Legal · free template

GDPR Data Subject Access Request Form

Structured DSAR intake with identity verification and a request-type branch for access, correction, deletion or portability.

A ready-to-use legal & professional services form for law firms and in-house legal teams: 14 questions, 3 pages, 5 conditional rules.

Questions
14
Pages
3
Layouts
classic · card
Conditional rules
5
Typical time
5 min
Preview it in the gallery

Searches this template answers

Also filed under

Live preview and test console

This is the real form. Answer it to test the 5 conditional rules — nothing is sent or stored.

Page 1 of 3About you

Data subject access request

Use this form to ask what personal data we hold about you, to correct it, to ask for it to be deleted, or to receive a copy in a portable format.

Use the email address associated with your account or interactions with us.

1 question is hidden by conditional logic right now — change an answer above to reveal it.

What happens after submit: nothing is stored in this preview. On your own copy, every response triggers an instant email notification and lands in your response dashboard, ready to export or forward.

Happy with it? Take a copy into your workspace — every question, rule and setting comes with it.

Who this template is for

GDPR Data Subject Access Request Form is built for law firms and in-house legal teams who need to intake a matter with the facts, parties and consent recorded.

  • Law firms and in-house legal teams working in legal & professional services.
  • Teams who need to intake a matter with the facts, parties and consent recorded without writing code or paying for a custom build.
  • Anyone replacing conflict checks delayed by missing intake detail with one structured record per enquiry.
  • Respondents are clients and claimants — the form asks them 14 questions across 3 screens.
  • Mobile-heavy audiences, thanks to the one-question-per-screen card layout.

Why this form is useful

It removes the cost of conflict checks delayed by missing intake detail and turns each submission into a record your team can act on immediately.

  • 5 questions are required, so submissions arrive complete instead of needing a follow-up email.
  • It collects a verified email address so replies and confirmations land.
  • It accepts a document or photo upload as evidence.
  • It captures a full postal address.
  • It allows multiple selections without free text.
  • Conditional logic hides 5 questions until they are relevant — shorter forms convert better than long ones.
  • Splitting the form across 3 pages keeps each screen short and shows respondents how much is left.
  • Every response is stored, searchable and exportable, so nothing depends on one person's inbox.

How to use this template

From copy to live form is a few minutes of work, and every step is reversible.

  1. 1Press “Use this template” — a fresh copy of GDPR Data Subject Access Request Form lands in your workspace, ready to edit.
  2. 2Rename or delete any question, and change what is required. Nothing here is fixed.
  3. 3Open Notifications and add the email addresses that should be alerted on each submission; add an auto-reply to the respondent if the form collects an email address.
  4. 4Check the upload limits on the file question so respondents can attach what you actually need.
  5. 5Publish it, then either share the link directly or paste the embed snippet into your site — the embedded form resizes to fit and loads no marketing or advertising trackers.
  6. 6Watch responses land in Submissions, where you can filter, label and export them to CSV or PDF.

Logic and conditions blueprint

Exactly how this form behaves as it is answered — 5 conditional rules ship with it.

  • Features advanced show logic: if “Are you submitting this on someone else's behalf?” is Yes, the form dynamically exposes “Your relationship to the individual and authority to act”. Otherwise that question never appears.
  • Features advanced show logic: if “What are you requesting?” is Access to my data, the form dynamically exposes “Which categories of data are you asking about?”. Otherwise that question never appears.
  • Features advanced show logic: if “What are you requesting?” is Correction of my data, the form dynamically exposes “What is incorrect and what should it say instead?”. Otherwise that question never appears.
  • Features advanced show logic: if “What are you requesting?” is Deletion of my data, the form dynamically exposes “Reason for the deletion request”. Otherwise that question never appears.
  • Features advanced show logic: if “What are you requesting?” is Portability of my data, the form dynamically exposes “Preferred format and destination”. Otherwise that question never appears.
  • All 5 rules are editable in the Logic tab, and the built-in checker warns about rules that contradict each other.

About this template

A subject access request only becomes actionable once you know who is asking, what they're asking for, and that they actually are who they say. This form starts by confirming the requester's relationship to the organization — customer, employee, former employee, job applicant or other — because that changes which system holds their data. It then asks for identity verification details rather than skipping straight to the request, since acting on an unverified request is its own risk. The request-type question branches the form: an access request asks which categories of data are relevant, a correction request asks what needs to be fixed and why, an erasure request asks for the reason under the applicable legal ground, and a portability request asks for the preferred file format and destination. A representative field appears only when someone is submitting on another person's behalf, with a place to note the authority they're acting under. The form closes with a plain description of the statutory response window your organization commits to and a note that identity may need to be confirmed further before any data is released. Have your privacy counsel confirm the exact response-time wording and legal-ground options for your jurisdiction before publishing this.

What this form asks

Every question is editable — rename it, make it optional, or delete it entirely.

Page 1 — About you

  • Full namerequired
  • Email address on filerequired
  • Your relationship to usrequired
  • Are you submitting this on someone else's behalf?required
  • Your relationship to the individual and authority to act

Page 2 — Verifying your identity

  • A recent order number, employee ID or account reference
  • Address on file
  • Upload identification (optional)

Page 3 — Your request

  • What are you requesting?required
  • Which categories of data are you asking about?
  • What is incorrect and what should it say instead?
  • Reason for the deletion request
  • Preferred format and destination
  • Any other detail that will help us process this request

14 questions in total.

How the form changes as it's filled in

This template ships with 5 conditional rules, grouped into 5 behaviours driven by 2 questions. Everything below is already set up — edit or delete any rule once the template is in your workspace.

Driven by “Are you submitting this on someone else's behalf?

  • Reveals questions

    If “Are you submitting this on someone else's behalf?” is Yes, the form reveals “Your relationship to the individual and authority to act”.

Driven by “What are you requesting?

  • Reveals questions

    If “What are you requesting?” is Access to my data, the form reveals “Which categories of data are you asking about?”.

  • Reveals questions

    If “What are you requesting?” is Correction of my data, the form reveals “What is incorrect and what should it say instead?”.

  • Reveals questions

    If “What are you requesting?” is Deletion of my data, the form reveals “Reason for the deletion request”.

  • Reveals questions

    If “What are you requesting?” is Portability of my data, the form reveals “Preferred format and destination”.

Set it up step by step

  1. 1

    Confirm identity before releasing anything

    Use the reference and address fields as a first check, and have a documented fallback for stronger verification before any data leaves the organization.

  2. 2

    Route by request type, not by inbox order

    Correction and deletion requests usually need a different reviewer than access requests — use the branch to trigger the right internal workflow.

  3. 3

    State your real response window

    Replace the generic timing note with the exact period your organization commits to, confirmed with your privacy counsel.

  4. 4

    Log every request, even declined ones

    Keep a record of the request and the outcome regardless of whether you fulfil it, in case the decision is challenged later.

Mistakes to avoid

  • Acting on a request before any identity check, especially for deletion requests.
  • Leaving 'what are you requesting' as a single free-text box instead of a branch, which slows down routing.
  • Not logging requests that are declined or only partially fulfilled.

What it pairs with

Most teams don't run this form on its own. These are the forms and systems it sits next to.

  • Privacy Complaint Form
  • Cookie Consent Preferences Form
  • Legal Intake Form

What to do with the responses

Log the request with a due date based on your response window, verify identity through your standard process, and route it to the team responsible for the affected system.

Works in both layouts

These pages cover the same subject ground as the gdpr data subject access request form, matched on the words people actually search for.

Privacy & compliance

This form collects identity or financial details. Enable encrypted answers on the sensitive fields, avoid emailing full values in notifications, and delete responses once the check is complete.

Frequently asked questions

Does this form make our organization GDPR compliant?

No — this is a structured intake form, not legal advice or a compliance certification. Your privacy counsel should confirm response timelines, legal grounds and verification steps for your jurisdiction.

What if the requester won't provide identification?

You can still log the request and use other reasonable means to verify identity — the upload field here is optional precisely because ID isn't always the right first ask.

Can this be used for CCPA or other privacy law requests too?

The structure works for similar access/correction/deletion regimes, but rename the request-type options and legal-ground wording to match the specific law, ideally with counsel's input.

Should the representative field be required?

Only make it required when 'Are you submitting this on someone else's behalf?' is Yes — that's exactly what the logic rule here does.

Is the GDPR Data Subject Access Request Form template free to use?

Yes. You can preview and test GDPR Data Subject Access Request Form on this page without an account, and take a copy into your own HelloForms workspace on the free plan. There is nothing to install and no card required to publish it.

What does the GDPR Data Subject Access Request Form template ask for?

It asks 14 questions across 3 pages, 5 of which are required. Every question is listed in full further down this page, and each one can be renamed, reordered, made optional or deleted after you copy the template.

Can I edit the GDPR Data Subject Access Request Form form after copying it?

Yes — the copy is entirely yours. Change wording, add or remove questions, switch between the classic and card layouts, restyle it to match your brand, and set who gets notified on each submission.

How does the conditional logic in this legal & professional services form work?

5 conditional rules ship with the template: Features advanced show logic: if “Are you submitting this on someone else's behalf?” is Yes, the form dynamically exposes “Your relationship to the individual and authority to act”. Otherwise that question never appears. Features advanced show logic: if “What are you requesting?” is Access to my data, the form dynamically exposes “Which categories of data are you asking about?”. Otherwise that question never appears. Features advanced show logic: if “What are you requesting?” is Correction of my data, the form dynamically exposes “What is incorrect and what should it say instead?”. Otherwise that question never appears. All rules are editable in the Logic tab.

Where do responses to the GDPR Data Subject Access Request Form form go?

Submissions land in your workspace under Submissions, where you can search, filter, label and export them to CSV or PDF. You can also email a notification to your team on every submission and send the respondent an auto-reply.

Can I embed the GDPR Data Subject Access Request Form form on my own website?

Yes. Publish the form and paste the embed snippet into any page or share the direct link. The embedded form resizes to fit its container and loads no advertising or marketing trackers inside the iframe.

Can respondents upload files?

Yes. This template includes a file upload question, so respondents can attach documents or photos with their answers. You can adjust the accepted file types and size limits on that question.

More forms teams pair with the gdpr data subject access request form.

Related categories