Cybersecurity, explained for the rest of us.

VPN & Privacy

Data Subject Access Requests: How to File One and What Happens Next

Margot 'Magic' Thorne@magicthorneAugust 2, 202614 min read
Person reviewing printed data report at desk with laptop showing privacy request form

You have the right to know what data a company holds about you. Not just the data you gave them directly , all of it. What they inferred, what they bought, what they collected while you browsed. Privacy laws in Europe, California, and a growing number of U.S. states guarantee this right through something called a data subject access request.

Most people have never filed one. The process sounds bureaucratic, the outcome uncertain. But the mechanism is straightforward, the legal obligation clear, and the information you receive often surprising. Here's how to file a data subject access request, what happens next, and what you'll actually get back.

What a Data Subject Access Request Actually Is

A data subject access request is your legal demand to see the personal information a company holds about you. The Electronic Privacy Information Center describes this as a fundamental privacy right , the ability to know what's being collected, processed, and shared in your name.

The request triggers a legal obligation. Under GDPR, companies have one month to respond. Under CCPA, they have 45 days. Both laws allow extensions in complex cases, but the company must notify you and explain why.

You can ask for several things in one request. What data they hold. How they use it. Who they share it with. Where they got it if you didn't provide it directly. How long they plan to keep it. The legal basis for processing it. Whether they use it for automated decision-making or profiling.

The company must respond in a structured, commonly used format , typically a spreadsheet or JSON file. They cannot charge you for your first request in a 12-month period. They can charge a reasonable fee for excessive or repetitive requests, but the bar for "excessive" is high.

This right exists because data asymmetry creates power asymmetry. Companies know everything about you. You know almost nothing about what they know. The access request rebalances that equation, at least partially.

Who Can File and What Laws Apply

If you're in the European Union, GDPR applies. If you're in California, CCPA applies. If you're in Virginia, Colorado, Connecticut, Utah, or one of the other states with comprehensive privacy laws, those state laws apply. The FTC's privacy enforcement work covers deceptive practices, but doesn't create a federal access right for most Americans.

GDPR is the strongest. It covers anyone in the EU, regardless of citizenship. It applies to any company that processes EU residents' data, even if that company has no physical presence in Europe. GDPR gives you the right to access, rectification, erasure, restriction of processing, data portability, and objection.

CCPA covers California residents. It applies to for-profit businesses that meet revenue or data-processing thresholds. CCPA gives you the right to know, delete, opt out of sales, and opt out of sharing for cross-context behavioral advertising. The law expanded in 2023 with the California Privacy Rights Act, adding rights around sensitive data and automated decision-making.

Other state laws vary. Some mirror CCPA closely. Others create weaker rights with more exceptions. If you're outside California and the EU, check whether your state has a comprehensive privacy law. The Electronic Privacy Information Center tracks state-level privacy legislation.

Many companies extend GDPR-like rights to users globally, even where not legally required. This isn't altruism , it's operational efficiency. Building separate data systems for different jurisdictions costs more than offering one privacy process worldwide. But the company decides which rights to extend, and those voluntary commitments can change.

Step 1: Identify the Right Entity and Contact Method

You need to know who actually controls your data. This isn't always obvious.

If you use a service through a third-party app, the app developer and the underlying platform might both be data controllers. If you bought something on Amazon from a third-party seller, both Amazon and the seller hold data. If your employer uses a cloud service, your employer is usually the controller, not the cloud provider.

Privacy laws distinguish between controllers (who decide how data gets used) and processors (who handle data on the controller's behalf). You file requests with controllers. Processors forward your request to the controller.

Most companies list a privacy contact in their privacy policy. Look for an email address, web form, or postal address. Some companies use dedicated privacy portals where you log in and submit requests through your account dashboard. Others require you to email or mail a written request.

The FTC's privacy guidance recommends that companies provide clear, accessible methods for rights requests. In practice, some companies make it easy. Others bury the contact information or route requests through generic customer service channels that don't understand the legal obligation.

If the privacy policy doesn't list a contact method, try emailing privacy@[company].com or dpo@[company].com (DPO stands for Data Protection Officer, a role required under GDPR for certain organizations). If email fails, send a written request to the company's registered business address.

Document everything. Save the privacy policy. Screenshot the contact information. Keep copies of your request and all responses. If the company later claims they never received your request, you'll need proof.

Step 2: Draft Your Request

Your request should be clear, specific, and reference the applicable law. You don't need a lawyer. You don't need legalese. You need clarity about what you're asking for and which legal right you're exercising.

Start with your identity. Full name, email address, account username if applicable, and any other identifiers the company uses. If you're requesting data about a closed account, include the dates you used the service and any transaction details you remember.

State the legal basis. "I am submitting this request under Article 15 of the GDPR" or "I am submitting this request under Section 1798.100 of the California Consumer Privacy Act." This signals that you know your rights and expect compliance within the legal timeframe.

Specify what you want. Here's a template that covers the main categories:

"I request access to all personal data you hold about me, including:

  • All data I provided directly
  • All data you collected through my use of your service
  • All data you obtained from third parties
  • All inferences or profiles you created about me
  • A list of third parties with whom you have shared my data
  • The purposes for which you process my data
  • The legal basis for processing my data
  • How long you intend to retain my data"

You can narrow this if you're looking for something specific. "I request access to all location data you collected from my account between January 1, 2025 and July 31, 2026." Specificity helps, but you don't need it. A general request for all personal data is valid.

If you want your data in a specific format, say so. "Please provide the data in CSV format" or "Please provide the data in JSON format." The company must use a structured, commonly used, machine-readable format. They can't send you screenshots or PDFs of database tables and call it compliant.

End with your contact information and a request for confirmation. "Please confirm receipt of this request within five business days and provide the requested data within the timeframe required by law."

Send the request through the company's designated channel. If they have a web form, use it. If they require email, send it. If they require postal mail, send it certified with return receipt. The method matters less than the paper trail.

Step 3: Verify Your Identity

The company will ask you to verify your identity before releasing your data. This is legal and necessary. They cannot hand your personal information to someone claiming to be you without verification.

The verification process must be proportionate. The company can ask for information they already have , your email address, account password, answers to security questions, a government-issued ID if you provided one during signup. They cannot demand information they don't need or don't already hold.

GDPR says verification must be "reasonable" and "proportionate to the risk." CCPA says the company must use "commercially reasonable efforts" to verify identity. In practice, this usually means logging into your account or responding from the email address on file.

If you're requesting data about a closed account, verification gets harder. The company might ask for old transaction details, account numbers, or other information only the real account holder would know. If you can't provide it, they can deny the request , but they must explain why and give you a chance to provide additional verification.

Some companies use third-party identity verification services. You upload a photo of your ID, take a selfie, answer knowledge-based questions. This feels invasive, but it's sometimes necessary for high-risk requests. If the company uses a third-party verifier, check that verifier's privacy policy. You're giving them data too.

Refuse unreasonable verification demands. If a company asks for your Social Security number and they never collected it in the first place, that's not proportionate verification , that's a fishing expedition. Push back. Reference the legal standard for proportionality.

If verification fails or the company claims they can't verify you, ask why. Document their explanation. If it's unreasonable, you can file a complaint with the relevant data protection authority.

Step 4: Wait for the Response

GDPR gives companies one month. CCPA gives them 45 days. Both laws allow extensions in complex cases , up to two additional months under GDPR, up to 45 additional days under CCPA. The company must notify you of the extension and explain why it's necessary.

Complex cases include requests that cover large volumes of data, requests that require manual review, or requests submitted during a period when the company is handling many similar requests. The bar for "complex" is higher than companies sometimes claim. Processing your data is their job. A well-designed system should handle access requests routinely.

If the deadline passes with no response, send a follow-up. Reference the original request, the legal deadline, and the current date. "I submitted a data access request on [date] under [law]. The legal deadline for response was [date]. I have not received a response. Please provide the requested data immediately or explain the delay."

If the company still doesn't respond, file a complaint. Under GDPR, you file with your national data protection authority. Under CCPA, you file with the California Attorney General. Both agencies have online complaint forms. Both have enforcement power.

Companies sometimes claim they have no data about you. This is occasionally true , if you never created an account or interacted with their service, they might genuinely hold nothing. But if you used the service, they almost certainly hold something. IP addresses, device identifiers, timestamps, behavioral data. Press for specifics. "You state you hold no data about me. Does this mean you hold no account data, no usage data, no log data, and no inferred data? Please confirm."

What You'll Actually Receive

The response format varies. Some companies send a zip file with spreadsheets. Some send JSON files. Some provide access through a web portal where you download the data yourself. The format must be structured, commonly used, and machine-readable. A PDF is not compliant. A CSV file is.

The data usually includes several categories. Account data , your name, email, phone number, address, payment information. Usage data , login times, IP addresses, device identifiers, pages viewed, features used. Content data , messages you sent, posts you made, files you uploaded. Inferred data , categories the company assigned you, predictions they made about you, segments they placed you in.

The volume surprises most people. A typical social media account generates hundreds of megabytes of data over several years. An e-commerce account might include thousands of transactions, each with timestamps, product details, shipping addresses, payment methods. A fitness app might hold years of location data, heart rate measurements, sleep patterns.

The company must explain what each data field means. A spreadsheet column labeled "usr_seg_17" is not compliant. They must provide a data dictionary or plain-language descriptions. "usr_seg_17" might mean "user segment 17: high-value customer, predicted to spend over $500 annually."

Third-party sharing is often the most revealing section. Companies list every entity they shared your data with , advertising partners, analytics providers, payment processors, cloud storage vendors, data brokers. The list can run to dozens or hundreds of companies. Each entry should include the recipient's name, the categories of data shared, and the purpose.

Some companies redact information to protect others' privacy. If you sent a message to another user, the company might provide your message text but redact the recipient's name. This is legal under GDPR's balancing test , your right to access versus the other person's right to privacy.

If the response seems incomplete, ask for clarification. "You provided account data and usage data, but no information about third-party sharing or automated decision-making. Please provide the complete data as required by law."

Using the Data You Receive

You now have a snapshot of what one company knows about you. Here's what to do with it.

Review for accuracy. Privacy laws give you the right to correct inaccurate data. If your address is wrong, your phone number outdated, your account settings different from what you thought, request correction. The company must fix it or explain why they won't.

Check third-party sharing. If the company shared your data with entities you don't recognize, research them. Some are legitimate service providers. Some are data brokers who sell your information. Under CCPA, you can opt out of sales. Under GDPR, you can object to processing.

Look for inferred data. Companies make predictions about you , your income level, your political views, your health status, your likelihood to buy. These inferences are often wrong. They're also often used to make decisions about what you see, what you pay, what opportunities you're offered. If the inferences are inaccurate, request deletion or correction.

Evaluate retention periods. If the company plans to keep your data for 10 years and you closed your account three years ago, ask why. Retention must be proportionate to the purpose. If the purpose no longer exists, the data should be deleted.

Consider deletion. You have the right to request deletion under both GDPR and CCPA, subject to exceptions. If you no longer use the service, if the data is no longer necessary, if you withdraw consent, you can ask the company to delete everything. They must comply unless they have a legal obligation to retain it (tax records, for example) or a legitimate interest that overrides your rights.

Document patterns across companies. If you file requests with multiple companies, you'll start to see which data brokers appear on every sharing list, which analytics providers track you everywhere, which advertising networks follow you across the web. This information is power. You can opt out, file complaints, or simply understand the scope of surveillance.

In The Return of the King, Gandalf tells Denethor, "Authority is not given to you to deny the return of the king." The line is about legitimate power versus claimed power. Your data belongs to you. The company holds it, processes it, profits from it , but the authority over that data is yours. The access request is you asserting that authority. The company's response shows whether they respect it.

Common Obstacles and How to Handle Them

Companies sometimes make this harder than the law requires. Here's what you'll encounter and how to respond.

Obstacle: The company claims the request is too broad. Response: GDPR and CCPA allow broad requests. You can ask for all personal data. The company must provide it or explain specifically why they can't. "Too broad" is not a legal basis for refusal.

Obstacle: The company asks for excessive verification. Response: Verification must be proportionate. If they're asking for information they never collected, push back. Reference the proportionality requirement in the law.

Obstacle: The company charges a fee. Response: Your first request in 12 months must be free. If they're charging, ask why. If you've submitted multiple requests, they can charge a reasonable fee, but they must justify the amount.

Obstacle: The company provides data in an unusable format. Response: The law requires structured, commonly used, machine-readable formats. If they send a PDF, it's not compliant. Request a proper format , CSV, JSON, XML.

Obstacle: The company extends the deadline without justification. Response: Extensions are allowed for complex cases, but the company must explain why your case qualifies. If the explanation is vague or generic, challenge it.

Obstacle: The company provides partial data and claims the rest doesn't exist. Response: Ask for specifics. "You provided account data but no usage data. Do you collect usage data? If not, please confirm. If so, please provide it."

Obstacle: The company ignores your request entirely. Response: Send a follow-up after the legal deadline. If they still don't respond, file a complaint with the data protection authority or attorney general.

Every obstacle is an opportunity to test the company's compliance. Most companies comply when you push back. Some don't. Those are the ones where a formal complaint becomes necessary.

Filing Complaints When Companies Don't Comply

If the company refuses your request, misses the deadline, or provides obviously incomplete data, you have enforcement options.

Under GDPR, file a complaint with your national data protection authority. Each EU member state has one. The process is usually online. You provide details about your request, the company's response (or lack of response), and why you believe they violated the law. The authority investigates. If they find a violation, they can issue fines, require compliance, or take other enforcement action.

Under CCPA, file a complaint with the California Attorney General's Privacy Enforcement Unit. The process is online. You provide similar details. The AG can investigate, sue for civil penalties, or require corrective action. CCPA also allows private lawsuits for data breaches, but not for access request violations , enforcement of access rights goes through the AG.

Other states with privacy laws have their own enforcement mechanisms. Check your state attorney general's website for the complaint process.

EPIC's consumer privacy work shows how advocacy organizations support enforcement. EPIC files complaints, submits comments on proposed regulations, and litigates when companies or governments violate privacy rights. You can file your own complaint and also alert organizations like EPIC to patterns of non-compliance.

Complaints work. Data protection authorities in Europe have issued billions in fines for GDPR violations. The California AG has sued companies for CCPA violations. Enforcement is real. Companies know it. A well-documented complaint gets attention.

Beyond Access: Other Privacy Rights You Can Exercise

The access request is one tool in a larger toolkit. Privacy laws give you other rights worth using.

Right to rectification: If your data is inaccurate, you can demand correction. The company must fix it or explain why the data is accurate as recorded.

Right to erasure: You can request deletion of your data. Exceptions exist , legal obligations, legitimate interests, public interest , but many requests succeed. If you closed an account years ago and the company still holds your data, deletion is often appropriate.

Right to restriction: You can ask the company to stop processing your data while they verify accuracy or assess a deletion request. The data stays in their systems but isn't used.

Right to data portability: Under GDPR, you can request your data in a format that lets you transfer it to another service. This right applies when processing is based on consent or contract and is carried out by automated means.

Right to object: You can object to processing based on legitimate interests, direct marketing, or profiling. The company must stop unless they demonstrate compelling legitimate grounds that override your rights.

Right to opt out: Under CCPA, you can opt out of sales and sharing for cross-context behavioral advertising. This is broader than the GDPR objection right and doesn't require justification.

Each right has specific requirements and exceptions. The access request is often the starting point. You file an access request, review what you receive, then decide which other rights to exercise based on what you learn.

What This Process Actually Accomplishes

Filing a data subject access request doesn't erase your digital footprint. It doesn't stop tracking. It doesn't delete your data from the dozens of companies that bought it from the first company. It's not a magic reset button.

What it does is give you information. Information about what's collected, how it's used, who it's shared with. Information you can use to make decisions , whether to continue using the service, whether to request deletion, whether to file complaints, whether to change your behavior.

It also creates accountability. Every request is a reminder to the company that users have rights, that data protection laws have teeth, that privacy is not optional. Companies that handle thousands of access requests learn to build better systems. Companies that ignore requests face enforcement.

The process is also a diagnostic tool for the privacy landscape. When you file requests with multiple companies and compare responses, you see patterns. Which companies are transparent and which obfuscate. Which data brokers appear everywhere. Which tracking technologies are ubiquitous. This knowledge shapes advocacy, regulation, and public understanding.

You won't get everything. Some data is gone , deleted, anonymized, or held by entities the company won't name. Some responses will be incomplete or misleading. Some companies will fight you. But the right exists, the mechanism works, and the information you gain is yours.

The access request is your legal lever to pry open the black box of data processing. Use it.

Stack of privacy request response documents with highlighted sections
→ Filed under
privacy rightsdata requestsGDPRCCPAconsumer privacydata protection
ShareXLinkedInFacebook

Frequently asked questions

A data subject access request is your legal right to ask a company what personal information they hold about you, how they use it, and who they share it with. Privacy laws like GDPR and CCPA guarantee this right.
Under GDPR, companies have one month to respond. Under CCPA, they have 45 days. Both laws allow extensions in complex cases, but the company must notify you.
No. Your first request in a 12-month period must be free under both GDPR and CCPA. Companies can charge a reasonable fee for excessive or repetitive requests.
You can file a complaint with your state attorney general (for CCPA) or your national data protection authority (for GDPR). Both agencies have enforcement power and complaint processes.
Yes. Companies can ask for verification to prevent fraud, but the process must be proportionate. They cannot demand more information than necessary to confirm you are who you claim to be.

You might also like