Definition
A Data Subject Access Request (DSAR) is a request made by an individual (data subject) under GDPR to access personal data that an organisation holds about them. For email marketing teams, DSARs require searching across email platforms, CRM systems, and analytics tools to compile the data the subscriber is entitled to receive.
DSARs are a fundamental right under GDPR. Organisations must respond within one month (extendable by two months for complex requests) and must provide the information free of charge in most cases.
What Must Be Provided in a DSAR Response
| Information | Where to Find It for Email |
|---|---|
| Confirmation that data is being processed | ESP account, CRM profile |
| Categories of personal data | Subscriber records, behaviour data, preference data |
| Purpose of processing | Consent records, privacy notice |
| Recipients of data | ESP, analytics tools, integrations |
| Retention periods | Data retention policy |
| Source of data | Consent records, signup forms, acquisition source |
| Automated decisions | Personalisation algorithms, scoring models |
DSAR Process for Email Marketers
| Step | Action | Timeline |
|---|---|---|
| 1. Receive request | Log the DSAR, verify identity | Day 1 |
| 2. Locate data | Search ESP, CRM, analytics, support systems | Day 1-10 |
| 3. Review data | Check for third-party data, confidential information | Day 5-15 |
| 4. Prepare response | Compile data in accessible format (CSV, PDF) | Day 10-20 |
| 5. Send response | Deliver to the requester securely | Day 20-30 |
Email Platforms and DSARs
Most email marketing platforms provide tools for responding to DSARs:
- Subscriber export: Most ESPs allow exporting a subscriber's full data profile including custom fields, engagement history, and consent records.
- Data deletion: ESPs typically provide a GDPR deletion function that removes the subscriber from all lists and segments.
- Activity logs: Email open, click, and conversion history should be included in the DSAR response.
Common DSAR Challenges for Email Teams
- Data scattered across systems: Subscriber data often lives in ESP, CRM, analytics, and support platforms. Locating all data requires searching multiple systems.
- Backup and archive data: Data in backups may need to be restored to fulfil the request.
- Third-party data: Data shared with analytics platforms or integrations may be outside the ESP and harder to locate.
- Pseudonymised data: Engagement data linked to a subscriber ID but not a name may still constitute personal data.
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
AIDA Model for Email
The AIDA model (Attention, Interest, Desire, Action) is a classic copywriting framework used to structure email campaigns that guide subscribers from awareness to conversion.
AMP for Email
AMP for Email is a Google-developed framework that allows email messages to include interactive elements like forms, carousels, accordions, and live content. It turns static emails into dynamic, interactive experiences directly inside the inbox.
Anchoring Effect in Email Marketing
The anchoring effect is a cognitive bias where the first piece of information presented (the anchor) influences subsequent decisions, used in email to frame pricing and value perception.
Announcement Email
An announcement email is a dedicated campaign that communicates a specific update, milestone, or change to subscribers, from product launches and feature releases to company news and events.
Frequently Asked Questions
GDPR requires response within one month of receiving the request. This can be extended by two months for complex requests, but the requester must be informed of the extension within the initial month.
DSARs must be fulfilled free of charge unless the request is manifestly unfounded or excessive, particularly if it is repetitive. In those cases, a reasonable fee based on administrative costs may be charged.
The information should be provided in a commonly used electronic format (CSV, PDF, JSON). The format should be accessible and allow the requester to easily review the data.
Yes. Data held in backup systems is still personal data and should be included if it is reasonably accessible. ICO guidance suggests focusing on readily available information rather than restoring all historical backups.
Inform the requester that you do not hold the requested data. If you know who does, you may advise the requester to contact that organisation directly.