> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What is the "Right of Access" under the GDPR?
- URL: https://www.thedelatorrereview.com/what-is-the-right-of-access-under-the-gdpr/
- Published: 2019-02-22T02:24:00.000Z
- Updated: 2026-07-15T02:59:41.000Z
- Description: The GDPR's right of access empowers individuals to obtain a copy of their personal data and understand how it is being used. This article explains Article 15, Subject Access Requests (SARs), response deadlines, exceptions, best practices, and practical compliance guidance for organizations.
- Author: Lydia
- Tags: Transparency, GDPR, Right of Access, SAR, Privacy Rights, Data Protection Law, EU

> **Key points:** (1) The GDPR gives individuals the right to know whether an organization is processing their personal data and, if so, to obtain a copy of that data together with information explaining how it is being used. (2) This right is commonly exercised through a **Subject Access Request (SAR)**. (3) A SAR may be made verbally or in writing and does not need to mention the GDPR or use any specific wording. (4) Organizations generally have **one month** to respond and, in most cases, cannot charge a fee. (5) The information provided must be clear, accessible, and easy to understand. (6) Organizations should have procedures in place to recognize, record, and respond to SARs promptly.

### What is the right of access?

The right of access is one of the GDPR's most important transparency rights. It allows individuals to understand whether an organization is processing their personal data, what information is held about them, how it is being used, and with whom it has been shared.

This right is set out in [**Article 15**](https://gdpr-info.eu/art-15-gdpr/?ref=thedelatorrereview.com) **of the GDPR** and serves as the foundation for many of the other rights granted to individuals, including the rights to rectification, erasure, restriction of processing, and objection. **Without access to their personal data, individuals cannot effectively exercise** these **other rights or verify that an organization is processing their information lawfully**.

### How can a Subject Access Request be made?

The GDPR deliberately makes the right of access **easy to exercise**. A Subject Access Request (SAR) may be submitted:

in writing or verbally;

- by email, letter, telephone, social media, or in person; and
- to any part of the organization.

The request does not need to include the words "Subject Access Request" or cite the GDPR. It simply needs to make clear that the individual wants access to their personal data.

Because any employee may receive a valid request, organizations should train staff to recognize SARs and know how to escalate them appropriately.

### Verifying identity

If an organization has reasonable doubts about the identity of the requester, it **may ask for additional information** to verify identity. However, the request should be proportionate and limited to what is necessary.

The one-month response period begins once the organization receives the additional information needed for verification.

Whenever additional identification is requested, the organization should explain:

- why the information is needed;
- the individual's right to complain to a supervisory authority; and
- the individual's right to seek a judicial remedy.

### What information must be provided?

When an organization processes an individual's personal data, the GDPR grants two distinct rights under [Article 15](https://gdpr-info.eu/art-15-gdpr/?ref=thedelatorrereview.com):

**1\. Confirmation and information about the processing**: Individuals have the right to obtain confirmation of whether an organization is processing their personal data. If it is, the organization must also provide information explaining how that data is being used. Much of this information mirrors what should already appear in the organization's privacy notice.

Specifically, the controller must provide information about:

- the purposes of the processing;
- the categories of personal data being processed;
- the recipients or categories of recipients with whom the data has been or will be shared, including recipients in third countries or international organizations;
- the retention period for the data, or, if that is not possible, the criteria used to determine that period;
- the individual's rights to request rectification, erasure, restriction of processing, or to object to the processing;
- the right to lodge a complaint with a supervisory authority;
- the source of the personal data, where it was not obtained directly from the individual;
- the existence of automated decision-making, including profiling, together with meaningful information about the logic involved and the significance and likely consequences of the processing; and
- where personal data is transferred outside the European Economic Area, the safeguards in place to protect the data.

**2\. A copy of the personal data**: In addition to information about the processing, individuals are entitled to receive a copy of the personal data undergoing processing.

The first copy must be provided free of charge. Controllers may charge a reasonable administrative fee for additional copies requested by the individual.

Where the request is made electronically, the information should generally be provided in a commonly used electronic format unless the individual requests otherwise.

Importantly, the right of access is not absolute. Providing a copy of the data must not adversely affect the rights and freedoms of others, meaning controllers may need to redact or withhold information relating to third parties where appropriate.

**Organizations cannot require individuals to submit a SAR**: Individuals choose whether to exercise their right of access. Organizations cannot require someone to submit a Subject Access Request in order to obtain information, and in some Member States requiring an individual to make a SAR in certain circumstances may constitute a criminal offense.

### How should the information be provided?

The GDPR requires organizations to provide information in a **concise, transparent, intelligible, and easily accessible**manner using **clear and plain language**.

If a response contains technical codes, abbreviations, or internal terminology, the organization should explain what those terms mean. However, the GDPR does not require organizations to rewrite illegible handwritten notes or translate information into another language solely because the requester cannot understand it, although doing so may be good customer service.

> **Example**: An individual made a request for their personal data. When preparing the response, the controller notices that a lot of it is in coded form. For example, attendance at a particular training session is logged as “A”, while non-attendance at a similar event is logged as “M”. Also, some of the information is in the form of handwritten notes that are difficult to read. Without access to your key or index to decode this information, it would be impossible for anyone outside the organization to understand it. In this case, the controller is required to explain the meaning of the coded information. However, although it is good practice to do so, controller's are not required to decipher the poorly written notes, as the GDPR does not require controllers to make information legible.

Where the request is submitted electronically, the response should generally be provided in a commonly used electronic format unless the individual requests otherwise.

### Best practices for handling SARs

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-14--2026-at-02_37_27-PM-1.png)

Although not legally required, organizations should establish internal procedures to ensure SARs are handled consistently. Good practices include:

- maintaining a policy for recording requests;
- documenting verbal requests;
- confirming the scope of unclear requests with the individual;
- maintaining a log of requests and deadlines; and
- providing electronic methods for submitting requests where appropriate.

Organizations may offer standard request forms to simplify the process, but individuals cannot be required to use them.

**Requests involving third-party information**: Sometimes personal data relates to more than one individual. In those situations, organizations must balance the requesting individual's right of access against the rights and freedoms of others.

Relevant considerations include:

- the sensitivity of the information;
- any duty of confidentiality;
- whether the third party has consented to disclosure;
- whether the third party is capable of consenting; and
- whether disclosure would otherwise be reasonable.

Information cannot be withheld simply because it originated from a third party. The key question is whether disclosing it would unfairly affect another person's rights.

**Large or complex requests**: Where an organization processes a large volume of information about an individual, it may ask for additional details to help identify the information being requested. For example, it may ask the individual to identify particular dates, services, or categories of records.

Even if the individual declines to narrow the request, the organization must still make reasonable efforts to locate and provide the personal data.

**Controllers remain responsible**: Even where personal data is processed by a service provider, the controller remains legally responsible for responding to Subject Access Requests.

Controllers should ensure that contracts with processors require appropriate cooperation so that requests can be answered within the GDPR deadline. Reliance on a processor does not extend the time available to respond.

**Requests made on behalf of others**: The GDPR does not require individuals to submit a Subject Access Request (SAR) personally. A third party—such as a lawyer, family member, or other representative—may make a request on an individual's behalf, provided they are authorized to do so. Organizations should take reasonable steps to verify that authority, for example by requesting a signed authorization or a power of attorney.

In some circumstances, organizations may choose to honor a request without formal documentation where the representative's authority is well established. However, they are generally not required to do so and may request more formal proof before disclosing personal data.

Where there are concerns that the individual may not fully understand the implications of authorizing a third party to receive their personal data, it is good practice to send the response directly to the individual. The individual can then decide whether to share the information with their representative.

**Individuals who lack legal capacity**: The GDPR does not specifically address requests made on behalf of individuals who lack the mental capacity to manage their own affairs. Instead, organizations should follow the applicable laws of the relevant Member State governing legal representation and decision-making.

**Requests involving children**: The right of access belongs to the child, not to the child's parents or guardians. Whether a parent may exercise that right on the child's behalf depends on the child's maturity, the applicable Member State law, and the circumstances of the request.

If a child is sufficiently mature to understand the nature of the request, the response should generally be provided directly to the child. Parents or guardians may exercise the child's rights where the child has authorized them to do so or where doing so is clearly in the child's best interests.

When assessing requests involving children, organizations should consider factors such as:

- the child's age, maturity, and ability to understand their rights;
- the nature and sensitivity of the personal data;
- any applicable court orders relating to parental responsibility or access;
- duties of confidentiality owed to the child;
- whether disclosure could place the child at risk, particularly in situations involving allegations of abuse or neglect;
- any potential harm if parents are denied access; and
- the child's own wishes, where these can be ascertained.

Some Member States establish legal presumptions that children above a certain age are capable of exercising their own data protection rights, although these rules vary across the European Union.

**Credit bureaus**: Access to personal data held by credit bureaus or credit reference agencies may also be subject to additional requirements under applicable Member State consumer protection laws.

### Time limits, refusals, and fees

**Time to respond**: Under the GDPR, controllers must respond to a Subject Access Request (SAR) **without undue delay and, in most cases, within one month** of receiving the request. In certain circumstances, this deadline may be extended where permitted by the GDPR. (See **Data Subject Rights under EU Data Protection Law**.)

**When can a controller refuse a request?** The right of access is fundamental, but it is not absolute. In limited circumstances, a controller may refuse to provide all or part of the requested information where disclosure would **adversely affect the rights and freedoms of others**.

This assessment must be made on a case-by-case basis by balancing the individual's right of access against competing rights and interests, such as the privacy rights of third parties, legal obligations of confidentiality, or the protection of trade secrets and other legitimate interests.

Importantly, a controller **cannot refuse access simply because**:

- the information was obtained from a third party; or
- disclosure may be inconvenient or potentially disadvantageous to the controller.

For example, a psychologist may refuse to disclose information requested by one individual where doing so would reveal confidential information provided by another patient and would breach the psychologist's professional duty of confidentiality.

In addition, Member State laws may restrict the right of access in specific situations. (See **Restrictions on the Rights of Individuals**.)

**Manifestly unfounded or excessive requests**: A controller may also refuse to act on a request—or charge a reasonable fee—if the request is **manifestly unfounded or excessive**, particularly where it is repetitive.

In these circumstances, the controller may:

- charge a reasonable fee to cover the administrative costs of responding; or
- refuse to comply with the request altogether.

The controller bears the burden of demonstrating that the request is manifestly unfounded or excessive and must be able to justify its decision.

**Informing the individual:** If a controller refuses to comply with a SAR, whether in whole or in part, it must inform the individual **without undue delay and no later than one month after receiving the request**. The response must explain:

- the reasons for refusing to take action;
- the individual's right to lodge a complaint with the competent supervisory authority; and
- the individual's right to seek a judicial remedy.

## Additional resources:

ICO:

- [ICO Publishes Detailed Guidance on Right of Access](https://www.engage.hoganlovells.com/knowledgeservices/news/the-ico-publishes-new-detailed-sar-guidance?ref=thedelatorrereview.com) / 27 October 2020
- [Subject Access Requests (SARs) Code of Practice](https://icdppc.org/wp-content/uploads/2018/10/20180922%5FICDPPC-40th%5FAI-Declaration%5FADOPTED.pdf?ref=thedelatorrereview.com): Best practices for SARs (not updated for GDPR as of Jan 2019)
- [How to disclose information safely: Removing personal data from information requested and data sets](https://ico.org.uk/media/for-organisations/documents/how-to-disclose-information-safely-removing-personal-data-from-information-requests-and-datasets/2013958/how-to-disclose-information-safely.pdf?ref=thedelatorrereview.com) (ICO guidelines)
- [Redaction Toolkit: editing exempted information from paper and electronic documents prior to release](http://www.nationalarchives.gov.uk/documents/information-management/redaction%5Ftoolkit.pdf?ref=thedelatorrereview.com)(The National Archives — UK)

#### Papers

[Security Analysis of Subject Access Request Procedures: How to authenticate data subjects safely when they request for their data](https://hal.inria.fr/hal-02072302/document?ref=thedelatorrereview.com) — by Coline Boniface, Imane Fouad, Nataliia Bielova, Cédric Lauradoux, Cristiana Santos for[ HAL](https://hal.archives-ouvertes.fr/?ref=thedelatorrereview.com)

#### Articles

[A date with my Tinder data](https://www.engadget.com/2018/09/08/tinder-gdpr-data-retrieval/?guccounter=1&ref=thedelatorrereview.com) by Max Smith, 8/9/18 for Engadget

[Hacking the vulnerabilities in privacy laws](https://www.axios.com/privacy-law-europe-gdpr-companies-personal-data-e7330ab1-5d7c-431b-a9b3-b4f81c7fbf53.html?ref=thedelatorrereview.com), [Joe Uchill](https://www.axios.com/authors/JoeUchill?ref=thedelatorrereview.com)Jul 11, 2019 for Axios

##