Free Tool

Data Subject Access Request (DSAR) Form Template
twelve sections that turn blank-page drafting into a privacy-counsel-defensible right-of-access response

A free, copy-ready DSAR form template for GRC and compliance teams, privacy officers, data protection officers, privacy programme leads, in-house counsel, CISOs, internal security teams, AppSec teams, vulnerability management teams, security engineering teams, data security teams, security operations leaders, and engineering and customer-success leads who receive named right-of-access requests on the inbound side of the privacy programme. Twelve structured sections covering header and version control and controller identity, request intake and statutory clock anchor across named regimes, request classification and statutory regime mapping with named right classes, identity verification with proportional tiering across authenticated session, known-requester one-time-token, unknown-requester reasonable-information, and high-risk processing tiers, scope-and-search plan across the named system list with a named search ledger per system, response content under GDPR Article 15(1) confirmation and 15(3) copy, third-party data redaction and exception assessment under Article 15(4) and Recital 63, automated decision-making and profiling and source-of-data disclosure under Article 15(1)(g) and (h), international transfer disclosure under Article 15(2) and Schrems II supplementary measures, secure delivery method and recipient acknowledgement, refusal pathway with named statutory basis and named supervisory authority complaint pathway under Article 77 and named judicial remedy under Article 79, and closure with named retention period and named disposition schedule. Aligned with GDPR Article 12, 15, 16, 17, 18, 20, 21, 22, 23, 77, 79, UK GDPR equivalents, California CCPA section 1798.130 and CPRA right-to-know and right-to-correct, Colorado CPA, Connecticut CTDPA, Virginia VCDPA, Utah UCPA, Texas TDPSA, Brazil LGPD Article 18 and 19, Singapore PDPA section 21, Canada PIPEDA Principle 9, Australia Privacy Act APP 12, China PIPL Article 45, Korea PIPA Article 35, Japan APPI Article 33, EDPB Guidelines 01/2022 on the right of access, ICO Right of Access guidance, ISO/IEC 27701:2019 Clause 6.10, NIST Privacy Framework v1.0, SOC 2 P1.0 to P8.0 Privacy Criteria, ISO/IEC 27001:2022 Annex A 5.34, and DORA Article 28.

No credit card required. Free plan available forever.

Loading tool...

Run DSAR responses on the live engagement record, not on ad-hoc downloads

SecPortal opens a DSAR engagement on receipt so the named clock anchor, the named verification tier, the named search ledger across the workspace finding records, the named redaction-and-exception register, the named secure-delivery chain-of-custody record, the named closure record, and the named retention period all live on one workspace with a named-actor activity log. Free plan available.

No credit card required. Free plan available forever.