Data subject access request

A data subject access request (DSAR) is a request submitted by an individual (data subject) to an organization to acquire the information collected and stored about them to verify the lawfulness of the processing.

A data subject can also ask for specific actions to be taken with regard to that data. For instance, they may request the deletion or correction of information, receive information on the data safeguards provided by the organization or opt out of future data collection.

Data subject access requests are a part of the data subject rights provided by the EU’s GDPR, California’s CCPA and many other privacy laws around the world.

DSARs give consumers unprecedented control over the personal information that organizations store. An organization served with a DSAR is legally obligated to fulfill these requests within a limited timeframe to avoid non-compliance.


  • What is considered protected health information (PHI) under HIPAA? A guide for healthcare marketers

    Quick summary What PHI is: Any individually identifiable health information created, received, maintained, or transmitted by a covered entity or its business associates Who it applies to: Healthcare providers, health plans, healthcare clearinghouses, and their business associates Why it matters for marketing: Marketing tools that collect or transmit PHI without a BAA create HIPAA compliance…

  • We checked 59 hospital websites. 73% kept tracking visitors after opt-out.

    A new study by Piwik PRO and Verified Data scanned 59 major US hospital and clinic websites for tracking and data compliance. The findings show just how common it is for major US healthcare websites to run marketing tools that weren’t built for a regulated environment. What we actually found Across the 59 scanned sites,…