Obtainer

Blog

Data subject access requests, explained

Guides and practical playbooks for handling DSARs: what a data subject access request is, how to respond step by step, the GDPR and CCPA deadlines, templates, redacting third-party data, exemptions, and choosing DSAR software. Helps you comply; not legal advice.

State Laws 8 min read

HIPAA Exemption From State Privacy Laws: Entity-Level vs Data-Level by State

Nine states exempt HIPAA covered entities outright. Six exempt only the protected health information, which leaves the rest of a health system's data, including its own employees in California, fully in scope with access, correction, and deletion rights. Here is the split by state and what it changes about how you handle requests.

Read article
State Laws 8 min read

Data Broker Registration Requirements: California, Texas, Oregon, and Vermont

Four states require data brokers to register, and California now charges $6,000 a year for the privilege of a recurring deletion duty that starts August 1, 2026. Here is who counts as a data broker in each state, what registration costs, when it is due, and what filing actually commits you to.

Read article
State Laws 9 min read

Consumer Health Data Privacy Laws by State: Washington, Nevada, Connecticut

Three states now regulate health data that HIPAA never touches, and Washington lets consumers sue you over it directly. New York came close and was vetoed in December 2025. Here is which health data laws are actually in force in 2026, who they cover, what they require, and why a wellness app can be more exposed than a hospital.

Read article
Process 8 min read

Data Subject Request Appeal: How to Handle a Denied Privacy Request

Almost every US state privacy law makes you offer a way to appeal a denied data subject request, and Utah is the only one that does not. Most states give you 60 days to answer an appeal in writing. Here is which states require it, what the appeal has to include, and why skipping it is a separate violation from the denial itself.

Read article
Process 9 min read

DSAR Identity Verification: How to Verify a Subject Access Request

Verification decides whether a data subject access request ends as a compliance win or a data breach. The CCPA standard is two matching data points for categories and three plus a signed declaration for specific pieces. Here is what each law requires, how to handle authorized agents, and what to do when you cannot verify someone.

Read article
Deadlines 9 min read

Missed DSAR Deadline: What Happens and How to Recover

Miss a DSAR deadline and the late response becomes the violation, while the obligation to answer continues. What you are exposed to and how to recover.

Read article
State Laws 10 min read

CCPA Penalties for Non Compliance: 2026 Fines and Amounts

CCPA penalties are $2,663 per violation and $7,988 per intentional violation in 2026, not the $2,500 and $7,500 in the statute, because the CPPA adjusts them for inflation. Here are the current amounts, the 2026 California enforcement actions, the maximum civil penalty in all twenty states, and what actually turns a mishandled data subject request into a countable violation.

Read article
State Laws 10 min read

State Privacy Law Changes in July 2026: Connecticut, Utah, New Jersey, and Arkansas

Four state privacy obligations changed inside two weeks. Connecticut cut its threshold from 100,000 consumers to 35,000, Utah switched on a right to correct, New Jersey lost its cure period on July 15, and Arkansas turned on a children and teens law. Here is what each change does and what it means for your request workflow.

Read article
Data Subject Rights 9 min read

DSAR vs Deletion Request: What Is the Difference and How to Handle Each

A deletion request is one type of data subject request, not a separate thing. Access asks you to show a person their data; deletion asks you to erase it. They share an intake and a 45-day clock but pull in opposite operational directions, and the exemptions differ. Here is how the two compare and how to run one workflow that handles both.

Read article
Data Subject Rights 9 min read

Right to Correct Personal Data: How to Handle a Correction Request Under US State Laws

Nineteen of the twenty comprehensive US state privacy laws now give consumers a right to correct inaccurate personal data, and Utah joined on July 1, 2026. Correction is operationally harder than access, because one wrong value can sit in a dozen systems. Here is the workflow that actually closes the loop.

Read article
State Laws 10 min read

State Privacy Law Cure Periods in 2026: Which States Still Give You One

Most US state privacy laws no longer give you a grace window to fix a violation. California, Colorado, Connecticut, Delaware, Oregon, Montana, Minnesota, and New Hampshire have all lost or repealed their cure periods. Here is where every state stands and what it changes about missing a 45-day deadline.

Read article
Buying Guide 9 min read

How Much Does It Cost to Fulfill a DSAR? The 2026 Per-Request Breakdown

Gartner puts the cost of manually fulfilling one data subject access request at roughly $1,400 to $1,524, almost all of it staff time. Here is where the hours actually go, what volume does to the number, and which five changes cut the cost per request.

Read article
Buying Guide 9 min read

How Much Does DSAR Software Cost? 2026 Pricing Guide

DSAR software ranges from about $49 a month for self-serve fulfillment to $10,000 to $90,000 a year for enterprise governance suites. Here is what drives the price, what you actually pay for at each tier, and how to tell which tier a company your size needs.

Read article
Fundamentals 10 min read

Which State Privacy Laws Apply to My Business? The 2026 Threshold Guide

Whether a state privacy law covers you rarely turns on revenue. It turns on how many residents you process, whether you sell data, and in a few states whether you touch sensitive data at all. Here is the 2026 threshold for every major state and how to tell where you land.

Read article
State Laws 9 min read

Connecticut Data Privacy Act 2026 Amendments: Lower Thresholds and What Changed

On July 1, 2026 the CTDPA threshold dropped from 100,000 to 35,000 Connecticut consumers, and selling data or processing sensitive data now brings you in scope regardless of volume. Here is exactly what changed, who is newly covered, and what to do first.

Read article
Fundamentals 10 min read

Universal Opt-Out Mechanisms and Global Privacy Control: Which States Require Them in 2026

A universal opt-out mechanism like Global Privacy Control is a browser signal that opts a person out of data sales and targeted ads. Twelve states now require you to honor it. Here is the list, what honoring it means, and how it connects to data subject requests.

Read article
Fundamentals 9 min read

Data Subject Request Deadlines by State: How Long You Have to Respond in 2026

Every US state privacy law gives you 45 days to answer a data subject request, extendable once by 45 more. Here is the deadline by state, when the clock starts, what extends it, and how the GDPR month differs.

Read article
Fundamentals 10 min read

Who Does the CCPA Apply To? The 2026 Thresholds and Exemptions

The CCPA applies to for-profit businesses that do business in California and cross one of three thresholds. Here are the 2026 figures, whether it reaches out-of-state and employee data, and the exemptions.

Read article
How-to 11 min read

CCPA Compliance Checklist: The 9 Requirements for 2026

A practical CCPA compliance checklist: confirm you are covered, map your data, post the right notices, honor the six rights on the 45-day clock, and meet the new 2026 risk-assessment and audit duties.

Read article
How-to 11 min read

Employee Subject Access Request: How to Handle a DSAR From an Employee

An employee subject access request is the hardest DSAR to answer: scattered data, other people in the file, and exemptions that are easy to get wrong. Here is how to run one, the deadline, and what you can withhold.

Read article
Fundamentals 10 min read

Right to Restrict Processing and Right to Object: GDPR Articles 18 and 21

The right to restrict processing (Article 18) and the right to object (Article 21) are the two GDPR rights teams handle worst. Here are the grounds for each, the absolute marketing opt-out, and how they connect.

Read article
Fundamentals 13 min read

States With Data Privacy Laws: All 20 State Privacy Laws in 2026

Twenty US states have a comprehensive consumer privacy law in effect in 2026. Here is the full state by state list, the 45-day response clock they nearly all share, and where they actually differ.

Read article
Fundamentals 10 min read

Right to Rectification: The GDPR Right to Correct Inaccurate Data

The right to rectification lets a person require you to correct inaccurate data and complete what is incomplete. Here is the one-month clock, the fact-versus-opinion line, and the Article 19 duty teams skip.

Read article
Templates 11 min read

GDPR Right to Erasure Response Template: Copy, Adapt, Send

A GDPR right to erasure response template for the three replies you actually send: erasure confirmed, erasure partly refused, and erasure refused. With the Article 17 wording to keep.

Read article
Fundamentals 12 min read

Right to Erasure: The GDPR Right to Be Forgotten, Explained

The right to erasure, also called the GDPR right to be forgotten, lets a person ask you to delete their data. Here are the six grounds, the five exceptions, and the one-month clock.

Read article
How-to 12 min read

CCPA Right to Delete: Responding to a Deletion Request in 45 Days

The CCPA right to delete gives a California consumer the right to have their personal information erased. Here is the 45-day clock, the nine exceptions, and what you owe your service providers.

Read article
Fundamentals 9 min read

What Is a DSAR? Data Subject Access Requests Explained

What is a DSAR? A data subject access request is a person's legal right to ask an organization for a copy of the personal data it holds about them. Here is how it works.

Read article
How-to 11 min read

How to Respond to a Data Subject Access Request, Step by Step

How to respond to a data subject access request step by step: verify identity, log the deadline, discover the data, compile a manifest, redact third-party data, and reply.

Read article
Deadlines 9 min read

DSAR Response Deadline: GDPR One Month, CCPA 45 Days

The DSAR response deadline is one month under the GDPR and 45 days under the CCPA. Here is when the clock starts, when you can extend it, and how to stay on time.

Read article
Templates 12 min read

DSAR Template: DSAR Response Template and Intake Form

A DSAR template set: the subject access request form you publish for intake, plus the acknowledgment, cover letter, and response templates you send back. With the wording to keep and adapt.

Read article
Guides 11 min read

The DSAR Process: From Intake to Response, Explained

The DSAR process explained end to end: intake, identity verification, deadline tracking, data discovery, manifest review, redaction, approval, and delivery of the response.

Read article
Checklists 9 min read

The DSAR Checklist: Every Step to Fulfill a Request on Time

A DSAR checklist covering every step to fulfill a request on time: log intake, verify identity, track the deadline, discover data, redact, get sign-off, and deliver.

Read article
How-to 10 min read

How to Redact a DSAR Response: Third-Party and Exempt Data

How to redact a DSAR response: identify third-party personal data and exempt material, apply redactions consistently, and keep a human in control of what gets disclosed.

Read article
Comparisons 10 min read

GDPR vs CCPA Data Requests: Deadlines, Scope, and Differences

GDPR vs CCPA data requests compared: response deadlines, who can ask, what you must disclose, fees, and the practical differences between the two access rights.

Read article
Guides 10 min read

DSAR Exemptions: When You Can Withhold or Refuse Data

DSAR exemptions explained: when you can withhold data, redact third-party information, or refuse a manifestly unfounded or excessive request, and how to document the reason.

Read article
Guides 10 min read

DSAR Software: How to Choose a Tool That Fits Your Team

DSAR software compared: what to look for in a tool for data discovery, deadline tracking, redaction, and human review, and how to choose one that fits your team.

Read article

Put it into practice

Run a request in the demo and watch Obtainer find the data, draft the response, and engage the redaction gate in minutes. Self-serve pricing, cancel anytime. Helps you comply; not legal advice.