Laws · GDPR ·art-15-par-3 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.
How it connects
Cited by
- Guidelines 01/2022 on data subject rights - Right of access
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive
- Guidelines 8/2020 on the targeting of social media users
- Kaufland România SCS: Insufficient fulfilment of data subjects rights
All 53
- Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights
- Kaufland Romania SCS: Insufficient fulfilment of data subjects rights
- Associazione Rescue Drones Network ODV: Insufficient fulfilment of data subjects rights
- Libra Internet Bank SA: Insufficient fulfilment of data subjects rights
- Vodafone Romania SA: Insufficient fulfilment of data subjects rights
- Med Life SA: Insufficient fulfilment of data subjects rights
- Suomen Yritysrekisteri: Insufficient fulfilment of data subjects rights
- Company: Insufficient fulfilment of data subjects rights
- Velvet Medical SRL: Insufficient fulfilment of data subjects rights
- Noy Business Tranzactions SRL: Insufficient fulfilment of data subjects rights
- Office Nova Concept SRL: Insufficient fulfilment of data subjects rights
- Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights
- One-Stop-Shop case digest on right of access
- Coordinated Enforcement Action, implementation of the right of access by controllers
- EDPB Annual Report 2024
- Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH
- Opinion 16/2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria
- Österreichische Datenschutzbehörde v CRIF
- Rb. Den Haag - C/09/689833
- OLG Wien - 13R70/25x
- Munich Court: §11(8) RBStV validly restricts Art. 15 GDPR access for broadcasting
- Svea Hovrätt - T 10711-21
- OVG Saarlouis - 2 A 165/24
- Dutch Supreme Court: patient not entitled to access peer-review assessment of medical file
- BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies
- Tribunal of Bologna orders Comet s.p.a. to fulfil data subject's Art. 15 GDPR access
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria
- EDPB Annual Report 2022
- EDPB Annual Report 2021
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- Austrian Fed Admin Court: AMS access response omitted 2018 family doctor call note
- CK v Magistrat der Stadt Wien
- Proceedings brought by J.M
- Ligue des droits humains ASBL v Conseil des ministres
- APD/GBA (Belgium) - 97/2026
- AZOP (Croatia) - Decision 08-03-2022 (energy company)
- Sibiu Tribunal: rail company liable for refusal of CCTV access request
- BAG - 8 AZR 169/25
- VG Berlin - 42 K 25/25
- DSB: Retailer must grant full access and delete data after third-party fraud order
- DSB: No processor access violation under Art. 15 GDPR when controller deleted data
- DSB (Austria) - DSB-D124.5337
- Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024)
- VG Osnabrück - 7 A 170/24
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- IP Slovenia: Controller breached Art. 15(1)(d) and 15(3) GDPR by denying storage info and
- BVwG - W605 2289290-2/18E