that lands, do not assume a missed deadline is consequence-free.

For scale, an EY survey of more than 500 financial services professionals published in March 2023 found that 60 percent of data protection and compliance leaders saw DSARs rise in 2022, and 46 percent were still handling them manually. One sector and one survey year rather than a current market picture, but the direction is clear enough.

A written policy does not stand in for the process, including one that was generated.

"You can imagine that in practice this often means considerably more work. You do not satisfy this whole data subject rights process by drafting a policy with AI. You have to actually sit down and ask yourself: what do I really have to do here? And you have to take the current case law into account as well."

Konstantin Steger, Senior Privacy Expert at Kertos, translated from German

DSAR automation: what it takes off you, and what it does not

The bottleneck in DSAR handling is rarely the legal call. It is step 4, working out where this one person's data actually sits. That is the part DSAR automation is worth buying, and the part it genuinely solves.

Kertos runs the request as a single process: intake with the clock started automatically, identity verification, and collection across connected systems. By Kertos's own figures, more than 500,000 data subject requests have been handled through it. The DSAR management page shows how that works in practice.

Customers tend to single out how far the process runs without anyone touching it:

"Kertos' GDPR features, especially the Data Subject Request (DSR) workflows, integrate seamlessly into our operations and have automated nearly all of our compliance processes. Tasks that once took days are now completed in minutes, often without any manual involvement from our compliance team."

Ferdinand S., Chief of Staff, G2 review, August 2025

The recipient list that Art. 15(1)(c) turns on comes from the same data as your record of processing activities, which is why the two obligations are hard to separate. A RoPA refreshed once a year will hand you last year's recipients when a request arrives; the privacy management system keeps both on one live data set instead.

What automation does not do is decide. Whether a passage is the requester's data or a colleague's, whether a request is genuinely excessive, and how a refusal has to be reasoned so it survives a complaint are judgment calls. Where nobody internally can make them, Kertos supplies an external data protection officer who does.

To see how long a DSAR would actually take across your systems, book a call.

Frequently asked questions

How long do you have to respond to a DSAR?

One month from receipt of the request. Where the request is particularly complex, or where you have received a high number at once, you can extend by two further months, but you must tell the requester within the first month and explain why. Miss that notice and the extension is not valid, which leaves you simply late.

Can you refuse a subject access request?

Only where it is manifestly unfounded or excessive under Art. 12(5), and you carry the burden of proving it. Since the CJEU's judgment of 19 March 2026 (C-526/24), even a first request can qualify if you can show it was made to prepare a compensation claim rather than to verify the processing. The bar is high, and suspicion on its own is not enough.

Do you have to provide a copy of the data or just a list of categories?

A copy. The CJEU held on 4 May 2023 (C-487/21) that "copy" means a faithful and intelligible reproduction of the personal data, which can extend to extracts from documents or entire documents where that is indispensable for the person to exercise their rights. Listing data categories does not satisfy Art. 15(3).

Is there a fee for a subject access request?

Not for the first copy, and the requester's motive makes no difference to that (C-307/22, 26 October 2023). For further copies of the same data you may charge a reasonable fee based on administrative costs under Art. 15(3). Charging for the first response is not permitted.

Do you have to name the recipients of the data?

Yes, where identifying them is possible. On 12 January 2023 (C-154/21) the CJEU held that the data subject is entitled to the actual identity of the recipients. You may fall back on categories of recipient only where those recipients cannot be identified, or where the request is manifestly unfounded or excessive.

Do you have to erase the data if an erasure request follows the DSAR?

Not always. Art. 17(3)(b) removes the erasure obligation to the extent that a legal obligation requires you to retain the data. With emails that is common: under German law, customer correspondence is regularly classified as a business letter and has to be kept for six years (section 257(4) HGB, section 147(3) AO), while an invoice sent by email counts as an accounting voucher and runs to eight. Periods differ by member state, so check the ones that apply to you. Erase what you are permitted to erase, restrict the rest to the retention purpose, and tell the person which provision the obligation comes from. The retention obligation does not affect the Article 15 response.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Dr. Kilian Schmidt

Dr. Kilian Schmidt

CEO & Co-Founder at Kertos

Kilian had a strong focus on legal processes from an early age and began his career at Home24 as a Senior Legal Counsel and Data Protection Officer for the Home24 group. After a stint at Freshfields Bruckhaus Deringer, he moved to TIER Mobility, where he expanded the company's legal and public policy departments from one to 65 cities and from 50 to 800 employees. Driven by the lack of technology in the legal field and confirmed by his consulting work at Gorillas Technologies, he decided to found Kertos to develop the next generation of compliance – made in Europe.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check