What data/information can a data subject request from me under the right of access?

read titleRead full title
Published on LexisPSL on 05/12/2019

The following Risk & Compliance Q&A provides comprehensive and up to date legal information covering:

  • What data/information can a data subject request from me under the right of access?

The General Data Protection Regulation provides for enhanced rights for data subjects including providing rights of rectification, erasure and restriction of processing, data portability, a right to object to processing and a right not to be subject to a decision based solely on automated processing, including profiling, with strict time limits for complying.

Article 15 of the GDPR provides that the data subject has the right to request confirmation of whether personal data concerning them is being processed, and where it is, access to the personal data and certain further information—a right of access.

The right of access is very similar in the GDPR to previous legislation, with a handful of notable changes, including in relation to the supplementary information the data subject has the right to obtain.

In addition to supplying a copy of the data requested, you must supply the following information:

  1. the purposes of the processing

  2. the categories of personal data concerned

  3. the recipients or categories of recipient to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organisations

  4. where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period—see Precedent: Records retention schedule

  5. the existence of the right to request from the controller rectification or erasure of pe

Popular documents