The month a data subject access request landed in my support inbox at $43K MRR: a founder diary (2026)
A composite founder diary (2026): at $43K MRR a sixteen-word email asking for "everything you have on me" turned out to be a valid data subject access request with a one month deadline that had already been running for nine days. What Article 15 actually requires, the eleven systems holding the data, why nine of the fourteen hours went on redaction rather than export, and the one scoping lever in Recital 63 that halved the work.
In this story
“Hi, can you send me everything you have on me? Thanks.”
That was the whole message. No legal language, no mention of any regulation, no formal request form, no solicitor cc'd. Sixteen words in my shared support inbox on a Friday afternoon, from a customer who had been paying me $49 a month for about fourteen months. I was at $43,000 MRR in 2026 and I did not read it for nine days, because it did not look like anything.
Quick answer (2026): This is a composite founder diary about receiving a data subject access request as a solo SaaS operator at $43K MRR. Three things cost me. The request was valid even though it never used the words "access request", the one month deadline started when it reached my inbox rather than when I read it (nine days gone before I began), and "all my data" turned out to live in eleven separate systems, four of which I had forgotten I owned. It took fourteen hours, nine of them redaction rather than export, and I could not charge a cent for any of it. The second one took forty minutes, because by then I had written down where everything was.
What made it a legal deadline instead of a support ticket
I want to be precise about the two facts that turned sixteen casual words into a countdown, because both of them are things I would have got wrong if you had asked me the week before.
First: there are no magic words. I had a vague assumption that a formal request would arrive formally. It does not have to. Ireland's Data Protection Commission puts it plainly: "the GDPR does not set out any particular method for making a valid access request" (Data Protection Commission). It can be written or spoken, it can go to any address the company publishes, it does not need to cite an article number, and the person does not have to explain why they want it. "Send me everything you have on me" is a request under Article 15. So is the same sentence typed into a live chat widget at 2am.
Second, and this is the expensive one: the clock starts on receipt, not on reading. Article 12(3) says the controller shall provide the information "without undue delay and in any event within one month of receipt of the request" (GDPR Article 12). Receipt means my organisation received it. My organisation is me and a shared inbox, and the shared inbox received it on the Friday. Nobody pauses the month while a founder triages.
So when I finally opened it, I did not have a month. I had twenty one days, and I had spent the first nine of them doing nothing, for a reason that would sound exactly as bad written down in a complaint as it does here.
There is an extension, and I want to note it because I nearly missed it too. Article 12(3) allows two further months "where necessary, taking into account the complexity and number of the requests", but you have to tell the person you are taking it, with reasons, within the original month. An extension you remember on day thirty two is not an extension.
Am I even in scope
I am a US founder with a US company. I assumed for about an hour that this was somebody else's problem.
It is not, and the test is embarrassingly simple: the regulation applies to a controller outside the EU where the processing relates to "the offering of goods or services" to people in the Union, whether or not payment is required (GDPR Article 3). I have a pricing page in euros. About 9% of my accounts have EU billing addresses. I am offering a service to people in the Union. That is the whole analysis.
And the American version is not a way out either. California gives a consumer a right to know, and a business has 45 calendar days to respond, extendable by another 45 if you notify them, free of charge (California Attorney General). Different clock, same shape of work. I have far more California customers than EU ones. The only reason this arrived as a European request first is that a European customer happened to ask first.
What "everything you have on me" actually means
I had assumed this meant a database export. It does not. Article 15(1) is a list of eight things you have to tell the person, and then Article 15(3) separately requires "a copy of the personal data undergoing processing" (GDPR Article 15). The eight include the purposes of processing, the categories of data, the retention period, their other rights, their right to complain to a supervisory authority, and, the one that did the damage:
(c) the recipients or categories of recipient to whom the personal data have or will be disclosed
Every vendor I hand customer data to is a recipient. So the question is not "what is in my database". The question is "what is in every system I have ever piped a customer email into", and I had never once written that list down.
Here is the list, reconstructed over two evenings.
Scroll to see more
| # | System | Personal data it held | Did I think of it unprompted? |
|---|---|---|---|
| 1 | Account row, name, email, billing address, last-seen IP | Yes | |
| 2 | Customer object, card fingerprint, billing address, invoice history | Yes | |
| 3 | Support desk | Every ticket, every reply, every internal note | Yes |
| 4 | Transactional email provider | Delivery logs, opens, bounce and suppression records | Yes |
| 5 | Product analytics | Full event stream keyed to their user id | Yes |
| 6 | Database backups | Thirty five daily snapshots, each containing all of the above | Yes, reluctantly |
| 7 | Onboarding call notes | A shared doc with their name and what they told me | Yes |
| 8 | Error events with user context and request breadcrumbs | No | |
| 9 | IP addresses joined to request paths | No | |
| 10 | Marketing email tool | Subscription state, tags, campaign opens, suppression list | No |
| 11 | My personal inbox | Fourteen months of direct threads with this person | No |
Eleven systems. Four I did not think of on my own, and the fourth one is the one that should worry you, because it is not a vendor at all. It is my own email client. I had been having a friendly ongoing conversation with this customer for over a year outside the support desk entirely, and none of my tooling knew that existed.
If you take one operational thing from this diary, take that table shape. Not my rows. Yours.
The nine hours nobody warns you about
I had budgeted for export. Export was fine. Export was about three hours of scripts and CSV downloads and clicking through vendor dashboards looking for the button.
The work was redaction, and the reason is a single sentence in Article 15(4): "The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others." Recital 63 widens that to trade secrets and intellectual property, "and in particular the copyright protecting the software" (Recital 63).
Which sounds abstract until you open a fourteen month support history and find that:
- Three threads are group emails with two other named customers from the same company on them.
- One ticket is a bug report that quotes a different customer's account name in a stack trace.
- Two internal notes discuss a pricing exception I gave them, and mention by name the reseller who introduced them.
- A referral record ties them to another user's account.
Every one of those has to be handled individually. There is no filter for it. It is a person reading, deciding, and blacking out, line by line, and it took me about nine hours to do fourteen months.
Now the part I got wrong, and it is the most common thing I have seen founders get wrong since. I assumed my internal notes were exempt because they were internal. They are not. An opinion recorded about a person is generally still that person's personal data, and "we wrote it in a private field" is not a category the regulation recognises. What Article 15(4) protects is other people's data inside those notes, not my comfort about what I wrote. So the reseller's name came out. My assessment of the customer stayed in, and they read it.
It was a fair assessment. I got lucky. I have written notes about other accounts that I would not want to defend in writing, and the honest reason I have stopped doing that is not professionalism. It is this Friday afternoon.
The one lever that halved the work
Buried in Recital 63 is the only cost control anybody handed me, and I have never seen it mentioned in a vendor explainer:
Where the controller processes a large quantity of information concerning the data subject, the controller should be able to request that, before the information is delivered, the data subject specify the information or processing activities to which the request relates.
So I asked. Politely, once, on day thirteen, with a genuine list of what I held and an offer to send all of it if they wanted it. They came back within a day: the support conversations, and whatever I had tied to their company. Not the analytics event stream. Not the CDN logs.
That is not a refusal and it is not a negotiation. They keep the right to the rest at any time. But it turned an unbounded job into a defined one, and it cut the remaining work roughly in half. It also has an obvious failure mode you should not walk into: if you ask in a way that reads as an obstacle, you have not scoped a request, you have discouraged one, and the same recital that gives you the lever is not going to help you explain that.
Two smaller things from the same territory. Article 12(6) lets you ask for more information to confirm identity where you have reasonable doubts, which for me meant replying from the account email rather than accepting a forwarded message. And under Article 12(5) all of this is "provided free of charge" unless the request is manifestly unfounded or excessive, and if you want to claim that, "the controller shall bear the burden of demonstrating" it. One ordinary request from one paying customer is not that, and it was never close.
What it cost
Fourteen hours. Three of export, nine of redaction, two of reading the actual regulation instead of a vendor blog post about the regulation.
I bill contract work at $150 an hour, so that is $2,100 of my time that I could not invoice to anyone. At $43K MRR I am turning over roughly $1,430 a day, so one sixteen-word email cost about a day and a half of revenue. There is no line item for it. It does not appear on any dashboard I own. If I had received four of them in the same month, which is entirely possible and which nothing prevents, it would have been most of a working week and the price would have been identical, which is to say nothing.
The comparison I keep coming back to is the enterprise security questionnaire I wrote about at $34K MRR, the one that nearly killed my biggest deal. That was 200 questions and a week of work, and it was attached to a contract worth five figures. This was sixteen words attached to $49 a month, and the obligation was not smaller. That asymmetry is the actual shape of compliance for a small operator, and nobody prices it in when they model a self-serve tier.
The backup question, honestly
I said thirty five daily snapshots. Somebody always asks what I did about them, so: I disclosed that backups exist, described what they contain and how long they are kept, and did not attempt to extract this person's rows from thirty five compressed archives.
I am not going to dress that up as a settled legal position, because it is not one, and this is a diary rather than advice. It is what my specialist advised, on the reasoning that backups are a restoration mechanism rather than an accessible processing system, and that the honest disclosure of their existence and retention window is the part that actually matters to the person asking. If your backups are trivially queryable, that reasoning is weaker for you than it was for me. Ask someone qualified. I did, and it was the best money in this whole story.
What I changed
Four things, and only one of them is technical.
A runbook, which is just that table with queries in it. Eleven systems, the exact export command or dashboard path for each, and who at the vendor to email if the export button lies. It took an afternoon to write. The next request, which arrived about seven weeks later, took forty minutes.
A privacy@ alias that routes into the support desk with its own tag, and a rule that the tag starts a thirty day timer on the timestamp of arrival. Not on the timestamp of reading. That single rule is the entire fix for the nine days, and it cost nothing.
A self-serve data export in the product. Recital 63 nudges directly at this: "where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data." Mine does not cover everything and I do not pretend it does, but it covers the database and the invoices, which is most of what people actually want.
A sub-processor register I keep current, because Article 15(1)(c) requires me to name recipients anyway and I would rather maintain one list than reconstruct it under a deadline. It is a markdown file. It has eleven rows. It is the single highest return per byte of anything I have ever written down about my own business, and it took me until the month I lost a day of customer data and this month to learn the same lesson twice, from two directions, about knowing where things are.
What actually happened
MRR went from $43K to about $44K over the following two months, which has nothing to do with any of this. Nobody churned. The customer who asked is still a customer and never told me why they asked, which is their right, and I have decided it does not matter. Curiosity, a job at a company with a policy, a competitor, or a bad week: the work is identical and the deadline is identical, and building a process that depends on the requester's motive is building nothing.
What changed is that a category of open-ended obligation became a forty minute task with a checklist. I did not get more compliant in any way a regulator would notice. I got faster, and I stopped being one unread Friday email away from a deadline I had already half spent.
The one thing I would tell you
Write down where the data is, before anybody asks you.
Not a policy. Not a page on your website. A list, with a system on each row and the export path next to it, including the systems that are not vendors: your own inbox, your notes app, the spreadsheet from the beta. Take an afternoon. You will find at least one system you had forgotten, and finding it on an ordinary Tuesday costs you nothing, whereas finding it on day twenty one of a thirty day clock costs you an evening and a small pit in your stomach.
The request itself was never the hard part. Sixteen words is not hard. The hard part was that I had spent two years accumulating places, and had never once made a list of them.
Written by
Anya PetrovaAnya Petrova writes first-person founder diaries for OperatorBook, reconstructed as composites from interviews with bootstrapped SaaS founders. She focuses on the months that do not make the highlight reel: the pricing changes, the churn scares, and the quiet operational decisions that move MRR.
Frequently asked questions
Is this a real founder's diary?
It is a composite. The founder is a blend of several bootstrapped SaaS operators who handled data subject access requests in 2026. The MRR figures (about $43K rising to roughly $44K), the roughly $49 price point, the eleven systems, the fourteen hours and the nine-day delay before the request was read are self-reported and lightly rounded, but the legal mechanics, the arithmetic and the operational fixes are real and every legal claim is sourced to the regulation text or a supervisory authority. No single named customer, company or request is described.
What are data subject access requests?
A data subject access request, often shortened to DSAR or SAR, is a person exercising their right under Article 15 of the GDPR to find out whether an organisation is processing their personal data and, if so, to get a copy of it plus eight categories of information about the processing: the purposes, the categories of data, the recipients it has been disclosed to, the retention period, their rights to rectification and erasure, their right to complain to a supervisory authority, the source of the data if it did not come from them, and details of any automated decision-making.
What is an example of a DSAR request?
"Can you send me everything you have on me?" is one. That is the entire request in this diary. The Irish Data Protection Commission states that the GDPR does not set out any particular method for making a valid access request, so it can be written or spoken, it can arrive through any channel the company publishes including a support inbox or a chat widget, and it does not need to cite Article 15 or use the words "access request" at all. The requester also does not have to say why they want it.
How long do you have to respond to a data subject access request?
Article 12(3) requires a response without undue delay and in any event within one month of receipt of the request. Receipt means when your organisation received it, not when a person read it, so a message sitting unopened in a shared inbox is already consuming the deadline. The month can be extended by two further months where necessary given the complexity and number of requests, but you must notify the requester of the extension, with reasons, inside the original month. Under the CCPA the equivalent clock for a California consumer request to know is 45 days, extendable by another 45 with notice.
Can you charge for responding to a DSAR?
Almost never. Article 12(5) says information and communications shall be provided free of charge. A controller may charge a reasonable fee based on administrative costs, or refuse to act, only where a request is manifestly unfounded or excessive, in particular because of its repetitive character, and Article 12(5) puts the burden of demonstrating that on the controller. A single ordinary request from a paying customer does not come close, so the hours are yours.
What grounds can a subject access request be refused?
Two narrow ones are relevant to a small operator. Article 12(5) allows refusal where the request is manifestly unfounded or excessive, with the burden of proof on the controller. And Article 15(4) says the right to obtain a copy shall not adversely affect the rights and freedoms of others, which Recital 63 extends to trade secrets and intellectual property including the copyright protecting the software. In practice that is not a ground to refuse the request, it is a ground to redact other people's personal data out of the copy you send.
Are internal notes about a customer disclosable?
Generally yes, and this is the assumption founders most often get wrong. An opinion recorded about a person is still that person's personal data, and storing it in a private or internal field is not a category the regulation recognises. What Article 15(4) protects is other people's data inside those notes, not the author's comfort about what they wrote. The practical consequence is that the redaction pass removes third-party names and details while your assessment of the requester stays in and they read it.
Do database backups have to be searched for a DSAR?
This is genuinely contested rather than settled, so treat any confident answer with suspicion. The approach taken in this diary, on specialist advice, was to disclose that backups exist, describe what they contain and their retention window, and not attempt to extract individual rows from thirty five compressed archives, on the reasoning that backups are a restoration mechanism rather than an accessible processing system. That reasoning is weaker if your backups are trivially queryable. It is a question for a qualified adviser, not for a blog post.
Does the GDPR apply to a US company with a few EU customers?
Yes, if you are offering goods or services to people in the Union. Article 3(2) applies the regulation to a controller outside the EU where the processing relates to the offering of goods or services to data subjects in the Union, whether or not payment is required. Having a pricing page in euros and a percentage of accounts with EU billing addresses is enough. There is no small-company exemption from the right of access.
More stories
The month a security questionnaire nearly killed my biggest deal at $34K MRR: a founder diary (2026)
At $34K MRR, running solo, a 214-question security questionnaire and a SOC 2 ask nearly froze my biggest deal. The interim packet that closed it, and what it really cost.
The month I lost a day of customer data at $40K MRR: a data-loss diary (2026)
In 2026, the fastest way to lose your biggest customer is a backup you never tested. A composite founder diary about the night a botched production migration erased roughly 22 hours of customer data at $40K MRR, when the newer backup had been failing silently for months and the freshest clean copy was almost a day old. It covers what was lost, the email that had to go out, the agency that churned, and the restore-drill and point-in-time-recovery changes that cut the recovery point objective from about a day to five minutes.
The month a website accessibility lawsuit threat landed at $45K MRR: a founder diary (2026)
A composite founder diary (2026): at $45K MRR a twelve page ADA demand letter arrived by certified mail alleging eleven barriers and giving fourteen days to respond. Why a demand letter is not a website accessibility lawsuit and what that changes, why the published filing counts of 3,117 and 4,928 describe a category I was not in, the overlay widget I nearly bought at 11pm, the nine defects behind the eleven allegations, and what the whole month actually cost.