Contact ussales@ventavid.com
VentaVid

Glossary

Our sales with video glossary is here to help you gain an understanding of specific video and marketing terms

DSAR - Data subject access request

In this article

What is a data subject request: DSAR explained

A data subject request is a person exercising one of their GDPR rights over their own personal data, most often the right of access under Article 15, which is why it is usually shortened to DSAR, or data subject access request. The clock starts the moment it arrives.

There is no required format. A request can be verbal, sent by email, made on social media, or handed to any employee, and it does not have to cite an article, use the word DSAR or go to a privacy inbox. That is the operational risk: the deadline can start running in a claims queue or a service reception without anyone recognising it.

What does a data subject request cover?

  • Access, Article 15: confirmation of processing, the information about it, and a copy of the data.
  • Rectification, Article 16: correcting inaccurate data and completing incomplete data.
  • Erasure, Article 17: deletion where one of the listed grounds applies. It is not absolute.
  • Restriction, Article 18: freezing processing while accuracy or an objection is worked out.
  • Portability, Article 20: a machine readable copy, limited to data processed by consent or contract and by automated means.
  • Objection, Article 21: objecting to processing based on legitimate interests or public task, and an absolute right to object to direct marketing.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

What you have to provide

Article 15(1) lists the information: the purposes, the categories of data, recipients or categories of recipients, the envisaged retention period or the criteria for setting it, the existence of the rights to rectification, erasure and restriction, the right to complain to a supervisory authority, and the source of the data. Article 15(1)(h) adds the existence of automated decision making, including profiling, together with meaningful information about the logic involved and the significance and envisaged consequences for the person. Article 15(3) then requires a copy of the personal data undergoing processing.

Note what that copy is not. A DSAR is a request for the personal data inside your documents, not for the documents themselves, and not for internal material that says nothing about the requester.

How long do you have, and what can you charge?

Article 12(3) requires you to act without undue delay and in any event within one month of receipt, extendable by two further months where necessary given the complexity and number of requests, provided you tell the person inside the first month. Article 12(5) makes the response free of charge, with one exception: where a request is manifestly unfounded or excessive, in particular because it is repetitive, you may either charge a reasonable fee based on administrative costs or refuse to act. Manifestly unfounded is a high bar, and irritating is not the same as excessive.

DSAR explained: a claims file example

A claimant asks for everything you hold on their claim. Their personal data includes the video and photos they submitted, the transcript of what they said, handler notes about them, and the case timeline. Article 15(4) says the right to a copy shall not adversely affect the rights and freedoms of others, so the neighbour's face and number plate in that footage are candidates for redaction rather than automatic disclosure. A note recording that a signal fired on their submission is still their personal data, and withholding it needs a specific exemption, not discomfort.

What a DSAR is commonly confused with

It is not a litigation disclosure route, although it is routinely used as an early one, and the motive behind a request does not make it invalid. It is not a freedom of information request, which applies to public authorities and to information generally rather than to one person's data. And it is not a request from a third party unless that party holds proper authority, which is why a solicitor's letter still needs verifying before anything leaves the building. Keeping a clean record of what was disclosed, to whom and when belongs to the same discipline as chain of custody on the underlying evidence.

The UK version and other regimes

The UK runs its own version through the UK GDPR and the Data Protection Act 2018, whose Schedule 2 exemptions cover areas such as crime and taxation and legal professional privilege. The Data (Use and Access) Act 2025 then changed the mechanics from 5 February 2026: a new Article 12A lets controllers pause the one month clock while waiting for identity verification or clarification of scope, and the search obligation is now expressed as a reasonable and proportionate search rather than an exhaustive one. Other jurisdictions grant comparable rights on different terms, with California allowing 45 days to respond and setting its own limits on lookback periods. Build the workflow for the regime you operate in, and make sure the people who receive customer media, not just the privacy team, know that personal data is what triggers all of it.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

See the damage before you decide

Send one link, get guided, verified claim video back. No app, no account.