Obtainer

Blog

Data subject access requests, explained

Guides and practical playbooks for handling DSARs: what a data subject access request is, how to respond step by step, the GDPR and CCPA deadlines, templates, redacting third-party data, exemptions, and choosing DSAR software. Helps you comply; not legal advice.

Comparisons 9 min read · September 2026

OneTrust vs Transcend: Pricing, DSAR Automation and Which One to Buy

Transcend is the more capable DSAR engine and the more expensive contract, with a reported average near $76,075 a year against OneTrust's reported $11,970 median. Neither publishes a price. Here is what drives the gap, why the two numbers are not measuring the same thing, and which one a US team should actually buy.

Read article
Comparisons 9 min read · September 2026

OneTrust vs Ketch: Pricing, DSAR Automation and Which One to Buy

Ketch publishes a free tier, $150 Starter and $499 Plus. OneTrust publishes nothing and carries a reported $10,000 minimum. Yet the reported median Ketch contract is about $35,000 a year against OneTrust's $11,970, a 2.9x inversion of how both are positioned. Here is what drives each number, why Ketch's rests on only seven buyers, and where subject rights actually sit on both price lists.

Read article
Comparisons 8 min read · September 2026

Ketch Pricing 2026: Plans, Cost Per Year, and What DSAR Automation Actually Costs

Ketch publishes a free tier, $150 Starter and $499 Plus, then quotes Pro. The published ladder tops out near $5,988 a year while the reported median contract sits close to $35,000, roughly six times higher. Rights workflows are an add-on at Plus and only bundled at Pro, and the median rests on just seven tracked buyers.

Read article
Comparisons 8 min read · September 2026

Osano Pricing 2026: Plans, Cost Per Year, and What DSAR Actually Costs

Osano publishes $0 and $199 a month, then quotes everything else. Reported buyer data puts the median contract near $8,459 a year, the cheapest of any established privacy platform. The catch is that the published prices buy consent management, and DSAR handling starts at the first custom-quoted tier.

Read article
Comparisons 9 min read · August 2026

OneTrust vs Securiti: Pricing, DSAR Automation, and Which Privacy Platform to Buy

Securiti's reported median contract runs about four times OneTrust's, roughly $49,841 a year against $11,970, and at the top of the market the comparison reverses. Here is why the medians diverge, how much confidence each number actually deserves, and which platform fits which kind of privacy team.

Read article
Comparisons 9 min read · August 2026

OneTrust vs BigID: Pricing, DSAR Features, and Which to Buy

BigID's reported median contract runs about eight and a half times OneTrust's, roughly $101,950 a year against $11,970, and the reason is packaging rather than value. Here is why the medians diverge, what each platform does on subject requests, and the one capability BigID has that OneTrust cannot match.

Read article
Comparisons 9 min read · August 2026

OneTrust vs TrustArc: Pricing, DSAR Features and Which Privacy Software to Buy

TrustArc's reported median contract runs higher than OneTrust's, about $15,120 a year against $11,970, which is the opposite of what both companies' positioning predicts. Here is why the medians invert, what each platform lists for subject rights, and the one capability TrustArc sells that OneTrust has no answer to.

Read article
Comparisons 9 min read · August 2026

OneTrust vs Osano: Pricing, DSAR Features and Which Privacy Software a US Team Should Buy

Osano is the cheaper and simpler of the two, at a reported median of about $8,459 a year against OneTrust's $11,970, and it is the only one that publishes a price. OneTrust is the broader platform. Neither publishes a price for the capability most buyers are shopping for. Here is the side-by-side on cost, subject rights, consent, and where each genuinely wins.

Read article
Buying guides 9 min read · August 2026

GDPR Compliance Consultants: What Consultants and Services Cost, and When Software Is Enough

What GDPR compliance consultants and services actually cost, how that compares to a privacy hire or software, where a consultant is genuinely the right call, and the part of the job no report can do for you.

Read article
Comparisons 8 min read · August 2026

OneTrust Pricing: What OneTrust Costs in 2026 and What Buyers Actually Pay

OneTrust does not publish list pricing. Reported buyer data puts the median contract near $11,970 a year across 307 tracked purchases, with a range from $1,620 to $48,230 and a platform minimum around $10,000. Here is what drives a quote, the implementation and renewal costs that sit outside the subscription, and how six privacy platforms compare on reported spend.

Read article
Guides 9 min read · August 2026

What Is Data Governance? The Framework, Principles, and the Question a Data Catalog Cannot Answer

Data governance is the exercise of authority and control over how an organization manages its data. It indexes data by asset: systems, tables, owners, retention. A data subject request asks something a catalog is not built for, which is where this person appears across everything you run. Here is the DAMA definition, the eleven knowledge areas, how to implement a program, and the gap that shows up on a 45-day clock.

Read article
Guides 9 min read · August 2026

What Is PII? Personally Identifiable Information, Examples, and Why It Is Not the Same as Personal Data

PII is a US security term, not a privacy law term, and it is narrower than what the CCPA and the GDPR actually make you find. Households, internally generated inferences and online identifiers all sit outside a standard PII inventory and inside the legal definition. Here is the NIST definition, real examples, and the three gaps that cause a data subject request to be answered incompletely.

Read article
Guides 9 min read · August 2026

Litigation Hold vs Deletion Request: When a Legal Hold Beats the Right to Erasure

A litigation hold beats a deletion request, but only for the records inside its scope and only for as long as the matter lasts. Everything else about that person still has to be deleted, on the original clock, with the exception named in writing. Here is which provision actually carries a US legal hold under the GDPR (not the one you think), what the CCPA and the state laws say, and the step almost nobody builds.

Read article
Compliance 9 min read · August 2026

Data Retention Policy Requirements: What Retention Policies and a Records Retention Schedule Must Disclose

No US state privacy law gives you a retention number. Several now require you to publish yours. California has to state a length of time for each category of personal information or the criteria used to determine it, Minnesota has to describe its retention policies in the privacy notice, and Maryland caps sensitive data at strictly necessary regardless of consent. Here is what each regime requires, the federal minimums that do set numbers, and the half of retention a records retention schedule cannot cover.

Read article
State Laws 9 min read · August 2026

Data Breach Notification Laws by State: Deadlines, AG Notice, and the New 30-Day Floor

All fifty states, DC and the territories have a breach notification law, and there is still no general federal one. Twenty states set a number between 30 and 60 days. Thirty-one say "without unreasonable delay". The strictest clock governs a multi-state breach, and as of January 1, 2026 that floor is 30 days because California SB 446 replaced its open-ended standard with a hard deadline. Here is the landscape, why two surveys give you two different lists, and what the notification list actually costs you to build.

Read article
State Laws 9 min read · August 2026

FCRA Exemption From State Privacy Laws: Why No State Exempts a Consumer Reporting Agency

Every comprehensive US state privacy law carves out the Fair Credit Reporting Act, and not one of them carves out you. Fifteen states lift a GLBA financial institution out of scope as an organization. No state does that for a consumer reporting agency. The FCRA carve-out is always an activity exemption, always qualified by "to the extent", and it ends where the exempt activity ends. Here is the split, state by state, and what stays in scope at a background screening company.

Read article
Vendor Management 8 min read · August 2026

Subprocessor Meaning: Processor vs Subprocessor and Subprocessor List Rules

A subprocessor is the vendor your vendor hired. You never signed with them, they hold data about your customers, and when a request lands you are still accountable for what they have. GDPR Article 28(2) gives you an objection right, Colorado is the only US state that copies it, and California does not use the word at all. Here is the chain, clause by clause.

Read article
State Laws 9 min read · August 2026

Data Processing Agreement Requirements by State: What Your Vendor Contracts Have to Say

Every comprehensive US state privacy law requires a written contract before a vendor processes personal data for you, and most of them copied Virginia almost word for word. Three states break the pattern: Colorado asks for an annual independent audit at the processor's expense, Utah and Iowa drop the assessment clause entirely, and California requires something structurally different that a European-style DPA usually fails to provide. Here is the split, clause by clause.

Read article
State Laws 9 min read · August 2026

Student Data Privacy Laws by State: SOPIPA, the Vendor Rules, and What Belongs in Every Contract

FERPA binds schools. The state student privacy laws bind you, the vendor, directly. California's SOPIPA started it in 2016 and more than twenty states followed, but three of them do the real work: SOPIPA, Illinois SOPPA, and New York Education Law 2-d, which between them require signed data privacy agreements, a seven-day breach notice, public vendor listings, and a parent correction right that FERPA never gave. Here is the split and what each one asks of an operator.

Read article
State Laws 9 min read · August 2026

FERPA Exemption From State Privacy Laws: The Seven States That Do Not Give Schools a Clean Pass

Most state privacy laws exempt nonprofits and carve out FERPA education records, which is why schools have mostly ignored them. Seven states break that pattern. Colorado exempts only state institutions and only for noncommercial use, Delaware writes universities out of its government exemption, New Jersey exempts neither nonprofits nor higher education, and Oregon's nonprofit grace period ended July 1, 2025. Here is the split and what stays in scope.

Read article
State Laws 8 min read · July 2026

GLBA Exemption From State Privacy Laws: The Five States That No Longer Exempt Financial Institutions

Fifteen states exempt GLBA-regulated financial institutions at the entity level. Five do not, and two of those changed in the last year. Montana removed its broad exemption on October 1, 2025 and Connecticut on July 1, 2026, both keeping a carve-out for chartered banks and taking it away from lenders, servicers, and fintechs. Here is the split, the thresholds, and what GLBA does not give you.

Read article
State Laws 8 min read · July 2026

HIPAA Exemption From State Privacy Laws: Entity-Level vs Data-Level by State

Nine states exempt HIPAA covered entities outright. Six exempt only the protected health information, which leaves the rest of a health system's data, including its own employees in California, fully in scope with access, correction, and deletion rights. Here is the split by state and what it changes about how you handle requests.

Read article
State Laws 8 min read · July 2026

Data Broker Registration Requirements: California, Texas, Oregon, and Vermont

Four states require data brokers to register, and California now charges $6,000 a year for the privilege of a recurring deletion duty that starts August 1, 2026. Here is who counts as a data broker in each state, what registration costs, when it is due, and what filing actually commits you to.

Read article
State Laws 9 min read · July 2026

Consumer Health Data Privacy Laws by State: Washington, Nevada, Connecticut

Three states now regulate health data that HIPAA never touches, and Washington lets consumers sue you over it directly. New York came close and was vetoed in December 2025. Here is which health data laws are actually in force in 2026, who they cover, what they require, and why a wellness app can be more exposed than a hospital.

Read article
Process 8 min read · July 2026

Data Subject Request Appeal: How to Handle a Denied Privacy Request

Almost every US state privacy law makes you offer a way to appeal a denied data subject request, and Utah is the only one that does not. Most states give you 60 days to answer an appeal in writing. Here is which states require it, what the appeal has to include, and why skipping it is a separate violation from the denial itself.

Read article
Process 9 min read · July 2026

DSAR Identity Verification: How to Verify a Subject Access Request

Verification decides whether a data subject access request ends as a compliance win or a data breach. The CCPA standard is two matching data points for categories and three plus a signed declaration for specific pieces. Here is what each law requires, how to handle authorized agents, and what to do when you cannot verify someone.

Read article
Deadlines 9 min read · July 2026

Missed DSAR Deadline: What Happens and How to Recover

Miss a DSAR deadline and the late response becomes the violation, while the obligation to answer continues. What you are exposed to and how to recover.

Read article
State Laws 10 min read · July 2026

CCPA Penalties for Non Compliance: 2026 Fines and Amounts

CCPA penalties are $2,663 per violation and $7,988 per intentional violation in 2026, not the $2,500 and $7,500 in the statute, because the CPPA adjusts them for inflation. Here are the current amounts, the 2026 California enforcement actions, the maximum civil penalty in all twenty states, and what actually turns a mishandled data subject request into a countable violation.

Read article
State Laws 10 min read · July 2026

State Privacy Law Changes in July 2026: Connecticut, Utah, New Jersey, and Arkansas

Four state privacy obligations changed inside two weeks. Connecticut cut its threshold from 100,000 consumers to 35,000, Utah switched on a right to correct, New Jersey lost its cure period on July 15, and Arkansas turned on a children and teens law. Here is what each change does and what it means for your request workflow.

Read article
Data Subject Rights 9 min read · July 2026

DSAR vs Deletion Request: What Is the Difference and How to Handle Each

A deletion request is one type of data subject request, not a separate thing. Access asks you to show a person their data; deletion asks you to erase it. They share an intake and a 45-day clock but pull in opposite operational directions, and the exemptions differ. Here is how the two compare and how to run one workflow that handles both.

Read article
Data Subject Rights 9 min read · July 2026

Right to Correct Personal Data: How to Handle a Correction Request Under US State Laws

Nineteen of the twenty comprehensive US state privacy laws now give consumers a right to correct inaccurate personal data, and Utah joined on July 1, 2026. Correction is operationally harder than access, because one wrong value can sit in a dozen systems. Here is the workflow that actually closes the loop.

Read article
State Laws 10 min read · July 2026

State Privacy Law Cure Periods in 2026: Which States Still Give You One

Most US state privacy laws no longer give you a grace window to fix a violation. California, Colorado, Connecticut, Delaware, Oregon, Montana, Minnesota, and New Hampshire have all lost or repealed their cure periods. Here is where every state stands and what it changes about missing a 45-day deadline.

Read article
Buying Guide 9 min read · July 2026

How Much Does It Cost to Fulfill a DSAR? The 2026 Per-Request Breakdown

Gartner puts the cost of manually fulfilling one data subject access request at roughly $1,400 to $1,524, almost all of it staff time. Here is where the hours actually go, what volume does to the number, and which five changes cut the cost per request.

Read article
Buying Guide 9 min read · July 2026

How Much Does DSAR Software Cost? 2026 Pricing Guide

DSAR software ranges from roughly $600 a year for self-serve fulfillment to reported medians of $8,459 to $76,075 a year for privacy platforms. Here is what drives the price, what you actually pay for at each tier, and how to tell which tier a company your size needs.

Read article
Fundamentals 10 min read · July 2026

Which State Privacy Laws Apply to My Business? The 2026 Threshold Guide

Whether a state privacy law covers you rarely turns on revenue. It turns on how many residents you process, whether you sell data, and in a few states whether you touch sensitive data at all. Here is the 2026 threshold for every major state and how to tell where you land.

Read article
State Laws 9 min read · July 2026

Connecticut Data Privacy Act 2026 Amendments: Lower Thresholds and What Changed

On July 1, 2026 the CTDPA threshold dropped from 100,000 to 35,000 Connecticut consumers, and selling data or processing sensitive data now brings you in scope regardless of volume. Here is exactly what changed, who is newly covered, and what to do first.

Read article
Fundamentals 10 min read · July 2026

Universal Opt-Out Mechanisms and Global Privacy Control: Which States Require Them in 2026

A universal opt-out mechanism like Global Privacy Control is a browser signal that opts a person out of data sales and targeted ads. Twelve states now require you to honor it. Here is the list, what honoring it means, and how it connects to data subject requests.

Read article
Fundamentals 9 min read · July 2026

Data Subject Request Deadlines by State: How Long You Have to Respond in 2026

Every US state privacy law gives you 45 days to answer a data subject request, extendable once by 45 more. Here is the deadline by state, when the clock starts, what extends it, and how the GDPR month differs.

Read article
Fundamentals 10 min read · July 2026

Who Does the CCPA Apply To? The 2026 Thresholds and Exemptions

The CCPA applies to for-profit businesses that do business in California and cross one of three thresholds. Here are the 2026 figures, whether it reaches out-of-state and employee data, and the exemptions.

Read article
How-to 11 min read · July 2026

CCPA Compliance Checklist: The 9 Requirements for 2026

A practical CCPA compliance checklist: confirm you are covered, map your data, post the right notices, honor the six rights on the 45-day clock, and meet the new 2026 risk-assessment and audit duties.

Read article
How-to 11 min read · July 2026

Employee Subject Access Request: How to Handle a DSAR From an Employee

An employee subject access request is the hardest DSAR to answer: scattered data, other people in the file, and exemptions that are easy to get wrong. Here is how to run one, the deadline, and what you can withhold.

Read article
Fundamentals 10 min read · July 2026

Right to Restrict Processing and Right to Object: GDPR Articles 18 and 21

The right to restrict processing (Article 18) and the right to object (Article 21) are the two GDPR rights teams handle worst. Here are the grounds for each, the absolute marketing opt-out, and how they connect.

Read article
Fundamentals 13 min read · July 2026

States With Data Privacy Laws: All 20 State Privacy Laws in 2026

Twenty US states have a comprehensive consumer privacy law in effect in 2026. Here is the full state by state list, the 45-day response clock they nearly all share, and where they actually differ.

Read article
Fundamentals 10 min read · July 2026

Right to Rectification: The GDPR Right to Correct Inaccurate Data

The right to rectification lets a person require you to correct inaccurate data and complete what is incomplete. Here is the one-month clock, the fact-versus-opinion line, and the Article 19 duty teams skip.

Read article
Templates 11 min read · July 2026

GDPR Right to Erasure Response Template: Copy, Adapt, Send

A GDPR right to erasure response template for the three replies you actually send: erasure confirmed, erasure partly refused, and erasure refused. With the Article 17 wording to keep.

Read article
Fundamentals 12 min read · August 2026

Right to Be Forgotten: The GDPR Right to Erasure Under Article 17, Explained

The right to be forgotten, written into the GDPR as the right to erasure, lets a person ask you to delete the data you hold about them. Here are the six grounds, the five exceptions, and the one-month clock.

Read article
How-to 12 min read · July 2026

CCPA Right to Delete: Responding to a Deletion Request in 45 Days

The CCPA right to delete gives a California consumer the right to have their personal information erased. Here is the 45-day clock, the eight exceptions (not the nine most guides still list), and what you owe your service providers.

Read article
Fundamentals 9 min read · July 2026

What Is a DSAR? Data Subject Access Requests Explained

What is a DSAR? A data subject access request is a person's legal right to ask an organization for a copy of the personal data it holds about them. Here is how it works.

Read article
How-to 11 min read · July 2026

How to Respond to a Data Subject Access Request, Step by Step

How to respond to a data subject access request step by step: verify identity, log the deadline, discover the data, compile a manifest, redact third-party data, and reply.

Read article
Deadlines 9 min read · July 2026

DSAR Response Deadline: GDPR One Month, CCPA 45 Days

The DSAR response deadline is one month under the GDPR and 45 days under the CCPA. Here is when the clock starts, when you can extend it, and how to stay on time.

Read article
Templates 12 min read · July 2026

DSAR Template: DSAR Response Template and Intake Form

A DSAR template set: the subject access request form you publish for intake, plus the acknowledgment, cover letter, and response templates you send back. With the wording to keep and adapt.

Read article
Guides 11 min read · July 2026

The DSAR Process: From Intake to Response, Explained

The DSAR process explained end to end: intake, identity verification, deadline tracking, data discovery, manifest review, redaction, approval, and delivery of the response.

Read article
Checklists 9 min read · July 2026

The DSAR Checklist: Every Step to Fulfill a Request on Time

A DSAR checklist covering every step to fulfill a request on time: log intake, verify identity, track the deadline, discover data, redact, get sign-off, and deliver.

Read article
How-to 10 min read · July 2026

How to Redact a DSAR Response: Third-Party and Exempt Data

How to redact a DSAR response: identify third-party personal data and exempt material, apply redactions consistently, and keep a human in control of what gets disclosed.

Read article
Comparisons 10 min read · July 2026

GDPR vs CCPA Data Requests: Deadlines, Scope, and Differences

GDPR vs CCPA data requests compared: response deadlines, who can ask, what you must disclose, fees, and the practical differences between the two access rights.

Read article
Guides 10 min read · July 2026

DSAR Exemptions: When You Can Withhold or Refuse Data

DSAR exemptions explained: when you can withhold data, redact third-party information, or refuse a manifestly unfounded or excessive request, and how to document the reason.

Read article
Guides 10 min read · July 2026

DSAR Software: How to Choose a Tool That Fits Your Team

DSAR software compared: what to look for in a tool for data discovery, deadline tracking, redaction, and human review, and how to choose one that fits your team.

Read article

Put it into practice

Run a request in the demo and watch Obtainer find the data, draft the response, and engage the redaction gate in minutes. Self-serve pricing. Helps you comply; not legal advice.