Skip to content

Handbook

European Union

The Regulation as it stands, block by block, with the article or the case number under each one. Reviewed block by block on 6 Sep 2026.

Last updated 6 Sep 2026Last reviewed 6 Sep 2026

Deadline and extension

Article 12(3) requires the controller to provide information on the action taken without undue delay and in any event within one month of receipt of the request.

That period may be extended by two further months where necessary, taking into account the complexity and the number of the requests. An extension is not silent: the controller has to inform the person of it within one month of receipt of the request, together with the reasons for the delay.

Article 12(4) covers the other outcome. Where the controller does not take action on the request, it informs the person without delay and at the latest within one month of receipt, of the reasons for not acting and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

How the month is counted is a question of Union law rather than of practice. Under Regulation No 1182/71, the day on which the triggering event occurs is not counted in the period, and a period expressed in months ends with the expiry of the day in the final month that falls on the same date as the day the period runs from.

Fees and refusal

Article 12(5) makes the information under Articles 13 and 14 and any communication and action under Articles 15 to 22 and Article 34 free of charge. Answering an access request is not a billable service.

The exception is narrow and it is the controller's to prove. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either charge a reasonable fee taking account of the administrative costs of providing the information or taking the action, or refuse to act on the request. Article 12(5) puts the burden of demonstrating the manifestly unfounded or excessive character on the controller.

Article 15(3) permits one other charge: a reasonable fee based on administrative costs for any further copies the same person requests. A first copy is not a further copy.

The Court of Justice has read those two provisions together in the medical records context and held that they preclude a national provision under which a patient bears the costs of a first copy of their records, and that the person does not have to give a reason for asking.

Identity verification

Article 12(6) is the whole of the controller's power to ask. Where the controller has reasonable doubts concerning the identity of the natural person making a request under Articles 15 to 21, it may request the provision of additional information necessary to confirm that identity.

Two limits sit inside that sentence. The trigger is a reasonable doubt about this request, not a policy applied to every request. And what may be asked for is what is necessary to resolve the doubt, which is a different quantity from whatever identity evidence the organisation happens to collect elsewhere.

Recital 64 asks the controller to use all reasonable measures to verify the identity of a person requesting access, in particular in the context of online services and online identifiers, and says in the same breath that a controller should not retain personal data for the sole purpose of being able to react to potential requests.

Article 11 runs the other way. Where the controller can demonstrate that it is not in a position to identify the data subject, Article 15 does not apply, unless the person provides additional information enabling their identification for that purpose.

The copy

Article 15(3) requires the controller to provide a copy of the personal data undergoing processing, and to provide it in a commonly used electronic form where the request was made by electronic means and the person has not asked for something else.

What a copy is has been decided. The Court of Justice has held that a copy under Article 15(3) means a faithful and intelligible reproduction of the personal data, that supplying it may require the reproduction of extracts of documents, of entire documents, or of extracts from databases where contextualisation is necessary to make the data intelligible, and that Article 15(3) does not confer a general right to a copy of documents as such.

That holding cuts in both directions, which is why it is worth reading rather than summarising. A controller cannot discharge the obligation with a list of field names stripped of the context that gives them meaning. A person cannot use it to obtain the file itself where the personal data in the file is intelligible without it.

In the medical records case the Court applied the same reading to a concrete file and held that the person was entitled to a faithful copy of the documents in it where that was necessary to understand the data they contained.

Other people and their data

Article 15(4) provides that the right to obtain a copy under Article 15(3) shall not adversely affect the rights and freedoms of others. It is one sentence and it is the whole of the provision.

Recital 63 names some of what those rights can include: trade secrets, intellectual property, and in particular the copyright protecting software. It then closes the loophole in the same paragraph, saying that the result of those considerations should not be a refusal to provide all information to the data subject.

Read together, the two put the work on the material rather than on the answer. A document that contains another person is not thereby a document that may be withheld, and Article 15(4) is not a category exemption for anything a third party appears in.

One question about other parties is settled rather than balanced. The Court of Justice has held that where personal data have been or will be disclosed, the person is entitled to be told the identity of the recipients themselves. Categories of recipient suffice only where it is impossible to identify those recipients, or where the request is manifestly unfounded or excessive.

Exemptions and limits

The Regulation limits Article 15 in four places, and each one carries its own conditions rather than a discretion.

  • Article 15(4). The copy must not adversely affect the rights and freedoms of others. Recital 63 says the result cannot be a refusal to provide all information.
  • Article 12(5). A manifestly unfounded or excessive request, in particular a repetitive one, may attract a reasonable fee or a refusal to act, with the burden of demonstrating that character on the controller.
  • Article 23. Union or Member State law may restrict the scope of Article 15 by a legislative measure, where the restriction respects the essence of the fundamental rights and freedoms and is necessary and proportionate to safeguard one of the objectives Article 23(1) lists, among them national security, defence, public security, and the prevention, investigation, detection and prosecution of criminal offences.
  • Article 89. Union or Member State law may provide for derogations from Article 15 for processing for scientific or historical research purposes, statistical purposes, or archiving purposes in the public interest, subject to the conditions and safeguards Article 89(1) requires.

Recital 63 adds one thing that reads like an exemption and is not. Where a controller processes a large quantity of information concerning the person, it should be able to request that the person specify the information or the processing activities the request relates to before the information is delivered. That is a request to narrow scope, not a ground to refuse.

The authority

Article 51 requires each Member State to provide for one or more independent public authorities responsible for monitoring the application of the Regulation. A person complains under Article 77 to a supervisory authority, in the Member State of their habitual residence, their place of work, or the place of the alleged infringement.

The courts sit alongside that rather than after it. Article 78 gives a right to an effective judicial remedy against a legally binding decision of a supervisory authority, Article 79 a right to an effective judicial remedy against a controller or a processor, and Article 82 a right to compensation for material or non-material damage suffered as a result of an infringement.

The Court of Justice has held that a mere infringement of the Regulation is not sufficient in itself to confer a right to compensation under Article 82. Damage has to be established.

For processing that crosses borders, Article 56 makes the supervisory authority of the controller's main establishment the lead authority for that processing, acting through the cooperation procedure in Article 60. The European Data Protection Board is established by Article 68 and is the body those authorities sit on. It is not a route of appeal for an individual complaint.

What is different here

This record states the Regulation and what the Court of Justice has held about it, and nothing else. It is the baseline, so by construction there is nothing in it that departs from the baseline.

The departures live in national law, because the Regulation invites them. Article 23 lets Union or Member State law restrict Article 15 by legislative measure. Chapter IX leaves further room: reconciling data protection with freedom of expression and information under Article 85, national identification numbers under Article 87, processing in the employment context under Article 88, and existing obligations of professional secrecy under Article 90.

Denmark, Norway, Sweden and Finland each fill parts of that room differently, and each has its own supervisory authority reading its own text. Those records are not published here. Writing them without a reviewer who practises in the jurisdiction would produce four pages that looked exactly as authoritative as this one and were not.

The words

Article 4 defines the terms this record uses. Personal data is any information relating to an identified or identifiable natural person. The data subject is that person. The controller determines the purposes and means of the processing, and the processor processes on the controller's behalf.

Recipient and third party are not synonyms, and Article 4 keeps them apart. A recipient is anybody to whom personal data are disclosed, whether a third party or not. A third party is anybody other than the data subject, the controller, the processor, and the people who are authorised to process the data under the direct authority of either.

Two more are used interchangeably in practice and are different in the text. Processing under Article 4(2) covers any operation performed on personal data, erasure and destruction included. Restriction of processing under Article 4(3) is the marking of stored personal data with the aim of limiting future processing, which is what Article 18 gives a right to. Restricting is not deleting.

One absence is worth knowing about. The Regulation does not use the phrase the whole subject is usually named after. Article 15 is headed Right of access by the data subject, and the abbreviation practitioners use does not appear in the text at all. A request does not have to name itself to be one.

Questions

How long is there to answer an access request under the Regulation?

One month from receipt of the request, under Article 12(3), extendable by two further months where that is necessary taking into account the complexity and the number of the requests. An extension has to be notified to the person, with the reasons for it, within the first month.

Can a controller charge for answering an access request?

Not as a rule. Article 12(5) makes the action free of charge, and permits a reasonable fee or a refusal only where the request is manifestly unfounded or excessive, which the controller has to demonstrate. Article 15(3) separately allows a reasonable fee for further copies beyond the first.

Does a copy under Article 15(3) mean copies of the documents?

Not as such. The Court of Justice has held that a copy means a faithful and intelligible reproduction of the personal data, and that this can require reproducing extracts, whole documents or database extracts where the context is what makes the data intelligible. It does not create a general right to the documents themselves.

Can a request be refused because other people appear in the documents?

No. Article 15(4) says the copy must not adversely affect the rights and freedoms of others, and Recital 63 says the result of that consideration should not be a refusal to provide all information to the person. The work goes on the material rather than on the answer.

Which authority does a person complain to?

A national supervisory authority under Article 77, in the Member State of their habitual residence, their place of work, or the place of the alleged infringement. There is no single Union regulator taking individual complaints, and the European Data Protection Board is not an appeal route.