Obtainer

Blog

Data subject access requests, explained

Guides and practical playbooks for handling DSARs: what a data subject access request is, how to respond step by step, the GDPR and CCPA deadlines, templates, redacting third-party data, exemptions, and choosing DSAR software. Helps you comply; not legal advice.

State Laws 10 min read

State Privacy Law Cure Periods in 2026: Which States Still Give You One

Most US state privacy laws no longer give you a grace window to fix a violation. California, Colorado, Connecticut, Delaware, Oregon, Montana, Minnesota, and New Hampshire have all lost or repealed their cure periods. Here is where every state stands and what it changes about missing a 45-day deadline.

Read article
Buying Guide 9 min read

How Much Does It Cost to Fulfill a DSAR? The 2026 Per-Request Breakdown

Gartner puts the cost of manually fulfilling one data subject access request at roughly $1,400 to $1,524, almost all of it staff time. Here is where the hours actually go, what volume does to the number, and which five changes cut the cost per request.

Read article
Buying Guide 9 min read

How Much Does DSAR Software Cost? 2026 Pricing Guide

DSAR software ranges from about $49 a month for self-serve fulfillment to $10,000 to $90,000 a year for enterprise governance suites. Here is what drives the price, what you actually pay for at each tier, and how to tell which tier a company your size needs.

Read article
Fundamentals 10 min read

Which State Privacy Laws Apply to My Business? The 2026 Threshold Guide

Whether a state privacy law covers you rarely turns on revenue. It turns on how many residents you process, whether you sell data, and in a few states whether you touch sensitive data at all. Here is the 2026 threshold for every major state and how to tell where you land.

Read article
State Laws 9 min read

Connecticut Data Privacy Act 2026 Amendments: Lower Thresholds and What Changed

On July 1, 2026 the CTDPA threshold dropped from 100,000 to 35,000 Connecticut consumers, and selling data or processing sensitive data now brings you in scope regardless of volume. Here is exactly what changed, who is newly covered, and what to do first.

Read article
Fundamentals 10 min read

Universal Opt-Out Mechanisms and Global Privacy Control: Which States Require Them in 2026

A universal opt-out mechanism like Global Privacy Control is a browser signal that opts a person out of data sales and targeted ads. Twelve states now require you to honor it. Here is the list, what honoring it means, and how it connects to data subject requests.

Read article
Fundamentals 9 min read

Data Subject Request Deadlines by State: How Long You Have to Respond in 2026

Every US state privacy law gives you 45 days to answer a data subject request, extendable once by 45 more. Here is the deadline by state, when the clock starts, what extends it, and how the GDPR month differs.

Read article
Fundamentals 10 min read

Who Does the CCPA Apply To? The 2026 Thresholds and Exemptions

The CCPA applies to for-profit businesses that do business in California and cross one of three thresholds. Here are the 2026 figures, whether it reaches out-of-state and employee data, and the exemptions.

Read article
How-to 11 min read

CCPA Compliance Checklist: The 9 Requirements for 2026

A practical CCPA compliance checklist: confirm you are covered, map your data, post the right notices, honor the six rights on the 45-day clock, and meet the new 2026 risk-assessment and audit duties.

Read article
How-to 11 min read

Employee Subject Access Request: How to Handle a DSAR From an Employee

An employee subject access request is the hardest DSAR to answer: scattered data, other people in the file, and exemptions that are easy to get wrong. Here is how to run one, the deadline, and what you can withhold.

Read article
Fundamentals 10 min read

Right to Restrict Processing and Right to Object: GDPR Articles 18 and 21

The right to restrict processing (Article 18) and the right to object (Article 21) are the two GDPR rights teams handle worst. Here are the grounds for each, the absolute marketing opt-out, and how they connect.

Read article
Fundamentals 13 min read

States With Data Privacy Laws: All 20 State Privacy Laws in 2026

Twenty US states have a comprehensive consumer privacy law in effect in 2026. Here is the full state by state list, the 45-day response clock they nearly all share, and where they actually differ.

Read article
Fundamentals 10 min read

Right to Rectification: The GDPR Right to Correct Inaccurate Data

The right to rectification lets a person require you to correct inaccurate data and complete what is incomplete. Here is the one-month clock, the fact-versus-opinion line, and the Article 19 duty teams skip.

Read article
Templates 11 min read

GDPR Right to Erasure Response Template: Copy, Adapt, Send

A GDPR right to erasure response template for the three replies you actually send: erasure confirmed, erasure partly refused, and erasure refused. With the Article 17 wording to keep.

Read article
Fundamentals 12 min read

Right to Erasure: The GDPR Right to Be Forgotten, Explained

The right to erasure, also called the GDPR right to be forgotten, lets a person ask you to delete their data. Here are the six grounds, the five exceptions, and the one-month clock.

Read article
How-to 12 min read

CCPA Right to Delete: Responding to a Deletion Request in 45 Days

The CCPA right to delete gives a California consumer the right to have their personal information erased. Here is the 45-day clock, the nine exceptions, and what you owe your service providers.

Read article
Fundamentals 9 min read

What Is a DSAR? Data Subject Access Requests Explained

What is a DSAR? A data subject access request is a person's legal right to ask an organization for a copy of the personal data it holds about them. Here is how it works.

Read article
How-to 11 min read

How to Respond to a Data Subject Access Request, Step by Step

How to respond to a data subject access request step by step: verify identity, log the deadline, discover the data, compile a manifest, redact third-party data, and reply.

Read article
Deadlines 9 min read

DSAR Response Deadline: GDPR One Month, CCPA 45 Days

The DSAR response deadline is one month under the GDPR and 45 days under the CCPA. Here is when the clock starts, when you can extend it, and how to stay on time.

Read article
Templates 12 min read

DSAR Template: DSAR Response Template and Intake Form

A DSAR template set: the subject access request form you publish for intake, plus the acknowledgment, cover letter, and response templates you send back. With the wording to keep and adapt.

Read article
Guides 11 min read

The DSAR Process: From Intake to Response, Explained

The DSAR process explained end to end: intake, identity verification, deadline tracking, data discovery, manifest review, redaction, approval, and delivery of the response.

Read article
Checklists 9 min read

The DSAR Checklist: Every Step to Fulfill a Request on Time

A DSAR checklist covering every step to fulfill a request on time: log intake, verify identity, track the deadline, discover data, redact, get sign-off, and deliver.

Read article
How-to 10 min read

How to Redact a DSAR Response: Third-Party and Exempt Data

How to redact a DSAR response: identify third-party personal data and exempt material, apply redactions consistently, and keep a human in control of what gets disclosed.

Read article
Comparisons 10 min read

GDPR vs CCPA Data Requests: Deadlines, Scope, and Differences

GDPR vs CCPA data requests compared: response deadlines, who can ask, what you must disclose, fees, and the practical differences between the two access rights.

Read article
Guides 10 min read

DSAR Exemptions: When You Can Withhold or Refuse Data

DSAR exemptions explained: when you can withhold data, redact third-party information, or refuse a manifestly unfounded or excessive request, and how to document the reason.

Read article
Guides 10 min read

DSAR Software: How to Choose a Tool That Fits Your Team

DSAR software compared: what to look for in a tool for data discovery, deadline tracking, redaction, and human review, and how to choose one that fits your team.

Read article

Put it into practice

Run a request in the demo and watch Obtainer find the data, draft the response, and engage the redaction gate in minutes. Self-serve pricing, cancel anytime. Helps you comply; not legal advice.