Privacy Rights & Requests
What is DSAR (Data Subject Access Request)?
A DSAR (data subject access request) is a formal request from an individual asking an organization to act on their privacy rights — most commonly to disclose, delete, or correct the personal data it holds about them — with response deadlines of one month under GDPR and 45 days under the CCPA.
DSAR began as GDPR shorthand for the Article 15 access right, but in practice the term (along with DSR, data subject request) now covers the whole request family: access ('what do you have on me'), deletion, correction, portability, restriction, objection, and US-style opt-outs. Whatever the flavor, the mechanics are the same — an individual asserts a right, and the organization must verify, execute, and respond on a statutory clock.
The workflow has four stages. Intake: requests can arrive through a web form, a privacy email address, or — under the CCPA — a toll-free number, and consumers cannot be forced to create accounts to submit them. Verification: the organization must confirm the requester is who they claim, calibrated to the sensitivity of the data — enough to stop impostors, not so much that verification becomes an obstacle. Fulfillment: locating the person's data everywhere it lives and executing the request. Response: within one month under GDPR (extendable by two months for complexity) or 45 days under CCPA (extendable once by 45), free of charge in the normal case.
Fulfillment is where organizations underestimate the work. A customer's data rarely lives in one system: it spreads across the commerce platform, email marketing, analytics, support desk, reviews, loyalty, shipping, and ad platforms. A deletion executed only in the primary database while nine SaaS tools keep their copies is a violation with an audit trail. This is why DSAR automation — connectors that propagate requests across the stack and log the evidence — has become its own product category.
Volume is rising: privacy-aware consumers, browser tooling, and authorized-agent services all generate requests, and each mishandled one is a complaint a regulator can pick up.
Why it matters for eCommerce
An eCommerce customer's data typically lives in 10-20 systems — Shopify, Klaviyo, Zendesk, review apps, analytics, ad audiences. Manual DSAR fulfillment means an employee touching each one per request, which stops scaling almost immediately. Automating propagation across connectors, with per-system completion logs, turns a compliance liability into a routine ticket.
Frequently asked questions
- How long do we have to answer a DSAR?
- GDPR: one month, extendable by two further months for complex or numerous requests, with notice of the extension in the first month. CCPA: 45 days, extendable once by another 45 with notice. The clock starts at receipt, not at verification.
- Can we charge a fee for DSARs?
- Not in the normal case — GDPR and CCPA both require free handling. Charges are allowed only for manifestly unfounded or excessive requests (GDPR) or excessive repetition (CCPA), and refusing on those grounds carries the burden of proving it.
- Do we have to delete data from backups and third-party tools?
- Deletion must reach everywhere the data is processed — including processors and service providers, who must be instructed to delete. Backups are typically handled by deleting on restore or documented rotation schedules; third-party SaaS tools holding your customer data are unambiguously in scope.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Automate DSARs with PieEye