Data Subject Request (DSR): Definition, Types, and How to Handle It Properly

September 14, 2026 / Published by: Editorial

Imagine the legal team at a fintech startup suddenly receiving an email from a former user demanding that all of their data be deleted from the system. The legal deadline is already ticking, while that user’s data turns out to be scattered across more than five different systems, from the CRM and transaction database to cloud backups.

This kind of situation is not rare. According to the UK Information Commissioner’s Office (ICO) official annual report for the 2025/26 period, the number of data protection complaints received by the regulator jumped from 42,315 to 76,743 in a single year, and most of those complaints were triggered by data access requests that were not handled properly.

This pressure is also visible in corporate budgets. The Cisco 2026 Data and Privacy Benchmark Study found that 38 percent of organizations across 12 countries now allocate at least USD 5 million to their data privacy programs, a sharp rise from just 14 percent the year before.

This surge in complaints and investment shares a single root cause: the growing number of data subject requests (DSRs) that companies must manage. This article will break down what a DSR is, its types, its legal basis, and how to handle it without sending the legal team into a panic every time a request email lands in the inbox.

What Is a Data Subject Request (DSR)?

A data subject request (DSR) is a formal request submitted by an individual, referred to as the data subject, to an organization that stores or processes their personal data. This request can take the form of asking to see the data the company holds, asking to correct inaccurate data, or even asking for that data to be deleted entirely.

What sets a DSR apart from an ordinary customer complaint is its legal basis. Every DSR rests on applicable data protection regulation, such as the General Data Protection Regulation (GDPR) in the European Union or Indonesia’s Personal Data Protection Law (UU PDP), which means companies are legally obligated to respond within a set period rather than treating it as optional.

There are three elements that legally qualify a request as a DSR. The requester must be the rightful owner of the data, the request must relate to one of the rights defined by law, and the company being approached must actually store or process that data.

Many people equate DSR with DSAR (data subject access request), even though the two are not identical. A DSAR refers specifically to the right to access data, while DSR is the broader umbrella term that covers access, rectification, erasure, restriction of processing, portability, and the right to object.

Here is an example. A former employee who resigned two years ago suddenly emails HR asking that all of their payslip and health record data be deleted from the company’s systems, and legally, that email already qualifies as a DSR even though it never uses the term “data subject request” at all.

The Legal Basis Governing Data Subject Requests

The obligation to respond to a DSR does not appear out of nowhere; it is explicitly set out in various data protection regulations around the world. The following two legal frameworks are the most relevant references for companies operating both globally and locally.

General Data Protection Regulation (GDPR)

The GDPR, in effect across the European Union since 2018, sets out eight data subject rights in Articles 15 through 22, including the rights to access, rectification, erasure, and portability. Companies that fail to comply face the risk of substantial fines, and according to DLA Piper’s annual survey published in January 2026, the cumulative total of GDPR fines since the regulation took effect has reached EUR 7.1 billion.

Indonesia’s Personal Data Protection Law (UU PDP)

In Indonesia, a similar obligation is set out under the UU PDP, which grants data subjects the right to access, update, or request deletion of their data from the data controller. For example, a user of an online lending app has the right to request a copy of the personal data used for their credit score assessment, and the data controller is obligated to fulfill that request within the timeframe set by implementing regulations.

Why Handling DSRs Properly Is Critical for Business

Handling a DSR is not merely an administrative compliance task; it is a direct bet on a company’s reputation and finances. When a request is ignored or answered late, the fallout rarely stops at a single complaint.

Data from the Cisco 2026 Data and Privacy Benchmark Study shows that 93 percent of organizations plan to increase their privacy investment this year, a signal that competitors are already moving ahead. If other companies already have a well-organized DSR system while your internal team still relies on manual spreadsheets, the trust gap with customers will only widen.

A clear example can be seen in cases where companies failed to respond to customer data deletion requests within the deadline, resulting in a public reprimand from the regulator. Beyond the fine itself, the company’s name also surfaces in the news, something that is clearly harder to repair than simply paying a penalty.

There is also a subtler but equally costly risk: lost operational efficiency. A legal team that has to manually search for customer data across a dozen different systems every time a DSR comes in is clearly losing time that could otherwise go toward more strategic work.

Steps to Handle a Data Subject Request Effectively

To keep the DSR process from turning into a sudden fire drill, companies need a clear and consistent workflow. Below are five steps that can serve as a basic framework, each with an example of how it applies in practice.

1. Verify the Requester’s Identity

Before any data is handed over or changed, make sure the request genuinely comes from the rightful data owner. For instance, ask the requester to confirm their identity through a registered email address or supporting documents, so data is not mistakenly sent to an unauthorized party.

2. Classify the Type of Request

Determine whether the request falls under access, rectification, erasure, or another category, since each one requires a different technical procedure. For example, an erasure request usually requires an additional check to confirm there is no other legal obligation requiring the data to be retained, such as tax records.

3. Conduct a Thorough Data Search

Search through every system that might hold the related data, from the main database and backups to third-party marketing tools. For instance, one e-commerce customer’s data might be scattered across the CRM system, an email marketing platform, and a customer service application all at once.

4. Respond Within the Set Deadline

Most regulations give a one-month deadline to respond to a DSR, though it can be extended if the case is complex. If a company anticipates it won’t finish on time, it should notify the requester early, along with the reason and a new estimated timeline.

5. Document Every Step of the Process

Record every step of handling the DSR, from the date it was received, the type of request, to the date it was resolved. This documentation matters not only for internal audits but also as proof of compliance if a regulator ever asks for clarification.

Common Challenges in Managing Data Subject Requests

Although the workflow above sounds simple on paper, many companies actually struggle to carry it out consistently. Below are some of the most common challenges, along with example situations.

  • Data scattered across disconnected systems. When customer data is stored separately in the CRM, a data warehouse, and third-party applications, searching for all of it manually can take days. For example, a customer service team may need to coordinate with three different divisions just to confirm that a single deletion request has truly been completed across every system.
  • A steadily rising volume of requests. As people become more aware of their privacy rights, more individuals are filing DSRs, a trend reflected in the surge of complaints across regulators worldwide. Companies still handling requests one by one manually will be overwhelmed once volume rises sharply.
  • Lack of a clear operating standard. Without a standardized internal guideline, different teams may handle DSRs in inconsistent ways. For example, one branch might respond within ten days, while another branch only responds after three weeks because it was unaware of the official deadline.
  • Limited resources for verification and audit. The process of identity verification and data search requires adequate people and tools, something that is often missing from the budgets of small and medium-sized companies. As a result, requests that should be resolved within days end up delayed for weeks.

Summary

A data subject request is clear proof that individuals now hold greater control over their personal data, and companies can no longer treat it as a side issue. From the right to access to the right to erasure, every type of DSR demands a response that is fast, accurate, and well documented.

Failing to handle a DSR is not just about fines; it is also about customer trust that is difficult to rebuild once it cracks. The more complex a company’s data systems become, the greater the need for a structured, reliable DSR process at all times.

Ready to Manage Privacy Compliance as a Business Risk?

See how GRC helps map personal data risks, monitor compliance with the PDP Law, and prepare companies for audits without complicated manual processes.

FAQ

1. What is a data subject request (DSR)?

A DSR is a formal request from an individual to a company to access, correct, or delete their personal data.

2. How long does a company have to respond to a DSR?

Usually one month, with an extension possible if the request is complex.

3. What’s the difference between DSR and DSAR?

A DSAR only covers the right to access data, while DSR covers all rights, including rectification, erasure, and portability.

Profil Adaptist Consulting

Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.

Read Related Post