The common way to answer a data subject access request is to send an export and consider it done. That satisfies half of the obligation and produces a surprising number of follow-up complaints, because the person asked what you hold and received a file they cannot interpret. This is the other half.
The copy, and what makes it usable
A copy of the personal data undergoing processing. Usable means a person can read it: column headers that mean something, codes expanded, and internal identifiers either explained or removed. An export of your database schema is technically the data and practically an insult.
The purposes
Why you hold each part. This is where people discover that their address is held for delivery and their click history for segmentation, and it is the part that turns a list of fields into an answer somebody can act on. It is also the section that most often reveals a purpose nobody had written down.
The categories and the recipients
What kinds of data, and who else has received it. Article 15 of the GDPR asks for the recipients or categories of recipients, and naming them is better than categorising them where you can. Your vendor list is the source for this, which is another reason it is worth maintaining.
The retention period
How long, or the criteria used to determine it if there is no fixed period. Where you cannot answer this, the honest answer is the criteria, and the fact that you could not answer it at all is a finding worth acting on afterwards rather than an embarrassment to write around.
Where it came from
Any available information about the source, where the data was not collected from the person. Imported and purchased data is the case this exists for, and it is the case where the answer is most awkward, which is precisely why the right is there.
Questions people ask about data subject access request
Do we have to send everything at once?
Ideally yes. Where a request is genuinely complex you may take an extension with notice, but drip-feeding without explanation reads as obstruction.
What format?
Commonly used, machine-readable where practical, and the same format the person asked for if that is reasonable. A PDF of screenshots is not a good answer to a request for a copy of the data.
What if most of it is meaningless log data?
Say so and describe it rather than dumping it. The obligation is to give the person their data and enough context to understand it, and a million rows of event logs with no explanation meets neither.