Introduction to Data Subject Access Requests: Purpose, Examples, Responding to Requests, Navigating Compliance
A live 60-minute CLE video webinar with interactive Q&A
This CLE webinar will provide a high-level overview of data subject access requests (DSARs). The panel will explain what a DSAR is and isn't, outline the purpose and key components of a DSAR, give examples of common DSAR requests, and provide tips for navigating compliance under the ever-evolving data privacy legal framework.
Outline
- Overview: understanding what a DSAR is and isn't
- Examples of common DSAR requests
- Legal and regulatory framework governing DSARs
- EU's General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- Other state privacy laws: common themes regarding DSARs and key differences
- Penalties and enforcement
- Key concepts for advising clients and spotting issues
- Assessing, planning, and preparing for common situations
- Creating effective policies and protocols
Benefits
The panel will review these and other key considerations:
- What is the typical process for an individual to make a DSAR with an organization?
- How long does an organization have to comply with a DSAR?
- How should an organization respond to a DSAR request and how much information does the organization need to provide?
- What are special issues and considerations to keep in mind?
- What steps can organizations take to prepare for DSARs to ensure compliance with applicable data privacy laws?
Faculty

Patrick J. Austin
Of Counsel
Woods Rogers
Mr. Austin advises clients on breach response, data privacy, information security, and regulatory compliance related to... | Read More
Mr. Austin advises clients on breach response, data privacy, information security, and regulatory compliance related to domestic and international privacy laws and regulations, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Virginia Consumer Data Protection Act (VCDPA), and the Health Insurance Portability and Accountability Act (HIPAA). He is a Certified Information Privacy Professional with expertise in both U.S. and European law (CIPP/US & CIPP/E) by the International Association of Privacy Professionals (IAPP).
Close
Christian M. Auty
Partner, U.S. Lead – Data Privacy and Security Team
Bryan Cave Leighton Paisner
Mr. Auty has led engagements with hundreds of companies in diverse industries. He works side-by-side with clients to... | Read More
Mr. Auty has led engagements with hundreds of companies in diverse industries. He works side-by-side with clients to navigate complex, intersecting data privacy and security regimes, including the California Consumer Privacy Act, the GDPR, HIPAA and the Gramm-Leach-Bliley Act. Mr. Auty also has significant experience responding to data breaches and defending privacy and security practices in investigations initiated by regulatory agencies around the world. He is a frequent writer and speaker on data privacy topics, in particular issues related to digital marketing.
CloseEarly Discount (through 06/20/25)