Data Subject Access Request (DSAR)

Definition

A formal request from a consumer to a business asking to know what personal data the business holds about them. Also called a consumer rights request or verifiable consumer request. Businesses must respond within a legally specified timeframe, usually 45 days.

Legal Definition

Under the CCPA (Cal. Civ. Code 1798.100): consumers have the right to request that a business disclose the categories and specific pieces of personal information it has collected. Under the VCDPA (Va. Code 59.1-577): consumers may exercise their right of access by submitting a request to the controller.

State Laws Using This Term

Practical Example

A consumer emails a company saying "I would like to know what personal data you have about me." The company must verify the consumer's identity, gather the data, and provide a response within 45 days.

Related Terms

Frequently Asked Questions

How long does a business have to respond to a DSAR?

Most state laws give businesses 45 days to respond, with a possible 45-day extension if reasonably necessary. The business must inform the consumer of the extension and the reason for it.