Blog
Data subject access requests, explained
Guides and practical playbooks for handling DSARs: what a data subject access request is, how to respond step by step, the GDPR and CCPA deadlines, templates, redacting third-party data, exemptions, and choosing DSAR software. Helps you comply; not legal advice.
HIPAA Exemption From State Privacy Laws: Entity-Level vs Data-Level by State
Nine states exempt HIPAA covered entities outright. Six exempt only the protected health information, which leaves the rest of a health system's data, including its own employees in California, fully in scope with access, correction, and deletion rights. Here is the split by state and what it changes about how you handle requests.
Read articleData Broker Registration Requirements: California, Texas, Oregon, and Vermont
Four states require data brokers to register, and California now charges $6,000 a year for the privilege of a recurring deletion duty that starts August 1, 2026. Here is who counts as a data broker in each state, what registration costs, when it is due, and what filing actually commits you to.
Read articleConsumer Health Data Privacy Laws by State: Washington, Nevada, Connecticut
Three states now regulate health data that HIPAA never touches, and Washington lets consumers sue you over it directly. New York came close and was vetoed in December 2025. Here is which health data laws are actually in force in 2026, who they cover, what they require, and why a wellness app can be more exposed than a hospital.
Read articleData Subject Request Appeal: How to Handle a Denied Privacy Request
Almost every US state privacy law makes you offer a way to appeal a denied data subject request, and Utah is the only one that does not. Most states give you 60 days to answer an appeal in writing. Here is which states require it, what the appeal has to include, and why skipping it is a separate violation from the denial itself.
Read articleDSAR Identity Verification: How to Verify a Subject Access Request
Verification decides whether a data subject access request ends as a compliance win or a data breach. The CCPA standard is two matching data points for categories and three plus a signed declaration for specific pieces. Here is what each law requires, how to handle authorized agents, and what to do when you cannot verify someone.
Read articleMissed DSAR Deadline: What Happens and How to Recover
Miss a DSAR deadline and the late response becomes the violation, while the obligation to answer continues. What you are exposed to and how to recover.
Read articleCCPA Penalties for Non Compliance: 2026 Fines and Amounts
CCPA penalties are $2,663 per violation and $7,988 per intentional violation in 2026, not the $2,500 and $7,500 in the statute, because the CPPA adjusts them for inflation. Here are the current amounts, the 2026 California enforcement actions, the maximum civil penalty in all twenty states, and what actually turns a mishandled data subject request into a countable violation.
Read articleState Privacy Law Changes in July 2026: Connecticut, Utah, New Jersey, and Arkansas
Four state privacy obligations changed inside two weeks. Connecticut cut its threshold from 100,000 consumers to 35,000, Utah switched on a right to correct, New Jersey lost its cure period on July 15, and Arkansas turned on a children and teens law. Here is what each change does and what it means for your request workflow.
Read articleDSAR vs Deletion Request: What Is the Difference and How to Handle Each
A deletion request is one type of data subject request, not a separate thing. Access asks you to show a person their data; deletion asks you to erase it. They share an intake and a 45-day clock but pull in opposite operational directions, and the exemptions differ. Here is how the two compare and how to run one workflow that handles both.
Read articleRight to Correct Personal Data: How to Handle a Correction Request Under US State Laws
Nineteen of the twenty comprehensive US state privacy laws now give consumers a right to correct inaccurate personal data, and Utah joined on July 1, 2026. Correction is operationally harder than access, because one wrong value can sit in a dozen systems. Here is the workflow that actually closes the loop.
Read articleState Privacy Law Cure Periods in 2026: Which States Still Give You One
Most US state privacy laws no longer give you a grace window to fix a violation. California, Colorado, Connecticut, Delaware, Oregon, Montana, Minnesota, and New Hampshire have all lost or repealed their cure periods. Here is where every state stands and what it changes about missing a 45-day deadline.
Read articleHow Much Does It Cost to Fulfill a DSAR? The 2026 Per-Request Breakdown
Gartner puts the cost of manually fulfilling one data subject access request at roughly $1,400 to $1,524, almost all of it staff time. Here is where the hours actually go, what volume does to the number, and which five changes cut the cost per request.
Read articleHow Much Does DSAR Software Cost? 2026 Pricing Guide
DSAR software ranges from about $49 a month for self-serve fulfillment to $10,000 to $90,000 a year for enterprise governance suites. Here is what drives the price, what you actually pay for at each tier, and how to tell which tier a company your size needs.
Read articleWhich State Privacy Laws Apply to My Business? The 2026 Threshold Guide
Whether a state privacy law covers you rarely turns on revenue. It turns on how many residents you process, whether you sell data, and in a few states whether you touch sensitive data at all. Here is the 2026 threshold for every major state and how to tell where you land.
Read articleConnecticut Data Privacy Act 2026 Amendments: Lower Thresholds and What Changed
On July 1, 2026 the CTDPA threshold dropped from 100,000 to 35,000 Connecticut consumers, and selling data or processing sensitive data now brings you in scope regardless of volume. Here is exactly what changed, who is newly covered, and what to do first.
Read articleUniversal Opt-Out Mechanisms and Global Privacy Control: Which States Require Them in 2026
A universal opt-out mechanism like Global Privacy Control is a browser signal that opts a person out of data sales and targeted ads. Twelve states now require you to honor it. Here is the list, what honoring it means, and how it connects to data subject requests.
Read articleData Subject Request Deadlines by State: How Long You Have to Respond in 2026
Every US state privacy law gives you 45 days to answer a data subject request, extendable once by 45 more. Here is the deadline by state, when the clock starts, what extends it, and how the GDPR month differs.
Read articleWho Does the CCPA Apply To? The 2026 Thresholds and Exemptions
The CCPA applies to for-profit businesses that do business in California and cross one of three thresholds. Here are the 2026 figures, whether it reaches out-of-state and employee data, and the exemptions.
Read articleCCPA Compliance Checklist: The 9 Requirements for 2026
A practical CCPA compliance checklist: confirm you are covered, map your data, post the right notices, honor the six rights on the 45-day clock, and meet the new 2026 risk-assessment and audit duties.
Read articleEmployee Subject Access Request: How to Handle a DSAR From an Employee
An employee subject access request is the hardest DSAR to answer: scattered data, other people in the file, and exemptions that are easy to get wrong. Here is how to run one, the deadline, and what you can withhold.
Read articleRight to Restrict Processing and Right to Object: GDPR Articles 18 and 21
The right to restrict processing (Article 18) and the right to object (Article 21) are the two GDPR rights teams handle worst. Here are the grounds for each, the absolute marketing opt-out, and how they connect.
Read articleStates With Data Privacy Laws: All 20 State Privacy Laws in 2026
Twenty US states have a comprehensive consumer privacy law in effect in 2026. Here is the full state by state list, the 45-day response clock they nearly all share, and where they actually differ.
Read articleRight to Rectification: The GDPR Right to Correct Inaccurate Data
The right to rectification lets a person require you to correct inaccurate data and complete what is incomplete. Here is the one-month clock, the fact-versus-opinion line, and the Article 19 duty teams skip.
Read articleGDPR Right to Erasure Response Template: Copy, Adapt, Send
A GDPR right to erasure response template for the three replies you actually send: erasure confirmed, erasure partly refused, and erasure refused. With the Article 17 wording to keep.
Read articleRight to Erasure: The GDPR Right to Be Forgotten, Explained
The right to erasure, also called the GDPR right to be forgotten, lets a person ask you to delete their data. Here are the six grounds, the five exceptions, and the one-month clock.
Read articleCCPA Right to Delete: Responding to a Deletion Request in 45 Days
The CCPA right to delete gives a California consumer the right to have their personal information erased. Here is the 45-day clock, the nine exceptions, and what you owe your service providers.
Read articleWhat Is a DSAR? Data Subject Access Requests Explained
What is a DSAR? A data subject access request is a person's legal right to ask an organization for a copy of the personal data it holds about them. Here is how it works.
Read articleHow to Respond to a Data Subject Access Request, Step by Step
How to respond to a data subject access request step by step: verify identity, log the deadline, discover the data, compile a manifest, redact third-party data, and reply.
Read articleDSAR Response Deadline: GDPR One Month, CCPA 45 Days
The DSAR response deadline is one month under the GDPR and 45 days under the CCPA. Here is when the clock starts, when you can extend it, and how to stay on time.
Read articleDSAR Template: DSAR Response Template and Intake Form
A DSAR template set: the subject access request form you publish for intake, plus the acknowledgment, cover letter, and response templates you send back. With the wording to keep and adapt.
Read articleThe DSAR Process: From Intake to Response, Explained
The DSAR process explained end to end: intake, identity verification, deadline tracking, data discovery, manifest review, redaction, approval, and delivery of the response.
Read articleThe DSAR Checklist: Every Step to Fulfill a Request on Time
A DSAR checklist covering every step to fulfill a request on time: log intake, verify identity, track the deadline, discover data, redact, get sign-off, and deliver.
Read articleHow to Redact a DSAR Response: Third-Party and Exempt Data
How to redact a DSAR response: identify third-party personal data and exempt material, apply redactions consistently, and keep a human in control of what gets disclosed.
Read articleGDPR vs CCPA Data Requests: Deadlines, Scope, and Differences
GDPR vs CCPA data requests compared: response deadlines, who can ask, what you must disclose, fees, and the practical differences between the two access rights.
Read articleDSAR Exemptions: When You Can Withhold or Refuse Data
DSAR exemptions explained: when you can withhold data, redact third-party information, or refuse a manifestly unfounded or excessive request, and how to document the reason.
Read articleDSAR Software: How to Choose a Tool That Fits Your Team
DSAR software compared: what to look for in a tool for data discovery, deadline tracking, redaction, and human review, and how to choose one that fits your team.
Read articlePut it into practice
Run a request in the demo and watch Obtainer find the data, draft the response, and engage the redaction gate in minutes. Self-serve pricing, cancel anytime. Helps you comply; not legal advice.