Blog
Data subject access requests, explained
Guides and practical playbooks for handling DSARs: what a data subject access request is, how to respond step by step, the GDPR and CCPA deadlines, templates, redacting third-party data, exemptions, and choosing DSAR software. Helps you comply; not legal advice.
OneTrust vs Transcend: Pricing, DSAR Automation and Which One to Buy
Transcend is the more capable DSAR engine and the more expensive contract, with a reported average near $76,075 a year against OneTrust's reported $11,970 median. Neither publishes a price. Here is what drives the gap, why the two numbers are not measuring the same thing, and which one a US team should actually buy.
Read articleOneTrust vs Ketch: Pricing, DSAR Automation and Which One to Buy
Ketch publishes a free tier, $150 Starter and $499 Plus. OneTrust publishes nothing and carries a reported $10,000 minimum. Yet the reported median Ketch contract is about $35,000 a year against OneTrust's $11,970, a 2.9x inversion of how both are positioned. Here is what drives each number, why Ketch's rests on only seven buyers, and where subject rights actually sit on both price lists.
Read articleKetch Pricing 2026: Plans, Cost Per Year, and What DSAR Automation Actually Costs
Ketch publishes a free tier, $150 Starter and $499 Plus, then quotes Pro. The published ladder tops out near $5,988 a year while the reported median contract sits close to $35,000, roughly six times higher. Rights workflows are an add-on at Plus and only bundled at Pro, and the median rests on just seven tracked buyers.
Read articleOsano Pricing 2026: Plans, Cost Per Year, and What DSAR Actually Costs
Osano publishes $0 and $199 a month, then quotes everything else. Reported buyer data puts the median contract near $8,459 a year, the cheapest of any established privacy platform. The catch is that the published prices buy consent management, and DSAR handling starts at the first custom-quoted tier.
Read articleOneTrust vs Securiti: Pricing, DSAR Automation, and Which Privacy Platform to Buy
Securiti's reported median contract runs about four times OneTrust's, roughly $49,841 a year against $11,970, and at the top of the market the comparison reverses. Here is why the medians diverge, how much confidence each number actually deserves, and which platform fits which kind of privacy team.
Read articleOneTrust vs BigID: Pricing, DSAR Features, and Which to Buy
BigID's reported median contract runs about eight and a half times OneTrust's, roughly $101,950 a year against $11,970, and the reason is packaging rather than value. Here is why the medians diverge, what each platform does on subject requests, and the one capability BigID has that OneTrust cannot match.
Read articleOneTrust vs TrustArc: Pricing, DSAR Features and Which Privacy Software to Buy
TrustArc's reported median contract runs higher than OneTrust's, about $15,120 a year against $11,970, which is the opposite of what both companies' positioning predicts. Here is why the medians invert, what each platform lists for subject rights, and the one capability TrustArc sells that OneTrust has no answer to.
Read articleOneTrust vs Osano: Pricing, DSAR Features and Which Privacy Software a US Team Should Buy
Osano is the cheaper and simpler of the two, at a reported median of about $8,459 a year against OneTrust's $11,970, and it is the only one that publishes a price. OneTrust is the broader platform. Neither publishes a price for the capability most buyers are shopping for. Here is the side-by-side on cost, subject rights, consent, and where each genuinely wins.
Read articleGDPR Compliance Consultants: What Consultants and Services Cost, and When Software Is Enough
What GDPR compliance consultants and services actually cost, how that compares to a privacy hire or software, where a consultant is genuinely the right call, and the part of the job no report can do for you.
Read articleOneTrust Pricing: What OneTrust Costs in 2026 and What Buyers Actually Pay
OneTrust does not publish list pricing. Reported buyer data puts the median contract near $11,970 a year across 307 tracked purchases, with a range from $1,620 to $48,230 and a platform minimum around $10,000. Here is what drives a quote, the implementation and renewal costs that sit outside the subscription, and how six privacy platforms compare on reported spend.
Read articleWhat Is Data Governance? The Framework, Principles, and the Question a Data Catalog Cannot Answer
Data governance is the exercise of authority and control over how an organization manages its data. It indexes data by asset: systems, tables, owners, retention. A data subject request asks something a catalog is not built for, which is where this person appears across everything you run. Here is the DAMA definition, the eleven knowledge areas, how to implement a program, and the gap that shows up on a 45-day clock.
Read articleWhat Is PII? Personally Identifiable Information, Examples, and Why It Is Not the Same as Personal Data
PII is a US security term, not a privacy law term, and it is narrower than what the CCPA and the GDPR actually make you find. Households, internally generated inferences and online identifiers all sit outside a standard PII inventory and inside the legal definition. Here is the NIST definition, real examples, and the three gaps that cause a data subject request to be answered incompletely.
Read articleLitigation Hold vs Deletion Request: When a Legal Hold Beats the Right to Erasure
A litigation hold beats a deletion request, but only for the records inside its scope and only for as long as the matter lasts. Everything else about that person still has to be deleted, on the original clock, with the exception named in writing. Here is which provision actually carries a US legal hold under the GDPR (not the one you think), what the CCPA and the state laws say, and the step almost nobody builds.
Read articleData Retention Policy Requirements: What Retention Policies and a Records Retention Schedule Must Disclose
No US state privacy law gives you a retention number. Several now require you to publish yours. California has to state a length of time for each category of personal information or the criteria used to determine it, Minnesota has to describe its retention policies in the privacy notice, and Maryland caps sensitive data at strictly necessary regardless of consent. Here is what each regime requires, the federal minimums that do set numbers, and the half of retention a records retention schedule cannot cover.
Read articleData Breach Notification Laws by State: Deadlines, AG Notice, and the New 30-Day Floor
All fifty states, DC and the territories have a breach notification law, and there is still no general federal one. Twenty states set a number between 30 and 60 days. Thirty-one say "without unreasonable delay". The strictest clock governs a multi-state breach, and as of January 1, 2026 that floor is 30 days because California SB 446 replaced its open-ended standard with a hard deadline. Here is the landscape, why two surveys give you two different lists, and what the notification list actually costs you to build.
Read articleFCRA Exemption From State Privacy Laws: Why No State Exempts a Consumer Reporting Agency
Every comprehensive US state privacy law carves out the Fair Credit Reporting Act, and not one of them carves out you. Fifteen states lift a GLBA financial institution out of scope as an organization. No state does that for a consumer reporting agency. The FCRA carve-out is always an activity exemption, always qualified by "to the extent", and it ends where the exempt activity ends. Here is the split, state by state, and what stays in scope at a background screening company.
Read articleSubprocessor Meaning: Processor vs Subprocessor and Subprocessor List Rules
A subprocessor is the vendor your vendor hired. You never signed with them, they hold data about your customers, and when a request lands you are still accountable for what they have. GDPR Article 28(2) gives you an objection right, Colorado is the only US state that copies it, and California does not use the word at all. Here is the chain, clause by clause.
Read articleData Processing Agreement Requirements by State: What Your Vendor Contracts Have to Say
Every comprehensive US state privacy law requires a written contract before a vendor processes personal data for you, and most of them copied Virginia almost word for word. Three states break the pattern: Colorado asks for an annual independent audit at the processor's expense, Utah and Iowa drop the assessment clause entirely, and California requires something structurally different that a European-style DPA usually fails to provide. Here is the split, clause by clause.
Read articleStudent Data Privacy Laws by State: SOPIPA, the Vendor Rules, and What Belongs in Every Contract
FERPA binds schools. The state student privacy laws bind you, the vendor, directly. California's SOPIPA started it in 2016 and more than twenty states followed, but three of them do the real work: SOPIPA, Illinois SOPPA, and New York Education Law 2-d, which between them require signed data privacy agreements, a seven-day breach notice, public vendor listings, and a parent correction right that FERPA never gave. Here is the split and what each one asks of an operator.
Read articleFERPA Exemption From State Privacy Laws: The Seven States That Do Not Give Schools a Clean Pass
Most state privacy laws exempt nonprofits and carve out FERPA education records, which is why schools have mostly ignored them. Seven states break that pattern. Colorado exempts only state institutions and only for noncommercial use, Delaware writes universities out of its government exemption, New Jersey exempts neither nonprofits nor higher education, and Oregon's nonprofit grace period ended July 1, 2025. Here is the split and what stays in scope.
Read articleGLBA Exemption From State Privacy Laws: The Five States That No Longer Exempt Financial Institutions
Fifteen states exempt GLBA-regulated financial institutions at the entity level. Five do not, and two of those changed in the last year. Montana removed its broad exemption on October 1, 2025 and Connecticut on July 1, 2026, both keeping a carve-out for chartered banks and taking it away from lenders, servicers, and fintechs. Here is the split, the thresholds, and what GLBA does not give you.
Read articleHIPAA Exemption From State Privacy Laws: Entity-Level vs Data-Level by State
Nine states exempt HIPAA covered entities outright. Six exempt only the protected health information, which leaves the rest of a health system's data, including its own employees in California, fully in scope with access, correction, and deletion rights. Here is the split by state and what it changes about how you handle requests.
Read articleData Broker Registration Requirements: California, Texas, Oregon, and Vermont
Four states require data brokers to register, and California now charges $6,000 a year for the privilege of a recurring deletion duty that starts August 1, 2026. Here is who counts as a data broker in each state, what registration costs, when it is due, and what filing actually commits you to.
Read articleConsumer Health Data Privacy Laws by State: Washington, Nevada, Connecticut
Three states now regulate health data that HIPAA never touches, and Washington lets consumers sue you over it directly. New York came close and was vetoed in December 2025. Here is which health data laws are actually in force in 2026, who they cover, what they require, and why a wellness app can be more exposed than a hospital.
Read articleData Subject Request Appeal: How to Handle a Denied Privacy Request
Almost every US state privacy law makes you offer a way to appeal a denied data subject request, and Utah is the only one that does not. Most states give you 60 days to answer an appeal in writing. Here is which states require it, what the appeal has to include, and why skipping it is a separate violation from the denial itself.
Read articleDSAR Identity Verification: How to Verify a Subject Access Request
Verification decides whether a data subject access request ends as a compliance win or a data breach. The CCPA standard is two matching data points for categories and three plus a signed declaration for specific pieces. Here is what each law requires, how to handle authorized agents, and what to do when you cannot verify someone.
Read articleMissed DSAR Deadline: What Happens and How to Recover
Miss a DSAR deadline and the late response becomes the violation, while the obligation to answer continues. What you are exposed to and how to recover.
Read articleCCPA Penalties for Non Compliance: 2026 Fines and Amounts
CCPA penalties are $2,663 per violation and $7,988 per intentional violation in 2026, not the $2,500 and $7,500 in the statute, because the CPPA adjusts them for inflation. Here are the current amounts, the 2026 California enforcement actions, the maximum civil penalty in all twenty states, and what actually turns a mishandled data subject request into a countable violation.
Read articleState Privacy Law Changes in July 2026: Connecticut, Utah, New Jersey, and Arkansas
Four state privacy obligations changed inside two weeks. Connecticut cut its threshold from 100,000 consumers to 35,000, Utah switched on a right to correct, New Jersey lost its cure period on July 15, and Arkansas turned on a children and teens law. Here is what each change does and what it means for your request workflow.
Read articleDSAR vs Deletion Request: What Is the Difference and How to Handle Each
A deletion request is one type of data subject request, not a separate thing. Access asks you to show a person their data; deletion asks you to erase it. They share an intake and a 45-day clock but pull in opposite operational directions, and the exemptions differ. Here is how the two compare and how to run one workflow that handles both.
Read articleRight to Correct Personal Data: How to Handle a Correction Request Under US State Laws
Nineteen of the twenty comprehensive US state privacy laws now give consumers a right to correct inaccurate personal data, and Utah joined on July 1, 2026. Correction is operationally harder than access, because one wrong value can sit in a dozen systems. Here is the workflow that actually closes the loop.
Read articleState Privacy Law Cure Periods in 2026: Which States Still Give You One
Most US state privacy laws no longer give you a grace window to fix a violation. California, Colorado, Connecticut, Delaware, Oregon, Montana, Minnesota, and New Hampshire have all lost or repealed their cure periods. Here is where every state stands and what it changes about missing a 45-day deadline.
Read articleHow Much Does It Cost to Fulfill a DSAR? The 2026 Per-Request Breakdown
Gartner puts the cost of manually fulfilling one data subject access request at roughly $1,400 to $1,524, almost all of it staff time. Here is where the hours actually go, what volume does to the number, and which five changes cut the cost per request.
Read articleHow Much Does DSAR Software Cost? 2026 Pricing Guide
DSAR software ranges from roughly $600 a year for self-serve fulfillment to reported medians of $8,459 to $76,075 a year for privacy platforms. Here is what drives the price, what you actually pay for at each tier, and how to tell which tier a company your size needs.
Read articleWhich State Privacy Laws Apply to My Business? The 2026 Threshold Guide
Whether a state privacy law covers you rarely turns on revenue. It turns on how many residents you process, whether you sell data, and in a few states whether you touch sensitive data at all. Here is the 2026 threshold for every major state and how to tell where you land.
Read articleConnecticut Data Privacy Act 2026 Amendments: Lower Thresholds and What Changed
On July 1, 2026 the CTDPA threshold dropped from 100,000 to 35,000 Connecticut consumers, and selling data or processing sensitive data now brings you in scope regardless of volume. Here is exactly what changed, who is newly covered, and what to do first.
Read articleUniversal Opt-Out Mechanisms and Global Privacy Control: Which States Require Them in 2026
A universal opt-out mechanism like Global Privacy Control is a browser signal that opts a person out of data sales and targeted ads. Twelve states now require you to honor it. Here is the list, what honoring it means, and how it connects to data subject requests.
Read articleData Subject Request Deadlines by State: How Long You Have to Respond in 2026
Every US state privacy law gives you 45 days to answer a data subject request, extendable once by 45 more. Here is the deadline by state, when the clock starts, what extends it, and how the GDPR month differs.
Read articleWho Does the CCPA Apply To? The 2026 Thresholds and Exemptions
The CCPA applies to for-profit businesses that do business in California and cross one of three thresholds. Here are the 2026 figures, whether it reaches out-of-state and employee data, and the exemptions.
Read articleCCPA Compliance Checklist: The 9 Requirements for 2026
A practical CCPA compliance checklist: confirm you are covered, map your data, post the right notices, honor the six rights on the 45-day clock, and meet the new 2026 risk-assessment and audit duties.
Read articleEmployee Subject Access Request: How to Handle a DSAR From an Employee
An employee subject access request is the hardest DSAR to answer: scattered data, other people in the file, and exemptions that are easy to get wrong. Here is how to run one, the deadline, and what you can withhold.
Read articleRight to Restrict Processing and Right to Object: GDPR Articles 18 and 21
The right to restrict processing (Article 18) and the right to object (Article 21) are the two GDPR rights teams handle worst. Here are the grounds for each, the absolute marketing opt-out, and how they connect.
Read articleStates With Data Privacy Laws: All 20 State Privacy Laws in 2026
Twenty US states have a comprehensive consumer privacy law in effect in 2026. Here is the full state by state list, the 45-day response clock they nearly all share, and where they actually differ.
Read articleRight to Rectification: The GDPR Right to Correct Inaccurate Data
The right to rectification lets a person require you to correct inaccurate data and complete what is incomplete. Here is the one-month clock, the fact-versus-opinion line, and the Article 19 duty teams skip.
Read articleGDPR Right to Erasure Response Template: Copy, Adapt, Send
A GDPR right to erasure response template for the three replies you actually send: erasure confirmed, erasure partly refused, and erasure refused. With the Article 17 wording to keep.
Read articleRight to Be Forgotten: The GDPR Right to Erasure Under Article 17, Explained
The right to be forgotten, written into the GDPR as the right to erasure, lets a person ask you to delete the data you hold about them. Here are the six grounds, the five exceptions, and the one-month clock.
Read articleCCPA Right to Delete: Responding to a Deletion Request in 45 Days
The CCPA right to delete gives a California consumer the right to have their personal information erased. Here is the 45-day clock, the eight exceptions (not the nine most guides still list), and what you owe your service providers.
Read articleWhat Is a DSAR? Data Subject Access Requests Explained
What is a DSAR? A data subject access request is a person's legal right to ask an organization for a copy of the personal data it holds about them. Here is how it works.
Read articleHow to Respond to a Data Subject Access Request, Step by Step
How to respond to a data subject access request step by step: verify identity, log the deadline, discover the data, compile a manifest, redact third-party data, and reply.
Read articleDSAR Response Deadline: GDPR One Month, CCPA 45 Days
The DSAR response deadline is one month under the GDPR and 45 days under the CCPA. Here is when the clock starts, when you can extend it, and how to stay on time.
Read articleDSAR Template: DSAR Response Template and Intake Form
A DSAR template set: the subject access request form you publish for intake, plus the acknowledgment, cover letter, and response templates you send back. With the wording to keep and adapt.
Read articleThe DSAR Process: From Intake to Response, Explained
The DSAR process explained end to end: intake, identity verification, deadline tracking, data discovery, manifest review, redaction, approval, and delivery of the response.
Read articleThe DSAR Checklist: Every Step to Fulfill a Request on Time
A DSAR checklist covering every step to fulfill a request on time: log intake, verify identity, track the deadline, discover data, redact, get sign-off, and deliver.
Read articleHow to Redact a DSAR Response: Third-Party and Exempt Data
How to redact a DSAR response: identify third-party personal data and exempt material, apply redactions consistently, and keep a human in control of what gets disclosed.
Read articleGDPR vs CCPA Data Requests: Deadlines, Scope, and Differences
GDPR vs CCPA data requests compared: response deadlines, who can ask, what you must disclose, fees, and the practical differences between the two access rights.
Read articleDSAR Exemptions: When You Can Withhold or Refuse Data
DSAR exemptions explained: when you can withhold data, redact third-party information, or refuse a manifestly unfounded or excessive request, and how to document the reason.
Read articleDSAR Software: How to Choose a Tool That Fits Your Team
DSAR software compared: what to look for in a tool for data discovery, deadline tracking, redaction, and human review, and how to choose one that fits your team.
Read articlePut it into practice
Run a request in the demo and watch Obtainer find the data, draft the response, and engage the redaction gate in minutes. Self-serve pricing. Helps you comply; not legal advice.