Get Demo
↑

How to Handle a Data Subject Access Request (DSAR) in 30 Days — with Template

Article 15 access requests: verify identity, search systems, apply exemptions carefully, and respond within one month under Article 12(3).

Published: September 2026 Compliance · GDPR 8–12 min read

A Data Subject Access Request (DSAR) is the operational face of Article 15. Controllers must confirm whether personal data are being processed and provide a copy of the data plus the Art 15 information set — on the Article 12(3) clock.

Related: GDPR hub · Rights hub · CSA.

Clock: Respond without undue delay and within one month (Art 12(3)). Complex/numerous requests: extend by up to two further months, telling the individual within the first month.

30-Day DSAR Process

  1. Intake & log — channel, timestamp, request type (access vs other rights)
  2. Identity verification — proportionate; do not collect excessive ID
  3. Scope clarification — if the request is vague, ask promptly (clock management)
  4. Systems search — CRM, email, tickets, logs, backups policy, vendor processors
  5. Exemptions & redactions — third-party data, legal privilege, manifestly unfounded/excessive
  6. Package & deliver — secure channel; include Art 15 information (purposes, categories, recipients, retention, rights, transfers)
  7. Close & retain evidence — what was searched, what was withheld and why

Template Outline (Copy into Your Tracker)

Field
Example
Request ID / received date
DSAR-2026-091
Identity verification status
Verified / pending
Systems searched
Salesforce, Zendesk, M365, ThreatHawk
Processors contacted (Art 28)
List + response dates
Due date / extension?
+1 month; +2 months if notified
Outcome
Fulfilled / partial / refused (reasons)

How CyberSilo Helps

Stop Missing the One-Month Clock

Standardise DSAR intake, search, and delivery so Article 12(3) becomes routine, not a scramble.

Frequently Asked Questions

What article covers DSARs?

Article 15 (right of access), with response timing under Article 12(3).

Can I charge a fee?

Generally no for the first copy. Manifestly unfounded or excessive requests may allow a reasonable fee or refusal under Article 12(5).

Do processors answer DSARs directly?

Controllers remain responsible. Processors assist under Article 28 contracts.

GDPR hub · Rights · DPA · SIEM logs · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!