Cybersecurity Awareness Month in Focus, Part I: Practical Data Rights Request Compliance Tips for U.S. Privacy Leaders
As the dust settles around the latest round of U.S. comprehensive state privacy laws that took effect in 2025, HR and business leaders in the United States may face new or heightened compliance obligations, including for data subject rights requests. Although the right to access data is only one of many data subject rights, data subject rights are typically referred to collectively as “DSARs,” or data subject access requests. This article, which offers pragmatic steps for navigating three common pitfalls when fielding and responding to DSARs under U.S. state privacy laws, is the first article in a four-part series aligned with Cybersecurity Awareness Month, which occurs annually in October. Parts 2 and 3 discuss tips and strategies under analogous privacy laws in Canada and the European Union, and Part 4 covers the considerations for responsible use of artificial intelligence (AI) and automated decisionmaking tools.