miniOrange Logo

Products

Services

Plugins

Pricing

Resources

Company

What Is DSAR? Understanding Data Subject Access Requests Under the DPDP Act

11th August, 202612 Min Read

A Data Subject Access Request (DSAR) gives individuals the right to ask these questions and gain greater visibility into how their personal data is being used. Under privacy laws such as India's Digital Personal Data Protection (DPDP) Act, Data Principals can request access to their information and exercise other privacy rights.

Every time you shop online, sign up for a service, or submit your details on a website, organizations collect and process personal data about you. But do you know what information they store, why they need it, or who they share it with?

What is DSAR Data Subject Access Request

Understanding DSARs, DSRs, and Individual Rights

A Data Subject Access Request (DSAR) is a formal request that allows individuals to understand what personal data an organization holds about them and how that information is collected, used, stored, and shared.

The global privacy laws typically use the term "data subject"; India's Digital Personal Data Protection (DPDP) Act refers to the individual as a "Data Principal." Regardless of the terminology, the objective remains the same: Allowing individuals to verify how their information is collected, shared, and retained.

DSAR vs DSR

Although the terms are often used interchangeably, there is a distinction between the two.

A Data Subject Request (DSR) is a broad category that includes requests related to access, correction, erasure, and grievance redressal.

Moreover, a Data Subject Access Request (DSAR) specifically focuses on accessing personal data and information about its processing.

What Information Can Individuals Request?

Individuals may request details about the personal data an organization has collected, the purpose for processing it, the third parties with whom it has been shared, consent records, and the period for which the data will be retained.

Why Do Organizations Need to Respond?

Organizations are expected to respond to these requests to comply with privacy laws, uphold individual rights, and demonstrate transparency in how personal data is handled. For example, a customer may request their purchase history from an e-commerce platform, while a former employee may ask an organization for records that are still being retained.

Why DSARs Matter Under DPDP and Globally

As organizations collect personal data through websites, mobile applications, payment systems, and customer interactions, individuals increasingly expect transparency around how their information is being used.

Data Subject Access Requests help meet these expectations by giving people a practical way to understand what data organizations hold and how it moves across different systems.

Why Individuals Care About DSARs

DSARs empower individuals to understand what data has been collected, why it is being processed, who has access to it, and how long it will be retained. This transparency strengthens trust and gives people greater control over their digital footprint.

How Privacy Laws Recognize Data Rights

Privacy regulations around the world recognize an individual's right to access and manage personal information, although the scope and terminology may vary across jurisdictions.

  • GDPR (European Union): Gives individuals the right to access their personal data and understand how it is collected, processed, and shared.
  • CCPA (California): Allows consumers to know what personal information businesses collect, use, disclose, and sell.
  • DPDP Act (India): Grants Data Principals rights over their personal data and places obligations on Data Fiduciaries to process it responsibly.

Why Businesses Should Care

An effective DSAR process goes beyond compliance. It demonstrates accountability, strengthens customer trust, and helps organizations understand where personal data resides across internal systems and third-party vendors.

As privacy expectations continue to evolve, the ability to manage DSARs efficiently is becoming a key part of modern privacy and compliance programs.

What is DSAR under the DPDP Act, 2023

India's Digital Personal Data Protection Act, 2023 establishes the rules that govern how organizations collect, process, store, and share digital personal data.

Under the Act, the individual to whom the data relates is referred to as a Data Principal, while the organization that determines why and how that data is processed is known as a Data Fiduciary.

Although the legislation does not explicitly use the term "Data Subject Access Request" (DSAR), the rights granted to Data Principals make such requests possible in practice.

Who Are the Key Stakeholders?

A Data Principal is the individual whose personal data is being processed, whether that person is a customer, employee, patient, student, or website visitor. A Data Fiduciary, on the other hand, decides the purpose and means of processing that data.

For example, an e-commerce platform collecting customer information to fulfill orders acts as the Data Fiduciary, while the customer is the Data Principal.

How Does the DPDP Act Enable DSARs?

The rights provided under Sections 11, 12, 13, and 14 collectively allow individuals to interact with organizations regarding their personal data. These rights include:

  • Accessing information about personal data processing.
  • Correcting or updating inaccurate records.
  • Requesting erasure where applicable.
  • Raising grievances against organizations.
  • Nominating another person to exercise these rights.

In practice, organizations often handle these interactions through DSAR workflows, even though the term itself does not appear in the Act.

What Responsibilities Do Organizations Have?

Supporting data requests requires organizations to go beyond legal compliance. They must:

  • Identify where personal data resides across systems.
  • Verify the identity of the requester.
  • Maintain accurate and up-to-date records.
  • Establish grievance redressal mechanisms.
  • Respond securely and maintain audit trails.

As privacy regulations mature in India, an effective DSAR process is becoming a key component of responsible data governance and compliance.

Rights of Data Principals Under the DPDP Act

The DPDP Act grants Data Principals a set of rights that determine how organizations collect, use, and manage personal data. Spread across Sections 11 to 14, these rights include access to information, correction and erasure, grievance redressal, and nomination.

While the Act does not explicitly use the term "DSAR," these requests are the practical way through which individuals exercise their rights. For organizations, supporting these requests requires systems that can identify, retrieve, and act on personal data across different platforms.

1. Right to Access Information

One of the most important rights available to Data Principals is the right to access information about how their personal data is being processed. Under Section 11, individuals can request details about the data an organization holds and how that information is being used.

This includes information such as:

  • The categories of personal data collected.
  • The purpose for which the data is being processed.
  • The identities of Data Fiduciaries and Data Processors involved.
  • The third parties with whom the data has been shared.
  • A summary of processing activities.

For example, a customer may ask an online marketplace what personal information it stores, why it collects it, and whether it has shared it with payment providers or logistics partners.

To support such requests, organizations must maintain clear records and ensure that information can be retrieved accurately and securely.

2. Right to Correction and Erasure

Personal data changes over time. Phone numbers are updated, addresses change, and certain records may not need to be retained. Recognizing this, Section 12 grants Data Principals the right to correct, complete, update, and erase personal data in specific circumstances.

Individuals may request that organizations:

  • Correct inaccurate information.
  • Update outdated records.
  • Complete incomplete data.
  • Erase personal data that is not required.

However, the right to erasure is not absolute. Organizations may still need to retain certain information to comply with legal, regulatory, or contractual obligations.

To fulfill these requests efficiently, businesses need mechanisms that can locate data across databases, applications, and third-party systems while maintaining compliance requirements.

3. Right of Grievance Redressal

Data Principals also have the right to raise concerns when they believe their requests have not been handled appropriately. Section 13 requires organizations to establish mechanisms for grievance redressal and complaint handling.

An effective grievance framework typically includes:

  • Dedicated channels for submitting complaints.
  • Defined response and escalation procedures.
  • Internal teams responsible for resolving issues.
  • Documentation of actions taken.

Clear communication and proper record-keeping are essential to ensure that grievances are resolved fairly and transparently.

4. Right to Nominate

The DPDP Act recognizes that there may be situations in which an individual is unable to exercise their rights personally. Under Section 14, Data Principals can nominate another person to act on their behalf in cases such as death or incapacity.

A nominee may be able to exercise rights related to:

  • Access to personal data.
  • Correction and erasure requests.
  • Grievance redressal.

This provision ensures that data rights do not automatically lapse when a person is no longer able to manage them directly.

For organizations, nomination introduces additional responsibilities, including verifying the nominee's authority and ensuring that requests are processed securely and in accordance with the law.

How Organizations Handle a Data Subject Access Request (DSAR)

Organizations need a structured workflow to verify identities, locate information across multiple systems, review the records being disclosed, and maintain evidence of every action taken. Without well-defined DSAR processes, requests can easily become delayed, incomplete, or even expose sensitive data to the wrong person.

Step 1: Receive and Log the Request

A data subject access request can arrive through several channels, including privacy portals, web forms, customer support emails, or help desks. Regardless of where the request originates, organizations should ensure that it enters a centralized workflow from the very beginning.

Most businesses use ticketing or case-management systems to record key details such as the requester's information, the type of request, the submission date, and the team responsible for handling it. Maintaining a central record helps organizations track progress, avoid duplicate efforts, and ensure that requests do not slip through the cracks.

Step 2: Verify the Requester's Identity

Before disclosing personal data, organizations must confirm that the request has been submitted by the correct individual. Identity verification is essential to prevent fraud, unauthorized access, and accidental data exposure.

Depending on the sensitivity of the information involved, organizations may rely on methods such as:

  • One-time passwords (OTPs)
  • Email verification links
  • Multi-factor authentication (MFA)
  • Government-issued identification

The verification process should be proportionate to the risk while still providing a smooth experience for legitimate users.

Step 3: Locate and Collect Personal Data

Once the requester's identity has been verified, organizations need to determine where the relevant personal data resides. This is often one of the most complex stages of the DSAR workflow, especially for enterprises that operate across multiple platforms.

Information may be spread across customer databases, cloud applications, email systems, support platforms, and internal repositories. Teams often need to collaborate with different departments and third-party providers to ensure that all relevant records are identified and collected before a response is prepared.

Step 4: Review and Validate the Information

Collecting data is only part of the process. Before sharing any information, organizations must review the records for accuracy, completeness, and relevance. In some cases, privacy, legal, and security teams may need to work together to validate the response.

This review helps organizations:

  • Confirm that the information belongs to the requester.
  • Remove duplicate or inaccurate records.
  • Identify data that may require additional review.

A structured validation process reduces errors and ensures that responses align with internal policies and regulatory obligations.

Step 5: Respond Securely to the Request

After the information has been reviewed, organizations must deliver it using secure communication channels. Sharing sensitive data through unsecured emails or public links can create additional privacy and security risks.

Common delivery methods include:

  • Secure customer portals
  • Encrypted email attachments
  • Password-protected files
  • Authenticated account downloads

Along with the requested information, organizations should clearly explain the purpose of processing and any actions taken in response to the request.

Step 6: Maintain Audit Records and Evidence

The DSAR process does not end once a response has been sent. Organizations should maintain records that demonstrate how the request was handled and the steps taken throughout the process.

Important evidence may include:

  • Request and response logs
  • Identity verification records
  • Internal approvals and reviews
  • Communication history

Maintaining audit trails strengthens accountability and provides valuable evidence during internal assessments, audits, or regulatory inquiries.

DSAR Response Timelines and Compliance Considerations Under the DPDP Act

Responding to a Data Subject Access Request requires coordination between privacy, legal, security, and operational teams. The DPDP Act establishes rights and obligations around personal data; therefore, organizations need internal processes to ensure that requests are handled consistently and securely.

Establish Internal Timelines and Ownership

The DPDP Act does not prescribe a universal response timeline for every type of request. Instead of waiting for issues to arise, organizations should establish internal service-level agreements (SLAs) that define responsibilities, review checkpoints, and escalation paths.

Clear ownership helps teams understand who is responsible for verifying requests, locating data, reviewing responses, and communicating with the requester.

Prioritize Documentation and Audit Readiness

Every stage of the DSAR process should be documented. From the initial request to the final response, organizations need evidence that demonstrates how the request was handled.

Documentation typically includes request logs, verification records, data searches, approvals, and communication history. Maintaining these records not only strengthens accountability but also simplifies internal reviews and compliance assessments.

Build Escalation Mechanisms for Complex Requests

Not every request is straightforward. Requests involving sensitive information, multiple departments, or third-party processors often require additional scrutiny.

Organizations should establish clear escalation mechanisms between privacy, legal, and security teams so that complex cases can be reviewed and resolved efficiently. Defined escalation paths also help reduce delays and ensure consistency across different requests.

Move Beyond Ad Hoc Processes

As the volume of data and privacy expectations continue to grow, organizations cannot manage data subject requests through disconnected systems. Structured workflows, documented procedures, and audit-ready records are essential for maintaining compliance and demonstrating accountability under the DPDP Act.

Common Challenges in Managing DSAR Requests

Managing a Data Subject Access Request (DSAR) is rarely as simple as retrieving a single record from a database. As organizations adopt more applications, cloud services, and third-party tools, personal data becomes scattered across multiple environments.

1. Data Is Spread Across Multiple Systems

Customer information may reside in CRM platforms, support tools, email systems, internal databases, and cloud applications. Without a centralized view of personal data, organizations often struggle to identify every system that contains relevant information.

2. Manual Workflows Slow Down Responses

Many organizations still rely on spreadsheets, email chains, and disconnected ticketing systems to manage data subject requests. Manual processes increase the risk of delays, duplicate work, and incomplete responses, especially as request volumes grow.

3. Identity Verification and Shadow Data

Verifying that a request originates from the correct individual is critical, but it can also be challenging. At the same time, organizations must account for shadow data stored in legacy applications, employee devices, and unmanaged systems that may not be part of the standard review process.

4. Cross-Functional Coordination

A single DSAR may require input from legal, IT, security, privacy, and compliance teams. Without clearly defined responsibilities and escalation paths, requests can become bottlenecked between departments.

5. Audit and Reporting Gaps

Organizations are expected to demonstrate how requests were handled, what actions were taken, and when responses were delivered. Missing documentation, incomplete audit trails, and limited reporting capabilities can make compliance reviews significantly more difficult.

How miniOrange Helps With DSARs

miniOrange simplifies the end-to-end management of Data Subject Access Requests by helping organizations discover personal data, automate workflows, and maintain records throughout the request lifecycle.

Using automated data discovery and classification capabilities, organizations can identify personal data across databases, cloud applications, endpoints, and internal systems. Once a request is received, teams can route it through structured workflows that support identity verification, approvals, escalation, and response management.

miniOrange also helps organizations:

  • Automate Data Principal request management.
  • Maintain audit trails and compliance reports.
  • Manage consent and privacy operations.
  • Coordinate responses across teams.
  • Deliver information securely.

By combining privacy operations, workflow automation, and reporting capabilities in a single DPDP compliance solution, miniOrange helps organizations reduce manual effort and improve accountability when handling DSARs.

Build an Audit-Ready DPDP Compliance Program

Key Takeaways

Data Subject Access Requests are becoming an essential part of modern privacy and compliance programs. They empower individuals to understand how organizations collect, process, retain, and share personal data while encouraging greater transparency and accountability.

Under the DPDP Act, businesses must establish processes to handle requests related to access, correction, erasure, and grievance redressal in a secure and efficient manner. As data moves across websites, applications, cloud platforms, and third-party systems, managing DSARs requires more than manual processes.

Organizations that invest in strong governance, data visibility, and audit-ready workflows will be better equipped to meet regulatory expectations and build long-term trust.

FAQs

1. Can a former employee submit a DSAR to their previous employer?

Yes. In many cases, former employees can request information about the personal data their employer still holds, such as payroll records, performance evaluations, or communication logs, subject to applicable legal and retention requirements.

2. Can parents or guardians submit a DSAR on behalf of a minor?

Under the DPDP Act, parents or lawful guardians may exercise certain rights on behalf of children, depending on the nature of the request and the organization's verification process.

3. Does a DSAR apply to emails, chat messages, and support tickets?

It can. Personal data may exist in emails, customer support systems, chat logs, and internal communication platforms. Organizations often need to search across multiple systems before responding to a request.

4. Can an organization ask for identity verification before processing a DSAR?

Yes. Before sharing personal information, organizations may ask for additional details or documents to confirm that the request is being made by the correct individual.

5. Does deleting an app or closing an account automatically remove all personal data?

No. Deleting an account does not necessarily mean that all related data is erased immediately. Organizations may retain certain information to comply with legal, contractual, or security obligations.

6. Can personal data requested through a DSAR be stored with third-party vendors?

Yes. Organizations often rely on cloud providers, payment processors, analytics platforms, and other vendors. As a result, responding to a DSAR may require collecting information from multiple third-party systems.

About the Author


Minal Purwar

Content Writer

Minal is an experienced B2B content writer. She has written over 250 articles across industries like UI/UX, real estate, automotive, digital marketing, SaaS, AI & ML, and cybersecurity. She brings her interest in cybersecurity to life by creating clear, engaging content tailored for technical, non-technical, and creative pieces. Her aim is to simplify complex topics, highlight product value, and connect with both technical and non-technical audiences.

Leave a Comment