A customer emails support: "Can you tell me what data you have on me?" A former employee asks HR to "send everything in my file." A website visitor replies to a marketing email with "stop contacting me and delete my info."
Are these all data subject access requests? Two of them are. The third is a mix of two different rights. Most small teams can't tell the difference in the moment — and under GDPR Article 15, that ambiguity is exactly what turns a routine email into a missed deadline.
Article 15 of the GDPR gives any individual the right to obtain confirmation of whether an organization is processing their personal data, and if so, access to that data plus a defined set of details: the purposes of processing, the categories of data involved, who it's been shared with, how long it will be kept, and where it came from. The UK ICO's guidance on the right of access is the clearest plain-language walkthrough of what that means in practice, and it's worth bookmarking even if you're a US-based team — most state privacy laws borrow the same structure.
The catch: nowhere does the law require the word "DSAR," a specific form, or even the phrase "data protection." A request just has to make clear that someone wants to know what personal data you hold about them. That's it.
The distinction matters because each of these rights carries its own deadline and its own required response — treating them all as the same ticket type is how teams miss the parts of a request that don't say "access" in the subject line.
"DSAR" and "subject access request" (SAR) are the same thing — DSAR is the more common shorthand in GDPR-adjacent conversation, SAR is the term UK guidance tends to use. Both map to Article 15 in the EU/UK.
In the US, the closest equivalent is the CCPA "right to know", and the mechanics diverge in ways that matter operationally:
| GDPR Article 15 (EU/UK) | CCPA "right to know" (California) | |
|---|---|---|
| Response deadline | 1 month, extendable to 3 for complex requests | 45 days, extendable to 90 |
| Verification standard | "Reasonable" — context-dependent | Explicit two-factor verification for sensitive data |
| Fee | Generally free (fee allowed only for "manifestly unfounded or excessive" repeat requests) | Free, twice per 12-month period |
| Format | "Commonly used electronic form" if requested electronically | Portable, readily usable format |
If you serve both EU and California residents — which most SaaS companies with a website do — you're not tracking one deadline. You're tracking two overlapping ones, on two different clocks, with two different verification bars. Our last post covered why 20 more US states now layer their own versions on top of this, each with its own thresholds and cure periods.
For a five-person team getting one DSAR a quarter, a shared doc with a due-date column is a perfectly reasonable system. The failure mode isn't complexity — it's volume and drift. The moment two requests land in the same week, from different jurisdictions, with different deadlines and different intake channels (one from a support ticket, one from a reply-to-marketing email, one from HR), a spreadsheet stops being a system and starts being a liability with a due-date column.
That's the gap between "we have a DSAR process" and "we have a DSAR process we can actually produce evidence of" — and evidence is what regulators ask for first, not intentions.
Platforms built for enterprise privacy teams — the DataGrails, Transcends, Kettles, and Mimecasts of the world — are built for organizations with dedicated privacy engineering staff, hundreds of internal systems to map, and procurement processes that assume a six-figure annual contract. That's the right tool for that job. It's a lot of tool for a team fielding a handful of requests a month.
DSAR Lite exists for the gap in between "spreadsheet" and "enterprise platform": deadline tracking that calculates the right clock automatically, letter templates by jurisdiction, and an Article 30 processing-activity record — without the implementation project. Plans start at $29/month for small teams, with a 14-day trial on every tier.
DSAR Lite is a DSAR and Article 30 tracking tool built for small privacy and compliance teams — not a substitute for legal advice. Start a 14-day trial or see how it works.