Introduction
For many companies, the GDPR right of access is the ultimate stress test for their own data landscape. Data subjects have the right to find out what data is stored about them, why it's being processed, and who it has been shared with.
Sounds simple, but in practice it often means a lot of work — especially for organizations with many systems, unstructured data, or missing processes. Meeting the tight one-month deadline can quickly become a monumental task.
So you can respond to access requests efficiently, correctly, and on time, let's take a detailed look at the fundamentals, obligations, and best practices.
What Is the Right of Access Under the GDPR?
The right of access under Art. 15 GDPR gives data subjects the right to receive full transparency about the processing of their personal data.
- Goal: To create transparency and enable control over one's own data.
- Core of the right: The right to know that data is being processed, how it is processed, and what data specifically exists.
Why the Right of Access Is So Important
The right of access is the lever data subjects use to enforce their other rights (such as erasure or rectification). For companies, compliance is of strategic importance:
- Strengthening data subject rights: Users retain control over their data.
- Transparency obligation for companies: Traceable data processing.
- Early detection of errors: Incorrect or outdated data (Art. 5) can be corrected before it causes follow-on problems.
- Reduced risk of misuse: Clear documentation of processing.
- Mandatory deadline: The tight one-month deadline makes clear processes essential.
The Legal Basis: Relevant GDPR Articles
| Article | Content |
| Art. 15 | Core of the right of access: scope, data copy, transparency of processing operations. |
| Art. 12 | Rules for handling requests: format (electronic), deadline (one month), clarity of language. |
| Art. 5 | Principles of data processing: the right serves to verify these principles (transparency, purpose limitation, data minimization). |
| Art. 13/14 | Information obligations: the response must contain the information you are already required to provide to data subjects. |
| Art. 30 | Record of Processing Activities (ROPA): serves as the central source of evidence for responding to access requests. |
Who Is Affected?
The right generally applies to any natural person whose data is processed.
This includes:
- Customers
- Users (even if they haven't made a purchase)
- Employees
- Job applicants
- Supplier contacts
- Website visitors (if personal data such as IP addresses or tracking IDs was collected)
Companies of every size must fulfill access requests — including start-ups.
The Two Components: Information and Data Copy
The response to an access request consists of two main parts.
Minimum scope under Art. 15: The Information
The response must include, among other things, the following information (the meta-information about the processing):
- What data is processed: Name, contact details, usage data, contract data, etc.
- For what purposes the data is processed (e.g. contract performance, marketing, security).
- Legal bases (consent, contract performance, legitimate interest, etc.).
- Recipients or categories of recipients (e.g. service providers, cloud providers, partners).
- Storage period or criteria (deletion periods, statutory retention periods).
- Data subject rights (rectification, erasure, restriction, objection).
- Origin of the data (if not collected directly from the individual).
- Existence of automated decision-making, including profiling.
The Data Copy
Upon request, a free copy of all personal data must also be provided. It must be delivered in a commonly used, structured, and machine-readable format (as far as technically feasible).
Examples of Typical Requests
| Scenario | Example Request |
|---|---|
| Customer wants to know what data is stored | "Please send me an overview of all data you process about me, and which service providers have received it." |
| Applicant wants a data copy | "I request a copy of all application documents stored about me, along with information about the planned deletion date." |
| User of a SaaS tool | "What tracking data is collected about me? I would like a copy of the usage data gathered." |
| Employee | "What data exists from my employment relationship (performance reviews, health data, etc.)?" |
7 Best Practices: How to Handle DSR (Data Subject Request) Requests Efficiently
Manual processing ties up valuable resources. Efficiency and security are only achievable through structure and automation.
1. Maintain a Central Record of Processing Activities (ROPA)
The ROPA (Art. 30) is the blueprint for responding: it lists all systems, purposes, legal bases, and recipients. Without an up-to-date ROPA, every access request turns into a search for a needle in a haystack.
2. Define a Standard Process and Roles
Define who within the company (DPO, IT, legal department, relevant business unit) is responsible for intake, processing, data extraction, approval, and documentation.
3. Verify Identity
Always verify the requester's identity before releasing sensitive data to prevent misuse (e.g. via ID verification, email verification, or access through the customer account).
4. Consolidate Central Data Sources
Identify which systems (CRM, HR system, log files, support tools) store personal data, and create a technical way to quickly consolidate that data.
5. Automate Data Provision
Use tools that enable automated data extraction from various sources and automatically populate response templates (the information section).
6. Monitor and Document Deadlines
The response must be provided within one month. Use workflows to monitor this deadline and document the entire communication (request, identity verification, response) — this is mandatory!
7. Create Legally Sound Response Templates
Use templates that consistently cover all 8 points of Art. 15 so no information gets missed.
The Consequences of Incorrect Handling (Liability & Audits)
Improper or incorrect handling of access requests can lead to far-reaching consequences:
- Fines under Art. 83 GDPR: Violations of data subject rights are severely penalized.
- Damages claims from data subjects in the event of a violation.
- Loss of trust: Delays or incomplete responses signal a lack of control over your own data.
- Negative impact on audits (e.g. ISO 27001, NIS2): An inefficient or faulty DSR process is considered a governance and IT security deficiency.
- Increased risk during data breaches: Errors in the access process point to broader data inconsistencies.
Access requests are therefore not just a data protection issue — they affect governance, compliance, and IT security.
Conclusion
The right of access is one of the central instruments of the GDPR and is often a challenge for companies without centralized data management. However, with clear processes, an up-to-date ROPA, and the right technical support, requests can be handled securely, efficiently, and on time.
Companies that implement the right of access properly turn it into an opportunity: you reduce legal risks, strengthen data subjects' trust, and improve your overall compliance.
Manual processing costs valuable time. Automation is the only scalable solution for reducing processing time from weeks to days while staying audit-proof.
FAQ
How quickly do I have to respond?
How quickly do I have to respond?
Within one month of receiving the request. In exceptional cases (high complexity or volume), an extension to three months is possible, but it must be justified within the one-month period.
Can I refuse a request?
Can I refuse a request?
Yes, e.g., in the case of manifestly unfounded, excessive, or abusive requests. However, this is only permitted within narrow limits and must also be justified within the deadline.
How do I provide the data copy correctly?
How do I provide the data copy correctly?
Electronically, in a structured and machine-readable format — where possible. The transfer should take place via a secure channel, as it involves sensitive personal data.
Do I also have to search files in backups?
Do I also have to search files in backups?
No. If data is only stored in backups (which serve the purpose of recovery), you don't have to actively search them. However, you must communicate that the data is stored there inactively and will be deleted once the backup cycles expire.








