Skip to content
Legiscope
Menu
Data Privacy

DSAR Software Compared: Automate Subject Requests

DSAR software compared for 2026: identity verification, one-month deadline tracking, cross-system search and cost per request, with honest vendor pros and cons.

Also available in:Français·Deutsch·Español·Nederlands

Get identity verification wrong and the tool becomes a liability: the Dutch DPA fined DPG Media EUR 525,000 in 2020 for demanding a copy of an ID document to process access requests. The software you pick should make the compliant path the default.

Key Takeaways

  • A DSAR tool must cover four stages: secure intake, proportionate identity verification, cross-system data discovery, and deadline-tracked delivery.
  • Over-verification is itself a violation. Requiring ID copies by default cost DPG Media EUR 525,000 (Dutch DPA, 2020) — pick software that verifies proportionately.
  • The one-month deadline (Art. 12(3) GDPR, extendable by two months for complex requests) is the hard constraint every tool must track.
  • Manual DSAR handling costs EUR 100-1,500+ per request in staff time; automation moves the cost of a routine request toward near-zero once configured.

What a DSAR Tool Must Do

The right of access is defined in Art. 15 GDPR and governed procedurally by Art. 12. A tool earns its price by covering the full lifecycle:

  • Intake — a branded, accessible request form (or email/portal capture) that logs the request and starts the clock.
  • Identity verification — confirming the requester is who they claim to be, using the least intrusive method sufficient. The EDPB Guidelines 01/2022 on the right of access are explicit that controllers should not collect more data than necessary to authenticate.
  • Data discovery — locating every copy of the requester’s personal data across CRM, support, marketing, HR and cloud systems. This is where cheap tools stop and expensive ones connect.
  • Review and redaction — removing third-party data and exempt material before disclosure.
  • Delivery and audit trail — providing the response in a durable format and logging every step for accountability under Art. 5(2) GDPR.

For the underlying obligation, see our guides to the data subject access request process and the right of access under the GDPR.

Identity Verification: Where Tools Help or Hurt

This is the single most misconfigured part of DSAR handling. The rule from Art. 12(6) GDPR is that a controller may request additional information to confirm identity only where there are reasonable doubts — not as a blanket policy.

  • Good default: verify through an existing authenticated channel (the logged-in account, the email already on file) before ever asking for documents.
  • Bad default: demanding a passport or ID scan up front. That is what earned DPG Media its EUR 525,000 fine, and it creates a fresh pile of sensitive data you now have to protect.

When comparing tools, test the out-of-the-box verification flow. If it asks for ID by default, it is configured against you.

The One-Month Deadline

Art. 12(3) GDPR requires a response without undue delay and within one month of receipt. That can be extended by up to two further months for complex or numerous requests, but only if you inform the requester within the first month and explain why. A DSAR tool must:

  • start the clock automatically on intake,
  • surface approaching deadlines before they are breached,
  • document any extension and the notice sent.

Missed deadlines are a common trigger for complaints, and complaints are how ordinary companies end up in an enforcement file. Transparency obligations around these communications are detailed in our guide to Art. 12 GDPR transparency.

DSAR Software Compared

For where DSAR fits in a full compliance stack, compare against the category leaders in our best GDPR compliance software roundup, and see the broader GDPR software cost and pricing benchmark.

Cross-System Discovery: Where Price Buys Depth

Discovery is the axis that separates a EUR 79/month module from a five-figure suite. A basic tool searches only the systems you connect by hand — CRM, helpdesk, primary mailbox. A deep one crawls the wider SaaS estate automatically and follows the data into backups, log stores, analytics warehouses and sub-processor systems where copies quietly accumulate. The test to run in a demo is concrete: give the vendor a real test identity and ask it to surface every place that person appears. If the answer is “the three systems you configured,” you are buying a workflow tracker, not a discovery engine — acceptable at low volume, inadequate for a consumer brand fielding hundreds of requests. Match discovery depth to how scattered your data genuinely is, not to the ambition of the demo.

Redaction and the Third-Party Data Problem

Art. 15(4) GDPR states the right to obtain a copy “shall not adversely affect the rights and freedoms of others” — which in practice means removing third-party personal data before disclosure. A support ticket naming another customer, an internal note about a colleague, a shared document: each must be redacted, and doing it by hand across a large export is slow and mistake-prone. Tools differ sharply here. The weaker ones offer only a document viewer; the stronger ones support inline redaction with an audit log of what was removed and why. Under-redacting leaks other people’s data; over-redacting withholds what the requester is legally entitled to. Neither is safe, and this review-and-redact step is where most of the human time in a manual DSAR is actually spent — so it is the first place automation earns back its price.

Cost Per Request: Manual vs Automated

The economics are what justify a purchase. A single manual DSAR — logging it, verifying identity, searching half a dozen systems by hand, redacting, drafting a response — routinely consumes several hours of skilled time.

Volume Manual cost/request With automation
Occasional (a few/year) EUR 100-400 Marginal once configured
Regular (dozens/year) EUR 300-1,000 Low per-request
High (hundreds/year, consumer brands) EUR 500-1,500+ Lowest per-request; automation essential

At high volume the manual route does not just cost money — it risks the deadline. A consumer app receiving hundreds of requests a year cannot answer them by hand inside a month without a dedicated team.

Choosing the Right Tool

FAQ

What is DSAR software?

DSAR software automates the handling of data subject access requests under Art. 15 GDPR — from intake and identity verification through cross-system data discovery, redaction and deadline-tracked delivery. It exists to answer requests correctly inside the one-month statutory limit while keeping an accountability trail.

Can I demand an ID copy to verify a DSAR?

Not by default. Art. 12(6) GDPR allows additional verification only where you have reasonable doubts about identity, and the least intrusive sufficient method must be used. Requiring ID scans as standard is exactly what the Dutch DPA fined DPG Media EUR 525,000 for in 2020. Verify through existing authenticated channels first.

How long do I have to answer a DSAR?

One month from receipt under Art. 12(3) GDPR, extendable by up to two additional months for complex or numerous requests — but only if you notify the requester within the first month and explain the delay. Good DSAR software starts and tracks this clock automatically.

How much does DSAR software cost?

It ranges from a module inside an SME GDPR platform (bundled, often low four figures per year) to enterprise suites at EUR 30,000-100,000+. The right benchmark is cost per request: manual handling runs EUR 100-1,500+ each, so automation pays off quickly once you handle more than a handful.

Conclusion

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
02Data Privacy

FADP vs GDPR: Breach Notification, Sanctions, Authorities

In one sentence. The revised Swiss FADP (nFADP) in force since 1 September 2023 and the GDPR in force since 25 May 2018 share most concepts but diverge on three operational points: (1) breach…

June 3, 2026
03Data Privacy

GDPR Audit Checklist + Best Audit Tools 2026

A GDPR audit checklist is a structured, section-by-section list of what you must be able to evidence under the GDPR: your lawful bases, your record of processing activities, your processor contracts,…

July 8, 2026
04Data Privacy

PIPEDA vs GDPR: What Canadian Businesses Must Know

PIPEDA and the GDPR are not two versions of the same law. They were built on different premises, they allocate risk differently, and a Canadian company that is compliant with one is measurably short…

July 30, 2026
05Data Privacy

ROPA Software: Automate Article 30 Records (2026)

The ROPA is not paperwork for its own sake. It is the first document every DPA requests when an inspection or complaint lands, and an incomplete one is itself evidence of an Art. 30 breach.

July 7, 2026
06Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
07Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
08Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026