Compliance

How to Handle Data Subject Access Requests When Using Enriched Data

Basel Ismail August 25, 2026 9 min read 2,100 words
How to Handle Data Subject Access Requests When Using Enriched Data

How to Handle Data Subject Access Requests When Using Enriched Data

Your sales team just got an email from a prospect they have never spoken to: I want to know what personal data you hold about me and where you got it. If your first reaction is mild panic, you are not alone. Data Subject Access Requests (DSARs) are one of those compliance obligations that teams know about in theory but are completely unprepared for in practice.

When your database includes enriched data from third-party sources, responding to a DSAR gets more complicated because you need to account for data that came from your enrichment vendors, not just data the person gave you directly. Here is the operational playbook for handling DSARs properly.

What a DSAR Actually Requires

Under GDPR, individuals have the right to request access to their personal data. When you receive a DSAR, you must provide:

  • Confirmation of whether you process their data
  • A copy of all personal data you hold about them
  • The purposes of the processing
  • The categories of personal data processed
  • The recipients or categories of recipients the data has been shared with
  • The source of the data (this is where enrichment vendors come in)
  • How long you will retain the data
  • Their rights regarding the data (correction, deletion, restriction, objection)

Under CCPA, the requirements are similar. Consumers can request to know what personal information you have collected, the categories of sources, the business purpose, and the third parties you share it with.

Response Timelines

GDPR: You must respond within 30 days. This can be extended by up to 60 additional days (90 days total) for complex requests, but you must inform the requester of the extension and the reason within the initial 30-day period.

CCPA: You must respond within 45 days. This can be extended by an additional 45 days (90 days total) with notice to the consumer.

These timelines are firm. Missing them is itself a compliance violation.

The Enrichment Complication

When your database contains enriched data, your DSAR response must include that data and disclose its source. This means:

  • You need to know which fields in a contact record came from enrichment versus which were provided directly by the data subject
  • You need to name the enrichment vendor (or at least the category of source) that provided each piece of data
  • You need to explain the legal basis for obtaining the data through enrichment

If you have not been tracking data provenance (which fields came from which source), responding to a DSAR becomes a scramble. This is why source tracking should be built into your enrichment workflow from day one.

Building the DSAR Response Workflow

Step 1: Verify the Requester's Identity

Before disclosing any personal data, verify that the person making the request is who they claim to be. Otherwise, you could accidentally disclose someone's data to an unauthorized third party. Verification methods include:

  • Requesting the DSAR from the same email address that is in your records
  • Asking verification questions that only the data subject could answer
  • Requesting a copy of government-issued ID (use this only when other methods are insufficient, and securely delete the ID after verification)

Step 2: Search All Systems

Personal data about a single individual might exist across multiple systems:

  • Your CRM (contact records, activity history, notes)
  • Your enrichment tool's logs (enrichment queries and results)
  • Your outreach platform (email sequences, engagement data)
  • Your marketing automation platform (campaign interactions)
  • Spreadsheets and ad-hoc databases (prospect lists, event attendee lists)
  • Email inboxes (correspondence with the individual)

You need to search all of these systems, not just your CRM. A DSAR response that misses data from a secondary system is incomplete and non-compliant.

Step 3: Compile the Data

Organize all the data you found into a clear, readable format. For each data point, note:

  • The category of data (name, email, phone, job title, company, etc.)
  • The source (directly provided, enriched via vendor name, collected via website analytics, etc.)
  • The purpose (B2B sales outreach, marketing, etc.)
  • The legal basis (legitimate interest for enriched data)

Step 4: Prepare the Response

Your response should include:

  • A summary of the data you hold (in plain language, not raw database exports)
  • The copy of the data itself (can be a structured table or list)
  • Source information for each data category
  • Your legal basis for processing
  • Your data retention policy
  • Information about their rights (correction, deletion, restriction, objection, complaint to supervisory authority)

Step 5: Send the Response

Send the response through a secure channel. Email is acceptable for most DSARs, but consider using a secure file-sharing link for responses containing sensitive data. The response should be free of charge.

Step 6: Log the Request

Maintain a log of all DSARs received, including: date received, requester identity, response date, summary of data disclosed, and any follow-up actions. This log demonstrates your compliance and helps you track patterns.

Including Enrichment Vendors in Your Workflow

Your enrichment vendor may hold data about the requester that you need to include in your response. Notify your vendor when you receive a DSAR and request:

  • Confirmation of what data they hold about the individual
  • The source of that data
  • Whether the data has been shared with other parties

Your DPA with the vendor should include clauses requiring their cooperation with DSARs. If it does not, add this requirement at your next contract review.

Handling Deletion Requests

A DSAR often leads to a deletion request. When someone asks you to delete their data:

  • Delete from all systems (CRM, outreach platform, spreadsheets, enrichment logs)
  • Add the email address to your suppression/do-not-contact list (you need to keep enough information to ensure you do not enrich or contact them again)
  • Notify your enrichment vendor of the deletion request so they can remove the data from their systems as well
  • Confirm deletion to the requester in writing

Proactive Measures to Simplify DSAR Handling

  • Track data provenance from day one. For every enrichment, record the source, date, and fields added. This makes DSAR compilation dramatically faster.
  • Centralize your data. The fewer systems your data lives in, the faster you can compile a DSAR response. CRM-centric architectures with automated enrichment beat scattered spreadsheets and manual processes.
  • Build a DSAR response template. Create a standard response template that you can populate for each request. This reduces response time from days to hours.
  • Train customer-facing teams. Sales and customer success reps should know how to recognize a DSAR, where to forward it, and how to acknowledge receipt without making commitments about timeline or content.
  • Test your process. Run a mock DSAR through your workflow annually to identify gaps and bottlenecks before a real request exposes them.

The Bottom Line

DSARs are not going away. As privacy awareness grows and regulations expand, expect more requests, not fewer. The teams that handle DSARs smoothly are the ones that built source tracking, centralized data management, and response templates into their enrichment workflow from the start. Retrofit these capabilities now if you have not already. The cost of preparation is hours of work. The cost of a botched DSAR response is regulatory scrutiny, potential fines, and reputational damage that no amount of enrichment quality can fix.

DSARGDPRData PrivacyCompliance
Share:

Try BetterEnrich Free

Start using BetterEnrich today and see the results for yourself.

Get Started Free

Related Articles