Auditen
Home / Frameworks / GDPR / Data subject rights and DSARs
GDPR · Ch. 3

Data subject rights and DSARs

GDPR requires organizations to facilitate the exercise of specific rights granted to individuals regarding their personal data, most notably through Data Subject Access Requests (DSARs). Organizations must provide a mechanism for individuals to access, correct, delete, or move their data within strict legal timeframes.

What it means

Chapter 3 establishes that individuals have ownership over their personal data. This includes the right to be informed about how data is used, the right to access their data (DSAR), the right to rectify inaccuracies, and the right to erasure (the "right to be forgotten"). It also covers more technical rights like data portability and the right to object to or restrict certain types of processing.

In practice, this means an organization cannot ignore a request for personal data simply because it is difficult to retrieve. The requirement applies regardless of whether the request comes via a formal legal letter, an email, or a social media message. Organizations must be able to identify all locations where a specific individual's data resides and extract or delete it accurately.

How to meet it

Evidence an auditor asks for

  • A copy of the organization's Data Subject Rights Policy and internal SOPs.
  • A DSAR Log recording the date requests were received, the nature of the request, the verification method used, and the date of completion.
  • Redacted samples of completed responses sent to data subjects.
  • Evidence of staff training records specifically covering the recognition and escalation of subject rights requests.

Common pitfalls

  • Missing the one-month response deadline due to a lack of centralized tracking or internal delays in gathering data from different departments.
  • Over-redaction or under-redaction, where organizations either fail to provide required information or accidentally leak other people's personal data within a DSAR response.
  • Failing to search all data silos, such as ignoring email archives, Slack/Teams logs, or backup tapes during the collection process.
  • Creating overly burdensome identity verification requirements that act as a barrier to the individual exercising their rights.