Use this free DSAR letter generator to produce a ready-to-send data subject access request letter in seconds. Fill in the company name and your details, choose your jurisdiction, and download a GDPR-grounded letter you can email directly to the data controller or DPO. No account required — your data never leaves your browser.

A dsar letter generator removes the guesswork: you get the right statutory language, the correct Article 15 framing, and a structured request that organisations cannot legally dismiss as informal correspondence. Exercising your right to access your identity record starts here.

Generate a ready-to-send data subject access request (DSAR), deletion request, or data portability request. Pre-filled templates for 20+ major companies with correct DPO addresses. GDPR, CCPA, UK GDPR, LGPD supported.

What Is a DSAR and When Should You Send One?

A Data Subject Access Request is a formal exercise of the right granted by Article 15 of the GDPR (and its equivalents under UK GDPR, CCPA, Brazil LGPD, and other privacy laws). It requires any organisation that processes your personal data to produce a complete copy of everything they hold about you, explain the purposes and legal bases for that processing, name any third parties the data has been shared with, and state how long the data will be retained.

You should send a DSAR whenever you want to audit the data a company holds on you — after a data breach notification, before closing an account, when disputing a credit decision, or simply as a routine privacy check. Unlike a deletion or objection request, a DSAR produces information rather than triggering a change. It is your audit tool.

From an identity perspective, a DSAR is the most direct way to see what an organisation believes your identity record to be: which email addresses, phone numbers, device identifiers, behavioural profiles, and inferred attributes they associate with you. That makes it a prerequisite for any meaningful identity hygiene.

How to Use This Generator

  1. Select the company from the pre-filled list or enter a custom name and DPO email address.
  2. Choose your request type: access (Art. 15), erasure (Art. 17), or portability (Art. 20).
  3. Select the applicable law — GDPR, UK GDPR, CCPA, or LGPD.
  4. Enter your name and any account identifiers (email, username, customer number) so the company can locate your records without ambiguity.
  5. Review the generated letter. Customise any bracketed fields to add scope or specific data categories you want to include.
  6. Copy or download the letter and send it to the DPO address shown. Note the send date — the statutory clock starts from receipt.

What to Include in a Valid Data Subject Access Request

A DSAR does not need to be drafted in legal language to be valid, but it must be clear enough for the organisation to identify you and process your request. The generator handles the statutory framing. These are the two elements you must supply.

Proof of Identity

Controllers are entitled to request reasonable identity verification before releasing personal data. Acceptable evidence typically includes a copy of a government-issued ID (with sensitive fields such as document numbers redacted), a confirmation email from the account address, or confirmation of account-specific information such as a billing postcode. Do not send unredacted passport scans to companies you do not fully trust — the GDPR allows proportionate verification, not a free pass to collect more data than necessary.

What to Request

Article 15 grants access to all personal data by default. You can broaden or narrow the scope in your letter:

  • Broad request: “All personal data you hold about me in any system, including structured records, email logs, call recordings, analytics profiles, and data shared with or received from third parties.”
  • Targeted request: Specify a date range, a product line, or a data category (for example, “location data collected by your mobile app between January 2023 and December 2024”).
  • Automated decisions: If the company uses profiling or automated decision-making that affects you, request the logic involved and the significance of that processing (Art. 15(1)(h)).

A more specific request reduces the time to response and the likelihood of a controller invoking the “manifestly unfounded or excessive” exemption.

What the Company Must Send Back — and by When

Under Article 15 GDPR, a controller that receives a valid DSAR must, within one calendar month, provide:

What they must disclose Legal basis
A copy of the personal data itself Art. 15(3)
The purposes of processing Art. 15(1)(a)
The categories of data Art. 15(1)(b)
Recipients or categories of recipients Art. 15(1)(c)
Retention periods or criteria used to determine them Art. 15(1)(d)
Your remaining rights (rectification, erasure, restriction, objection) Art. 15(1)(e)–(f)
The right to lodge a complaint with a supervisory authority Art. 15(1)(f)
Source of the data if not collected directly from you Art. 15(1)(g)
Logic of automated decision-making if applicable Art. 15(1)(h)

The one-month deadline can be extended by a further two months for complex or numerous requests, but the controller must notify you of the extension and the reasons within the first month. First responses must be free of charge. Repeated or manifestly unfounded requests may attract a reasonable fee or be refused, but the controller bears the burden of demonstrating this. Companies that ignore a DSAR entirely expose themselves to GDPR fines for ignoring DSARs.

Reading Your DSAR Response: Understanding the Identity Data You Receive

The response you receive is a snapshot of what an organisation believes about you. Reading it critically reveals more than most people expect.

What companies typically provide: account registration data, purchase or transaction history, support ticket transcripts, email correspondence, device identifiers and IP addresses, cookie and behavioural analytics data, and inferred attributes such as age bracket, interests, or income segment derived from third-party data enrichment.

What they routinely redact: data relating to other individuals (a legal requirement, not evasion), internal risk scores or fraud flags (sometimes protected as commercial confidential information, though this exemption is narrow), and data held by sub-processors that the controller claims falls outside their direct record-keeping.

How to read for identity accuracy: check whether the email addresses, phone numbers, and physical addresses match what you provided. Look for duplicate profiles, unfamiliar device IDs, or location data from periods when you did not use the service — these may indicate account sharing, a data-matching error, or a breach. Cross-reference third-party sources listed as data origins against your actual relationships with those companies.

If the response is incomplete, contradictory, or you believe data has been withheld without valid grounds, you can request clarification or escalate to your national supervisory authority. You can also check if your website is GDPR compliant to understand the obligations from the controller’s perspective.

Frequently Asked Questions

What information can I request in a DSAR?
You can request all personal data a company holds about you — account data, behavioural profiles, correspondence, device identifiers, inferred attributes, and records of who the data was shared with. Under Article 15, the default is comprehensive access. You may narrow the scope in your letter to speed up the response.
How long does a company have to respond to a DSAR?
Under GDPR and UK GDPR, the deadline is one calendar month from receipt of the request. This can be extended by a further two months for complex cases, but you must be notified within the first month. CCPA gives California residents 45 days (extendable by 45 more). Brazil LGPD requires a response within 15 days.
Can a company charge a fee for responding to a DSAR?
The first response must be free. A reasonable fee can be charged only if the request is manifestly unfounded or excessive — a high bar that the controller must justify. Simply making a detailed or broad request does not make it excessive.
What makes a DSAR valid?
A DSAR is valid when it is a clear, written request to access personal data, accompanied by enough identifying information for the controller to locate your records. You do not need to cite specific articles of law or use formal language. This generator produces letters that meet the standard threshold without being unnecessarily complex.
What if the company ignores my DSAR?
Ignoring a DSAR is a breach of GDPR. If you receive no response within one month, you can file a complaint with the supervisory authority in your country — the ICO in the UK, the relevant DPA in your EU member state, or an equivalent body. Supervisory authorities have the power to compel a response and issue fines. Keep your sent email and any read receipts as evidence.
How do I prove my identity without sending sensitive documents?
Reasonable verification does not require a full passport copy. An email sent from the account address on record, confirmation of account details (order number, billing address), or a redacted ID showing only your name and photo is typically sufficient. If a company demands disproportionate identity evidence, challenge this — it may itself constitute an obstacle to exercising your rights under GDPR Article 12(2).