Table of Contents
The Purpose of the Right of Access to Data, the Structure of Article 15 of the GDPR, and General Principles Related to This Matter
The right of access is intended to guarantee the individual whose data is being processed the right to privacy and the protection of personal data in relation to their processing, as well as to exercise other rights arising from the GDPR (e.g., rectification, erasure, objection).

The individual whose data is being processed must be provided with appropriate, transparent, and easily accessible information regarding the personal data being processed about them, so that they are aware of what is happening with their data, what processing activities are taking place, what the consequences of such processing are, and so that they can verify the accuracy of these processes.
According to the EDPB, a proper understanding of the structure of Article 15 of the GDPR is crucial for the proper consideration of a request regarding the right of access, in a manner that ensures that no element is overlooked. To clarify this issue, the EDPB has identified eight different elements from Article 15, namely:
- confirmation of whether the applicant's data is being processed by the data controller;
- access to the applicant's personal data;
- access to information about the processing activities, as stated in Article 15(1), i.e., purposes, categories of data, recipients, the expected duration of processing or criteria for determining the duration of processing, the rights of the individual whose data is being processed – rectification, erasure, restriction of processing, and objection, the right to lodge a complaint with a supervisory authority, all available information about the sources of the data if not collected from the individual whose data is being processed, information about automated decision-making, including profiling, and other related information;
- information about the appropriate safeguards referred to in Article 46 of the GDPR, in the case of data transfers to third countries;
- the obligation of the data controller to provide a copy of the personal data being processed;
- the collection of a reasonable fee by the data controller, covering administrative costs for any subsequent copies requested by the applicant;
- the provision of information in electronic form;
- the consideration of the rights and freedoms of other individuals.
As noted by the EDPB, elements 1-4 collectively define the content of the right of access, while points 5-7 concern the conditions of access, in addition to the general requirements specified in Article 12 of the GDPR. Point 8 supplements the limits and restrictions provided for in Article 12(5) concerning the data subject, with particular emphasis on the rights and freedoms of other individuals in the context of access.
General considerations regarding the assessment of requests for the right of access
The data subject submitting a request for the right of access is not obliged to justify it. It is not the responsibility of the data controller to analyze whether providing information in accordance with the request will actually allow the party to verify the accuracy of the processing or exercise other rights. The data controller is obliged to respond to the request, except in situations where it determines that the request is made in a manner other than that provided for by data protection regulations, as well as when there are grounds referred to in Article 12(5) of the GDPR. According to this provision, if the requests of the data subject are clearly unjustified or excessive, particularly due to their persistent nature, the data controller may:
- charge a reasonable fee, taking into account the administrative costs of providing the information, conducting communication, or taking the requested actions; or
- refuse to take action in response to the request.
The obligation to demonstrate that the request is clearly unjustified or excessive rests with the data controller.
The data controller should verify the request in the context of whether it pertains to the personal data of the applicant and falls within the scope of Article 15 of the GDPR (also whether the request concerns all data of the individual or only part of it), or whether there are other, more specific provisions regulating access in this regard.
It may happen that national regulations, issued based on Article 23 of the GDPR, restrict access to certain information, regulating, for example, the issue of information exchange between parties to a legal dispute.
There are no specific requirements regarding the format of the access request. The data controller should provide an easily accessible method for individuals whose data is being processed to submit requests; however, there is no obligation for the individual to use this method, as they may communicate with the data controller's official contact point instead. The EDPB has indicated that the data controller is not obliged to respond to requests sent to completely random or incorrect addresses.
In the event that the data relating to the requester cannot be identified, the data controller should inform them of this fact and the necessity to provide additional information enabling identification. The data controller should also request additional information from the requester to verify their identity if there are doubts regarding their actual identity.
The obligation to issue a copy of the data does not constitute an additional right for the individual whose data is being processed, but rather a method of providing data, which is the primary means of data provision, although in certain cases other methods may be more appropriate (e.g., oral information, access to records, on-site access, or remote access without the possibility of downloading data). It is indicated that such a method of accessing data may be appropriate when the interest of the individual whose data is being processed supports it, or when it is a method chosen by that individual. The data controller should reasonably consider such a request, as they are not obliged to provide information in a manner other than by issuing a copy. Providing data in a manner other than by issuing a copy does not deprive the individual whose data is being processed of the right to also have such a copy, unless they unequivocally waive that right.
Scope of the Right of Access
An integral part of the assessment that must be conducted by the data controller is determining the scope of the data to which the individual whose data is being processed has the right of access. Therefore, the data controller must distinguish personal data from other data that is not covered by the request. It should also be noted that the right of access can only be exercised within the material and territorial scope of the GDPR.
EROD referred to the definition of personal data, emphasizing its broad nature, which should be assessed in the context of Article 4(1) of the GDPR, indicating, based on the case law of the Court of Justice of the European Union, that personal data may also include notes made on a document concerning the individual to whom the data relates (e.g., notes made by a person conducting an interview with a candidate on their CV).
EROD also indicates that within the right of access, the concept of personal data includes data concerning the individual generated by the service provider (unlike the right to data portability, which only encompasses data provided by the individual to whom the data relates).
The applicant may obtain access only to the data concerning that individual, excluding data concerning other individuals, whose rights and freedoms the data controller must also respect. However, particular caution must be exercised to avoid unjustifiably broadening the legally prescribed limitations on the right of access, which are permissible only under strictly defined conditions. EROD points out that the right of access pertains to the personal data of the individual making the request; however, this scope should not be interpreted excessively restrictively, i.e., the scope of this data may include data about other individuals, citing the history of incoming and outgoing communications as an example (e.g., recordings of telephone conversations between the individual to whom the data relates and the data controller).
Practical DPO Course
will confirm your high competencies
The EROD guidelines also address the situation of identity theft, that is, when a certain person dishonestly acts as another person. The victim of such a crime should then receive all data concerning their person, even if it was collected from the identity thief.
If the individual to whom the data pertains submits another request for access to their data, the data controller cannot solely limit themselves to providing information only about the changes that have occurred regarding the data provided in response to the previous request, unless the requester explicitly asks for this. Such a situation would mean that the requester would be obliged to independently compare the data provided to them in order to compile the complete information.
When providing access to data, additional information about data processing must also be provided, which may be based on the records of processing activities (Article 30 GDPR) and information on data protection (Articles 13 and 14), and if necessary, it should be appropriately updated or adjusted, so that it adequately reflects the processing operations carried out in relation to the requesting individual.
Method of Providing Access to Data
The method of providing access may vary depending on the amount of data and the complexity of the processing process. Unless explicitly stated otherwise, a request for access to data should be understood as concerning all data related to the requester. In cases of a large amount of data processed by the data controller, they may request clarification of the scope of the requested data if they have only submitted a general request for access.The EROD provides certain guidelines and practical examples in the guidelines for fulfilling the obligation related to the right of access, and it also explains what is meant by the commonly used electronic form through which a copy of the data is provided and the deadlines for ensuring access.
Since the data subject has the right to access all information concerning them that is processed by the data controller, the data controller should search all of its systems, both IT and non-IT data collections, in order to determine the entirety of the data resource.
EROD emphasizes that already at the stage of implementing technical and organizational measures concerning the processing of personal data, the data controller should introduce features that enable compliance with the rights of data subjects. Therefore, solutions should be implemented by the data controller that facilitate the search for information in this regard.
According to Article 12(1) of the GDPR, the data controller takes appropriate measures to provide the data subject with all information referred to in Articles 13 and 14 in a concise, transparent, intelligible, and easily accessible form, using clear and plain language – particularly when the information is addressed to a child – and to conduct any communication with the data subject under Articles 15–22 and 34 regarding processing. Information is provided in writing or by other means, including, where appropriate, electronically. If the data subject requests it, information may be provided orally, provided that the identity of the data subject is confirmed by other means.
In its guidelines, EROD indicates how to understand the appropriate measures mentioned above, bearing in mind that the data controller must facilitate the exercise of rights by the data subject. It emphasizes that appropriate measures can never be understood as a way to limit the scope of data covered by the right of access. It also does not mean that the efforts of the data controller to provide information can be balanced against any interest of the data subject. When assessing appropriate measures, the aim should be to choose the most suitable method of providing all information under the right of access, depending on the specific circumstances of the case.
The primary means of ensuring access to personal data is the issuance of a copy of the processed data along with supplementary information, as mentioned in the earlier part of the article.
In the event that the data subject requests a copy of their data electronically and does not specify otherwise, the information shall be provided in a commonly used electronic format. The GDPR does not specify what this term entails; however, the EDPB has attempted to elaborate on this issue in its guidelines. Primarily, it has emphasized that what may be considered a commonly used electronic format should be based on the reasonable expectations of the data subjects, rather than referring to the format used by the data controller in their daily operations. The data subject should not be required to purchase specific software to access the information. The electronic format used should be understandable and easily accessible. It should also be stable and durable over time. Where appropriate, a copy of personal data may be stored on an electronic storage device, such as a CD or USB.
The EDPB also stipulates that for the data controller to consider that they have provided personal data to the data subject, it is not sufficient to merely share the data; the individual must have the ability to download their data in a commonly used electronic format.
Within one month from the date of receipt of the request, the data controller should inform about the actions taken in relation to the request. This period may be extended by an additional two months due to the nature of the request or the number of requests, provided that the individual has been informed of the reasons for such delay within one month from the receipt of the request.
The EDPB indicates that the period begins to run from the day the request is received through one of the official channels; it does not matter whether the data controller has actually noticed the receipt of such a request. In cases where the data controller must contact the requester due to uncertainty regarding their identity or the need to clarify the scope of processing activities to which the request pertains, this period may be suspended until the necessary additional information is obtained, provided that the data controller has promptly requested such information.
The EDPB points out that the mere fact that fulfilling the request for access to data requires significant effort does not constitute the complexity of the request. Similarly, the fact that the data controller receives a large number of requests regarding the right of access does not, in itself, justify an extension of the period, although the EDPB indicates that a situation where, for example, due to extraordinary publicity regarding the activities of the data controller, they receive a large number of such requests in a short time may be an exception that justifies an extension. Nevertheless, it emphasizes that the data controller, especially one that handles a large volume of data, should have implemented procedures and mechanisms that allow for the timely fulfillment of requests under normal circumstances.
Access Limitations
The right of access is subject to limitations arising from the rights and freedoms of other individuals, as referred to in Article 15(4) GDPR, evident groundlessness or excessive nature of the request, as mentioned in Article 12(5) GDPR, as well as limitations arising from EU regulations or those of EU member states, introduced in accordance with Article 23 GDPR and (with certain reservations) concerning the processing of personal data for scientific or historical research purposes or for statistical purposes, if it is likely that these rights will prevent or seriously hinder the achievement of the mentioned specific purposes and if such exceptions are necessary to achieve those purposes. Similarly, exemptions regarding, among others, the right of access may apply to processing for journalistic purposes, academic, artistic, or literary expression, if such provisions are provided by the member state in accordance with GDPR.
No other exemptions or exceptions to the right of access are permitted. This right may not be restricted within the framework of an agreement between the data controller and the data subject.
The right of access should not negatively affect the rights or freedoms of other individuals, including trade secrets or intellectual property, particularly copyright protecting software. Each case must be assessed appropriately in the context of Article 15(4) GDPR, taking into account the likelihood and severity of potential threats to rights and freedoms. As indicated by the EDPB, these rights or freedoms may also concern the data controller or the data processor; if the EU legislator intended to exclude the rights and freedoms of controllers or processors, they would have used the term “third party,” as defined in Article 4(10) GDPR.
One cannot invoke the rights and freedoms of others based solely on a general concern that exercising the right of access may adversely affect them. The data controller must be able to demonstrate that exercising the right of access in a specific situation will indeed adversely affect the rights of another person. The outcome of these considerations should not be a refusal to provide all information about the data subject, but rather, in cases where a limitation applies, the information concerning other individuals should be rendered unreadable by the controller (e.g., in the case of issuing a copy of the data).
EROD concludes that the right to personal data protection is not an absolute right and therefore must be balanced with other fundamental rights. Assessing that the exercise of the right of access will impact the rights and freedoms of others, the data controller should strive to reconcile conflicting rights, for example, by implementing measures to mitigate the risk of infringement. However, if such reconciliation is not possible, the data controller will have to decide which of the conflicting rights and freedoms takes precedence.
Check what you remember - a reward for the correct answer !
The person to whom the data relates:



