Area · GDPR — Privacy & personal data
Right of access
It is the right that guarantees every individual the ability to know what personal data a company holds, how it is used, for what purposes and for how long.
What it is
The right of access is the right to obtain confirmation as to whether or not personal data concerning you is being processed and, if so, to access a copy of that data together with a set of information about the processing.
It is the most basic right: you need to know who has which of your data, why they have it, what they do with it and who they share it with.
An analogy: it is like walking into your bank and asking for a detailed statement. They tell you:
- how much you have (= which data);
- the transactions (= how they process it);
- the payees (= who they disclose it to).
What you can request (Art. 15 GDPR)
An access request gets you three things.
a) Confirmation of the processing
The first piece of information: “Are you processing data about me? Yes or no?”
b) A copy of your personal data
All the personal data being processed, in a readable format. It includes:
- personal details (name, address, email, phone);
- identifiers (customer code, user ID);
- browsing and usage data (history, logs);
- content you generated (posts, photos, messages);
- profiling data (preferences, marketing segments);
- metadata (account creation date, last login, IP address).
c) Information about the processing (Art. 15.1.a-h)
The controller must tell you:
- The purposes of the processing — “Why do you have my data?” For example: “performance of the contract”, “marketing”, “compliance with tax obligations”.
- The categories of data processed — “What kinds of data?” For example: “personal details, contact data, browsing data, banking data”.
- The recipients or categories of recipients — “Who do you share it with?” For example: “business partners [list], cloud providers, couriers”.
- The retention period — “How long do you keep it?” For example: “10 years from the end of the contract, for tax purposes”.
- The rights you can exercise — rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), objection (Art. 21), portability (Art. 20) and a complaint to the data protection authority.
- The source of the data, if it was not collected from you — “Where did you get it?” For example: “a list bought from a data broker”, “public registers”, “social media”.
- The existence of automated decision-making (profiling, algorithms) — “Do you use algorithms to make decisions about me?” With the logic involved, its significance and the envisaged consequences. For example: “Yes, a credit-scoring algorithm to assess creditworthiness”.
- Transfers outside the EU — “Do you send my data outside Europe?” With the third country and the appropriate safeguards (standard contractual clauses, etc.).
The information on this page is for general guidance and is not a substitute for legal advice.