Privacy

Access request under Article 15 GDPR: identity, deadline and data copy

How businesses in Austria assess Article 15 GDPR access requests, verify identity, calculate the deadline and prepare a clear copy of the data.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

15 August 2026 · Mag. Bernhard Brandauer, Rechtsanwalt

An access request under Article 15 GDPR may look like a simple request for stored data. In practice, the first questions are who is making the request, which processing activities are concerned and whether the identity has been verified sufficiently. The deadline, search effort and preparation of the data copy then have to be managed together.

This article describes the process from the perspective of a business receiving a request. It focuses on receipt, identity verification, the one-month period, a possible extension and a clear response. A civil-law accounting claim or a general request for access to a file must be distinguished from the data subject right of access.

First assessment

What should you check in an access request now?

Answer the questions about receipt, identity and scope. The result is an initial orientation, not a decision on the individual case, but it indicates which documents and next steps matter first.

01 Question 1

In what role are you handling the request?

The next steps differ depending on whether your business is the controller or a service provider.

Ergebnis

Ihre Orientierung

01

The request has arrived, but the allocation of roles must be mapped first.

Record the receipt and clarify without delay whether your business answers the request or supports the controller. A processor should not decide the request independently, but should follow the agreed process and secure the necessary information.
Read more about processors and service providers →
02

A reliable allocation of responsibilities is missing before the substantive response.

Allocate responsibilities, systems and contact persons. The data subject should receive a clear response even if several businesses are involved in the processing.
Data subject rights and access →
03

The requester has not yet been allocated with sufficient certainty.

Ask clearly and proportionately for the limited additional information needed for identity verification. Record the request, the timing and the data that could already be allocated securely.
Open the access request checklist →
04

The request is broad and requires a structured search.

Identify the relevant processing activities and systems. A broad request should not be rejected automatically. A focused clarification can help prepare a complete and understandable response.
Check data protection roles →
05

Identity and search scope are broadly clear.

Calculate the response deadline from receipt of a sufficiently allocated request. Search the relevant data, review the rights of others and prepare a clear response with the copy of the data.
Review the process step by step →

What Article 15 GDPR requires

Article 15 GDPR gives the data subject the right to obtain confirmation from the controller as to whether personal data is being processed and, where that is the case, access to the data. The information can include the purposes of processing, categories of personal data, recipients or categories of recipients, the envisaged storage period or the criteria used to determine it, and information about the available rights. The source of the data and automated decision-making may also be relevant.

The first copy of the personal data must generally be provided free of charge. Further copies may be charged at a reasonable fee, or the controller may refuse further action, where requests are manifestly unfounded or excessive. This exception requires a careful assessment and should not be assumed merely because the search is time-consuming.

The data copy is not simply an unstructured collection of all files. It must make the personal data accessible and understandable. Explanations about sources, recipients and retention help the data subject understand the response.

Verify identity securely and proportionately

A business must not disclose data to an arbitrary person. The risk of confusion matters especially for customer accounts, employee information or health data. The additional verification should reflect the information already held and the risk that a mistaken disclosure would create. It should not become a general request for more documents.

A follow-up question can often use a previously verified communication channel or known contract details. If an identity document is needed, information that is not required should be redacted where possible. Record the request, the follow-up, the timing and the final allocation in a traceable way.

If identity remains unclear despite reasonable steps, the matter is not resolved by a blanket refusal. Explain what allocation is still missing and which limited information would allow the request to be processed. The communication should make it possible for the data subject to exercise the right effectively.

Calculate the deadline and any extension

Under Article 12(3) GDPR, an access request must generally be answered without undue delay and in any event within one month of receipt. The period may be extended by up to two further months where necessary, taking into account the complexity and number of requests. The data subject must be informed of the extension within one month of receipt, together with the reasons for the delay.

The start of the period is one of the most important records. Note when the request arrived, when the identity was sufficiently clarified and what communication followed. Internal routing should not mean that a request is only recognised weeks later.

Do not wait until the deadline is about to expire before asking individual departments to search their systems. Assign coordination, identify the participating teams and nominate a person to check the data copy for completeness and the rights of others before sending it.

Search for data and prepare a clear copy

The search should follow the actual processing activities. Depending on the business, this may include a CRM, customer portal, email system, support platform, recruitment records, payroll, video management or paper files. Search not only by name, but also by contact details, customer number, user ID and earlier spellings.

Separate personal data from documents that only concern internal organisation. At the same time, do not remove information simply because it appears in an internal file. The question is whether it relates to the data subject. The answer should present the data in a form that can be understood without specialist knowledge.

Before sending, review the rights and freedoms of other people. This can require redactions or a separate presentation of particular content. Trade secrets, professional secrecy and ongoing proceedings can create additional issues. A blanket redaction of an entire document is not a substitute for an individual assessment.

Avoid common mistakes in access requests

The receipt is not recorded: A request sent to customer service, a manager or a contact form is not recognised as a data subject request. Clear internal responsibilities and a central deadline record are needed.

Identity checks are too strict or too weak: An unstructured request for an identity document may collect unnecessary data, while an uncritical disclosure may reach the wrong person. The check must match the risk and the information already held.

Only one system is searched: A CRM response may be incomplete if emails, support, archives or personnel records are not considered. The search areas should be documented and justified.

The data copy is confused with a complete file: Article 15 GDPR concerns personal data and the associated information required by the Regulation. Not every internal note must be transferred unchanged, but relevant personal data cannot be omitted without assessment.

An extension is announced without reasons: An extension requires timely notice and understandable reasons. A general reference to workload is not a careful explanation of the delay.

Distinguish other information rights

An Article 15 request may be combined with other requests. The data subject may also ask for rectification, erasure or restriction of processing. Those rights have their own requirements and should be recorded separately. An overview of the wider subject rights is available on the data subject rights and access page.

Not every request for documents is an Article 15 access request. Accounting, company-law information rights, employment records or the delivery of a complete contract may be governed by other rules. The title used by the requester is less important than the substance of the request. The identifiable data protection part should not be overlooked.

Where several businesses are involved, controllers, processors and joint controllers must be distinguished carefully. The role check offers an initial orientation. The contractual and actual cooperation still requires an individual assessment.

Check the response before sending

A useful response first explains whether personal data is being processed. It then provides the data copy and the information about purposes, categories, recipients, retention, source and other rights where relevant. The presentation should distinguish the data itself from the additional information required by Article 15.

Before sending, check the recipient, attachments, redactions and transmission channel. A secure channel is particularly important for sensitive data. Also check whether a rectification request, erasure request or another subject right must be handled at the same time.

For internal handling, the access request checklist provides a useful sequence for receipt, identity, search, deadline, response and documentation. It does not replace an individual legal assessment, but it helps keep the process complete.

Frequently asked questions about access requests

Does an access request have to follow a specific format? No. It can generally be made through different communication channels. What matters is that the exercise of the Article 15 right can be recognised. Businesses should not overlook the request because it has no formal heading.

Does the one-month period only start after an identity document is provided? Not automatically. Receipt and the circumstances of the identity check are relevant. Additional information may only be requested where it is necessary for identification. The calculation should be documented for the individual case.

Must the business disclose every email? That depends on which personal data the emails contain and which rights of other people are affected. An unchecked transfer of complete correspondence is not always correct, but neither is a blanket exclusion of email communication.

FAQ

Frequently asked questions about access requests

Does an access request have to follow a specific format? +
No. It can generally be made through different communication channels. What matters is that the exercise of the Article 15 right can be recognised.
Does the one-month period only start after an identity document is provided? +
Not automatically. Receipt and the circumstances of the identity check are relevant. Additional information may only be requested where it is necessary for identification.
Must the business disclose every email? +
That depends on which personal data the emails contain and which rights of other people are affected. An unchecked transfer of complete correspondence is not always correct, but neither is a blanket exclusion of email communication.

Clarify the concrete process

An access request depends on the actual processing activities, the systems used and the communication with the requester. We assess the role of your business, the documented deadline and the form of the data copy that fits the matter. Contact us with the request, previous responses and relevant internal documents so that the next steps can be defined clearly.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich