Right of Access
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Data subject right to access their personal data
Overview
24 sources · Jul 23, 2026Legal Framework
The right of access is anchored at both the constitutional and statutory levels. Article 8 of the EU Charter establishes the fundamental right, providing that "[e]veryone has the right of access to data which has been collected concerning him or her." Article 15 GDPR operationalises this right in detail, requiring controllers to confirm whether personal data are being processed and, where so, to provide access to the data together with a specified catalogue of supplementary information — purposes, categories of data, recipients, retention periods, and the existence of other data-subject rights.
"The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information"
— GDPR Art. 15(1)
Where data are transferred to third countries, Article 15(2) adds a right to be informed of appropriate safeguards. Article 15(3) obliges the controller to provide a copy of the personal data. Supporting obligations under Article 32 (security of processing) and Article 38 (DPO involvement) ensure that controllers can retrieve and disclose data in a structured, secure manner.
Key Developments
The CJEU's ruling in Minister v. M (2014) remains the leading authority on the scope of access. The Court held that the right of access exists to enable the data subject to verify accuracy and lawfulness of processing — not to obtain administrative documents more broadly. Crucially, the Court drew a line between personal data and legal analysis contained in administrative minutes:
The Court confirmed that providing "a full summary of those data in an intelligible form" satisfies the access obligation — controllers need not hand over raw documents if a comprehensive, intelligible summary allows the data subject to check accuracy and exercise downstream rights.
The earlier X judgment (2013) established the procedural baseline: access must be provided without constraint, excessive delay, or excessive expense. The Bara decision (2015) reinforced that where data are not obtained from the data subject, the controller must still inform the individual of the categories of data concerned and the existence of the right of access and rectification.
Status of the Debate
This topic is actively contested in court. The core fault line concerns the boundary between personal data and administrative or legal analysis — the Minister v. M distinction is repeatedly tested in national litigation, and courts diverge on how far the access right reaches into internal deliberations, profiling logic, and automated decision-making outputs. The EDPB's 2025 coordinated enforcement action on right-of-access implementation signals that regulators are also pushing to define practical thresholds. What would resolve the open question is a further CJEU reference clarifying whether the "intelligible summary" standard from Minister v. M survives under the GDPR's expanded Article 15(1)(h) requirements for meaningful information about profiling logic.
Practical Guidance
- Confirm and disclose: On receipt of an access request, confirm whether processing is underway and provide the data plus all Article 15(1)(a)–(h) information, including sources and automated decision-making logic where applicable.
- Provide an intelligible summary: Following Minister v. M, a full, intelligible summary of personal data satisfies the access right; raw administrative documents need not be disclosed where they contain legal analysis beyond the personal data.
- Respond without excessive delay: Per the X judgment, ensure responses are provided without constraint, excessive delay, or excessive expense — align internal SLAs with the one-month GDPR deadline.
- Involve the DPO early: Article 38(1) requires DPO involvement in access requests; ensure the DPO has resources and access to processing operations to validate completeness.
- Secure the retrieval process: Article 32 requires technical measures ensuring data can be restored and accessed in a timely manner — maintain retrieval capabilities that support access-request deadlines.