Under the GDPR, what does a subscriber's right of access entitle them to receive, and by when must the controller respond?
answer
- more than a data dump
- confirmation, copy, context
- Art. 15(1) points (a) to (h)
- Art. 12(3) sets the clock
basics
~20 sUnder GDPR Art. 15, the person gets confirmation that their data is processed, a copy of it, and context: purposes, categories, recipients, retention, source, rights and automated decisions. Art. 12(3) requires a reply within one month of receipt, extendable by two further months.
solid answer
~50 sUnder the GDPR, `Art. 15` gives three things: **confirmation** of whether personal data about the person is processed; **access** to that data, delivered as a copy under `Art. 15(3)`; and the **context** in `Art. 15(1)(a)-(h)` — purposes, categories, recipients (especially in third countries), the storage period or its criteria, the rights to rectify, erase, restrict and object, the right to complain to a supervisory authority, the source where the data was not collected from them, and meaningful information about any `Art. 22` automated decision-making. The first copy is free (`Art. 12(5)`); further copies may carry a reasonable fee based on administrative costs. An electronic request gets a commonly used electronic form unless the person asks otherwise. `Art. 12(3)` sets the clock: without undue delay and at the latest **one month from receipt**, extendable by **two further months** for complexity or volume if the person is told, with reasons, within the first month.
go deeper
Recall the three layers of an access response: confirmation, a copy of the data, and the Art. 15(1) context items. Know that the reply is due within one month of receipt and the first copy is free.
Explain the Art. 12(3) extension: two further months for complexity or volume, announced with reasons inside the first month. Walk through points (a) to (h) and say where each answer comes from in your records.
Show how you make a complete response possible: knowing every store and processor holding one person's data, redacting other people's data instead of refusing, and tracking each request's deadline from receipt.
Treat access as the test of your data inventory: if a single request cannot be answered completely within a month, the records of processing are wrong. Weigh self-service access against per-request handling.
## Why the right of access exists Under the GDPR, the right of access in **Art. 15** is the entry point to every other data subject right: a person cannot ask to correct, erase or restrict data they do not know exists. Recital 63 states the purpose plainly — to be aware of, and verify, the lawfulness of the processing — and says the right should be exercisable easily and at reasonable intervals. The request is answered by the **controller**, the body that decides why and how the data is processed. A **processor** acting for it must assist by appropriate technical and organisational measures under `Art. 28(3)(e)`, but the answer remains the controller's duty. ## What the response must contain An access response has three layers, and a response that delivers only one of them is incomplete. | Layer | Provision | What it means for a streaming subscriber | |---|---|---| | Confirmation | Art. 15(1) | Yes or no: is data about this person processed at all | | The data itself | Art. 15(1), 15(3) | A copy: account details, payment references, viewing history, support tickets, device identifiers | | Context | Art. 15(1)(a)-(h), 15(2) | Why, what, to whom, how long, from where, and which rights apply | The context items in `Art. 15(1)` are: - **(a)** the purposes of the processing; - **(b)** the categories of personal data concerned; - **(c)** the recipients or categories of recipient, in particular recipients in third countries or international organisations; - **(d)** where possible, the envisaged storage period, or else the criteria used to determine it; - **(e)** the existence of the rights to rectification, erasure, restriction and objection; - **(f)** the right to lodge a complaint with a supervisory authority; - **(g)** where the data was not collected from the person, any available information about its source; - **(h)** the existence of automated decision-making under `Art. 22(1)` and `(4)`, with meaningful information about the logic involved and its significance and envisaged consequences. `Art. 15(2)` adds that where data is transferred to a third country or an international organisation, the person has the right to be informed of the `Art. 46` safeguards relating to that transfer. ## The copy: format, fees and other people `Art. 15(3)` requires the controller to provide **a copy of the personal data undergoing processing**. Three rules shape it: 1. **Cost.** `Art. 12(5)` makes communications and actions under Arts. 15 to 22 free of charge. For *further* copies, `Art. 15(3)` allows a reasonable fee based on administrative costs. 2. **Format.** If the request arrived by electronic means, the copy is provided in a commonly used electronic form, unless the person asks otherwise. Recital 63 encourages, where possible, remote access to a secure system that gives the person direct access to their data. 3. **Other people's rights.** `Art. 15(4)` says the right to obtain a copy must not adversely affect the rights and freedoms of others. Recital 63 names trade secrets and intellectual property, including software copyright — but adds that those considerations should not result in a refusal to provide all information. A household account whose profiles belong to several people is the typical case: redact the others' data, do not refuse the requester. Where the controller processes a large quantity of information about the person, recital 63 lets it ask them to specify, before delivery, the information or processing activities the request relates to. ## The clock under Art. 12(3) The timeline comes from **Art. 12(3)**, which applies to requests under Arts. 15 to 22: 1. Respond **without undue delay and in any event within one month of receipt** of the request. 2. The period **may be extended by two further months** where necessary, taking into account the complexity and number of the requests. 3. The person must be told of any extension **within one month of receipt**, together with the reasons for the delay. 4. If the controller will not act at all, `Art. 12(4)` requires it to say so without delay and at the latest within one month, giving its reasons and the possibility of complaining to a supervisory authority and seeking a judicial remedy. The deadline is expressed in months, not working days, and it runs from receipt. "Without undue delay" comes first: one month is the outer limit, not a target. ## What this means for a system For an engineer, the practical consequence is that an access response is only as complete as the controller's knowledge of where one person's data lives. The copy covers all personal data *undergoing processing* — not only the profile table, but support tickets, event records keyed by a user identifier and data that processors hold on the controller's behalf. The context in points (a) to (h) usually comes from the controller's records of processing and its privacy notice, so those must be accurate enough to answer for one person, including which recipients actually received that person's data. ## Common mistakes - Sending a list of data categories with no copy of the data itself. - Treating the one-month limit as working days, or as starting when the team first opens the ticket. - Charging for the first copy. - Refusing outright because the data mentions other people or touches a trade secret, instead of redacting. - Omitting recipients, retention criteria or the disclosure about automated decision-making.
- Under the GDPR, may a controller refuse an access request because the person clearly wants the data for a dispute with it?Art. 15 attaches no purpose test: the text does not require the person to explain why they are asking. The grounds for refusing sit elsewhere: Art. 12(5) for manifestly unfounded or excessive requests, with the burden of demonstrating that on the controller, and restrictions made by Member State law under Art. 23, which the controller must be able to point to.
- Under the GDPR, what can a controller do when it holds years of data about the requester?Recital 63 lets it ask the person, before delivery, to specify the information or processing activities the request relates to. The recital does not say the one-month clock pauses while it waits, so a genuinely complex request is handled through the Art. 12(3) extension of two further months, announced with reasons within the first month. Size alone is not the Art. 12(5) test, whose named example is repetitive requests.
saying these in an interview costs you the question
- An access request is satisfied by listing the categories of data held
- The controller has 30 working days, counted from when staff pick it up
- The first copy can carry a fee to cover the search effort
- Any mention of another person or a trade secret justifies refusing the copy
- Automated decision-making never has to be mentioned in an access response