How Much Does It Cost to Fulfill a DSAR? The 2026 Per-Request Breakdown
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Fulfilling a single data subject access request manually costs an organization roughly $1,400 to $1,500 in staff time, according to Gartner research that put the figure at about $1,400 and later at $1,524 per request. At 200 requests a year, that is around $300,000 in labor spent finding, reviewing, and packaging data you already own. The cost is almost entirely people: engineers searching systems, a privacy or legal reviewer reading the output, and someone chasing the deadline. It is also the cost that scales worst, because request volume grows with your customer base while the manual process stays linear.
Why does one request cost that much?
Because a DSAR is not a database query, it is a search problem across systems that were never designed to be searched by person. A typical mid-market company holds one customer's data in a production database, an analytics warehouse, a billing processor, a help desk, a marketing platform, a support inbox, and backups of all of the above. Nobody maintains a live index of which of those hold a given individual. So the work starts with an engineer writing ad hoc queries, then a second pass to catch systems the first pass missed, then a human reading everything to strip out other people's data before it goes out. The cost lands hardest on product companies, where the same user exists in a dozen services at once, which is the problem GDPR and CCPA compliance for SaaS companies is built around.
Here is where the money actually goes on a manual request. The hour estimates below are representative of a mid-market company with a moderately complex stack, not a fixed rule.
| Step | Who does it | Typical hours | What drives the cost |
|---|---|---|---|
| Intake and identity verification | Support or privacy ops | 0.5 to 1 | Back-and-forth email to confirm the requester is who they claim |
| Data discovery across systems | Engineering | 3 to 8 | Number of systems, absence of a data map, ad hoc queries |
| Collation into one package | Privacy ops | 1 to 3 | Different export formats from every source |
| Review and redaction | Privacy or legal | 2 to 5 | Third-party data, privileged material, free-text fields |
| Drafting and delivery | Privacy or legal | 1 to 2 | Legal wording, exemption explanations, secure delivery |
| Deadline tracking and follow-up | Privacy ops | 0.5 to 1 | Extensions, appeals, consumer chasing |
Add it up and a straightforward request runs 8 to 20 hours across three or four people. At blended loaded rates for engineering and legal time in the US, that lands right on the Gartner figure. A complex request, one involving an employee, a former employee, or years of support history, can run several times higher.
What is the most expensive part of a DSAR?
Discovery, by a wide margin. Finding where a person's data lives typically consumes half or more of the total hours, and it is the step most likely to be done badly under time pressure. Review and redaction is the second most expensive, because it is genuinely human work: someone has to decide whether a support ticket mentioning two customers can be released, whether a free-text note contains another person's information, and whether an exemption applies. Automating discovery removes the biggest cost. Automating the judgment calls is where you should not: a human review and approval gate before disclosure is the control that keeps a mistake from becoming a breach.
How many DSARs will we get?
Volume is the variable that decides whether this is an annoyance or a budget line. A few honest generalizations hold. Consumer-facing businesses receive far more requests than B2B ones. Volume spikes after a data breach notification, a privacy policy change, or press coverage naming your company. And it rises every time a new state law switches on, because each one adds a new population of residents who can ask.
The compounding factor most teams underestimate is deletion requests routed through third parties. Data removal services submit requests on behalf of consumers in bulk, and those are valid requests you still have to verify and process. A company receiving two requests a month in 2024 can be receiving twenty a month in 2026 without its customer base changing at all.
Manual cost versus tooling cost
The comparison people usually get wrong is buying software against doing nothing. The real comparison is buying software against the labor you are already spending. Set them side by side.
| Requests per year | Manual cost at ~$1,500 each | Self-serve tooling from $49/mo | Enterprise suite at ~$40k+/yr |
|---|---|---|---|
| 12 | ~$18,000 | ~$600 plus review time | Overbuilt |
| 60 | ~$90,000 | ~$600 to $3,000 plus review time | Overbuilt for most |
| 200 | ~$300,000 | Tooling plus a part-time owner | Defensible with a privacy team |
| 1,000+ | ~$1.5M | Needs scaled tooling | Usually the right tier |
The point of the table is not that software is free. It is that the manual line moves with volume and the tooling line mostly does not, which is why the crossover arrives sooner than teams expect. Even a company handling one request a month is spending more on labor than a self-serve subscription costs. If you are comparing vendors rather than comparing against your own labor, the DSAR software pricing breakdown covers what each tier actually includes.
Can you charge the consumer a fee for a DSAR?
Almost never for the first request. Under the GDPR and every US state privacy law, the first response in a given period must be free. You may charge a reasonable administrative fee, or decline, only when a request is manifestly unfounded, excessive, or repetitive, and you carry the burden of proving that. In practice, charging is a rare exception used for a consumer submitting the same request repeatedly within a short window. It is not a cost recovery strategy, and attempting to use it as one invites a complaint.
What actually reduces the cost per request?
Five changes move the number, roughly in order of impact.
- Automate discovery. This is the largest single line. Software that connects to your systems and surfaces where a person's data sits removes the engineering hunt entirely and turns the slowest step into minutes.
- Maintain a data map. Even a spreadsheet listing which systems hold personal data, who owns each one, and how to export from it will cut hours off every future request.
- Standardize intake and verification. A single form with a defined identity check ends the email back-and-forth and starts the clock cleanly. It also stops requests from getting lost in a shared inbox, which is the most common cause of a missed deadline.
- Template the response. Most of the legal wording is identical between requests. Drafting from a reviewed template rather than from scratch saves an hour or more of expensive time each time.
- Consolidate multi-state handling. Do not run twenty state workflows. Meet the strictest requirement once. The deadline is 45 days plus a 45-day extension in 18 of the 20 states, with Iowa longer and Florida shorter, so building to the tightest of them covers the rest.
What none of these should touch is the review gate. The efficiency gains belong in finding and assembling data. The decision about what leaves the building stays with a person, and the record of that decision is what you show a regulator if a request is ever challenged. The same principle applies to any system that surfaces answers buried across your internal systems: retrieval can be automated, disclosure should not be.
Frequently asked questions
How much does it cost to respond to a data subject access request?
Gartner research puts the cost of manually fulfilling one request at roughly $1,400 to $1,524, driven almost entirely by staff time across engineering, privacy, and legal. A straightforward request consumes 8 to 20 hours across several people; complex ones involving employee records or years of support history cost considerably more. Automating the discovery step removes the largest share of that cost.
How long does a DSAR take to complete?
Legally you have 45 days under US state privacy laws and one month under the GDPR, extendable once with notice. In practice, surveys have found most organizations take more than two weeks to respond and a substantial share miss the statutory deadline entirely. The elapsed time is usually not the work itself, it is the gap between the request arriving and someone starting on it.
Do small businesses have to pay for DSAR tooling?
No law requires software. The obligation is to respond accurately within the deadline, and a small company receiving one or two requests a year can do that with a documented manual process. The economics change quickly with volume: at even one request a month, manual labor costs more than a self-serve subscription. Buy tooling when the labor exceeds it, not because a vendor says the law requires it.
Does automation risk disclosing the wrong data?
It can, if the automation extends to the disclosure decision. That is why the sensible design separates the two: let software find and assemble the data, and require a person to review, redact, and approve before anything is released. Handling third-party data in a DSAR response is a judgment call about other people's rights, and it is not one to hand to an automated pipeline.
The takeaway
The cost of a DSAR is real, measurable, and mostly invisible because it hides inside salaries you are already paying. At roughly $1,500 per manual request, a modest volume turns into a six-figure line item without ever appearing in a budget. The way out is not to work faster on the same process. It is to remove the discovery hunt, standardize intake and drafting, and keep human judgment only where it belongs. Obtainer does that specific job: it intakes the request, finds where the person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the 45-day clock, with a human approving anything before it leaves. Self-serve from $49/mo. Obtainer helps you comply. It is not legal advice.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.