Data Request (DSAR) Letter Generator
Ask any organisation what it holds about you — and make it act on time.
Checks
Preview
Highlighted hints mark fields you have not filled in; downloads and printouts show a blank line there instead. To print, choose your printer or “Save as PDF” and turn off “Headers and footers”.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the Data Request (DSAR) Letter Generator
Privacy laws let you ask an organisation what personal data it holds about you, and make it correct, delete or stop using that data. This generator writes the request under the law that protects you — the GDPR in the EU and EEA, the UK GDPR, California’s CCPA, or India’s law — citing the right articles and sections, addressed to the data protection officer, privacy team or grievance officer.
Tick the rights you want — access to a copy of your data, correction, erasure, restriction, portability, objection, an end to direct marketing, human review of an automated decision, withdrawal of consent, or under the CCPA opt-out of sale or sharing and a limit on sensitive data — and the letter asks for exactly what the law gives you. The page shows the reply deadline (one month under the GDPR, 45 days under the CCPA, up to 90 days under India’s DPDP Rules), what a lawful extension looks like, and where to complain if the reply does not come: your national authority, the UK’s Information Commission, the California Privacy Protection Agency or India’s Data Protection Board.
How to use it
- Choose the law: where you live, or where the organisation operates (for India, the letter follows the law in force on its date).
- Tick the rights you want to use and fill in the details each needs — what is wrong for a correction, the reason for an objection, where to send portable data.
- Enter your name and how they can find you in their records (account e-mail, customer or policy number). Do not attach ID unless they ask.
- Enter the organisation’s privacy contact from its privacy policy, then read the Checks for the deadline and the complaint route.
- Copy the text into an e-mail or their web form — or download DOCX or PDF to post — and keep a dated copy.
Examples
GDPR · request sent 5 Oct 2026 · lives in Berlin
Reply due by 5 November 2026 (art. 12(3)); up to 5 January 2027 if they tell you, with reasons, that they need longer. If they ignore you: the data protection authority of your federal state — the BfDI lists them.
CCPA · received Monday 5 Oct 2026
Receipt confirmed by 19 October (10 business days), reply by 19 November 2026 (45 days, 90 at most); selling or sharing must stop by 26 October (15 business days).
India · October 2026
A request under rule 5(6) and 5(7) of the SPDI Rules to review and correct the data and withdraw consent to promotional messages; the Grievance Officer has one month (r.5(9)). The same request dated after 13 May 2027 is written under the DPDP Act.
Common uses
- Finding out what a company, app or employer holds about you, and who it shared it with.
- Closing an account properly — erasure, and no more marketing.
- Correcting a wrong date of birth, address or credit record.
- Opting out of the sale or sharing of your data by a US business.
Deadlines by law
- GDPR (EU/EEA): without undue delay and within one month of receipt; for complex or many requests, two more months if they tell you within the first month, with reasons (art. 12(3)). Free, unless a request is manifestly unfounded or excessive (art. 12(5)).
- UK GDPR: one month from receipt — or from when they get the ID or fee they asked for — paused while they wait for a clarification they reasonably need (art. 12A); searches must be reasonable and proportionate (art. 15(1A)).
- CCPA (California): confirm receipt within 10 business days; reply within 45 calendar days, once extendable by 45 days with notice (Civ. Code §1798.130(a)(2); Regulations §7021); stop selling or sharing, or limit sensitive data, within 15 business days (§7026(f), §7027(g)).
- India: under the DPDP Rules, the organisation answers within the period it publishes — at most 90 days (r.14(3)) — from 13 May 2027, when the DPDP Act’s rights start. Until then the SPDI Rules give the right to review and correct the information you provided and to withdraw consent in writing, and the Grievance Officer must resolve a grievance within one month (r.5(6), (7), (9)).
Where to complain
- EU/EEA: the data protection authority where you live, work or where the infringement happened (GDPR art. 77) — the tool names it when you choose your country (from the EDPB’s list of members). If it does not tell you about progress within three months, you can go to court (art. 78(2)).
- UK: complain to the organisation first — it must acknowledge within 30 days (DPA 2018 s.164A) — then to the Information Commission (the successor of the Information Commissioner, at ico.org.uk).
- California: the California Privacy Protection Agency’s complaint form (cppa.ca.gov).
- India: you must use the organisation’s grievance process first (DPDP Act s.13(3)), then the Data Protection Board of India.
Sources
- GDPR, Regulation (EU) 2016/679 — arts. 7, 12, 15–22, 77, 78 · EDPB members
- UK GDPR — arts. 12, 12A, 15 · Data Protection Act 2018 — ss.164A, 165 (as amended by the Data (Use and Access) Act 2025) · ICO: make a complaint
- California Consumer Privacy Act and Regulations — Civ. Code §§1798.105–1798.130; 11 CCR §§7021, 7026, 7027 · CPPA complaints
- Digital Personal Data Protection Act, 2023 — ss.6, 11–15 · DPDP Rules, 2025 (G.S.R. 846(E)) — rr.1, 14 · SPDI Rules, 2011 — r.5
Limitations
- A template, not legal advice. Organisations may lawfully refuse parts of a request (for example to protect other people’s data, or where the law requires them to keep records) — they must tell you why.
- It writes requests from you about your own data. For someone else, include their signed authority and the organisation may verify it.
- The CCPA applies only to businesses above its size thresholds; India’s DPDP rights cover data processed on the basis of your consent.
- US “business days” are counted Monday to Friday without public holidays; UK deadlines can pause while the organisation waits for ID, a fee or a clarification.
Privacy
Everything happens in your browser. Your name, identifiers and the details of your request are not uploaded or stored by MySmartCoPilot. If you tick Keep a draft in this browser, the form is saved in this browser’s local storage until you untick it.
Frequently asked questions
How long does a company have to answer a GDPR subject access request?
Without undue delay and within one month of receiving it. For complex or numerous requests it can take two more months, but it must tell you within the first month and explain why (GDPR art. 12(3)). It is free, unless the request is manifestly unfounded or excessive (art. 12(5)).
Do I have to give a reason for a subject access or erasure request?
Not for access. Erasure applies on one of the grounds in GDPR art. 17(1) — for example the data are no longer needed, or you withdraw consent — and an objection under art. 21(1) rests on your particular situation; objecting to direct marketing needs no reason at all (art. 21(2)–(3)).
How long does a business have under the CCPA?
45 calendar days from receiving your request to know, delete or correct, once extendable by 45 more days if it tells you within the first 45. It must confirm receipt within 10 business days, and stop selling or sharing your data within 15 business days of an opt-out.
Can I make a data access request in India?
Yes. Until 13 May 2027 the SPDI Rules 2011 let you review and correct the information you gave and withdraw consent in writing; the Grievance Officer must resolve your grievance within a month. From 13 May 2027 the DPDP Act gives rights to a summary of your data and who it was shared with, correction, erasure and nomination, with replies within at most 90 days.
What if they ignore my request?
Complain to the regulator: in the EU, your national data protection authority; in the UK, to the organisation and then the Information Commission; in California, the California Privacy Protection Agency; in India, the organisation’s grievance process and then the Data Protection Board. Keep a dated copy of your request.
Should I send a copy of my passport or Aadhaar?
Not unless they ask. An organisation may ask for more information when it has reasonable doubts about who you are (GDPR art. 12(6)); send only what is necessary, and hide most of any ID number.