CHAPTER IIIRIGHTS OF THE DATA SUBJECT

Article 15Right of access by the data subject

Official text

(1)The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:

(a)the purposes of the processing;

(b)the categories of personal data concerned;

(c)the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;

(d)where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;

(e)the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;

(f)the right to lodge a complaint with a supervisory authority;

(g)where the personal data are not collected from the data subject, any available information as to their source;

(h)the existence of automated decision-making, including profiling, referred to in Article 22 (1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

(2)Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer.

(3)The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.

(4)The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others.

Commentary

1. Introduction: The Central Role of the Right of Access in the GDPR Framework

Article 15 of the General Data Protection Regulation (GDPR) establishes one of the most fundamental and practically significant rights available to data subjects: the right to access personal data held about them by controllers and to obtain meaningful information about how such data are processed.

The right of access represents the operational expression of the GDPR's transparency principle contained in Article 5(1)(a), which requires that personal data be processed lawfully, fairly, and transparently. Transparency cannot exist merely through general privacy notices or abstract disclosures. A data subject must have the ability to discover what personal information an organisation actually holds, how it is being used, who receives it, how long it is retained, and whether automated processes influence decisions affecting them.

Article 15 therefore addresses a fundamental problem inherent in modern data processing: the informational imbalance between controllers and individuals.

Controllers generally possess extensive knowledge regarding:

  • what categories of personal data are collected;

  • where such data are stored;

  • who has access to them;

  • how algorithms analyse them;

  • how long they are retained;

  • whether they are transferred internationally; and

  • whether they influence decisions concerning individuals.

By contrast, individuals often have little visibility into these processing operations. Article 15 seeks to correct this imbalance by giving data subjects a legal mechanism to obtain knowledge about their personal data and verify whether processing complies with the GDPR.

As recognised by the Court of Justice of the European Union (CJEU), the right of access is not merely an administrative convenience but a fundamental right protected under Article 8(2) of the Charter of Fundamental Rights of the European Union (CFR).

Article 8(2) CFR provides:

“Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.”

Consequently, Article 15 must be interpreted not only as a procedural right under the GDPR but also as a fundamental right requiring effective implementation consistent with the principles of necessity and proportionality under Article 52(1) CFR.

2. Purpose and Function of the Right of Access

2.1 Correcting the Informational Imbalance Between Controllers and Data Subjects

Modern data processing frequently operates invisibly. Individuals interact with digital platforms, financial institutions, healthcare providers, employers, advertising networks, and public authorities without necessarily knowing:

  • what data points are collected;

  • how those data points are combined;

  • whether profiles are created;

  • whether decisions are automated;

  • whether information is shared with third parties.

A privacy policy provided under Articles 13 and 14 GDPR attempts to address this problem by providing general information before processing occurs. However, such information remains generic because it describes intended or possible processing activities applicable to users generally.

Article 15 performs a different function.

It provides specific, personalised, ex-post transparency.

The distinction between Articles 13 and 14 and Article 15 can therefore be summarised as:

Articles 13 and 14 GDPRArticle 15 GDPR
Proactive obligationReactive obligation
Provided before or at collectionProvided after processing has occurred
General informationIndividualised information
Explains intended processingReveals actual processing
Applies generally to groups of usersApplies to a specific data subject

Example

a social media platform may state in its privacy policy:

“We may use information to personalise content, improve services, and provide advertising.”

This disclosure satisfies a general transparency obligation.

However, when an individual submits an Article 15 request, the controller must provide information such as:

  • whether that specific person's data was used for advertising;

  • which categories of data were analysed;

  • which advertisers received access;

  • what profile was created;

  • whether automated systems evaluated the person.

A mere reference to the privacy policy is insufficient.

The European Data Protection Board (EDPB) has repeatedly emphasised that Article 15 requires tailored and updated information concerning actual processing operations.

3. Relationship Between Article 15 and Other GDPR Rights

The right of access operates as the foundation for the effective exercise of many other GDPR rights.

A data subject cannot meaningfully exercise:

  • Article 16, right to rectification;

  • Article 17, right to erasure;

  • Article 18, right to restriction of processing;

  • Article 20, right to data portability;

  • Article 21, right to object;

  • Article 22, rights concerning automated decision-making,

unless they first understand what personal data are being processed.

For example:

A person cannot request rectification of inaccurate credit information unless they know:

  • that the information exists;

  • what information is recorded;

  • which organisation supplied it;

  • how it affects their credit assessment.

Similarly, an individual cannot challenge an automated employment decision unless they understand:

  • whether automated processing occurred;

  • what data influenced the decision;

  • what logic or criteria were applied.

Therefore, Article 15 functions as an enabling right.

It provides the factual foundation upon which other GDPR rights can operate.

4. Article 15 as an Independent Fundamental Right

A common misunderstanding is that individuals may only use Article 15 when they intend to exercise another GDPR right.

This interpretation is incorrect.

The right of access is an independent right.

A data subject does not need to explain:

  • why they want access;

  • whether they suspect unlawful processing;

  • whether they intend litigation;

  • whether they want to correct information;

  • whether they simply want awareness.

The controller has no authority to evaluate the individual's motivation.

The EDPB Guidelines 01/2022 on Data Subject Rights, Right of Access state that controllers should assess:

“what the data subject is requesting” rather than “why the data subject is requesting”.

This prevents controllers from refusing access based on assumptions regarding the individual's intentions.

4.1 CJEU Judgment: FT and DW (Case C-307/22)

The CJEU confirmed the independence of the right of access in FT and DW v Krankenversicherung Nordrhein (C-307/22).

The case concerned a patient requesting access to medical records from a dentist.

Under German law, patients could obtain copies of medical records but might be required to pay costs. The healthcare provider argued that the patient's request was not genuinely connected to exercising GDPR rights but was instead motivated by another purpose.

The CJEU rejected this argument.

It held that:

  • the reason behind an access request is irrelevant;

  • the first copy of personal data must generally be provided free of charge;

  • the right exists independently of the individual's purpose.

The Court stated that Article 15 GDPR:

“cannot be made conditional upon the data subject demonstrating a particular purpose.”

This judgment confirms that controllers cannot conduct a subjective assessment of whether a request is “legitimate enough”.

5. Passive Ex-Post Information Obligation

Unlike Articles 13 and 14 GDPR, Article 15 does not require controllers to provide information automatically.

It creates a passive obligation.

The controller must respond when a data subject makes an access request.

However, once triggered, the obligation is extensive.

The controller must provide:

  1. confirmation whether personal data are processed;

  2. access to those personal data;

  3. information listed under Article 15(1)(a), (h);

  4. information concerning international transfers under Article 15(2);

  5. a copy of personal data under Article 15(3).

Therefore, Article 15 combines two separate but connected elements:

(a) Access to personal data itself

The individual receives the actual personal information processed.

(b) Transparency regarding processing operations

The individual receives information explaining:

  • why data are processed;

  • who receives them;

  • retention periods;

  • automated decision-making;

  • data sources.

Both components are necessary.

Providing only a summary of processing activities does not satisfy Article 15.

Similarly, providing raw data without explaining processing would undermine transparency.

6. Scope of the Right: “Personal Data Concerning Him or Her”

The scope of Article 15 depends on the meaning of “personal data”.

Article 4(1) GDPR defines personal data broadly as:

“any information relating to an identified or identifiable natural person.”

The right of access therefore covers a wide range of information.

According to the EDPB, this includes:

6.1 Data Directly Provided by the Individual

Examples

  • account registration details;
  • contact information;
  • questionnaire responses;
  • application forms;
  • customer complaints.

6.2 Observed Data

These are data generated through interaction with services.

Examples

  • browsing history;
  • location data;
  • purchase history;
  • search activity;
  • device information;
  • access logs;
  • behavioural patterns.

Example

a streaming platform's record of:

  • films watched;

  • viewing duration;

  • pauses;

  • searches;

constitutes personal data accessible under Article 15.

6.3 Derived and Inferred Data

Article 15 also covers information created by the controller through analysis.

Examples

include:

  • credit scores;
  • risk classifications;
  • customer profiles;
  • predicted interests;
  • fraud assessments;
  • health predictions. This is particularly important because individuals often have no awareness that such information exists. A bank may not only store: “Customer income: €50,000” but may also create: “Customer represents low credit risk.” That assessment relates to the individual and falls within the scope of access.

7. Confirmation Whether Personal Data Are Being Processed

The first obligation under Article 15(1) is confirmation.

The controller must inform the data subject whether personal data concerning them are processed.

This obligation applies even where no data exists.

If the controller does not process any personal data concerning the individual, it must state this clearly.

A controller cannot simply ignore the request.

The response must therefore be:

  • positive confirmation; or

  • negative confirmation.

The obligation is important because individuals may not know whether an organisation holds information about them.

For example:

A person may request access from a marketing company after discovering targeted advertising. The company must confirm whether it holds personal data about that person, even if the answer is that no such data exist.

Article 15 GDPR, Right of Access by the Data Subject

8. Detailed Analysis of Article 15(1)(a), (h)

Once the controller confirms that it processes personal data relating to the requesting individual, Article 15 requires the controller to provide not only the data themselves but also detailed contextual information about the processing. These transparency requirements transform access from a simple disclosure of information into an explanation of how and why personal data are used. Each element serves a distinct purpose in enabling the data subject to verify compliance with the GDPR and exercise other data protection rights effectively.

(a) Purposes of the Processing

The first item that must be disclosed is the purposes for which the personal data are actually being processed.

This requirement appears straightforward, but it differs significantly from the obligations under Articles 13 and 14 GDPR.

Articles 13 and 14 require controllers to explain the intended purposes of processing at the time personal data are collected or obtained. Article 15, by contrast, requires controllers to disclose theactual purposes for which the specific data subject's information is being processed at the time of the access request.

The distinction is important because processing activities frequently evolve over time.

Example

an online retailer may initially collect customer information for the purpose of processing purchases. Subsequently, the same information may also be used for:

  • behavioural advertising;

  • fraud detection;

  • customer analytics;

  • personalised recommendations;

  • marketing campaigns;

  • product development.

An access response must therefore identify which of these purposes actually apply to the requesting individual.

Merely copying a list of all possible purposes from the privacy policy would not satisfy Article 15 because such information may include processing activities that never occurred in relation to that particular data subject.

The EDPB emphasises that responses under Article 15 must be updated, individualised and factually accurate.

Good practice therefore requires controllers to explain:

  • which personal data support each processing purpose;

  • whether all collected data are used for every purpose;

  • whether processing purposes have changed since collection.

Where legal bases differ between purposes, for example, contractual necessity for account administration and legitimate interests for fraud prevention, the controller should also indicate the applicable legal basis, even though Article 15 does not expressly require this. The EDPB considers disclosure of legal bases an important aspect of transparent processing.

(b) Categories of Personal Data Concerned

Article 15(1)(b) requires controllers to identify the categories of personal data being processed.

Although the data subject simultaneously receives access to the actual personal data under Article 15(3), categorisation serves an additional transparency function by helping individuals understand the overall structure of processing.

Examples

include:

  • identification information;
  • contact information;
  • financial data;
  • employment records;
  • medical information;
  • biometric identifiers;
  • location information;
  • browsing behaviour;
  • purchasing history;
  • communication records;
  • inferred preferences;
  • risk scores. This overview becomes particularly valuable where controllers process very large datasets.

Example

a multinational social media platform may process thousands of individual data points relating to one user. Rather than forcing the user to analyse every single record individually, categories provide an organised overview of the types of information collected.

The categories must accurately reflect the data actually processed and not merely reproduce broad classifications contained in generic privacy notices.

(c) Recipients or Categories of Recipients

One of the most practically important elements of Article 15 concerns disclosure of recipients.

Individuals are entitled to know:

  • who has received their personal data;

  • who may receive them in the future;

  • whether disclosures occurred internationally.

This provision has become increasingly significant because modern digital ecosystems involve extensive sharing between controllers, processors, affiliates, advertisers, cloud providers and analytics companies.

The Österreichische Post Judgment (Case C-154/21)

A landmark judgment of the Court of Justice clarified the meaning of Article 15(1)(c).

In Österreichische Post, the controller argued that identifying categories of recipients should satisfy the obligation.

The CJEU rejected this interpretation.

The Court held that, where possible, controllers must disclose the actual identity of recipients rather than merely describing categories.

Only where identifying recipients is impossible, or where the request is manifestly unfounded or excessive under Article 12(5), may controllers limit disclosure to recipient categories.

This judgment significantly strengthens transparency.

Example

instead of stating:

"Your data may have been shared with marketing partners."

The controller should state:

  • Company A Ltd.

  • Company B GmbH.

  • Company C SAS.

This enables individuals to understand precisely where their information has travelled and, if necessary, exercise rights directly against those recipients.

The judgment reflects the GDPR's objective of ensuring meaningful rather than theoretical transparency.

(d) Retention Period

Article 15(1)(d) requires controllers to inform individuals of:

  • the period for which personal data will be stored; or

  • if that is impossible, the criteria used to determine that period.

Storage limitation represents one of the core principles of Article 5 GDPR.

Without knowing retention periods, individuals cannot assess whether controllers continue processing personal data longer than necessary.

Generic statements are insufficient.

Example

responses such as:

"We retain data as long as necessary."

or

"We retain information in accordance with applicable law."

do not satisfy Article 15 because they fail to provide meaningful information.

Instead, controllers should explain:

  • contract data retained for seven years after termination;

  • recruitment files retained for twelve months after rejection;

  • CCTV recordings deleted after thirty days;

  • customer service calls retained for two years.

Where multiple categories of personal data have different retention schedules, each should be identified separately.

The EDPB further recommends identifying the event that triggers deletion, such as:

  • contract termination;

  • account closure;

  • withdrawal of consent;

  • expiry of statutory limitation periods.

Such specificity enables individuals to understand precisely when their information will cease to be processed.

(e) Information About Other GDPR Rights

Article 15 requires controllers to remind individuals of their continuing rights, including:

  • rectification (Article 16);

  • erasure (Article 17);

  • restriction of processing (Article 18);

  • objection (Article 21).

This provision reinforces the enabling function of Article 15.

Once individuals discover inaccurate, excessive or unlawfully processed personal data through an access request, they should immediately understand the legal mechanisms available to challenge such processing.

The EDPB recommends tailoring this information wherever possible.

Example

if a particular processing operation is based on legal obligation, the right to object may not be available in the same manner as processing based upon legitimate interests.

Providing only relevant rights improves transparency and avoids unnecessary confusion.

Although Article 15 does not expressly mention the right to data portability or withdrawal of consent, many supervisory authorities recommend informing individuals about these rights where applicable, consistent with Article 12's transparency principle.

(f) Right to Lodge a Complaint

Controllers must also inform data subjects that they have the right to lodge a complaint with a supervisory authority.

Unlike several other elements of Article 15, this requirement does not require individual tailoring.

Every data subject has the right under Article 77 GDPR to complain to a supervisory authority if they believe the Regulation has been infringed.

Including this information reinforces the accountability of controllers and reminds individuals that enforcement ultimately lies not only with private rights but also with independent public authorities.

(g) Source of Personal Data

Where personal data were not obtained directly from the data subject, Article 15 requires controllers to disclose any available information concerning the source of those data.

This obligation complements Article 14 GDPR.

However, Article 15 concerns actual historical collection rather than anticipated collection.

Examples

include:

  • data purchased from brokers;
  • public registers;
  • employers;
  • insurers;
  • financial institutions;
  • government databases;
  • CCTV systems;
  • cookies;
  • online tracking technologies. Transparency requires more than merely naming the source. Where possible, controllers should explain:
  • which categories of personal data originated from each source;
  • when those data were obtained;
  • by what means they were collected. For example: Identity information may have been obtained from an employer, while behavioural data originated through website cookies. Such distinctions allow data subjects to understand the complete lifecycle of their personal information. The EDPB interprets "any available information" broadly. Controllers cannot deliberately avoid documenting data sources in order to evade disclosure obligations. Effective accountability under Articles 24 and 30 GDPR requires organisations to maintain adequate records of data provenance.

(h) Automated Decision-Making and Profiling

Perhaps the most technologically significant element of Article 15 concerns automated decision-making.

Controllers must disclose:

  • whether automated decision-making exists;

  • whether profiling is involved;

  • meaningful information about the logic used;

  • the significance of the processing;

  • its envisaged consequences.

This provision has become increasingly important in the age of artificial intelligence, machine learning and predictive analytics.

Individuals increasingly encounter automated decisions concerning:

  • loan applications;

  • insurance pricing;

  • recruitment;

  • fraud detection;

  • healthcare;

  • education;

  • social media moderation.

Without adequate explanations, individuals cannot understand why particular decisions were reached.

Dun & Bradstreet Austria (Case C-203/22)

The CJEU significantly strengthened transparency obligations in Dun & Bradstreet Austria.

The Court held that Article 15(1)(h) creates a genuine right to an explanation regarding automated decision-making.

Controllers must explain:

  • the procedure actually applied;

  • the principles governing the decision;

  • which personal data influenced the outcome;

  • how those data contributed to the final result.

Importantly, merely disclosing source code or complex algorithms does not satisfy Article 15.

Instead, explanations must be meaningful from the perspective of the data subject.

Example

rather than stating:

"A neural network assigned probability weights."

the controller should explain:

"Your repayment history, current income, outstanding debts and previous defaults were analysed. These factors resulted in a high credit risk classification, which contributed to the refusal of your loan application."

This interpretation aligns Article 15 with emerging global debates concerning explainable AI and algorithmic accountability.

Article 15 GDPR, Right of Access by the Data Subject

9. Article 15(2): Right to Information Regarding International Data Transfers

Globalisation has fundamentally changed the way personal data are processed. Cloud computing, multinational corporate structures, outsourcing arrangements, artificial intelligence services, software-as-a-service (SaaS) providers, and international analytics platforms frequently involve transfers of personal data outside the European Economic Area (EEA). Such transfers may expose individuals to legal systems that do not provide an equivalent level of data protection.

Recognising this risk, Article 15(2) grants data subjects an additional transparency right. Where personal data are transferred to a third country or an international organisation, the controller must inform the data subject about the appropriate safeguards adopted pursuant to Article 46 GDPR.

Unlike Article 15(1), which focuses on processing generally, Article 15(2) specifically addresses cross-border data transfers.

The provision serves two important objectives.

First, it enables individuals to understand where their personal information travels beyond the European Union.

Secondly, it allows individuals to assess whether international transfers are adequately protected and comply with Chapter V GDPR.

Example

if a European company stores customer information on servers operated by a cloud provider in the United States, the controller should explain:

  • the destination country;

  • the legal transfer mechanism;

  • the safeguards implemented;

  • how a copy of those safeguards may be obtained.

Where transfers rely on Standard Contractual Clauses (SCCs) under Article 46(2)(c), the controller should identify this mechanism and explain how the individual may access the relevant contractual safeguards.

Similarly, if transfers rely upon Binding Corporate Rules (BCRs), approved codes of conduct or certification mechanisms, these safeguards should be clearly identified.

Providing this information enhances transparency regarding one of the most legally sensitive aspects of international data processing.

10. Article 15(3): The Right to Receive a Copy of Personal Data

Perhaps the most frequently exercised component of Article 15 is contained in paragraph (3), which provides that:

"The controller shall provide a copy of the personal data undergoing processing."

This obligation gives practical effect to the right of access.

Merely informing a person that personal data exist would not allow meaningful verification of accuracy or lawfulness.

Instead, individuals must receive an actual copy of the personal data.

The copy enables them to:

  • verify correctness;

  • identify inaccuracies;

  • detect unlawful processing;

  • assess excessive collection;

  • understand profiling;

  • preserve evidence where necessary.

The EDPB emphasises that the copy requirement is not an independent right separate from Article 15(1) but rather the principal method through which access is implemented.

11. What Constitutes "Personal Data Undergoing Processing"?

The phrase "personal data undergoing processing" has broad scope.

It encompasses all personal data that continue to exist within the controller's processing operations at the time the access request is handled.

Examples

include:

Identity Data

  • name

  • address

  • date of birth

  • passport number

Financial Data

  • salaries

  • bank accounts

  • invoices

  • payment history

Employment Data

  • evaluations

  • attendance records

  • disciplinary reports

Health Data

  • diagnoses

  • prescriptions

  • laboratory results

  • medical history

Technical Data

  • IP addresses

  • device identifiers

  • cookies

  • server logs

Behavioural Data

  • browsing history

  • clicks

  • searches

  • purchases

Derived Data

  • customer segmentation

  • fraud scores

  • risk classifications

  • recommendation profiles

AI-generated Inferences

  • creditworthiness

  • behavioural predictions

  • fraud probability

  • purchasing propensity

  • health risk assessments

Deleted or anonymised information no longer undergoing processing falls outside Article 15.

However, archived information, pseudonymised records, backup systems, or information stored in long-term databases generally remain within scope if they continue to constitute personal data.

12. The Meaning of "Copy"

One of the most important developments in Article 15 jurisprudence concerns the interpretation of the word "copy."

Does "copy" merely require controllers to reproduce extracted personal data?

Or must controllers provide copies of the original documents themselves?

This issue was settled by the Court of Justice.

13. The CRIF Judgment (C-487/21)

In Österreichische Datenschutzbehörde and CRIF, the Court held that Article 15(3) requires the controller to provide a "faithful and intelligible reproduction" of personal data.

This judgment represents one of the most influential interpretations of Article 15.

The Court rejected both extremes.

On one hand, controllers cannot satisfy Article 15 by merely describing the information they possess.

On the other hand, Article 15 does not automatically entitle individuals to complete copies of every document in which their personal data appear.

Instead, the appropriate form depends upon what is necessary for the effective exercise of GDPR rights.

Where context matters, complete documents, or extracts thereof, may be required.

Examples

include:

  • emails;
  • meeting minutes;
  • investigation reports;
  • handwritten notes;
  • contracts;
  • database entries;
  • complaint files. The decisive question is whether providing only isolated data points would prevent the individual from understanding how the information was processed. The Court therefore adopted a practical rather than formal interpretation.

14. Faithful and Intelligible Reproduction

The concept of "faithful reproduction" serves two complementary objectives.

Accuracy

The copy must accurately reflect the original personal data.

Controllers cannot paraphrase, summarise or selectively reproduce information in a way that alters its meaning.

Understandability

The copy must remain intelligible.

Providing incomprehensible technical database exports without explanation may not satisfy Article 12's transparency requirements.

For example:

A database entry reading:

USR_10245: CL_RSK=4 FRAUD_IND=Y

would provide little meaningful information.

Instead, controllers should explain that:

  • the customer has been assigned a high credit risk score;

  • a fraud indicator has been applied;

  • these assessments influence transaction monitoring.

Transparency therefore concerns not merely disclosure but understandable disclosure.

15. Documents Versus Data

An important distinction emerges from CRIF.

Article 15 grants access to personal data, not necessarily to documents.

Nevertheless, where the document itself provides essential context, supplying the document may become necessary.

Examples

include:

Emails

A person's name appearing in an internal email may have little meaning without surrounding text.

Providing the relevant email excerpt may therefore be required.

Medical Records

A diagnosis cannot always be understood separately from accompanying examination results.

Complete medical reports may therefore constitute the appropriate form of access.

Handwritten Notes

Where handwriting itself forms part of the personal data, for example, forensic handwriting analysis, the original handwritten record may need to be reproduced.

Audio Recordings

A transcript may sometimes suffice.

However, where voice characteristics themselves constitute personal data (such as biometric voice recognition), access to the recording itself may become necessary.

Thus, Article 15 adopts a functional rather than rigid approach.

16. Electronic Copies

The GDPR reflects the realities of digital processing.

Where requests are submitted electronically, Article 15(3) provides that information should normally be supplied in a commonly used electronic format, unless the data subject requests otherwise.

Suitable formats include:

  • PDF

  • CSV

  • XML

  • JSON

  • HTML

  • Microsoft Word

  • Excel

  • OpenDocument

The EDPB emphasises that controllers should consider accessibility.

Individuals should not be required to purchase proprietary software merely to access their own personal data.

Where specialised formats are unavoidable, controllers should explain how they may be opened.

17. First Copy Free of Charge

The first copy must generally be provided free of charge.

This reflects the status of access as a fundamental right.

Charging individuals for exercising basic transparency rights would discourage accountability and undermine effective enforcement.

The FT and DW judgment confirms that controllers cannot charge merely because individuals intend to use the information for litigation or other purposes.

18. Charging for Additional Copies

Article 15 distinguishes between:

  • the first copy; and

  • subsequent copies.

Only additional copies may attract a reasonable administrative fee.

The fee must correspond to actual administrative costs.

Controllers cannot use charges to discourage access requests.

The EDPB recommends that controllers:

  • calculate genuine administrative expenses;

  • avoid allocating general overheads;

  • inform individuals in advance of the expected cost;

  • permit withdrawal of the request before costs are incurred.

Importantly, requesting updated personal data at a later date does not constitute a request for an additional copy.

A new access request concerns different information because processing may have changed.

19. Article 15(4): Protecting the Rights and Freedoms of Others

Article 15(4) introduces the principal limitation on the right to receive copies.

It provides:

"The right to obtain a copy shall not adversely affect the rights and freedoms of others."

This provision requires balancing competing fundamental rights.

Examples

include:

  • privacy of third parties;
  • confidentiality obligations;
  • intellectual property;
  • trade secrets;
  • copyright;
  • commercial confidentiality. However, Recital 63 makes one principle absolutely clear: The existence of competing rights cannot justify refusing all access. Instead, controllers must seek less restrictive alternatives.

20. Balancing Fundamental Rights

The CJEU has repeatedly emphasised that Article 15(4) must be interpreted consistently with Article 52(1) of the Charter.

Any limitation must therefore satisfy proportionality.

Controllers should consider measures such as:

  • redacting third-party names;

  • blurring faces in CCTV footage;

  • removing confidential commercial information;

  • separating relevant extracts;

  • anonymising unrelated individuals.

Only where disclosure genuinely cannot occur without seriously affecting protected rights may restrictions become appropriate.

This approach ensures that Article 15 remains effective while respecting competing legal interests.

21. Trade Secrets and Intellectual Property

Controllers frequently argue that disclosure would reveal:

  • algorithms;

  • software;

  • proprietary methodologies;

  • confidential investigations.

Recital 63 acknowledges that trade secrets deserve protection.

Nevertheless, the GDPR expressly states that these considerations must not result in refusal to provide all information.

Controllers should therefore disclose as much information as possible while protecting genuinely confidential elements.

Example

a credit scoring company need not disclose proprietary source code.

However, it must explain:

  • which personal data influenced the score;

  • which factors were considered;

  • how those factors affected the outcome.

This distinction has become increasingly significant in the regulation of artificial intelligence.

22. Article 15 in the Era of Artificial Intelligence

Although the GDPR predates the recent explosion of generative AI, Article 15 has become one of its most powerful accountability mechanisms.

Modern AI systems routinely process:

  • behavioural data;

  • location information;

  • purchasing history;

  • facial images;

  • biometric identifiers;

  • voice recordings;

  • interaction logs;

  • inferred preferences.

Article 15 enables individuals to discover:

  • whether AI processed their data;

  • whether profiling occurred;

  • what categories of information influenced automated decisions;

  • how those decisions affected them.

The Dun & Bradstreet Austria judgment significantly expands this protection by requiring meaningful explanations rather than opaque algorithmic references.

As AI governance develops under the EU AI Act, Article 15 will increasingly complement AI-specific transparency obligations by ensuring individuals retain direct access to the personal data underpinning algorithmic decision-making.

Article 15 GDPR - Right of Access by the Data Subject

23. Controller's Practical Obligations When Responding to an Access Request

Article 15 does not merely create a substantive right for the data subject; it also imposes significant operational obligations on controllers. Compliance with Article 15 requires organisations to establish internal governance mechanisms capable of locating, reviewing, compiling and securely delivering personal data within the strict timelines prescribed by Article 12 GDPR.

A compliant response generally involves the following steps:

(a) Verify the Identity of the Requester

Before disclosing personal data, the controller must verify that the request genuinely originates from the data subject or an authorised representative. This obligation stems from Article 12(6) and is reinforced by Recital 64. However, verification must be proportionate. Controllers should request additional information only where they have reasonable doubts regarding the requester's identity.

Example

if a customer submits an access request through their authenticated online account, demanding a copy of their passport would ordinarily be excessive and contrary to the data minimisation principle. Conversely, where a request arrives from an unfamiliar email address with no identifying information, reasonable identity verification measures are justified to prevent unauthorised disclosure.

(b) Identify All Relevant Personal Data

Controllers must conduct a comprehensive search across all systems where personal data may be processed. This includes:

  • customer relationship management (CRM) databases;

  • HR systems;

  • payroll records;

  • email archives;

  • cloud storage;

  • backup systems where retrieval is reasonably possible;

  • CCTV footage;

  • mobile device records;

  • paper files organised in filing systems.

The search should not be artificially limited to the systems most convenient for the organisation. Failure to conduct an adequate search may result in incomplete disclosure and a breach of Articles 12 and 15.

(c) Review and Prepare the Information

After identifying the relevant data, controllers should review the material to:

  • identify personal data belonging to the requester;

  • redact personal data relating to third parties where necessary;

  • assess whether any statutory restrictions under Article 23 GDPR apply;

  • determine whether trade secrets or confidential commercial information require limited protection;

  • ensure the response remains complete and intelligible.

(d) Provide the Information Securely

The final response should be transmitted using secure methods appropriate to the sensitivity of the personal data, such as encrypted email, secure download portals, password-protected files, or registered postal services where appropriate.

24. Interaction with Other Data Subject Rights

Article 15 occupies a central position within the GDPR because it enables the effective exercise of almost every other substantive right granted to data subjects.

(a) Relationship with Article 16 (Right to Rectification)

Individuals cannot meaningfully request correction of inaccurate personal data unless they first know what information is being processed. Access therefore serves as the gateway to rectification.

Example

a bank customer who discovers through an Article 15 request that their address or date of birth is incorrect may subsequently invoke Article 16 to require correction.

(b) Relationship with Article 17 (Right to Erasure)

Similarly, individuals often rely on Article 15 before requesting deletion of unlawfully processed or no longer necessary personal data. Access allows the data subject to identify the data they seek to erase and to verify whether the controller has complied with deletion requests.

(c) Relationship with Article 18 (Restriction of Processing)

Article 15 enables individuals to determine whether grounds exist for restricting processing while disputes concerning accuracy or lawfulness are resolved.

(d) Relationship with Article 20 (Data Portability)

Although Article 15 and Article 20 both involve obtaining copies of personal data, they serve distinct purposes. Article 15 concerns transparency and lawfulness, whereas Article 20 facilitates switching between service providers by allowing structured, machine-readable transmission of certain categories of data.

(e) Relationship with Article 21 (Right to Object)

Access enables data subjects to identify processing operations based on legitimate interests or direct marketing and thereby exercise their right to object under Article 21.

Accordingly, Article 15 functions as the practical foundation upon which most other GDPR rights are exercised.

25. Interaction with Articles 13 and 14

Articles 13 and 14 establish proactive transparency obligations. Controllers must provide prescribed information either when personal data are collected directly from the data subject (Article 13) or obtained indirectly (Article 14).

Article 15 differs fundamentally in several respects:

  • Articles 13 and 14 provide ex ante information before or at the commencement of processing.

  • Article 15 provides ex post information concerning actual processing activities.

  • Articles 13 and 14 generally describe intended processing applicable to categories of data subjects.

  • Article 15 requires personalised information tailored to the requesting individual.

Consequently, controllers cannot simply respond to an access request by referring the data subject to their privacy notice. The EDPB has consistently emphasised that Article 15 requires updated and individualised information reflecting the processing actually carried out in relation to the requester.

26. Restrictions under Article 23 GDPR

While Article 15 establishes a broad right of access, Union or Member State law may restrict this right where such limitations satisfy the conditions laid down in Article 23 GDPR.

Permissible restrictions may be adopted to safeguard interests such as:

  • national security;

  • defence;

  • public security;

  • prevention and investigation of criminal offences;

  • judicial independence;

  • important economic or financial interests;

  • regulatory inspections;

  • protection of the rights and freedoms of others.

However, restrictions must satisfy the principle of proportionality under Article 52(1) of the Charter of Fundamental Rights. Blanket exclusions from the right of access are inconsistent with the GDPR.

27. EDPB Guidelines on the Right of Access

The European Data Protection Board's Guidelines 01/2022 on Data Subject Rights, Right of Access provide authoritative practical guidance on the interpretation of Article 15. Several principles emerging from these Guidelines deserve particular emphasis.

First, controllers should interpret access requests broadly and avoid formalistic requirements. A request need not explicitly cite Article 15 or use legal terminology. Any communication indicating that an individual wishes to know what personal data are held should ordinarily be treated as an access request.

Secondly, controllers should not question the motives underlying the request. Whether the individual seeks information for personal curiosity, litigation, employment disputes, consumer complaints or academic research is legally irrelevant.

Thirdly, responses must be complete, accurate and tailored to the particular processing operations affecting the requester. Generic descriptions copied from privacy notices will rarely satisfy this obligation.

Fourthly, where controllers process very large quantities of information, they may invite the data subject to specify the scope of the request. Nevertheless, if the individual insists on obtaining all personal data, the controller must generally comply.

Finally, controllers should design internal systems that facilitate rather than hinder the exercise of access rights. Organisational convenience cannot justify incomplete disclosure.

28. Landmark CJEU Jurisprudence

The Court of Justice of the European Union has substantially developed the scope of Article 15 through several important judgments.

(a) Österreichische Post (Case C-154/21)

The Court held that where personal data have been disclosed, the controller must identify the actual recipients, not merely categories of recipients, unless identifying those recipients is impossible or the request is manifestly unfounded or excessive.

This judgment significantly strengthened transparency regarding data sharing.

(b) Österreichische Datenschutzbehörde and CRIF (Case C-487/21)

The Court clarified that the right to obtain a copy requires a faithful and intelligible reproduction of personal data. Where necessary, extracts from documents, or entire documents, must be provided if this is essential for the effective exercise of GDPR rights.

This decision confirms that context matters and that access cannot be reduced to isolated data fields where doing so would impair understanding.

(c) FT v DW (Case C-307/22)

The Court rejected the argument that controllers may refuse free copies because the requester intends to use the information for litigation or another non-privacy purpose. The first copy under Article 15(3) must generally be provided free of charge regardless of the data subject's motive.

(d) Dun & Bradstreet Austria (Case C-203/22)

This landmark judgment addressed automated decision-making and profiling. The Court held that Article 15(1)(h) grants individuals a genuine right to receive meaningful explanations of the logic underlying automated decisions. Controllers must explain the procedure and principles applied in a manner that enables the individual to understand how their personal data contributed to the outcome.

Collectively, these judgments reinforce a broad, purposive interpretation of Article 15 centred on effective transparency rather than formal compliance.

29. Comparison with the Indian Digital Personal Data Protection Act, 2023

The right of access under the GDPR is significantly more detailed than the corresponding rights available under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

Under Section 11 of the DPDP Act, a Data Principal is entitled to obtain information regarding:

  • a summary of personal data being processed;

  • processing activities undertaken;

  • identities of Data Fiduciaries and Data Processors with whom data have been shared;

  • any other prescribed information.

Although these rights promote transparency, they differ from Article 15 in several important respects.

Unlike the GDPR, the DPDP Act does not expressly require:

  • confirmation of whether processing is taking place;

  • disclosure of all categories of personal data;

  • provision of an actual copy of personal data;

  • disclosure of data sources;

  • disclosure of retention periods;

  • detailed information concerning automated decision-making;

  • information regarding international transfer safeguards;

  • identification of actual recipients rather than categories.

Accordingly, Article 15 provides a considerably broader and more operational right of access than the DPDP Act.

30. Practical Examples

Example 1

Social Media Platform A user requests access to their account data. The platform should provide:

  • profile information;
  • uploaded photographs;
  • messages (subject to third-party rights);
  • search history;
  • advertising profiles;

  • inferred interests;

  • recipients of shared information;

  • retention periods;

  • explanations of recommendation algorithms where Article 22 applies.

Example 2

Employer An employee submits an access request. The employer may need to disclose:

  • personnel files;
  • attendance records;
  • appraisal reports;
  • disciplinary records;
  • payroll information;

  • internal emails containing the employee's personal data (with appropriate redactions);

  • performance scores;

  • automated HR assessments.

Example 3

Hospital A patient requests access to their records. The hospital should provide:

  • diagnoses;
  • laboratory reports;
  • imaging results;
  • prescriptions;
  • treatment notes;

  • consultation reports;

  • information regarding recipients of medical data;

  • retention periods;

  • sources of externally obtained health information.

31. Challenges in the Digital Economy

Article 15 faces increasing challenges in modern digital environments.

Artificial intelligence systems generate large volumes of inferred data, including behavioural predictions and risk assessments. Determining whether such inferences constitute personal data, and how they should be disclosed, remains a developing area of law, though recent CJEU jurisprudence clearly favours broad disclosure where the information relates to an identifiable individual.

Similarly, cloud computing and complex data ecosystems often involve numerous processors and sub-processors operating across multiple jurisdictions. Controllers must therefore maintain robust records of processing activities to identify recipients, sources and international transfers accurately.

Large-scale behavioural advertising presents further difficulties because personal data are continuously combined, enriched and shared among multiple actors. Article 15 serves as one of the principal mechanisms through which individuals can illuminate these otherwise opaque processing activities.

32. Critical Evaluation

Article 15 represents one of the GDPR's greatest strengths. By empowering individuals to inspect the processing of their personal data, it transforms transparency from an abstract principle into an enforceable legal entitlement.

Its strengths include:

  • reducing informational asymmetry between controllers and individuals;

  • facilitating accountability and regulatory compliance;

  • enabling the effective exercise of all other data subject rights;

  • promoting trust in digital services;

  • increasing algorithmic transparency in automated decision-making.

Nevertheless, implementation remains challenging. Controllers often struggle to identify personal data across fragmented IT systems, redact third-party information efficiently and respond within statutory deadlines. Large access requests may require significant organisational resources.

Despite these challenges, administrative inconvenience cannot justify weakening a fundamental right. Instead, organisations should invest in privacy governance, records management, and privacy-by-design measures that facilitate efficient compliance.

As digital ecosystems become increasingly data-driven, Article 15 will continue to play a pivotal role in ensuring that individuals retain meaningful visibility and control over the processing of their personal information.