Data Subject Request
A Data Subject Request (DSR) is a formal request that an individual makes to an organization to exercise their rights over the personal data the organization holds about them. These requests typically ask the organization to give the person access to their data, correct it, delete it, or transfer it. The term is often used broadly to cover any such privacy-rights request.
A Data Subject Request (DSR) is a formal request submitted by an individual to an organization to exercise privacy rights over personal data concerning them. In industry usage the term is applied broadly to encompass the range of associated rights requests, commonly including access, rectification (correction), erasure (deletion), and portability (transfer) of personal data. The narrower term Data Subject Access Request (DSAR) is frequently used, sometimes interchangeably, to denote requests focused specifically on access. The precise rights available, applicable conditions, response timelines, and enforcement mechanisms are governed by the specific data protection law or regulation applicable in a given jurisdiction; those statutory particulars fall outside the scope of this definition and should be verified against the relevant primary legal source.
Why it matters
Data Subject Requests operationalize the privacy rights that individuals hold over their personal data, transforming statutory or regulatory rights into concrete obligations that an organization must be able to receive, verify, and act upon. For compliance functions, the ability to handle DSRs reliably is a visible indicator of an organization's broader data governance maturity: fulfilling a request to access, correct, delete, or transfer personal data requires the organization to know what personal data it holds, where it resides, and on what basis it is processed. Where that underlying data inventory is weak, DSR handling tends to expose the gap.
DSRs also sit at the intersection of compliance and operational risk. Because the specific rights available, the conditions attached to them, and the timelines for response are set by the data protection law applicable in a given jurisdiction, the same categories of request may carry different obligations depending on where the individual and the organization are situated. Mishandling or failing to respond to a valid request can expose an organization to enforcement action and reputational harm, and the applicable enforcement mechanisms vary by jurisdiction. Organizations should verify the statutory particulars against the relevant primary legal source rather than relying on a general definition.
Because the term DSR is used broadly in industry to cover the full range of privacy-rights requests, while the narrower Data Subject Access Request (DSAR) is often used interchangeably and sometimes limited to access requests, clarity of terminology matters. Ambiguity about which rights a given request invokes can lead to incomplete responses, and treating an access-focused label as if it excluded correction, deletion, or portability rights may leave obligations unmet.
Who it's relevant to
Inside DSR
Common questions
Answers to the questions practitioners most commonly ask about DSR.

