Rising DSARs Demand: Striking a Balance between Data Protection and Organizational Viability

In the evolving landscape of data protection legislation, the rise in Data Subject Access Requests (DSARs) brings with it complexities and burdens that can present significant challenges to organizations. Generally, DSARs are legal requests made by individuals—referred to as “data subjects”—to obtain personal data an organization holds about them. This practice, codified in UK data protection legislation, symbolizes a global shift towards greater data control for consumer, with similar rights outlined in both the EU’s General Data Protection Regulation and the California Consumer Privacy Act.

As defined in these legislative pieces, a DSAR allows a data subject to receive a copy of their personal data being processed. However, the benefits of data control for the data subject can often translate into an onerous obligation for organizations—particularly those with limited resources to manage the surge in DSARs. The increased frequency of these requests and the high stakes involved—the potential privacy risks and regulatory repercussions—reinforces the need for robust data management procedures in businesses of all sizes.

However, as law firm Vedder Price recently pointed out, responding to DSARs effectively requires a careful balance. Firms need to ensure they meet their legal obligations whilst avoiding unnecessary disclosure of sensitive business information. The challenge lies in extracting and compiling masses of individualized data in a reasonable timeframe, a process that can significantly drain organizational time and resources. Furthermore, if businesses fail to respond suitably to DSARs, they can face regulatory sanctions and reputational damage.

Going forward, it remains crucial for businesses to stay updated on their obligations under data protection legislation, construct efficient processes for handling DSARs and ensure that their interests are protected against unnecessary disclosure. These measures would essentially contribute to fostering an environment of trust with data subjects without compromising organizational viability. On the flip side, ensuring these measures are effectively put in place and maintained requires a significant organizational commitment both in terms of resources and a culture of data protection.