Skip to main content
Glossary

Data Subject Access Request (DSAR)

A formal request by an individual to receive all personal data an organisation holds about them, under Kenya's DPA or GDPR.

Data Subject Access Request (DSAR)

A Data Subject Access Request (DSAR) is a formal request made by an individual (the data subject) to receive all personal data an organisation holds about them. The right is granted by Kenya's Data Protection Act, 2019 and similarly by GDPR and most modern privacy regimes.

The DSAR fulfilment deadline under the Kenyan DPA is 30 days. Failing to fulfil — or fulfilling incompletely — is a compliance violation that can be enforced by the ODPC.

DSAR fulfilment requires:

  1. Verifying the requestor's identity
  2. Searching across all systems holding personal data
  3. Compiling responsive documents (with redactions for third-party data)
  4. Excluding documents covered by legitimate exemptions (legal privilege, ongoing investigations)
  5. Delivering the package securely
  6. Logging the entire process

Papyrus's DSAR workflow makes this manageable: identity verification, tenant-wide search, scope review by DPO, secure delivery, audit log entry.

See also

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.