Skip to content
Datenschutz

GDPR Subject Access Requests: Answering Correctly

A customer asks for their data. What Article 15 GDPR requires, how the one-month deadline runs and how small firms work through the request in an orderly way.

13 min read DSGVODatenschutzRecht

An email with a single sentence: "Please send me all the data you hold about me." No subject line, no reason, no reference number. That is a subject access request under Article 15 GDPR, and the moment it arrives a one-month deadline starts running (Article 12(3) GDPR). In many small firms nothing has been prepared for this: data subject rights appear as a bullet point in the privacy policy and as an obligation in the contracts with service providers — the workflow behind them nowhere. This article describes what is required, how the deadline runs and what the website should have ready. It sets out the legal framework and supervisory practice; it is not legal advice, and borderline cases belong with a qualified adviser.

Access request: the workflow From receipt to answer, with the checks in between Deadline Day 0 Request received 30 days standard period Day 30 Answer or extension 60 days extension Day 90 Latest answer Article 15(1): points (a) to (h) a Purposes of processing b Categories of data c Recipients of the data d Storage period e Right to rectify f Right to complain g Source of the data h Automated decisions Plus the copy of the data under (3) Checked before answering Identity Scope Rights of others Deadline under Article 12(3) GDPR

What an access request is

Article 15(1) GDPR gives every person the right to obtain confirmation from a controller as to whether personal data concerning them are being processed. Where that is the case, they have a right of access to those data and to a list of further information set out in points (a) to (h) of the same provision (GDPR). The request is not bound to any form. It needs no template, no signature and no keyword, and the requesting person does not have to explain what they intend to do with the answer. The European Data Protection Board puts it plainly: it is not for the controller to analyse whether the request will actually help the data subject (EDPB Guidelines 01/2022).

What falls within the scope follows from Article 4(1) GDPR. Personal data there means "any information relating to an identified or identifiable natural person" (GDPR). That is broad and reaches well beyond name and address: order history, appointment records, payment details, complaint threads, notes in the customer record, submissions from the website form, email correspondence, photographs with a clear attribution. Pseudonymised data remain personal data as long as the link can be restored (EDPB Guidelines 01/2022). Anyone who reduces the answer to the master record in the till system has usually missed the scope of the provision.

Not every message that sounds like a request is one. Someone asking about delivery times is making a customer enquiry; someone asking which data you hold about them is making an access request. Conversely, a request is still a request when it sits inside a complaint letter, arrives through the messenger contact route or is made verbally at the counter. In its 2024 coordinated enforcement action the European Data Protection Board recorded that some responding controllers simply did not recognise access requests as such and could therefore neither track nor report them (EDPB).

The deadline starts on receipt

Article 12(3) GDPR requires the controller to provide information on the action taken "without undue delay and in any event within one month of receipt of the request" (GDPR). That period may be extended by a further two months where the complexity and number of requests make it necessary. The extension is not a silent right: the data subject has to be informed within the first month about the extension and the reasons for the delay. Anyone who lets the first month pass and then extends has already missed the condition for doing so. Where the controller does not act at all, Article 12(4) GDPR requires reasons within one month, together with a reference to the right to lodge a complaint and to a judicial remedy.

Scroll table sideways

Point in timeWhat is dueBasis
Day 0Request arrives, receipt is logged and acknowledgedArticle 12(3) GDPR
Day 1 to 3Assign responsibility, check identity only where doubts are reasonableArticle 12(6) GDPR
Day 3 to 20Search the systems, compile the data, check the rights of othersArticles 15(1) and 15(4) GDPR
Day 30Answer provided, or extension communicated with reasonsArticle 12(3) GDPR
Day 90Latest answer where the extension was communicated in timeArticle 12(3) GDPR

The period starts when the request reaches the controller through one of its official channels; it is not necessary that anyone in the firm has already read it (EDPB Guidelines 01/2022). If the inbox rests over the summer break, the deadline does not rest with it. There is one suspension: where doubts about identity make a follow-up question necessary and that question is asked without undue delay, time stops until the data subject replies. As good practice the Board recommends confirming receipt in writing and stating from which day to which day the month runs (EDPB Guidelines 01/2022). That costs one text module and removes any later dispute about when the clock started — the same logic as with response times for ordinary enquiries, only with a statutory ceiling.

What belongs in the answer

The answer has three parts: confirmation that processing takes place, the data themselves, and the additional information listed in points (a) to (h) of Article 15(1) GDPR. The third part is the one most often overlooked. In the 2024 coordinated action, 44 per cent of responding controllers reported that none of the access requests they received included a specific request for information on the underlying processing activities (EDPB). That does not release anyone: a general request for one's data is a request for the full scope of Article 15.

Purposes of processing

What the data are used for: performing the contract, scheduling, invoicing, audience measurement. Point (a).

Categories of data

Which kinds of data exist: master data, contract data, payment data, communication threads. Point (b).

Recipients

Who has received or will receive the data, including recipients in third countries. Point (c).

Storage period

How long the data are kept, or the criteria used to determine that period. Point (d).

Rights and complaints

Rectification, erasure, restriction, objection, and the right to lodge a complaint with a supervisory authority. Points (e) and (f).

Source and automation

Where the data came from if not collected from the person, and whether automated decision-making takes place. Points (g) and (h).

Then there is the copy. Article 15(3) GDPR obliges the controller to provide a copy of the personal data undergoing processing; where the request is made electronically, the information shall be provided in a commonly used electronic form unless the person asks otherwise (GDPR). A screenshot of the customer screen rarely meets that. A compiled, readable file works better — the Board accepts a transcript or compiled form as long as all the information is included and the content is neither altered nor changed (EDPB Guidelines 01/2022). For further copies a reasonable fee based on administrative costs may be charged; for the first one it may not.

Checking identity without asking for too much

The concern is legitimate: handing data to the wrong person is itself a personal data breach. Article 12(6) GDPR therefore allows the controller to request additional information — but only where there are "reasonable doubts concerning the identity of the natural person making the request" (GDPR). The doubt is the precondition, not the routine. If a customer writes from the email address held in her account and quotes an order number and an invoice date, the attribution has already been made.

The European Data Protection Board is explicit here: requiring a copy of an identity document is disproportionate where the person making the request is already authenticated by the controller. Using such a copy creates a security risk of its own and should generally be considered inappropriate unless it is necessary, suitable and in line with national law (EDPB Guidelines 01/2022). Where a document is genuinely needed, details that are not required — serial number, nationality, height, eye colour, photograph and machine-readable zone — may be redacted before it is sent. Confirmation links by email, a code by text message or questions about details already held in the account are the more proportionate route.

A reflex ID request gets noticed

During the coordinated action several supervisory authorities observed controllers issuing a generic request for additional identification on receipt of any access request (EDPB). A blanket check of that kind delays the answer, collects data without cause and is regularly criticised in complaint proceedings. Whoever does ask should record in the case file what the reasonable doubt consisted of.

Where requests arrive in the firm

A controller may offer appropriate and easy-to-use communication channels and name them in the privacy policy. It may not pin data subjects down to them: a request sent instead to an official contact point of the firm has been validly made. Only completely random or apparently incorrect addresses create no obligation to act (EDPB Guidelines 01/2022). In practice this means every channel you present as a contact route on the website is a possible entry point for an access request.

  • The general inbox from the imprint and the personal inboxes of the owners
  • The contact form and any service form for existing customers
  • Telephone and voicemail, including requests made verbally
  • Post sent to the address given in the imprint
  • Messaging channels you have linked from the website
  • The counter, the workshop, the reception desk: requests made in person count as well

Verbal requests are valid

Article 12(1) GDPR allows the information to be given orally at the data subject's request, provided identity has been proven by other means. In the 2024 action one supervisory authority reported that 70 per cent of the participating controllers do not answer an access request verbally at all because of authentication concerns; the remaining 30 per cent did so where several identifiers were provided (EDPB). For people with visual or cognitive impairments the verbal route is often the only practical one.

The workflow in eight steps

The strongest lever is not legal finesse but a written workflow. The European Data Protection Board itself traces back why firms with many requests perform better: controllers receiving a higher number of requests were more likely to have formalised an internal process than those who had not yet handled one (EDPB). That process can be written before the first case arrives.

  • Record the arrival. Date, time, channel and wording go into a case file. This timestamp defines when the deadline ends.
  • Acknowledge receipt. A short reply stating that the message is being treated as an access request and by when the answer will come.
  • Assign responsibility. One named person handles it, a second stands in. Without a stand-in every holiday week becomes a deadline risk.
  • Check identity where doubts are reasonable. Ask straight away, otherwise the question does not suspend the clock.
  • Search the systems. Customer database, invoicing software, inboxes, the website form mailbox, calendar, messengers, backups within reach.
  • Check the rights of others. Redact third-party personal data in documents and threads instead of refusing the request as a whole.
  • Compile the answer. Confirmation, copy of the data and the points (a) to (h) in one readable file.
  • Close and file the case. What was released and when belongs in the record — the burden of proof sits with the controller.

Step five is the one that eats the time. Writing down in advance which systems hold customer data shortens every later search considerably. That list overlaps heavily with what you already gathered for the contracts with your service providers and with the overview of roles and access rights in the team. There is a side effect: knowing where data sit also helps to protect them, and the same overview keeps the attack surface of the website small.

Limits: third-party rights, fees and excessive requests

Two provisions limit the right, and both are narrower than they look on first reading. Article 15(4) GDPR states that the right to obtain a copy shall not adversely affect the rights and freedoms of others (GDPR). The Board makes clear that applying it must not result in refusing the request altogether; it results at most in leaving out or rendering illegible those parts that would have negative effects, and the controller must be able to demonstrate the adverse effect in the specific situation (EDPB Guidelines 01/2022). Article 12(5) GDPR in turn permits a reasonable fee or a refusal for manifestly unfounded or excessive requests — with the burden of proof expressly on the controller. Both concepts are to be interpreted narrowly (EDPB Guidelines 01/2022).

  • The first answer is free of charge; a fee only comes into play for further copies or for demonstrably excessive requests
  • A repeat request after a reasonable interval is not excessive, particularly where the data have changed since
  • A missing reason is no ground for refusal, because no reason has to be given in the first place
  • Internal assessments and notes about the person are personal data too, even when they are uncomfortable
  • Third-party names in threads get redacted while the remaining passages stay in the answer
  • Restrictions under national law based on Article 23 GDPR need careful checking before anyone relies on them

What supervisory authorities see in practice

In 2024 the European Data Protection Board made the right of access the topic of its coordinated enforcement action. Thirty supervisory authorities across the European Economic Area took part and 1,185 controllers answered the joint questionnaire (EDPB). The picture is mixed: eleven authorities rated compliance among responding controllers as high and one even as very high, seven as average; ten found the results too varied to describe an average level (EDPB). Awareness of the guidelines came out considerably weaker: ten authorities rated it average or low, only nine as high or very high (EDPB).

In Germany the annual reports show how much the pressure has grown. The Bavarian Data Protection Authority recorded 9,746 complaints and inspection referrals in 2025, an increase of 61 per cent on the previous year; 67 per cent of them were formal complaints and 21 per cent inspection referrals (BayLDA). Despite the rise, 62 per cent of the formal complaints closed that year were dealt with within three months (BayLDA). The State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg counted 7,673 complaints in the same year after 4,034 the year before (LfDI Baden-Württemberg). The subject split hits small firms directly: in Bavaria 21 per cent of complaints concerned internet and digital services and 20 per cent video surveillance (BayLDA).

Complaints in the context of the right of access under Article 15 GDPR rank among the most frequent infringements across almost every specialist area.

What happens when a firm simply does not answer is described in the same report through a single case. A citizen wanted to know how a company unknown to her had obtained her data and received no reply. The authority ordered the controller to provide the information, at the controller's cost, and threatened penalty payments of 5,000 euros for the answer itself and 2,500 euros for confirming completion. After several rounds two fines totalling 50,000 euros were imposed; across the case penalty payments were threatened five times, adding up to 66,000 euros (BayLDA). The statutory ceiling itself sits in Article 83(5) GDPR: up to 20 million euros or up to 4 per cent of total worldwide annual turnover, whichever is higher (GDPR). For a trades business the ceiling is not the point; the road towards it is, and it starts with one unanswered email.

What to prepare on the website

The website does not decide the legal position, but it decides whether an access request arrives where it can be found and whether you know the scope at all. Four things can be done in advance, and all four also serve the rest of the data protection work — from cookie consent through a data-minimal basic setup to embedded maps, videos and fonts.

A named contact route

The privacy policy states the address for data subject rights. That same address is actually read and has a stand-in behind it.

Arrival with a timestamp

The form logs date and time and sends an acknowledgement. The start of the deadline is then fixed rather than reconstructed later.

A systems overview

A list of every place holding customer data: website form, mailing list, invoicing software, calendar, inboxes, review replies.

An answer template

A prepared letter using points (a) to (h) as its structure. The specifics get added per case; the structure is already there.

The systems overview includes the places you rarely think of: the newsletter sign-up with double opt-in with its consent log, the replies to customer reviews and the questions collected through the FAQ page. Sectors with their own confidentiality duties add a second layer: for a medical practice website, a law firm website or the site of a home care service, access requests regularly touch third-party data and professional rules. The State Commissioner in Baden-Württemberg devotes a chapter of the 2025 report to the right of access precisely because uncertainty is widespread there (LfDI Baden-Württemberg).

The route for your firm

An access request is not an attack. In most cases there is someone behind it who wants to retrace a process — after a complaint, the end of a contract or an unexpected marketing email. Answering cleanly and on time usually settles the matter with a single message. Staying silent produces the complaint you were hoping to avoid.

  • Write down which systems hold customer data and keep the list current whenever something changes
  • Name one responsible person and one stand-in, both with access to the stated mailbox
  • Create two text modules: an acknowledgement stating the deadline and an answer letter structured along points (a) to (h)
  • Check that the privacy policy names a route for data subject rights that is genuinely monitored
  • Have the workflow reviewed once by a qualified adviser before the first case arrives

Sources and Studies

This article is based on data from GDPR, EDPB, EDPB Guidelines 01/2022, BayLDA and LfDI Baden-Württemberg. The figures quoted refer to the state of the respective publication.