Subject Rights Request
A subject rights request is when a person asks an organisation to act on the rights they have over their own personal information, such as getting a copy of the data an organisation holds about them or learning how it is being used. Anyone can make such a request, and you generally do not need a lawyer to do so. One common type is a subject access request, where a person asks for a copy of their personal data.
A subject rights request is a request made by an individual (a data subject) to exercise one or more of their rights over the processing of their personal data. The most commonly encountered form is the right of access, exercised through a subject access request (SAR or DSAR), which under the EU GDPR and UK GDPR entitles the individual to obtain confirmation of processing, a copy of their personal data, and supplementary information including the purposes of processing, the categories of personal data concerned, and the recipients or categories of recipients. The term is often used more broadly to encompass requests engaging other data subject rights (for example rectification, erasure, restriction, portability, or objection), though the specific rights available, their conditions, and applicable exemptions differ by legal regime; the terminology and scope under regimes such as the CCPA and CPRA are not equivalent to those under the GDPR. Note that acronym usage varies in practice: 'SAR'/'DSAR' typically denote access requests specifically, while 'DSR'/'SRR' are broader. This entry defines the request concept and does not cover response timescales, permitted charges, verification requirements, exemptions, or enforcement, which are governed separately and vary by jurisdiction and instrument.
Why it matters
Subject rights requests are the primary mechanism through which individuals exercise control over their personal data, and they translate abstract data protection principles into concrete operational obligations for organisations. The most commonly encountered form, the subject access request, allows a person to obtain confirmation that their data is being processed, a copy of that data, and supplementary information such as the purposes of processing, the categories of personal data involved, and the recipients or categories of recipients. Because anyone can make such a request and generally does not need legal representation to do so, organisations should expect to receive them from a wide range of individuals, not only those with legal support.
For organisations, the ability to locate, retrieve, and disclose an individual's personal data on request is a practical test of underlying data governance. Handling these requests depends on knowing where personal data resides, understanding how it flows across systems, and being able to demonstrate accountability rather than merely asserting it. Weak data mapping, poor lineage, or fragmented records tend to surface first when an access request cannot be answered accurately or completely.
The rights that a subject rights request may engage, and the conditions attached to them, differ by legal regime. The rights available under the EU GDPR and UK GDPR are not equivalent to those under the CCPA and CPRA, and terminology varies in practice, with 'SAR' and 'DSAR' typically referring to access requests specifically while 'DSR' and 'SRR' are broader. Organisations operating across jurisdictions should not assume a single process satisfies every applicable regime.
Who it's relevant to
Inside SRR
Common questions
Answers to the questions practitioners most commonly ask about SRR.