What is Data Subject Access Request (DSAR)?

A Data Subject Access Request (DSAR) is a request from an individual asking an organisation for a copy of the personal data it holds about them and information about how it’s being used. DSARs are a legal right in many jurisdictions (for example under the EU’s GDPR).

A DSAR lets a person (the data subject) ask an organisation to confirm whether it processes their personal data and, if so, to provide a copy of that data plus certain information about the processing (purpose, categories of data, recipients, retention period, and their rights). It applies to identifiable personal data — not anonymised or aggregated information. Organisations must verify the requester’s identity, respond within a legally defined timescale (commonly one month under GDPR), and may refuse or limit requests in specific situations (for example where fulfilling the request would infringe others’ rights or is manifestly unfounded). DSARs are separate from, but related to, other privacy rights such as rectification, erasure (right to be forgotten), restriction, objection and data portability.

Usage example

A parent asks the local school for a copy of all survey responses that mention their child. The school verifies the parent’s identity, searches the survey platform for any responses containing the child’s name, exports the relevant entries (redacting other children’s personal data where required), and sends the records to the parent within the required timeframe. If parts of the data are in other languages, the school provides translated copies or a summary in the parent’s preferred language as appropriate.

Practical application

DSARs matter because they are a legal obligation and a core part of building trust with the people you serve. Responding properly reduces regulatory risk (fines and enforcement), shows transparency, and demonstrates respect for individuals’ rights. For organisations using multilingual survey tools, DSARs introduce practical challenges: locating and exporting personal data across languages, verifying identity, deciding when to translate responses, and redacting third-party data. Features like searchable exports, audit logs, and reliable translation (and the ability to view or export responses translated into an admin’s language) make it easier to find the right records, verify what was collected, and deliver the response on time and in a format the requester can use.

FAQ

How long do we have to respond to a DSAR?

Timescales vary by law, but under GDPR you generally must respond without undue delay and within one month of receipt. That period can be extended by a further two months for complex or numerous requests, but you should inform the requester and explain the reasons for the delay.

What counts as personal data in a survey response?

Any information that identifies or could reasonably identify an individual is personal data — names, contact details, ID numbers, or contextual details that make someone identifiable. Answers that are truly anonymised (no-one could identify the person) aren’t personal data for DSAR purposes.

Do we have to provide translations when someone requests their data?

There’s no blanket rule — requirements depend on the law and the requester’s needs. Practically, if the requester asks for translations or for data in a particular language, you should consider that request and whether you can reasonably provide it. Using multilingual platform features and clear communication about format and language expectations helps manage this efficiently.

Can we refuse or charge for a DSAR?

You can refuse requests that are manifestly unfounded or excessive (for example repetitive requests) and you may charge a reasonable fee for repeated requests in some jurisdictions. Generally, however, organisations must provide access free of charge for the first request and cannot refuse simply because complying is inconvenient.