Subject Access Request
A Subject Access Request is a request an individual makes to an organization asking for a copy of the personal data that the organization holds about them. It gives people a way to see what information a company has collected on them and, in many cases, to exercise related rights over that data. The organization receiving the request is responsible for locating and providing the requested personal data.
A Subject Access Request (SAR), also called a Data Subject Access Request (DSAR), is a formal request submitted by an individual (the data subject) to a data controller for a copy of the personal data the controller holds about them, typically supplied as a copy of the data rather than the original documents. According to the evidence, the request is directed to the organization acting as data controller and may accompany other individual rights over that personal data; the evidence does not specify the governing regulation, required response timeframes, or format, so those details are out of scope here. Note that a SAR is a privacy and data-governance process concerning disclosure of held personal data, and is distinct from runtime authentication or authorization mechanisms that verify a principal's identity or determine access to systems.
Why it matters
Subject Access Requests give individuals a direct mechanism to see what personal data an organization holds about them, making them a cornerstone of data-subject rights and organizational transparency. For the organization acting as data controller, the ability to receive, locate, and fulfill these requests is a measure of how well it understands and governs the personal data it collects. A SAR effectively tests whether an organization can find all the personal data tied to a single individual across its systems, which is often harder than it appears when data is spread across directories, applications, logs, and backups.
For IAM and identity governance teams, SARs matter because personal data is frequently entangled with identity data such as directory attributes, account records, and access histories. Responding accurately depends on knowing where an individual's data lives and being able to correlate records back to the correct data subject. Weak data mapping or fragmented identity stores can make it difficult to compile a complete and accurate response, which raises both compliance and operational risk.
It is worth emphasizing that a SAR is a privacy and data-governance process concerned with disclosing held personal data, not a runtime access-control mechanism. It does not authenticate a principal into a system or determine what a user may do once inside; those enforcement concerns are separate. Conflating the two can lead teams to treat a disclosure obligation as an access-management function, which it is not.
Who it's relevant to
Inside SAR
Common questions
Answers to the questions practitioners most commonly ask about SAR.