Handling a Data Subject Access Request: What Customers Can Actually Demand From Your Business

As privacy laws have expanded across states, small businesses that collect customer data — which is nearly all of them, even just through email lists or a website contact form — increasingly need a plan for what to do when a customer formally requests to know what personal information the business holds about them, or asks for it to be deleted. Getting caught without a process when the first request arrives usually means scrambling under a deadline you didn't know existed.

Understand That This Applies to More Businesses Than You'd Expect

State privacy laws like the CCPA in California and similar laws in other states set specific criteria — often based on revenue, the volume of consumer data processed, or the percentage of revenue from selling data — that determine which businesses are covered. Many small businesses assume these laws only apply to large tech companies, but a business well under those thresholds can still choose to honor these rights as a customer trust practice, and businesses closer to the thresholds should specifically check whether they're legally covered.

Know What a Typical Request Can Ask For

Common rights include the right to know what personal information is being collected and how it's used, the right to request a copy of that data, the right to request deletion, and sometimes the right to opt out of the sale or sharing of personal information. The exact rights and their scope vary by state, so the specific obligations depend on which state laws apply to your business and your customers.

Set Up a Simple Intake Process Before You Need One

Requests need to come through a verifiable channel and be logged with a date received, since most laws set a specific deadline (often around 30-45 days) to respond. Create a simple dedicated email address or web form for privacy requests, and make sure whoever monitors it knows to flag these immediately rather than letting them sit in a general inbox.

Verify the Requester's Identity Before Releasing Data

Responding to a data request from someone who isn't actually the person in question is itself a privacy and security risk, so have a reasonable identity verification step before fulfilling a request — matching the request to account information you already have on file is often sufficient for most small businesses, without requiring invasive additional verification.

Know Where Your Customer Data Actually Lives

Fulfilling a request requires knowing what data exists and where — your CRM, email marketing platform, point of sale system, and any spreadsheets or backups. Many small businesses have never actually mapped out everywhere customer data is stored, which makes both fulfilling requests and identifying a data breach's scope much harder than it needs to be. A simple inventory of what data you collect and where it's stored is worth creating before the first request arrives, not during it.

Understand That Deletion Requests May Have Exceptions

Most privacy laws allow businesses to retain certain data despite a deletion request when it's needed to complete a transaction, comply with a legal obligation like tax recordkeeping, or maintain security. Don't assume every deletion request must be honored completely and immediately without exception; understand the specific carve-outs that apply under the relevant law rather than either over-complying or under-complying by guessing.

Document Your Response for Each Request

Keep a record of what was requested, when, how identity was verified, and what action was taken in response. This documentation matters if a regulator ever asks how your business handles these requests, and it protects you by showing a consistent, good-faith process rather than ad hoc handling.

Data subject access requests are becoming a normal part of doing business as privacy law expands, and having even a basic process in place — a dedicated intake channel, a data inventory, and a clear response procedure — turns what could be a stressful scramble into a routine, manageable task. Getting this in place before the first request arrives is far easier than building it under a compliance deadline.

Comments