Use this free DSAR letter generator to produce a ready-to-send data subject access request letter in seconds. Fill in the company name and your details, choose your jurisdiction, and download a GDPR-grounded letter you can email directly to the data controller or DPO. If you only want the wording, the full DSAR template is written out in plain text further down the page, along with a short version and a response template for organisations that have received a request. No account required — your data never leaves your browser.
A dsar letter generator removes the guesswork: you get the right statutory language, the correct Article 15 framing, and a structured request that organisations cannot legally dismiss as informal correspondence. Exercising your right to access your identity record starts here.
Generate a ready-to-send data subject access request (DSAR), deletion request, or data portability request. Pre-filled templates for 20+ major companies with correct DPO addresses. GDPR, CCPA, UK GDPR, LGPD supported.
The DSAR Template in Full
If you would rather not use the form, here is the same letter as plain text. Copy it, replace every bracketed field, and send it from the email address the company already has on file for you. Nothing beyond that is required for the request to be valid.
[Today's date] To: Data Protection Officer [Company name] Email: [DPO or privacy address from their privacy policy] From: [Your full name] Email: [The address your account is registered to] Subject: Data subject access request - Article 15 GDPR Dear Data Protection Officer, I am exercising my right of access under Article 15 of the General Data Protection Regulation. Please send me a copy of all personal data you hold about me, together with: - the purposes for which each category of data is processed; - the categories of personal data concerned; - the recipients or categories of recipient it has been disclosed to, including any outside the EEA; - the retention period for each category, or the criteria you use to set it; - the source of any data you did not collect from me directly; - whether you apply automated decision-making or profiling to me and, if so, the logic involved and its likely consequences for me. As this request is made by electronic means, please supply the data in a commonly used electronic format, as provided for by Article 15(3). So that you can find my records without further correspondence, my identifiers are: - Full name: [Your full name] - Account email: [Email address] - Customer or account number: [If you have one] - Postal address held on file: [If applicable] - Other identifiers: [Phone number, username, order references] This message is sent from the email address registered to my account, which should be sufficient to confirm my identity. If you need anything further, please tell me within five working days. Under Article 12(3) you must respond without undue delay and in any event within one month of receiving this request. If you intend to rely on the two-month extension that article allows, please write to me within that first month and explain why. Yours faithfully, [Your full name]
The identifiers block is the part most people leave out, and it is the part that decides how fast you get an answer. The ICO’s guidance on recognising a subject access request is explicit that the clock does not start until the controller holds enough information to confirm who you are. A request sent without account details therefore hands the organisation a free pause; listing your identifiers up front removes that excuse before it can be used.
A Shorter DSAR Template
A request does not have to read like a legal document. Under UK GDPR it can be made verbally, through a contact form, or on social media, and it never has to use the phrase “subject access request” or quote an article number. If you want something to paste into a support chat, this carries the same legal weight:
Hello, This is a subject access request. Please send me a copy of all personal data you hold about me, along with what you use it for, who you have shared it with, and how long you keep it. My account is registered to [email address]. My name is [full name] and my customer number is [number]. Please confirm receipt and tell me the date by which you will reply. [Your name]
The long template still earns its length wherever you expect resistance: it names the article, sets out the categories you expect back, and leaves a dated record you can attach to a complaint later. The short one suits the more common case, where a support agent simply forwards your message to whoever owns the data.
DSAR Response Template for the Organisation Receiving One
Plenty of small businesses reach this page from the other side of the request: someone has emailed asking for their data, and there is no privacy team to pass it to. The acknowledgement below buys no extra time, but it opens the record properly and keeps the exchange from drifting into an argument about dates.
Dear [Requester name], Thank you for your message of [date], which we are handling as a subject access request under Article 15 GDPR. We have located an account registered to [email address] and are treating your message from that address as confirmation of your identity. [Alternative wording: before we can release your data we need [what you need]. The one-month period will begin once we receive it.] We will send your data by [date one month from receipt] in a commonly used electronic format. Should the request prove complex enough to need the two-month extension permitted by Article 12(3), we will write to you before that date and set out our reasons. There is no charge for this response. [Your name], [role] [Company name]
Two rules settle almost every dispute that follows. The response is free: Article 12(5) allows a fee only where a request is manifestly unfounded or excessive, and the burden of proving that sits with you, not the requester. And the deadline runs one calendar month from the day the request arrived, weekends and public holidays included, rather than from the day someone got round to reading it.
Before you draft anything, the real work is inventory. Every system holding a name, an email address or a device identifier has to be searched, and analytics and advertising cookies count as personal data once they carry a persistent identifier. The wizard for working out which trackers need consent is the quickest way to see which of them store an identifier tied to the person asking. If that audit turns up more identifiers than the business has any use for, privacy-first analytics tools that collect less to begin with shrink the surface you have to disclose next time.
Vendors do sell DSAR workflow software with response templates built into it, and for an organisation fielding requests every week that is a defensible purchase. For one that sees three or four a year, a text file, a shared mailbox and a calendar reminder set to the one-month date cover the same ground without the licence fee.
What Is a DSAR and When Should You Send One?
A Data Subject Access Request is a formal exercise of the right granted by Article 15 of the GDPR (and its equivalents under UK GDPR, CCPA, Brazil LGPD, and other privacy laws). It requires any organisation that processes your personal data to produce a complete copy of everything they hold about you, explain the purposes and legal bases for that processing, name any third parties the data has been shared with, and state how long the data will be retained.
You should send a DSAR whenever you want to audit the data a company holds on you — after a data breach notification, before closing an account, when disputing a credit decision, or simply as a routine privacy check. Unlike a deletion or objection request, a DSAR produces information rather than triggering a change. It is your audit tool.
From an identity perspective, a DSAR is the most direct way to see what an organisation believes your identity record to be: which email addresses, phone numbers, device identifiers, behavioural profiles, and inferred attributes they associate with you. That makes it a prerequisite for any meaningful identity hygiene.
How to Use This Generator
- Select the company from the pre-filled list or enter a custom name and DPO email address.
- Choose your request type: access (Art. 15), erasure (Art. 17), or portability (Art. 20).
- Select the applicable law — GDPR, UK GDPR, CCPA, or LGPD.
- Enter your name and any account identifiers (email, username, customer number) so the company can locate your records without ambiguity.
- Review the generated letter. Customise any bracketed fields to add scope or specific data categories you want to include.
- Copy or download the letter and send it to the DPO address shown. Note the send date — the statutory clock starts from receipt.
What to Include in a Valid Data Subject Access Request
A DSAR does not need to be drafted in legal language to be valid, but it must be clear enough for the organisation to identify you and process your request. The generator handles the statutory framing. These are the two elements you must supply.
Proof of Identity
Controllers are entitled to request reasonable identity verification before releasing personal data. Acceptable evidence typically includes a copy of a government-issued ID (with sensitive fields such as document numbers redacted), a confirmation email from the account address, or confirmation of account-specific information such as a billing postcode. Do not send unredacted passport scans to companies you do not fully trust — the GDPR allows proportionate verification, not a free pass to collect more data than necessary.
What to Request
Article 15 grants access to all personal data by default. You can broaden or narrow the scope in your letter:
- Broad request: “All personal data you hold about me in any system, including structured records, email logs, call recordings, analytics profiles, and data shared with or received from third parties.”
- Targeted request: Specify a date range, a product line, or a data category (for example, “location data collected by your mobile app between January 2023 and December 2024”).
- Automated decisions: If the company uses profiling or automated decision-making that affects you, request the logic involved and the significance of that processing (Art. 15(1)(h)).
A more specific request reduces the time to response and the likelihood of a controller invoking the “manifestly unfounded or excessive” exemption.
What the Company Must Send Back — and by When
Under Article 15 GDPR, a controller that receives a valid DSAR must, within one calendar month, provide:
| What they must disclose | Legal basis |
|---|---|
| A copy of the personal data itself | Art. 15(3) |
| The purposes of processing | Art. 15(1)(a) |
| The categories of data | Art. 15(1)(b) |
| Recipients or categories of recipients | Art. 15(1)(c) |
| Retention periods or criteria used to determine them | Art. 15(1)(d) |
| Your remaining rights (rectification, erasure, restriction, objection) | Art. 15(1)(e) |
| The right to lodge a complaint with a supervisory authority | Art. 15(1)(f) |
| Source of the data if not collected directly from you | Art. 15(1)(g) |
| Logic of automated decision-making if applicable | Art. 15(1)(h) |
The one-month deadline can be extended by a further two months for complex or numerous requests, but the controller must notify you of the extension and the reasons within the first month. First responses must be free of charge. Repeated or manifestly unfounded requests may attract a reasonable fee or be refused, but the controller bears the burden of demonstrating this. Companies that ignore a DSAR entirely expose themselves to GDPR fines for ignoring DSARs.
Reading Your DSAR Response: Understanding the Identity Data You Receive
The response you receive is a snapshot of what an organisation believes about you. Reading it critically reveals more than most people expect.
What companies typically provide: account registration data, purchase or transaction history, support ticket transcripts, email correspondence, device identifiers and IP addresses, cookie and behavioural analytics data, and inferred attributes such as age bracket, interests, or income segment derived from third-party data enrichment.
What they routinely redact: data relating to other individuals (a legal requirement, not evasion), internal risk scores or fraud flags (sometimes protected as commercial confidential information, though this exemption is narrow), and data held by sub-processors that the controller claims falls outside their direct record-keeping.
How to read for identity accuracy: check whether the email addresses, phone numbers, and physical addresses match what you provided. Look for duplicate profiles, unfamiliar device IDs, or location data from periods when you did not use the service — these may indicate account sharing, a data-matching error, or a breach. Cross-reference third-party sources listed as data origins against your actual relationships with those companies.
If the response is incomplete, contradictory, or you believe data has been withheld without valid grounds, you can request clarification or escalate to your national supervisory authority. You can also check if your website is GDPR compliant to understand the obligations from the controller’s perspective.
Frequently Asked Questions
- Is there a free DSAR template I can copy?
- Yes — three of them, all on this page. The full template covers Article 15 in the wording a data protection officer expects, the shorter one works for a support chat or contact form, and the response template is for organisations that have received a request. Copy any of them; nothing you type into the generator above is stored or transmitted.
- Does a DSAR have to be in writing?
- No. A request can be made verbally, through a contact form, or on social media, and it does not have to use the phrase “subject access request” or cite Article 15. A written template is still the better choice, because it fixes the date and the scope of the request in a form you can produce later if the organisation misses its deadline.
- What information can I request in a DSAR?
- You can request all personal data a company holds about you — account data, behavioural profiles, correspondence, device identifiers, inferred attributes, and records of who the data was shared with. Under Article 15, the default is comprehensive access. You may narrow the scope in your letter to speed up the response.
- How long does a company have to respond to a DSAR?
- Under GDPR and UK GDPR, the deadline is one calendar month from receipt of the request. This can be extended by a further two months for complex cases, but you must be notified within the first month. CCPA gives California residents 45 days (extendable by 45 more). Brazil LGPD requires a response within 15 days.
- Can a company charge a fee for responding to a DSAR?
- The first response must be free. A reasonable fee can be charged only if the request is manifestly unfounded or excessive — a high bar that the controller must justify. Simply making a detailed or broad request does not make it excessive.
- What makes a DSAR valid?
- A DSAR is valid when it is a clear, written request to access personal data, accompanied by enough identifying information for the controller to locate your records. You do not need to cite specific articles of law or use formal language. This generator produces letters that meet the standard threshold without being unnecessarily complex.
- What if the company ignores my DSAR?
- Ignoring a DSAR is a breach of GDPR. If you receive no response within one month, you can file a complaint with the supervisory authority in your country — the ICO in the UK, the relevant DPA in your EU member state, or an equivalent body. Supervisory authorities have the power to compel a response and issue fines. Keep your sent email and any read receipts as evidence.
- How do I prove my identity without sending sensitive documents?
- Reasonable verification does not require a full passport copy. An email sent from the account address on record, confirmation of account details (order number, billing address), or a redacted ID showing only your name and photo is typically sufficient. If a company demands disproportionate identity evidence, challenge this — it may itself constitute an obstacle to exercising your rights under GDPR Article 12(2).