Home / Guides / Mastering the DAZN’s Access Request Saga: A Practical Guide for Website Owners

Website Compliance

Mastering the DAZN’s Access Request Saga: A Practical Guide for Website Owners

This guide explores the DAZN’s access request saga and its implications for website GDPR compliance. It covers practical steps for implementing DSAR processes, consent management, and disclosure practices, with a focus on using GDPRChecker for validation. Learn to avoid common mistakes and ensure your site meets regulatory expectations.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

July 2026

Reading time

9 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

Introduction

*Updated for 2026 compliance practices.*

The DAZN’s access request saga has become a pivotal case study for website owners navigating the complexities of GDPR compliance. This saga highlights the critical importance of handling Data Subject Access Requests (DSARs) effectively, ensuring that consent mechanisms, tag management, and privacy disclosures are not only in place but also verifiable. For website owners, the DAZN’s access request saga serves as a wake-up call: without robust processes, you risk non-compliance, user distrust, and potential regulatory scrutiny. This guide provides a practical, step-by-step approach to understanding and implementing the necessary measures, using GDPRChecker to validate your efforts. Remember, this is technical implementation guidance, not legal advice.

What the DAZN’s Access Request Saga Means for Website Owners

The DAZN’s access request saga underscores a fundamental GDPR principle: individuals have the right to access their personal data. For website owners, this means you must be able to respond to DSARs promptly and comprehensively. The saga revealed gaps in how organizations handle user data, particularly around consent and disclosure. When a user submits an access request, you need to provide all personal data you hold, including data collected via cookies, tags, and other tracking technologies. This requires a clear understanding of your data flows and the ability to extract and present that data in a usable format. The DAZN’s access request saga also highlights the need for transparency—users must know what data is collected and how to request access. Without this, you risk complaints and enforcement actions.

Requirements and Compliance Expectations

To avoid the pitfalls seen in the DAZN’s access request saga, website owners must meet several compliance expectations. First, you must have a lawful basis for processing personal data, typically consent for non-essential cookies and tags. Consent must be freely given, specific, informed, and unambiguous, as outlined by the European Data Protection Board (EDPB). This means your cookie banner cannot use dark patterns or pre-ticked boxes. Second, you must maintain records of consent and be able to demonstrate compliance. Third, your privacy policy must clearly explain how users can exercise their rights, including access requests. Finally, you must respond to DSARs within one month, providing data in a structured, commonly used format. These requirements are not just theoretical; they are enforceable, and the DAZN’s access request saga shows the consequences of non-compliance.

How to Implement Step by Step

Implementing a robust DSAR process involves several concrete steps. Start by mapping all data collection points on your website. Identify every tag, cookie, and third-party service that processes personal data. Use a tag management system to control when and how tags fire based on consent. For example, configure Google Consent Mode to adjust tag behavior according to user consent choices, as detailed in Google’s official guidance. Next, set up a dedicated DSAR handling procedure. This should include a verification step to confirm the requester’s identity, a method to collect and compile data from all systems, and a secure delivery mechanism. Test your process regularly with dummy requests to ensure it works end-to-end. Finally, document everything—regulators will expect evidence of your compliance efforts.

Step 1: Audit Your Data Collection

Begin by auditing all data collection on your site. List every cookie, pixel, and script that collects personal data, including analytics, advertising, and functional tools. For each, note the purpose, legal basis, and retention period. This audit is crucial for responding to DSARs accurately. Without it, you may miss data sources, leading to incomplete responses—a key issue in the DAZN’s access request saga.

Step 2: Configure Consent Management

Implement a consent management platform (CMP) that integrates with your tag manager. Ensure your CMP blocks non-essential tags before consent is given. Use Google Consent Mode to signal consent states to Google services, allowing them to adjust data collection accordingly. Test your setup by checking network requests in your browser’s developer tools: no marketing or analytics tags should fire before consent. This pre-consent blocking is a critical compliance measure.

Step 3: Establish a DSAR Workflow

Create a clear workflow for handling access requests. Designate a responsible person or team, set up a dedicated email address (e.g., privacy@yourdomain.com), and create templates for acknowledgment and response. Your workflow should include steps for identity verification, data retrieval from all systems (including backups), and secure data transmission. Automate where possible, but always include human oversight for complex cases.

Step 4: Update Your Privacy Policy

Your privacy policy must explicitly state users’ right to access their data and provide clear instructions on how to submit a request. Include the contact details for your data protection officer or privacy team. Link to your policy prominently on your website, especially in the footer and cookie banner. This transparency is a key lesson from the DAZN’s access request saga.

Step 5: Test and Validate

Regularly test your entire DSAR process. Submit test requests and verify that you can retrieve all data within the one-month deadline. Use GDPRChecker to scan your site for compliance gaps, such as tags firing without consent or missing policy disclosures. After any website change, re-scan to ensure ongoing compliance.

Common Mistakes and How to Avoid Them

Many website owners fall into traps that the DAZN’s access request saga exposed. One common mistake is failing to block tags before consent. Even if your banner appears, tags may still fire, collecting data illegally. To avoid this, use a tag manager with built-in consent checks and verify with GDPRChecker scans. Another mistake is incomplete DSAR responses—missing data from third-party processors or backups. Mitigate this by maintaining a data inventory and establishing data processing agreements with all vendors. A third mistake is ignoring the “reject” flow: your banner must make it as easy to reject cookies as to accept them. Test this by navigating your site with reject options and checking for any non-essential data collection. Finally, many sites neglect to update their privacy policies after changes, leading to outdated disclosures. Regularly review and update your policy to reflect current practices.

Edge Case: Handling Third-Party Data

When responding to a DSAR, you must include data held by third-party processors. This requires contractual clauses that obligate them to assist with access requests. Without this, you may be unable to provide a complete response, a scenario that could mirror the DAZN’s access request saga. Ensure your data processing agreements cover DSAR cooperation.

Edge Case: Verifying Identity

Verifying the requester’s identity is crucial to prevent unauthorized data disclosure. However, requesting excessive additional information can itself be a GDPR violation. Strike a balance by asking for minimal information that confirms identity, such as a copy of an ID with sensitive fields redacted, or by using a logged-in account verification.

How to Validate with GDPRChecker

GDPRChecker provides a practical way to validate your compliance posture, especially in light of the DAZN’s access request saga. The scanner checks for pre-consent network requests, banner behavior, and disclosure gaps. After implementing your DSAR process, run a scan to identify any tags that fire without consent. The tool will highlight issues like missing consent mode signals or incomplete policy disclosures. Use these insights to fine-tune your setup. Regular scans after website updates ensure that new tags or changes don’t introduce compliance risks. While GDPRChecker doesn’t offer legal advice, it gives you the technical verification needed to maintain a compliant site.

What to Look for in a Scan

When using GDPRChecker, focus on three key areas: consent defaults, tag behavior, and policy presence. Ensure that no non-essential tags fire on page load before consent. Check that your consent banner correctly records user choices and that the reject option works as intended. Verify that your privacy policy is accessible and includes all required disclosures. Address any flagged issues promptly.

Integrating Scans into Your Workflow

Make GDPRChecker scans part of your regular compliance routine. Schedule scans after any tag or policy update, and at least monthly. Document scan results and remediation actions as evidence of your ongoing compliance efforts. This proactive approach helps prevent the kind of gaps highlighted by the DAZN’s access request saga.

Implementation Checklist

Use this checklist to ensure you’ve covered all bases in your DSAR and consent implementation:

  1. Audit all cookies, tags, and data collection points.
  2. Implement a consent management platform that blocks tags before consent.
  3. Configure Google Consent Mode for Google services.
  4. Set up a dedicated DSAR handling process with identity verification.
  5. Create a data inventory mapping personal data to systems.
  6. Update your privacy policy with clear access request instructions.
  7. Test your cookie banner’s accept and reject flows.
  8. Verify pre-consent blocking using browser developer tools.
  9. Run a GDPRChecker scan to identify compliance gaps.
  10. Remediate any issues found and re-scan.
  11. Document all compliance measures and scan results.
  12. Schedule regular scans and DSAR process reviews.

FAQ

What is DAZN’s access request saga? The DAZN’s access request saga refers to a notable case where a user’s request to access their personal data exposed compliance gaps in consent management and data disclosure. It highlights the importance of robust DSAR processes for all website owners.

Do I need to worry about the DAZN’s access request saga for GDPR? Yes, if your website collects personal data from EU users. The saga illustrates common pitfalls in handling access requests, and regulators expect all data controllers to have effective DSAR procedures in place.

How do I implement a DSAR process to avoid issues like the DAZN’s access request saga? Start by auditing data collection, implementing a consent-aware tag manager, setting up a clear DSAR workflow, and updating your privacy policy. Regularly test and validate your process with tools like GDPRChecker.

How can I verify my site’s compliance with a scanner? Use GDPRChecker to scan for pre-consent network requests, banner behavior, and policy gaps. The scanner provides actionable insights to fix issues, helping you maintain compliance and avoid scenarios like the DAZN’s access request saga.

What are common mistakes related to the DAZN’s access request saga? Common mistakes include failing to block tags before consent, providing incomplete DSAR responses, neglecting the reject flow on cookie banners, and not updating privacy policies. These can lead to non-compliance and user complaints.

Conclusion

The DAZN’s access request saga is more than a cautionary tale—it’s a practical blueprint for what to avoid in GDPR compliance. By understanding the requirements, implementing a thorough DSAR process, and using tools like GDPRChecker for validation, you can close the gaps that this saga exposed. Remember, compliance is an ongoing journey. Regular audits, scans, and updates are essential to stay ahead of regulatory expectations. For more detailed guidance, explore our related guides on closing the Consent Mode gap, the Google CMP gap, the Cookie Banner gap, the Privacy Policy gap, and the DSAR gap. Take action today to ensure your website respects user rights and stands up to scrutiny.

<!-- schema:faq ready -->

GDPRChecker guides are educational resources and do not constitute legal advice. Use them to understand technical and operational privacy requirements, and consult qualified counsel for legal interpretation.

Check Your Website in Under 60 Seconds

  • No signup required
  • GDPR-focused checks
  • Cookie banner detection
  • Privacy policy verification
DAZN’s Access Request Saga: GDPR Compliance Guide for Websites | GDPRChecker