Right of Access
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Data subject right to access their personal data
Overview
28 sources · Sep 25, 2026Legal Framework
The right of access is governed primarily by Article 15 GDPR, which grants data subjects a layered set of entitlements: confirmation of whether processing is occurring, access to the personal data itself, and a specified bundle of accompanying information including processing purposes, recipient categories, retention periods, and the existence of automated decision-making. Recital 63 frames the right as a verification mechanism:
"a data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing"
— GDPR Recital 63
Article 15(3) additionally requires controllers to provide a copy of the personal data undergoing processing, with Article 15(4) stipulating that this right must not adversely affect the rights and freedoms of others — including trade secrets and intellectual property. Article 32 GDPR touches peripherally on access insofar as technical and organisational measures must safeguard the ability to restore availability and access to personal data after incidents.
Key Developments
The CJEU has confirmed that Article 15 introduced a broader right than its predecessor under Directive 95/46, specifically by granting an explicit right to obtain a copy rather than mere communication of data in intelligible form. In Österreichische Datenschutzbehörde v CRIF, the Court stated:
"Article 15 of that regulation provides, in that regard, for a right to obtain a copy, unlike the second indent of Article 12(a) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995"
— CJEU, CRIF ¶33
The EDPB's Guidelines 01/2022 clarify that the assessment must reflect the situation when the request was received and that even unlawfully processed data must be disclosed:
"Even data that may be incorrect or unlawfully processed will have to be provided."
— EDPB Guidelines 01/2022 §9
Enforcement actions confirm that denying access outright invites sanctions. The Irish DPA found Limerick City and County Council in violation of Article 15 for refusing access requests relating to traffic-management camera footage. The Italian DPA fined Experian Italia for incomplete Article 15 responses, demonstrating that partial or cursory compliance falls short.
The EDPB's one-stop-shop digest addresses the tension between access and third-party rights under Article 15(4), noting that the provision's wording may suggest the limitation applies only to copies under Article 15(1), though the broader text indicates a wider scope.
Status of the Debate
The right of access is actively contested in court. The core entitlement — confirmation, access, and a copy — is settled. But the boundaries remain disputed, particularly around the scope of Article 15(4)'s limitation on third-party rights, what constitutes a "copy" in practice, and how controllers should handle requests involving large volumes or mixed personal data of multiple individuals. The CRIF ruling clarified that copies must faithfully reproduce the data but left open questions about format and redaction. No definitive court split is on record yet; a future CJEU referral clarifying the outer limits of Article 15(4) — particularly how trade secrets and third-party data should be redacted without rendering the response meaningless — would resolve the principal open question.
Practical Guidance
Respond to the full scope of Article 15(1): Provide confirmation of processing, access to the data, and all eight enumerated categories of information. Partial responses based on the data subject's perceived needs risk enforcement, as the Experian Italia case illustrates.
Provide a faithful copy under Article 15(3): The copy must accurately reproduce the personal data undergoing processing. Do not withhold data simply because it was unlawfully collected or contains errors — the EDPB is explicit that such data must still be disclosed.
Apply Article 15(4) redactions narrowly: Where third-party rights or trade secrets are implicated, redact only what is strictly necessary. The EDPB cautions that the limitation should not become a blanket refusal mechanism.
Assess at the moment of receipt: Base your response on the data held when the request arrived. Data deleted under a retention policy before that point need not be provided, but data still in your systems — regardless of its accuracy or lawfulness — must be.
Document the access-response process: Maintain internal logs showing what was provided, what was redacted, and the legal basis for each redaction. This creates an evidentiary record if a supervisory authority challenges the completeness of your response.
why this is here
The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data
The provision defines the very right of access itself, including the right to obtain a copy of processed personal data and related information.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.
This is the central topic of the entire document.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
right of access (Article 15 GDPR)
The document lists Article 15 as a restrictable right, but does not detail the right of access itself.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
concerning data subjects’ rights
Broadly references data subjects' rights, but does not specifically discuss right of access.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Request from Uber drivers to Uber for access as referred to in Article 15 (1) AVG to certain personal data concerning them (including "ratings" given by passengers)
The document centers on a data subject access request under Article 15 GDPR, directly invoking the right of access.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
modifying certain key provisions in relation to accountability, lawful grounds for processing, data subject access requests and cookies
The article explicitly mentions data subject access requests, which is the right of access under Article 15 GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 77 Guidance · all 110 Case Law · all 136 Enforcement · all 26 Literature · all 49 News