If you operate in or handle candidate data from the UK or EU, DSAR is an acronym you need in your daily vocabulary.
Here is a quick breakdown of what a DSAR is, why job applicants use them, and how recent court rulings change the game for CRAs and screening vendors.
1. What does DSAR stand for?
DSAR stands for Data Subject Access Request.
Under Article 15 of the GDPR (and UK GDPR), any individual (the "Data Subject") has the legal right to ask any company (the "Data Controller") whether they are processing their personal data—and if so, to receive a full copy of that data.
2. How do job applicants use DSARs in screening?
When a candidate is flagged or rejected during a background check, they often submit a DSAR to the screening agency or employer to:
- Inspect their file and see what adverse information was found.
- Challenge the accuracy of court records, employment history, or verification notes.
- Investigate potential legal claims against the employer or screening vendor.
3. The Big Shift: Recent European & UK Court Rulings
Recent landmark cases (Brillen Rottler in the EU and Ashley v HMRC in the UK) have set clear boundaries on how DSARs must be handled:
- Protection Against "DSAR Trolls": A DSAR can be legally rejected under Article 12(5) if an applicant submits it with proven abusive intent—such as trying to provoke a procedural error to manufacture a lawsuit.
- Data, Not Entire Documents: A candidate has a right to their personal data, not an unrestricted right to inspect your entire proprietary software archive or complete email mailboxes.
- Beyond the Final PDF: Sending only the completed PDF background report is no longer enough. Personal data residing in internal researcher notes, verification queue logs, or manual court record entries falls within the scope of a DSAR.
- It Must Be Intelligible: Handing over raw database codes or internal flags (like DISC-PEND-02) without explaining what they mean violates transparency rules.
The Bottom Line for Screening Professionals
A DSAR is not just a consumer dispute—it’s a formal data privacy mechanism. Ensuring your operations team knows how to pull internal research notes, translate disposition codes, and protect proprietary system data is essential for maintaining GDPR compliance.
