Privacy
Data protection focus

Data subject rights and access

Structure access requests under Article 15 GDPR, answer them on time and document the process clearly.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

An access request may come from a customer, employee, applicant or business contact. For the company, it is not simply an export from one system. It must determine which personal data concerning the person is processed, for which purposes, from which sources and in what form the answer can be understood.

Article 15 GDPR gives the data subject the right to obtain confirmation that personal data is being processed, access to that data and further information. This data protection right is separate from civil-law information claims. This page deals with the data protection request, not inheritance claims, accounting or other claims for disclosure of documents.

A reliable process matters: record receipt and the deadline, request additional identity information only where there are reasonable doubts, involve the relevant systems and assess the rights of other people as well as trade and business secrets. This overview cannot replace an assessment of the individual request.

Mag. Bernhard Brandauer, Rechtsanwalt

What an access request sets in motion

The request generally does not have to state a reason. A short message may be sufficient if it shows that a person wants to know whether and which personal data concerning them is being processed. The company should therefore record the substance of the message and its date of receipt, rather than relying only on the subject line.

Four questions help with the first classification: Who made the request? What role does the person have in the company or customer relationship? Which processing activities may be relevant? And which entity decides the purposes and means of processing? The controller must organise the response. A processor can assist with the search but does not replace the controller’s responsibility.

  • Record receipt, the communication channel and the responsible internal team.
  • Assign the request to the correct controller and the relevant processing activities.
  • Do not automatically treat every civil-law information claim as an Article 15 request.

Verify identity proportionately

The controller must facilitate the exercise of data subject rights. Additional evidence should therefore not be requested as a routine formality. If there are reasonable doubts about identity, however, the controller may request further information necessary to confirm it. The type and extent of the check must match the risk of the processing.

For an existing customer account, verified contact details or a secure login may be sufficient. For particularly sensitive data or a request from an unknown address, an additional proportionate confirmation may be necessary. A blanket request for an identity document in every case is not a substitute for a risk-based decision. The check and its reasons should be recorded.

What the response must contain

The response must be more than a statement that data is stored. Article 15 GDPR requires, in addition to the personal data, information on the purposes of processing, categories of personal data, recipients or categories of recipients, the storage period or the criteria used to determine it, the other data subject rights and the right to lodge a complaint with a supervisory authority.

If the data was not collected directly from the data subject, the available information on its source must also be included. Where automated decision-making, including profiling, is involved, the legally required information about the logic involved and the envisaged effects must be considered. For transfers to third countries, the appropriate safeguards must be identified.

The information must be provided in an intelligible form. An unexplained system extract may therefore be insufficient if the person cannot understand the processing or the allocation of the data. At the same time, the right of access is not a blanket right to every internal business document. The relevant personal data and the information required by law must be provided in a complete and comprehensible way.

Deadline, extension and communication

The controller must provide information on the measures taken without undue delay and at the latest within one month of receiving the request. The period may be extended by up to two further months where necessary because of the complexity or number of requests. The data subject must be informed of the extension and the reasons for it within the first month.

If the company takes no action, it must also explain the reasons at the latest within one month and inform the data subject about the possibility of lodging a complaint with a supervisory authority or seeking a judicial remedy. A deadline calendar with responsibility, interim checks and recorded dispatch helps prevent a response from being assembled at the last moment.

Copies, fees and limits

The first copy of the personal data is generally free of charge. For further copies, a reasonable fee based on administrative costs may be charged under the statutory conditions. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may charge a reasonable fee or refuse to act. The company must be able to substantiate the conditions for that decision.

If the request is made electronically, the information should be provided in a commonly used electronic form where possible, unless the data subject asks otherwise. Access may also be limited where the rights and freedoms of other people, trade or business secrets or specific statutory protections are affected. These limits require a concrete assessment. A blanket refusal of the entire request is not a substitute for that assessment, and the remaining information must still be provided.

Documentation for businesses

A good response is usually prepared before the final letter is drafted. Businesses should define who receives requests, which systems and processors are queried, who assesses the results and who approves the final response. The internal search should remain traceable without collecting more personal data than necessary for the request.

The file should record at least receipt and the deadline calculation, the identity check, the systems and teams queried, the data categories found, the review of recipients and storage periods, any redactions or limits, an extension with reasons and the dispatch of the response. You can use the access request checklist for the individual steps. The role check can help where responsibilities are unclear. The organisational framework is covered in privacy compliance and governance.

FAQ

Questions about data subject rights and access

Does an access request have to state a reason? +

No. The data subject generally does not have to give a particular reason. The company should nevertheless record the request clearly, assign it to the correct controller and document the requested communication channel.

How long does a business have to respond? +

The response must be provided without undue delay and at the latest within one month of receipt. For complex or numerous requests, the period may be extended by up to two months. The extension and its reasons must be communicated within the first month.

May the company request proof of identity? +

Further information may be requested where there are reasonable doubts about identity and the information is necessary to confirm it. The check must be proportionate. A blanket requirement for every request is not automatically justified.

Must the company provide every internal document? +

The right of access covers the personal data and the information listed in Article 15 GDPR. It is not an unlimited right to every internal document. The response must nevertheless explain the processing and the data clearly enough for the data subject to exercise their rights.

What should the company say if it finds no data? +

If no personal data concerning the applicant is processed, this should be stated clearly. The internal search and its scope should still be documented so that the negative response remains traceable.

Is an access response always free? +

The first copy is generally free. A reasonable fee for further copies may be possible under the statutory conditions. Manifestly unfounded or excessive requests are subject to additional requirements. The decision should be explained and documented.

Sources

  • Articles 12 and 15 GDPR

    Rules on the exercise of rights, deadlines, access information, copies and fees.

  • Austrian Data Protection Act, sections 1 and 4

    The Austrian framework for the protection of natural persons and its relationship with the GDPR.

  • Austrian Data Protection Authority, rights of the data subject

    Practical explanations of access, negative responses, identity checks and deadlines.

  • European Data Protection Board, guidelines on the right of access

    European guidance on the scope and practical handling of access requests.

BRANDaktuelle Legal News

Keep up with data protection law

Receive new articles and legal guidance from the firm through BRANDaktuelle Rechtsnews.

Subscribe to the newsletter

Clarify an access request in your business

If the request, deadline or scope is unclear, we can classify the processing and discuss the next sensible step.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich