A data access request asks a company to show you the personal information it collects, uses, and shares about you. People often call it a DSAR, but U.S. businesses may use terms such as "request to know," "privacy request," or "personal information request." The practical path is to find the company's privacy channel, submit a narrow request, verify your identity, and keep proof.
There's no single federal DSAR form, and no one deadline covers every consumer. The controlling rule may be a state privacy law, a sector-specific federal rule, or the company's own privacy process. The Congressional Research Service overview describes this mix of state and sectoral privacy rules.
California gives residents a specific right to know under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Depending on the request and any exceptions, you may ask for categories of personal information, sources, purposes, recipients, and specific pieces. Other states can have different eligibility rules, verification standards, and response periods.
What rule controls your request?
Start with your state of residence and the kind of company holding the data.
California requests
If California law applies, you can ask a covered business what personal information it collects and how it uses or shares it. The California Privacy Protection Agency FAQ identifies the right to know as covering categories, sources, purposes, and certain specific pieces of personal information.
The California Attorney General's CCPA guidance is also useful for identifying rights and request procedures. A California request usually goes through the privacy contact or request form listed in the company's privacy notice.
Other U.S. states
Several states have broad privacy laws, but the terminology and rights don't match exactly. A company may check whether you live in the covered state, whether it meets the law's coverage threshold, and whether the requested information falls within an exemption.
Don't assume a California deadline applies somewhere else. Check the privacy notice and the official privacy guidance for your state.
Sector-specific records
Some records may follow a separate law or industry process. Credit reports, certain health records, financial information, employment records, and education records can involve extra rules. If your goal is to dispute a credit report or obtain a medical file, a general privacy request may not be the fastest or most complete route.
How to submit the request
1. Find the right company and channel
Identify the business that decides why and how your information is used. Look in its privacy notice for phrases such as:
- Request to know
- Access my personal information
- Privacy rights
- Your privacy choices
- Data subject rights
- Do not sell or share my personal information
Use the listed web form, privacy email, telephone number, or mailing address. A marketing unsubscribe link usually isn't the same as an access request.
If customer support is the only contact you can find, say that you're making a privacy request and ask for it to be routed to the privacy team. Save the ticket or chat transcript.
One company may not hold every record connected to you. An app, retailer, advertising company, payment processor, and data broker can be separate businesses. The Congressional Research Service report on online data collection describes how third-party trackers and software development kits can appear in apps. If you want records from a separate company named in a privacy notice, you may need to submit a separate request.
2. Decide what you want
A focused request is easier to verify and review than "send me everything." Choose the right that matches your goal:
| Goal | What to request | What it does not automatically do |
|---|---|---|
| Access or right to know | Categories, sources, purposes, recipients, and specific pieces where applicable | Correct or delete the information |
| Correction | Correction of inaccurate or incomplete personal information | Produce a complete copy of your records |
| Deletion | Deletion of personal information subject to legal exceptions | Give you a copy before it is removed |
| Opt out | Stop sale, sharing, or certain targeted advertising where the law provides that right | Tell you every piece of information the company holds |
Include a date range, such as "January 1, 2024, through the present." If you want the entire account history, say so. Useful categories can include:
- Account and profile information
- Orders, returns, and payment-related records
- Customer service messages and call records
- Marketing preferences and campaign history
- Device identifiers, cookies, and approximate location
- Inferences or audience segments associated with your account
- Information shared with or received from service providers
A look-back limit or another exemption may cut off older records. If the company excludes part of the requested period, ask it to explain the limit.
3. Prepare for identity verification
A company can take reasonable steps to confirm that it's giving personal information to the correct person. Verification may involve your name, account email, phone number, order number, billing address, or another account detail. A request for specific pieces of information can require stronger verification than a request for general categories.
Use details that already match the account. If the account is closed, include an old email address, phone number, customer number, or recent order number.
Don't send a driver's license, Social Security number, bank login, password, or one-time security code to an unverified email address. If the company requests identification, use its official privacy portal or ask for a secure upload method. Ask whether unnecessary fields can be covered before you submit the document.
4. Write and send the request
You don't need complicated legal language. State your residence, identify the account, describe the date range, and name the information you want.
You can adapt this template:
Subject: Request to know or access personal information
Hello Privacy Team,
I am a resident of [state] and am requesting access to the personal information your business maintains about me under applicable privacy law.
My identifying details are:
Name: [full name]
Account email: [email address]
Other account identifier: [customer number, username, or phone number]
Please search for information associated with me from [start date] through [end date]. If applicable, please provide:
- The categories of personal information collected about me
- The sources of that information
- The business or commercial purposes for collecting or using it
- The categories of recipients, service providers, or third parties that received it
- The categories of information sold or shared, if applicable
- The specific pieces of personal information that I am entitled to receive
Please tell me what identity verification is required and provide a secure method for completing it. Please confirm receipt of this request and provide the response through [secure portal or email].
If any portion is withheld, please identify the general reason and provide the remaining non-exempt information.
Thank you,
[Your name]
[Date]
For California, the list tracks the main parts of a right-to-know request. For another state, keep the general wording but check whether that state uses different terms or limits.
5. Save proof and track the response
Keep the request, submission confirmation, verification messages, and final response. Record:
- The date and time you submitted the request
- The method you used
- The business or legal entity contacted
- Your ticket or confirmation number
- The date verification was completed
- Any deadline stated by the business
The date a business receives a valid or verifiable request can matter more than the date you first drafted it. If the company says your request is incomplete, ask exactly what is missing and provide only what is reasonably necessary.
California deadlines
For California requests, a business generally has 45 calendar days after receiving a verifiable request to respond. It may extend the response period by up to another 45 days when reasonably necessary, but it should notify you during the initial response period.
The CPPA FAQ says businesses must confirm receipt of requests to know, delete, or correct within 10 business days. A confirmation isn't the same as a substantive response.
A standard California privacy request is generally free. If a business proposes a fee or refuses the request, ask it to identify the basis.
Don't apply the EU or UK one-month deadline unless that law actually controls your situation. EU and UK requests follow separate rules and regulator procedures.
What a useful response should contain
Review the response against what you asked for. Depending on the law and request type, look for:
- The correct account or customer record
- The requested date range
- Categories of personal information collected
- Sources of the information
- Business or commercial purposes
- Categories of recipients or third parties
- Specific pieces of personal information, when covered and properly verified
- A readable electronic file or access method
- An explanation for information the company did not provide
A response may be a structured export, a category summary, or both. It may not include every internal note, duplicate system record, security control, trade secret, or another person's personal information.
A business may redact or withhold information because of another person's privacy, legal privilege, security concerns, or a statutory exemption. That doesn't automatically make the entire response improper. Ask for any non-exempt portion and the general reason for each significant omission.
What to do if the response is incomplete
Send a short written follow-up rather than starting over. Include the original submission date and identify the missing items precisely.
For example:
Subject: Follow-up to privacy request submitted [date]
Hello Privacy Team,
I am following up on my request submitted on [date], confirmation number [number].
The response did not address these requested items:
1. [Missing category or date range]
2. [Missing source, purpose, recipient, or specific record]
3. [Other omission]
Please confirm whether this information is not held, was withheld under an exception, or was outside the scope of the request. If it was withheld, please provide the non-exempt portion and the general reason.
Thank you,
[Your name]
If the business says it can't verify you, ask whether it has a secure alternative or what account detail is needed. Don't keep sending increasingly sensitive documents without understanding why they're required.
If the company says the law doesn't apply, ask which coverage rule or exemption it relied on. You can then compare that explanation with your state's official privacy guidance.
How to escalate a denied request
Use the company's privacy appeal process if one exists. Keep the appeal factual:
- Identify the request and submission date.
- State which part was denied or omitted.
- Explain why the response doesn't address the request.
- Ask for review and a written explanation.
- Save the appeal and the company's reply.
California consumers can consult current materials from the California Privacy Protection Agency and the California Attorney General for complaint and enforcement information. Consumers in other states should use the official privacy regulator or attorney general listed in their state's law.
A regulator complaint is different from a private lawsuit. The California Attorney General explains that, before suing under certain CCPA claims, a consumer must provide written notice of the alleged violation and allow 30 days for a written cure in the circumstances covered by that provision. That doesn't mean every access dispute creates a private claim.
Protect your information during the process
Treat a privacy request as a security-sensitive transaction.
- Use the company's official website or a privacy address listed in its policy.
- Check the domain before uploading identification.
- Never provide your password or a one-time authentication code.
- Ask whether an ID can be partially redacted.
- Don't include unrelated family members' information.
- Store the response securely because it may contain account numbers, addresses, or transaction history.
- If you forward the response to a regulator, redact information about other people when possible.
Common questions
Do I need a lawyer?
Usually not. Most consumers can submit a request directly through the company's privacy channel. Legal advice may be useful if the request involves a dispute, a regulated record, identity theft, or a potential legal claim.
Can a company ask for identification?
Yes. A business may need to verify that you're the person connected to the account. Use a secure method and ask why each requested document is necessary.
Does an access request delete my information?
No. Access, correction, deletion, and opt-out requests are separate. If you want information first and deletion afterward, say so in separate requests so the company doesn't mistake one purpose for another.
What if the business never responds?
Send one documented follow-up, use any available appeal process, and then check the official regulator for your state. If you're in California, review the current CPPA and Attorney General guidance. Keep your submission proof and all response dates.
Before sending your request, open the company's privacy notice, confirm the correct legal entity and submission method, and prepare a narrow list of the information you actually need.