Data Subject Request

Data & Tracking

Also: DSR · Subject Access Request · SAR

What it isSomeone asking for their personal data
Response windowReasonable period, not indefinite
Watch forData scattered across tools
Who it applies toAnyone holding personal data

Quick definition

A Data Subject Request (DSR) is a formal request from a person asking an organisation to show them what personal data it holds, correct it, delete it or stop using it. It's the practical, individual-level mechanism behind privacy law rather than an abstract compliance concept.

How it varies across Australia

Most Australian marketing teams have never processed a real Data Subject Request and don't have a documented process for one. The gap shows up fastest in businesses running loyalty programmes, CRM-heavy retention plays or extensive UTM parameter tracking, where personal data is spread across more tools than anyone can name from memory.

See data and tracking maturity across Australian industries

What it actually means

A Data Subject Request is what happens when the abstract idea of privacy becomes a specific email in your inbox. Someone writes in and says show me what you hold on me, or delete it, or stop using it for marketing. Suddenly the segmentation rules, the email marketing platform, the CRM, the ad platform pixels and the spreadsheet someone kept on the side all have to answer the same question.

Most marketing teams treat privacy as a policy document and a cookie banner. A DSR exposes whether that policy actually maps to where data lives. If your first-party data sits in six systems and nobody can produce a single view of one customer's record, the request becomes a scramble rather than a five-minute lookup.

The request itself is usually simple. Access, correction, deletion or objection to processing. The difficulty is entirely operational. Consent records, attribution logs, retention rate cohorts and segmentation lists all need to be searchable by person, not just by campaign. If churn analysis or lifetime value modelling depends on data you can't locate on demand, the DSR is the moment that becomes a business problem instead of a technical one.

A Data Subject Request is a pop quiz on whether your data map is real or aspirational.

How it shows up

A DSR shows up as an email or web form submission, usually through a privacy contact address or a dedicated request form. It shows up in the CRM as a flagged record that needs manual review. It shows up in ad platforms when someone asks to be removed from a custom audience built from customer lists. And it shows up in the awkward silence when a marketing manager is asked which systems hold a given customer's email address and can't answer without checking four tools.

The Australian context

Under the Privacy Act, Australian organisations covered by the Act must respond to individuals asking to access or correct their personal information, and increasing reform pressure is pushing toward broader rights closer to erasure and objection, similar to European rules. The Office of the Australian Information Commissioner (OAIC) oversees complaints when requests are ignored or mishandled.

For marketing teams specifically, the practical risk sits in ad platform custom audiences and third-party data enrichment tools. If a customer asks to be deleted and their email is still sitting inside a Meta custom audience upload from eight months ago, the request hasn't actually been fulfilled even if the CRM record is gone.

Where people get this wrong

Treating the CRM as the full picture of where personal data lives.Ad platform audiences, email platform suppression lists, analytics exports and spreadsheets used for one-off campaigns all hold personal data too. A DSR response that only checks the CRM is incomplete.
Ignoring requests that don't use formal legal language.A customer emailing to say stop sending me stuff and delete my details is still making a valid request even without citing the Privacy Act. The obligation isn't triggered by wording, it's triggered by intent.
Deleting the record but leaving the backups and audience uploads untouched.Partial deletion creates false confidence. If the person's data still exists in a backup, a data warehouse or an ad platform audience, the request isn't actually fulfilled.

Related terms

Common questions

Who can make a Data Subject Request?

Any individual whose personal information an organisation holds, whether they're a customer, a former customer, a job applicant or someone who filled in a form once and never bought anything. The request right sits with the person, not with the organisation.

What happens if we ignore a Data Subject Request?

In Australia, ignoring a valid request can lead to a complaint to the Office of the Australian Information Commissioner (OAIC), which can investigate and, in serious cases, issue penalties. Beyond the legal risk, ignoring requests damages trust and often surfaces publicly.

Does a Data Subject Request cover data in ad platforms?

Yes. If a customer's email or phone number was uploaded into a custom audience on a platform like Meta or Google, that counts as personal data held by your organisation. A complete response needs to include removing it from those audiences, not just the CRM.

Is a Data Subject Request the same as an unsubscribe request?

No, though they overlap. Unsubscribing stops marketing emails specifically. A DSR can ask for access, correction, deletion or a broader objection to processing across every system, not just the email platform.

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Keep exploring

About New Rebellion

New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.

How we think →