1. Introduction: The Central Role of the Right of Access in the GDPR Framework
Article 15 of the General Data Protection Regulation (GDPR) establishes one of the most fundamental and practically significant rights available to data subjects: the right to access personal data held about them by controllers and to obtain meaningful information about how such data are processed.
The right of access represents the operational expression of the GDPR's transparency principle contained in Article 5(1)(a), which requires that personal data be processed lawfully, fairly, and transparently. Transparency cannot exist merely through general privacy notices or abstract disclosures. A data subject must have the ability to discover what personal information an organisation actually holds, how it is being used, who receives it, how long it is retained, and whether automated processes influence decisions affecting them.
Article 15 therefore addresses a fundamental problem inherent in modern data processing: the informational imbalance between controllers and individuals.
Controllers generally possess extensive knowledge regarding:
-
what categories of personal data are collected;
-
where such data are stored;
-
who has access to them;
-
how algorithms analyse them;
-
how long they are retained;
-
whether they are transferred internationally; and
-
whether they influence decisions concerning individuals.
By contrast, individuals often have little visibility into these processing operations. Article 15 seeks to correct this imbalance by giving data subjects a legal mechanism to obtain knowledge about their personal data and verify whether processing complies with the GDPR.
As recognised by the Court of Justice of the European Union (CJEU), the right of access is not merely an administrative convenience but a fundamental right protected under Article 8(2) of the Charter of Fundamental Rights of the European Union (CFR).
Article 8(2) CFR provides:
“Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.”
Consequently, Article 15 must be interpreted not only as a procedural right under the GDPR but also as a fundamental right requiring effective implementation consistent with the principles of necessity and proportionality under Article 52(1) CFR.