---
title: Data Subject Request what is it and how to do it?
description: "What is the Data Subject Request (DSR)
Data Subject Request Examples
Data Subject Request, should it also be done in SAP?

#AgleaSAPSecurity"
image: https://www.aglea.com/hubfs/Aglea/Imported_Blog_Media/DSR-Jun-14-2024-10-11-17-7686-AM.jpg
---

[linkedin](https://www.linkedin.com/company/292350?trk=vsrp_companies_res_name&trkInfo=VSRPsearchId%3A3373431891426179412478%2CVSRPtargetId%3A292350%2CVSRPcmpt%3Aprimary) [YouTube](https://www.youtube.com/c/AgleaSAPSecurity?sub_confirmation=1) [Twitter](https://twitter.com/AgleaItaly?lang=en)

[![Logo-Aglea-horsa-company](https://www.aglea.com/hubfs/Aglea/Aglea_November2018%20Theme/Images/Logo-Aglea-horsa-company.webp) ](https://www.aglea.com/en)

# Data Subject Request what is it and how to do it?

# Data Subject Request what is it and how to do it?

Posted by [Klea Duro](https://www.aglea.com/en/blog/author/klea-duro) on Jun 2, 2023 12:00:00 AM

- [Tweet](https://twitter.com/share)

Have you ever heard Data Subject Request (DSR)? It is a request to know where, what and how our personal data is handled.

 

![DSR](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/DSR-Jun-14-2024-10-11-17-7686-AM.jpg?width=517&name=DSR-Jun-14-2024-10-11-17-7686-AM.jpg)

 

In fact, every European citizen, through the GDPR (Art. 15), has the possibility to request a copy of his or her personal data for information purposes. Whatever service it is.

 

## What is the Data Subject Request (DSR)

This is a right that the European Data Protection Regulation ([GDPR](https://www.aglea.com/en/sap-gdpr)) has introduced.

 

Through this request, therefore, any interested party can request a copy of his or her managed personal data from the data holder.

 

## Data Subject Request Examples

Several platforms offer this option, usually under the menu called Privacy. [But are privacy and personal data the same thing](https://www.aglea.com/en/blog/corso-gdpr-general-data-protection-regulation)?

 

Let's look together at some examples in the various platforms. Starting with the SAP Universal ID platform. Through the Privacy menu, it is possible to request the deletion of your data (another right introduced by the GDPR) but also to request a copy of your data "Request data export"

 

- Universal ID -> SAP (the functionality present in SAP's Universal ID).

![SAP Universal ID Request](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/SAP%20Universal%20ID%20Request-Jun-14-2024-10-11-18-7089-AM.jpg?width=537&name=SAP%20Universal%20ID%20Request-Jun-14-2024-10-11-18-7089-AM.jpg)

 

It is also possible to do the same extraction in other platforms, such as, for example, Google.

 

- In the Google account settings via the "Data and privacy" menu you can do a "Download your data"
  
  ![Google](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/Google-Jun-14-2024-10-11-19-8731-AM.jpg?width=545&name=Google-Jun-14-2024-10-11-19-8731-AM.jpg)

Facebook also offers, clearly the same possibility, in the menu "Your information on Facebook" - "Access your information"

 

- Facebook

 

![Facebook](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/Facebook-Jun-14-2024-10-11-19-2818-AM.jpg?width=541&name=Facebook-Jun-14-2024-10-11-19-2818-AM.jpg)

 

But what do we find in this report? There is no common, standard form each platform often has different methods of providing this data. A ZIP archive with all the data, grouped in folders or not, additional data in more technical formats e.g. XML

 

## Data Subject Request, should it also be done in SAP?

In case there is data from interested parties ([read here about who are the figures under the GDPR](https://www.aglea.com/en/sap-gdpr)), it is necessary to define a procedure to deal with this request that might arise. But from whom? From Employees, suppliers or customers. Clearly in the latter cases they must be individuals.

 

In case your company's business is totally "business to business" so toward companies, you will probably have to handle this request only for employees.

 

In case data of customers or suppliers are saved within SAP systems as individuals then it will be necessary to activate the procedure for them as well.

 

## But what should I do then in SAP if I fall into the cases seen above?

There are several scenarios that can be explored. Also because of the complexity of the systems and the amount of data to be extracted.

 

In some SAP systems, for example, only the SAP ERP management system is involved (thus only one system) in a very limited way (the data of the stakeholders are in very specific tables).

 

In other more complex scenarios, the data of the interested party are "scattered" across multiple SAP systems. For example, ERP, not necessarily one. In the case of utilities in IS-U (Industry Solutions Utility) systems or CRM (Customer Relationship Management) or SRM (Supply Relationship Management) systems, in On premise or [Cloud](https://www.aglea.com/en/sap-security-cloud) systems.

 

Technology aspects can also clearly influence. Especially in a hybrid situation where some systems are on premise and others cloud.

 

In general, it can be helpful to follow these steps:

1. **Identify the case you are in** (do you need to manage data from employees, suppliers, customers, or a subset of these)?
2. **Identify what systems the data may be in **(note, you may also find non-SAP systems in the company here) you had thought that as much as you register visitors at the entrance, that too is personal data. What system are they in?
3. For real systems, **identify exactly where the personal data are**. When I say exactly I mean the very **tables and fields** (in the case of SAP) where this data resides. It becomes necessary to perform a mapping of this data across systems. In this context, in very complex scenarios, the paid Information Steward tool can be useful (read here what other [tools SAP offers for GDPR management](https://www.aglea.com/en/blog/gdpr-sap-quali-sono-i-sistemi/strumenti-coinvolti-0))
4. Identify which tools could be used to extract data 
     - In simpler cases, SE16 or similar tools could also be used ([how to use SE16 transaction](https://www.aglea.com/en/blog/se16-in-sap))
     - Evaluate whether it might be useful to use the tool that SAP has designed for this situation, namely the [Information Retrieval Framework (IRF](https://help.sap.com/docs/SAP_NETWEAVER_740/1b0aa06133bd47ce8843635a99ee8ef5/b7ce5c62b41947adbf034900bd7eb084.html))  
       ![IRF](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/IRF-Jun-14-2024-10-11-18-2720-AM.jpg?width=468&name=IRF-Jun-14-2024-10-11-18-2720-AM.jpg)
     - There are other tools on the market that may also offer alternative solutions, for example, the [EPI-USE ](https://app.hubspot.com/blog/4422290/editor/105978112420/content)suite or [Inquaero](https://www.youtube.com/watch?v=USDIFLFf1YA)
5. **Define the internal procedure** for what should be done in case of a request and who should take action. Define how interested parties can make this request, through an email request? Through a portal request?

 

Topics: [SAP GDPR](https://www.aglea.com/blog/tag/sap-gdpr), [gdpr](https://www.aglea.com/blog/tag/gdpr), [sap ilm](https://www.aglea.com/blog/tag/sap-ilm), [dsr](https://www.aglea.com/blog/tag/dsr), [data subject request gdpr](https://www.aglea.com/blog/tag/data-subject-request-gdpr), [data access subject request](https://www.aglea.com/blog/tag/data-access-subject-request)

### Subscribe Here!

### Blog Aglea, cosa puoi trovare?

Ogni mercoledì pubblichiamo articoli, interviste e documenti relativi alla security SAP.

Cosa puoi trovare:

- Suggerimenti su come mettere in sicurezza i sistemi SAP
- Come fare a … (How To)
- Checklist
- Gli errori comuni che spesso vengono fatti in ambito Security SAP
- Interviste con esperti del settore
- Chi è AGLEA quale è la nostra vision security SAP

### Recent Posts

### Post By Topic

- [SAP Security (12)](https://www.aglea.com/en/blog/tag/sap-security)
- [SAP GRC (11)](https://www.aglea.com/en/blog/tag/sap-grc)
- [pfcg (8)](https://www.aglea.com/en/blog/tag/pfcg)
- [gdpr (7)](https://www.aglea.com/en/blog/tag/gdpr)
- [SAP GDPR (5)](https://www.aglea.com/en/blog/tag/sap-gdpr)
- [Segregation of duties (5)](https://www.aglea.com/en/blog/tag/segregation-of-duties)
- [governance (5)](https://www.aglea.com/en/blog/tag/governance)
- [sod (5)](https://www.aglea.com/en/blog/tag/sod)
- [SAP ECC (4)](https://www.aglea.com/en/blog/tag/sap-ecc)
- [audit sap (4)](https://www.aglea.com/en/blog/tag/audit-sap)
- [auditing (4)](https://www.aglea.com/en/blog/tag/auditing)
- [sap consulenza security (4)](https://www.aglea.com/en/blog/tag/sap-consulenza-security)
- [sap password (4)](https://www.aglea.com/en/blog/tag/sap-password)
- [HANA (3)](https://www.aglea.com/en/blog/tag/hana)
- [SAP HR (3)](https://www.aglea.com/en/blog/tag/sap-hr)
- [UI logging (3)](https://www.aglea.com/en/blog/tag/ui-logging)
- [rfc security (3)](https://www.aglea.com/en/blog/tag/rfc-security)
- [sap cyber security (3)](https://www.aglea.com/en/blog/tag/sap-cyber-security)
- [sap hana (3)](https://www.aglea.com/en/blog/tag/sap-hana)
- [sap_all (3)](https://www.aglea.com/en/blog/tag/sap_all)
- [security audit log (3)](https://www.aglea.com/en/blog/tag/security-audit-log)
- [sicurezza sap (3)](https://www.aglea.com/en/blog/tag/sicurezza-sap)
- [su53 (3)](https://www.aglea.com/en/blog/tag/su53)
- [HANA Security (2)](https://www.aglea.com/en/blog/tag/hana-security)
- [ISO (2)](https://www.aglea.com/en/blog/tag/iso)
- [Profiles (2)](https://www.aglea.com/en/blog/tag/profiles)
- [SAP FIORI Security (2)](https://www.aglea.com/en/blog/tag/sap-fiori-security)
- [SAP audit (2)](https://www.aglea.com/en/blog/tag/sap-audit)
- [Secure programming (2)](https://www.aglea.com/en/blog/tag/secure-programming)
- [UCON (2)](https://www.aglea.com/en/blog/tag/ucon)
- [UI Masking (2)](https://www.aglea.com/en/blog/tag/ui-masking)
- [access management (2)](https://www.aglea.com/en/blog/tag/access-management)
- [authorization concept (2)](https://www.aglea.com/en/blog/tag/authorization-concept)
- [autorizzazioni sap (2)](https://www.aglea.com/en/blog/tag/autorizzazioni-sap)
- [consulenti (2)](https://www.aglea.com/en/blog/tag/consulenti)
- [corso (2)](https://www.aglea.com/en/blog/tag/corso)
- [e-learning (2)](https://www.aglea.com/en/blog/tag/e-learning)
- [password policy (2)](https://www.aglea.com/en/blog/tag/password-policy)
- [patch (2)](https://www.aglea.com/en/blog/tag/patch)
- [programmazione sicura (2)](https://www.aglea.com/en/blog/tag/programmazione-sicura)
- [quality (2)](https://www.aglea.com/en/blog/tag/quality)
- [rfc (2)](https://www.aglea.com/en/blog/tag/rfc)
- [ruoli (2)](https://www.aglea.com/en/blog/tag/ruoli)
- [sap access control (2)](https://www.aglea.com/en/blog/tag/sap-access-control)
- [sap custom (2)](https://www.aglea.com/en/blog/tag/sap-custom)
- [sap etd (2)](https://www.aglea.com/en/blog/tag/sap-etd)
- [sap gui (2)](https://www.aglea.com/en/blog/tag/sap-gui)
- [sap query (2)](https://www.aglea.com/en/blog/tag/sap-query)
- [sap security guidelines (2)](https://www.aglea.com/en/blog/tag/sap-security-guidelines)
- [sap siem (2)](https://www.aglea.com/en/blog/tag/sap-siem)
- [sap standard role (2)](https://www.aglea.com/en/blog/tag/sap-standard-role)
- [sap super user (2)](https://www.aglea.com/en/blog/tag/sap-super-user)
- [sap vulnerability (2)](https://www.aglea.com/en/blog/tag/sap-vulnerability)
- [se16 (2)](https://www.aglea.com/en/blog/tag/se16)
- [security ams (2)](https://www.aglea.com/en/blog/tag/security-ams)
- [siem (2)](https://www.aglea.com/en/blog/tag/siem)
- [soar (2)](https://www.aglea.com/en/blog/tag/soar)
- [supporto sap ams (2)](https://www.aglea.com/en/blog/tag/supporto-sap-ams)
- [test system (2)](https://www.aglea.com/en/blog/tag/test-system)
- [threat detection (2)](https://www.aglea.com/en/blog/tag/threat-detection)
- [upgrade (2)](https://www.aglea.com/en/blog/tag/upgrade)
- [312 (1)](https://www.aglea.com/en/blog/tag/312)
- [ABAP (1)](https://www.aglea.com/en/blog/tag/abap)
- [AI (1)](https://www.aglea.com/en/blog/tag/ai)
- [CVA (1)](https://www.aglea.com/en/blog/tag/cva)
- [DPO (1)](https://www.aglea.com/en/blog/tag/dpo)
- [FIORI Security (1)](https://www.aglea.com/en/blog/tag/fiori-security)
- [HANA Roles (1)](https://www.aglea.com/en/blog/tag/hana-roles)
- [PFCG SAP transaction (1)](https://www.aglea.com/en/blog/tag/pfcg-sap-transaction)
- [SAP Cloud Security (1)](https://www.aglea.com/en/blog/tag/sap-cloud-security)
- [SAP Consulting (1)](https://www.aglea.com/en/blog/tag/sap-consulting)
- [SAP DLP (1)](https://www.aglea.com/en/blog/tag/sap-dlp)
- [SAP Fraud Management (1)](https://www.aglea.com/en/blog/tag/sap-fraud-management)
- [SAP IDM (1)](https://www.aglea.com/en/blog/tag/sap-idm)
- [SAP LOG (1)](https://www.aglea.com/en/blog/tag/sap-log)
- [SAP Security Documentation (1)](https://www.aglea.com/en/blog/tag/sap-security-documentation)
- [SAP Table (1)](https://www.aglea.com/en/blog/tag/sap-table)
- [SAP Transactions (1)](https://www.aglea.com/en/blog/tag/sap-transactions)
- [SPOOL (1)](https://www.aglea.com/en/blog/tag/spool)
- [Security Analyzer (1)](https://www.aglea.com/en/blog/tag/security-analyzer)
- [Statistiche security SAP (1)](https://www.aglea.com/en/blog/tag/statistiche-security-sap)
- [Trace autorizzazioni SAP (1)](https://www.aglea.com/en/blog/tag/trace-autorizzazioni-sap)
- [User Access Management (1)](https://www.aglea.com/en/blog/tag/user-access-management)
- [aglea (1)](https://www.aglea.com/en/blog/tag/aglea)
- [audit (1)](https://www.aglea.com/en/blog/tag/audit)
- [authorization model (1)](https://www.aglea.com/en/blog/tag/authorization-model)
- [biometric (1)](https://www.aglea.com/en/blog/tag/biometric)
- [chatGPT (1)](https://www.aglea.com/en/blog/tag/chatgpt)
- [codice sicuro SAP (1)](https://www.aglea.com/en/blog/tag/codice-sicuro-sap)
- [consulenti sap security (1)](https://www.aglea.com/en/blog/tag/consulenti-sap-security)
- [consulenza sap security (1)](https://www.aglea.com/en/blog/tag/consulenza-sap-security)
- [crittografia SAP (1)](https://www.aglea.com/en/blog/tag/crittografia-sap)
- [custom transactions (1)](https://www.aglea.com/en/blog/tag/custom-transactions)
- [cyber security (1)](https://www.aglea.com/en/blog/tag/cyber-security)
- [data loss prevention (1)](https://www.aglea.com/en/blog/tag/data-loss-prevention)
- [data privacy (1)](https://www.aglea.com/en/blog/tag/data-privacy)
- [documentazione sap security (1)](https://www.aglea.com/en/blog/tag/documentazione-sap-security)
- [emergency users (1)](https://www.aglea.com/en/blog/tag/emergency-users)
- [gxp (1)](https://www.aglea.com/en/blog/tag/gxp)
- [identity management system (1)](https://www.aglea.com/en/blog/tag/identity-management-system)
- [idm (1)](https://www.aglea.com/en/blog/tag/idm)
- [log sap (1)](https://www.aglea.com/en/blog/tag/log-sap)
- [mail security sap (1)](https://www.aglea.com/en/blog/tag/mail-security-sap)
- [microsoft (1)](https://www.aglea.com/en/blog/tag/microsoft)
- [parameter sap (1)](https://www.aglea.com/en/blog/tag/parameter-sap)
- [processi security (1)](https://www.aglea.com/en/blog/tag/processi-security)
- [profili (1)](https://www.aglea.com/en/blog/tag/profili)
- [profili sap (1)](https://www.aglea.com/en/blog/tag/profili-sap)
- [progetti security sap (1)](https://www.aglea.com/en/blog/tag/progetti-security-sap)
- [quotazione borsa (1)](https://www.aglea.com/en/blog/tag/quotazione-borsa)
- [rfc destination (1)](https://www.aglea.com/en/blog/tag/rfc-destination)
- [role translation (1)](https://www.aglea.com/en/blog/tag/role-translation)
- [s_tabu_dis (1)](https://www.aglea.com/en/blog/tag/s_tabu_dis)
- [s_tabu_nam (1)](https://www.aglea.com/en/blog/tag/s_tabu_nam)
- [s_tabu_rfc (1)](https://www.aglea.com/en/blog/tag/s_tabu_rfc)
- [sap FIORI (1)](https://www.aglea.com/en/blog/tag/sap-fiori)
- [sap btp (1)](https://www.aglea.com/en/blog/tag/sap-btp)
- [sap data masking (1)](https://www.aglea.com/en/blog/tag/sap-data-masking)
- [sap dati personali (1)](https://www.aglea.com/en/blog/tag/sap-dati-personali)
- [sap developer (1)](https://www.aglea.com/en/blog/tag/sap-developer)
- [sap earlywatch (1)](https://www.aglea.com/en/blog/tag/sap-earlywatch)
- [sap grc 12 (1)](https://www.aglea.com/en/blog/tag/sap-grc-12)
- [sap grc tables (1)](https://www.aglea.com/en/blog/tag/sap-grc-tables)
- [sap gui history (1)](https://www.aglea.com/en/blog/tag/sap-gui-history)
- [sap gui security (1)](https://www.aglea.com/en/blog/tag/sap-gui-security)
- [sap gxp compliance (1)](https://www.aglea.com/en/blog/tag/sap-gxp-compliance)
- [sap ilm gdpr (1)](https://www.aglea.com/en/blog/tag/sap-ilm-gdpr)
- [sap license auditing (1)](https://www.aglea.com/en/blog/tag/sap-license-auditing)
- [sap logon (1)](https://www.aglea.com/en/blog/tag/sap-logon)
- [sap patch (1)](https://www.aglea.com/en/blog/tag/sap-patch)
- [sap security blog (1)](https://www.aglea.com/en/blog/tag/sap-security-blog)
- [sap security teal (1)](https://www.aglea.com/en/blog/tag/sap-security-teal)
- [sap sos (1)](https://www.aglea.com/en/blog/tag/sap-sos)
- [sap splunk (1)](https://www.aglea.com/en/blog/tag/sap-splunk)
- [sap sso (1)](https://www.aglea.com/en/blog/tag/sap-sso)
- [sap tabelle custom (1)](https://www.aglea.com/en/blog/tag/sap-tabelle-custom)
- [sap tdms (1)](https://www.aglea.com/en/blog/tag/sap-tdms)
- [sap_all_only_view (1)](https://www.aglea.com/en/blog/tag/sap_all_only_view)
- [se16n (1)](https://www.aglea.com/en/blog/tag/se16n)
- [secpol (1)](https://www.aglea.com/en/blog/tag/secpol)
- [secure coding sap (1)](https://www.aglea.com/en/blog/tag/secure-coding-sap)
- [secure operation map (1)](https://www.aglea.com/en/blog/tag/secure-operation-map)
- [security awareness (1)](https://www.aglea.com/en/blog/tag/security-awareness)
- [security bridge (1)](https://www.aglea.com/en/blog/tag/security-bridge)
- [sentinel (1)](https://www.aglea.com/en/blog/tag/sentinel)
- [sicurezza codice ABAP (1)](https://www.aglea.com/en/blog/tag/sicurezza-codice-abap)
- [sicurezza dei dati sap (1)](https://www.aglea.com/en/blog/tag/sicurezza-dei-dati-sap)
- [slaw (1)](https://www.aglea.com/en/blog/tag/slaw)
- [social engineering (1)](https://www.aglea.com/en/blog/tag/social-engineering)
- [sost (1)](https://www.aglea.com/en/blog/tag/sost)
- [sql (1)](https://www.aglea.com/en/blog/tag/sql)
- [su25 (1)](https://www.aglea.com/en/blog/tag/su25)
- [super utenti sap (1)](https://www.aglea.com/en/blog/tag/super-utenti-sap)
- [system users (1)](https://www.aglea.com/en/blog/tag/system-users)
- [tabelle (1)](https://www.aglea.com/en/blog/tag/tabelle)
- [tabelle SAP grc access control (1)](https://www.aglea.com/en/blog/tag/tabelle-sap-grc-access-control)
- [ticket management system (1)](https://www.aglea.com/en/blog/tag/ticket-management-system)
- [training (1)](https://www.aglea.com/en/blog/tag/training)
- [transazioni sap (1)](https://www.aglea.com/en/blog/tag/transazioni-sap)
- [userid (1)](https://www.aglea.com/en/blog/tag/userid)
- [usmm (1)](https://www.aglea.com/en/blog/tag/usmm)
- [ust04 (1)](https://www.aglea.com/en/blog/tag/ust04)
- [zero trust security (1)](https://www.aglea.com/en/blog/tag/zero-trust-security)

[See all](https://www.aglea.com/en/blog/data-subject-request-what-is-it-and-how-to-do-it#)

## [SAP Security Blog AGLEA RSS Feed](https://www.aglea.com/blog/rss.xml)

Aglea s.r.l. P. IVA: IT 03868780960 - 2026  | Copy | [Note legali](https://cdn2.hubspot.net/hubfs/4422290/Aglea_November2018%20Theme/Pdfs/Privacy-policy-AGLEA.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Klea Duro",
    "url" : "https://www.aglea.com/en/blog/author/klea-duro"
  },
  "dateModified" : "2024-06-14T10:12:46.878Z",
  "datePublished" : "2023-06-01T22:00:00.000Z",
  "headline" : "Data Subject Request what is it and how to do it?",
  "image" : [ "https://www.aglea.com/hubfs/Aglea/Imported_Blog_Media/DSR-Jun-14-2024-10-11-17-7686-AM.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.aglea.com/en/blog/data-subject-request-what-is-it-and-how-to-do-it",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    },
    "name" : "Horsa S.p.A."
  }
}
```