What Is a Data Subject Access Request (DSAR) Under CCPA?

HD
Hakim Danyal
A DSAR lets California consumers see, correct, or delete their data. Learn the CCPA 45-day timeline, verification rules, exemptions, and how to respond.

Under the California Consumer Privacy Act (CCPA), consumers can ask a business to show, correct, or delete the personal information it holds about them. That request is called a Data Subject Access Request (DSAR) — and once it lands, a regulated clock starts. This guide explains what a DSAR is under the CCPA, who can file one, the exact timelines you must hit, how to verify identity, the exemptions that let you withhold data, and how to respond at scale without missing a deadline.

» Is your online store CCPA compliant? Here's how to ensure CCPA compliance and cookie consent on your Shopify store.

What a DSAR Is Under the CCPA

A Data Subject Access Request (DSAR) is a formal request made by a data subject — a consumer — to learn which personal information a company has gathered and saved about them, and in many cases to correct or delete it. Under the CCPA (as amended by the CPRA), a DSAR can cover several distinct consumer rights:

  • Right to know — what personal information you collected, the sources, the purposes, and the categories of third parties you shared it with.
  • Right to access — a copy of the specific pieces of personal information you hold.
  • Right to delete — removal of personal information, subject to exemptions.
  • Right to correct — fixing inaccurate personal information.
  • Right to opt out — of the sale or sharing of personal information.

Another party may submit a DSAR on behalf of the data subject as long as consent is provided in the form of a written authorization letter or other supporting documents. The most common examples are requests by parents or legal guardians on behalf of their minor children, by relatives or friends, or by lawyers on behalf of their clients.

Fulfilling these requests comes with certain risks. Here are some guidelines:

  • Requests should be authenticated
  • Ensure adherence to strict deadlines
  • Automated data scanning can help with data deduplication
  • Avoid personal data sprawl by centralizing data in a secure area
  • Avoid data leaks by encrypting consumer responses
  • Track and record all activities for compliance validation
  • Ensure that the information gets into the right hands

» What if a data breach occurs? Learn how to avoid a CCPA personal data breach.

CCPA Requirements for DSAR Compliance

Anytime a customer, employee, or other person submits a Data Subject Access Request, the business is required to disclose:

  • The categories of personal information collected
  • The company's data collection purpose
  • Which third parties the company shares the person's data with
  • The sources from which the business collected personal data, if not directly
  • The specific pieces of personal data collected

Before processing a data request, organizations must verify the user's identity and maintain a log of all activities. After collecting the relevant data, companies must ensure that it meets DSAR standards without disclosing proprietary information or someone else's personal information, and transmit it securely.

The financial stakes are real. The CCPA provides a private right of action for certain data breaches, with statutory damages reportedly ranging from $100 to $750 per consumer per incident (or actual damages, if greater). Treat any specific dollar figure here as a starting point and confirm the current statutory range and per-record exposure with counsel before relying on it.

How to Respond to a CCPA DSAR: Step by Step

Most DSAR failures aren't legal — they're operational. A repeatable workflow keeps you inside the deadline and out of trouble:

  1. Intake and log the request. Capture who asked, what they asked for, and the date received. This timestamp anchors every downstream deadline.
  2. Verify identity. Match the requester to the data before you disclose anything. For logged-in customers, existing credentials are often enough; for authorized agents, require documented proof of authority. (See our guide on how to verify user identity for DSARs.)
  3. Acknowledge receipt within 10 business days. Confirm to the consumer that the request arrived and explain how you'll process it.
  4. Locate and collect the data. Pull personal information from every system — order history, email platform, analytics, support tickets, ad pixels — and deduplicate it.
  5. Apply exemptions and redactions. Remove third-party data, privileged information, and anything covered by a statutory exemption.
  6. Deliver securely within 45 days. Transmit the response in a portable, readable format over an encrypted channel, and extend once (up to 45 more days) only if reasonably necessary, with notice.
  7. Retain the record. Keep a log of the request and your response for the required period.

DSARs get tricky when you're dealing with large amounts of data across many tools. To keep them legal and optimally streamlined, consider automating the DSAR workflow — the benefits of automating the DSAR process compound as your request volume grows.

CCPA Timelines for DSARs

Businesses subject to CCPA must disclose and deliver the requested data within 45 days, with one extension allowed for up to 45 more days. Other important timelines include:

  • Confirm receipt of the request within 10 business days
  • Respond to opt-out requests within 15 business days
  • Inform vendors to stop selling information within 90 business days
  • Maintain a log of requests for at least 24 months

These windows are unforgiving because they run from the moment the request arrives — not from when your team notices it. That's why intake and logging belong at the very front of your process.

DSAR Exemptions: When You Can Withhold Data

Compliance is paramount, but the CCPA does recognize situations where a business may decline part or all of a request. Common categories include:

  • Security and fraud prevention — keeping personal information needed to detect or prevent fraudulent or illegal activity.
  • Legal compliance — retaining information the law requires you to keep, or that's needed to comply with a legal obligation.
  • Third-party and privileged data — information that would reveal another person's personal data, or that is protected by privilege.
  • Manifestly unfounded or excessive requests — repetitive or abusive requests, where a business may charge a reasonable fee or decline to act.

When you invoke an exemption, document the legal basis. Regulators expect you to show your work, and a clear record is your best defense if a decision is later challenged.

DSAR Under CCPA vs. Other Privacy Laws

A CCPA DSAR is not the same as a DSAR under the GDPR or other state laws. The rights overlap — access, correction, deletion — but the covered population, response deadlines, and definitions of "personal information" differ. If you sell across regions, you can't run a single one-size-fits-all process. For a side-by-side breakdown, see GDPR vs. CCPA: understanding the difference, and for a broader walkthrough of the request lifecycle, read our guide to navigating Data Subject Access Requests for eCommerce.

How DSARs Impact Your eCommerce Operations

When a customer submits a DSAR to your Shopify store, the request doesn't just affect your marketing team — it ripples across your entire business. Your customer service reps need to know they're receiving these requests. Your analytics team (running Google Analytics or similar tools) needs to understand which data points fall under the request. Your email marketing platform (Klaviyo, Omnisend, etc.) needs to be searchable and auditable.

The practical challenge: your customer data lives in multiple places. Order history in Shopify. Email preferences in your email service provider. Pixel data (Meta Pixel, Google Analytics) in third-party platforms. Abandoned cart information in your recovery tool. Customer notes scattered across support tickets. A DSAR requires you to pull data from all these sources, deduplicate it, and deliver it in a readable format — all within 45 days.

Your brand needs a documented process for this. Who receives the request first? How do you route it internally? Which team member verifies the customer's identity? How do you ensure the data you send doesn't accidentally include information belonging to other customers? Without a clear workflow, you risk missing deadlines or sending incomplete (or worse, incorrect) data — both of which trigger regulatory scrutiny.

Authenticating DSAR Requests Without Friction

Not every request claiming to be from a customer actually is. Authenticated requests protect you, but authentication also needs to work for your real customers.

If someone emails your support inbox saying "Send me my data," you need to verify they actually own that email address and have the right to that data. For parents requesting on behalf of minors, you need documentation proving guardianship. For lawyers requesting on behalf of clients, you need a signed power of attorney.

The catch: overly strict authentication frustrates legitimate customers. A customer who submits a DSAR through your website portal can be verified via login credentials they already have. That's simple. But a parent requesting data for their 14-year-old needs a different process — you'll likely need a birth certificate or custody papers, which takes longer and requires careful handling.

For eCommerce brands, a hybrid approach works best. Offer an easy self-service portal where logged-in customers can request their own data immediately. For requests from authorized representatives, build a secondary workflow that requires documented proof of authority before you start the clock. This respects legitimate requests while protecting against fraudulent ones.

Managing Third-Party Data Sharing Disclosures

Your DSAR response must include not just the data you collected, but also which third parties you shared it with. For eCommerce brands, this list is often longer than you'd expect.

When you run Facebook ads, Meta gets pixel data about your site visitors. When you use Google Analytics, Google receives behavioral data. Your payment processor (Stripe, PayPal, Square) has transaction details. Your shipping carrier knows addresses and order contents. Your review platform has customer names and purchase history. Your attribution tool tracks user journeys. Each of these is a "third party" under CCPA, and you must disclose them in every DSAR response.

The complexity compounds when you're unsure whether a vendor is actually a "third party" under CCPA or just a "service provider" (which has different disclosure rules). A DSAR forces you to audit your entire martech stack and vendor agreements. You should be asking: Do we have contracts that define how this vendor can use our customer data? Are we sharing identifiable information or just aggregated analytics? Do they combine our data with data from other sources?

Document these vendor relationships clearly — your DSAR fulfillment depends on it, and regulators scrutinize this section heavily.

The Cost of Slow or Incomplete DSAR Responses

Missing a DSAR deadline or sending incomplete data isn't a small slip-up. California's Attorney General and the California Privacy Protection Agency can pursue enforcement, and the CCPA's private right of action allows consumers to seek statutory damages for certain breaches.

For a mid-market eCommerce brand processing hundreds or thousands of DSARs per year, that exposure adds up fast. If you send incomplete data (say, you forget to include data from your email platform), regulators may view that as non-compliance, not an honest mistake.

The financial incentive to get this right is strong. But so is the operational burden. You need clear documentation of when requests arrive, when you began processing, and what data sources you queried. You need to show you checked your work before sending it out. You need evidence that the customer actually received the data securely.

This is where many eCommerce brands realize they need help. Building these systems in-house — developing data mapping, automating queries across platforms, securing transmission — takes engineering time and ongoing maintenance. As your business scales and collects more data, DSARs become harder to manage manually. PieEye's data subject request automation connects to your stack, verifies requesters, and tracks every deadline so a single missed email doesn't become a regulatory problem.

Frequently Asked Questions About CCPA DSARs

What is a DSAR under the CCPA?

A Data Subject Access Request is a formal request from a California consumer asking a business to disclose, correct, or delete the personal information it has collected about them. The business must verify the requester's identity and respond within the statutory deadline.

How long does a business have to respond to a CCPA DSAR?

Confirm receipt within 10 business days and respond substantively within 45 calendar days. You can extend once by up to 45 more days when reasonably necessary, with notice to the consumer.

Does a DSAR have to be free?

Generally yes. Businesses must respond to verifiable consumer requests free of charge, except where a request is manifestly unfounded or excessive (for example, a repetitive request), in which case a reasonable fee or refusal may be allowed.

What's the difference between a DSAR under CCPA and under GDPR?

Both grant access, correction, and deletion rights, but they differ on who is covered and the response deadline — the CCPA covers California residents and allows up to 45 days, while the GDPR covers people in the EU and generally requires a response within one month.

Conclusion

A Data Subject Access Request under the CCPA is, at its core, an operational test: can you find every piece of a person's data, verify who's asking, apply the right exemptions, and deliver it securely before the clock runs out? Get the workflow right and DSARs become routine. Get it wrong and they become liability. To navigate this landscape — including the right to delete data under the CCPA — consider partnering with a specialist solution like PieEye.

» Worried about remaining compliant? Explore PieEye's data subject request automation for a solution.

For a walkthrough of how PieEye handles CPRA compliance, book a demo.

Related Posts

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.