Handle a data subject access request
From the first message to a traceable response: work through an Article 15 GDPR access request step by step.
A practical checklist for businesses: receipt, identity, data searches, deadlines, the copy of personal data and a documented response.
An access request under Article 15 GDPR requires an organised review. It is not enough to find personal data. You should also be able to show when the request arrived, how identity was checked, how the deadline was calculated and why the response is complete.
This checklist is limited to the data protection right of access. It does not cover civil-law information claims, accounting claims or file inspection. An early classification of an unclear or extensive request helps you prepare a complete response within the statutory deadline.
Tick off the points on your device. Your progress is stored locally and can be reset at any time.
0 of 39 points complete
01 Record the request and define its scope
Secure the original request first and clarify what the person is asking for.
02 Check identity and authority proportionately
An identity check should protect the right of access without creating an unnecessary barrier.
03 Search all relevant processing and data holdings
Create a reliable search trail covering every place where personal data may be processed.
04 Prepare the information, copy and third-party review
The response should cover the required information and provide an understandable copy.
05 Control the deadline and response route
Keep the one-month period and any lawful extension under active review.
06 Send the response and close the file
A good response shows what was checked and which information the data subject receives.
Legal framework
Article 15 GDPR gives the data subject the right to confirmation whether personal data are being processed, access to the processing information and a copy of the personal data. The information includes, among other things, purposes, data categories, recipients, retention, sources and information about automated decision-making.
Under Article 12(3) GDPR, the information must be provided without undue delay and generally within one month. The period may be extended under the statutory conditions for complex or numerous requests. Article 12(5) GDPR addresses the limited cases for reasonable costs or refusal, while Article 12(6) GDPR addresses additional identity checks where there are reasonable doubts.
The copy must not adversely affect the rights and freedoms of other people. Any exclusion, redaction or partial response therefore needs a specific and traceable assessment.
This checklist provides general orientation on the right of access under Article 15 GDPR. Whether a restriction, redaction or deadline decision is lawful depends on the circumstances of the individual case.
When the request becomes legally or practically difficult
Seek an early review if identity remains unclear, data are spread across several controllers, third-party rights may be affected or a complete response within the deadline is uncertain.
Subscribe to legal updates
Receive new articles and legal updates from the firm with BRANDaktuelle Rechtsnews.
Subscribe to the newsletter →
Mag. Bernhard Brandauer, Rechtsanwalt
BRANDAUER Rechtsanwälte
Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000