DSAR — Data Subject Access Request
What is DSAR?
A Data Subject Access Request (DSAR) is the formal mechanism a person uses to exercise rights over the personal data a business holds about them — access, deletion, correction, portability, or opt-out-of-sale, depending on the applicable privacy law. Privacy laws give the business a hard deadline to respond; GDPR requires 30 calendar days (extendable once), and CCPA/CPRA, which define broader access, deletion, portability, and opt-out-of-sale rights, set the deadline at 45 days from the date it receives the request.
More detail
Orbit routes DSARs through two intake paths — operator-filed (your team logs a request against a contact) or self-service (the data subject submits unauthenticated via an email + SMS OTP identity-gate) — and queues them against a fixed fulfilment SLA. GDPR's 30-day clock starts on verification, and a complex or verified requester can extend it once; CCPA's 45-day clock is not extendable, though the response can take more time only in rare narrowly-defined cases.
The data-subject rights surface spans every regulated privacy regime: under GDPR the request is access-only or deletion-only, while under CCPA/CPRA and ISO-style frameworks the request may combine access and deletion (or define new rights like opt-out-of-sale — which a CPaaS platform handles as an opt-out across channels, not just a data-access fulfilment). Orbit captures the request type at intake so the response, and the downstream fulfilment, match the law actually invoked.
Orbit's DSAR pipeline enforces the GDPR or CCPA SLA as a tenant-side control — the intake, identity, verification, and fulfilment stages all run under the tenant's authority. The platform never gate-blocks a regulator-defined fulfilment, and the SLA timer belongs to the tenant's configured deadline rather than a hard-coded platform-imposed clock.
Frequently asked
- What does a typical DSAR SLA look like — 30 days or 45 days?
- It depends on the regime: GDPR requires 30 calendar days, with one permitted extension if the request is complex; CCPA/CPRA requires 45 days and the few narrow extension paths differ. Orbit's fulfilment queue treats the law actually invoked as the governing deadline rather than the longest or shortest possible one.
- What's the difference between access and deletion DSARs? Is there an 'opt-out' variant?
- Access asks for what you hold; deletion asks you to remove it. Depending on the regime there is also a portability variant (deliver data in a structured format) and an opt-out-of-sale variant (CCPA/CPRA-specific — no downstream sale or sharing of the data subject's personal data). A CPaaS platform namespaces the intake so the required response is clear.
- Why can't a DSAR be fulfilled informally — by ad-hoc dashboard search?
- Because a fulfilment has to be a verified identity check and a reproducible export — the request has to be queued, the data subject verified, and the resulting export/delete logged against a formal SLA. Informal dashboards give answers without an audit trail; the DSAR pipeline records who asked, who responded, and when, which is the evidence the law demands.
See also
Build it on Orbit
Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.