What does GDPR Article 15 require?
GDPR Article 15 gives a person the right to obtain confirmation of whether their personal data is being processed and, if so, access to that data plus set information about it. A data subject access request, or DSAR, is that right being exercised. The first copy is free.
Applies to: Controllers that receive a request from a data subject to access their personal data under the GDPR; the Article 15 right of access applies to any organisation within the GDPR's scope.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanA data subject access request, usually shortened to DSAR, is one of the most common demands a business receives under the GDPR, and one of the easiest to mishandle. It is a person using their Article 15 right of access to find out what personal data you hold about them and to get a copy. There is no special form, no fee for the first copy, and a hard one-month clock.
What is a data subject access request?
Article 15(1) gives every data subject the right to obtain confirmation of whether you are processing their personal data and, where you are, access to that data plus a defined set of information: the purposes of the processing; the categories of personal data; the recipients or categories of recipient, including any in third countries; the envisaged storage period or the criteria used to set it; the existence of their rights to rectification, erasure, restriction and objection; the right to lodge a complaint with a supervisory authority; the source of the data where you did not collect it from them; and the existence of any automated decision-making, including profiling, with meaningful information about the logic involved.
Do you have to provide a copy, and can you charge?
Yes. Article 15(3) requires you to provide a copy of the personal data undergoing processing, and the first copy is free. You may charge a reasonable fee based on administrative costs only for further copies, or, under Article 12(5), where a request is manifestly unfounded or excessive, in which case you may charge a reasonable fee or refuse. Where the person asks by electronic means, provide the information in a commonly used electronic form unless they ask otherwise. Article 15(4) adds that the right to a copy must not adversely affect the rights and freedoms of others, which is why you redact third-party data.
How long do you have to respond?
Article 12(3) sets the deadline: without undue delay, and in any event within one month of receiving the request. You can extend by two further months where the request is complex or numerous, provided you tell the person within the first month and explain the delay. Because the clock starts on receipt, and a DSAR can arrive by email, chat, or in passing, the practical risk is missing a request rather than answering it wrongly.
How to handle a DSAR without slipping up
The common failures are treating an informal message as not counting, missing data held in scattered systems, and releasing another person's data by accident. Recognise a request in any format, confirm the requester's identity, search across your systems, and redact information about other people before you send. A current record of processing activities makes the search far quicker, and a person who asks for access will often follow with an erasure request.
What a compliant DSAR process actually looks like
Compliance here is an intake and search problem more than a legal one. The obligations are settled; the failures are operational.
A workable process has five parts. A single logged entry point, so a request arriving by email, chat, or support ticket is recorded rather than lost in an inbox. An identity check that starts immediately, because the clock in Article 12(3) runs from receipt and not from the point verification finishes. A documented search across every system holding personal data, which is where an out-of-date data inventory costs you weeks. A redaction pass before release, since Article 15(4) requires that the right to a copy not adversely affect the rights and freedoms of others. And a record of what you sent and when, which is the only evidence you have if the response is later challenged.
The most common cause of a missed deadline is not a hard search. It is a request that nobody recognised as a request for the first three weeks.
Where DSARs overlap with other rights
A person who asks for access often follows with something else, and the deadlines differ. Portability under Article 20 is a narrower right covering only data the person provided where processing is by consent or contract, so an access request is not automatically a portability request. Erasure runs on its own conditions. Treating all three as one queue is how the wrong deadline gets applied.
If you also handle US consumers, note that the clocks are different again: most US state privacy laws run on 45 days rather than one month, which the state response deadline comparison sets out.
Next step
If DSARs land unpredictably and you are not sure your process meets the one-month deadline, the free 2-minute Obligation Scan checks whether the GDPR applies to you and which data-subject-right processes, including access, you need in place. The GDPR compliance hub sets out the wider duties and how they connect.
Compliance checklist
- Recognise a DSAR in any format: it does not have to mention Article 15 or use a form.
- Confirm the requester's identity, then find the personal data you hold about them across your systems.
- Provide a copy of the data plus the Article 15(1) information: purposes, categories, recipients, retention, the source, and any automated decision-making.
- Give the first copy free of charge; only charge for further copies, or where the request is manifestly unfounded or excessive.
- Respond within one month under Article 12(3), and redact third-party data so you do not affect others' rights.
Sources
- GDPR Article 15 (right of access by the data subject), EUR-Lex, Regulation (EU) 2016/679
- GDPR Article 12(3) and 12(5) (timeline; fees for excessive requests), EUR-Lex
- UK Information Commissioner's Office, right of access
Last verified: 2026-08-28
Informational, not legal advice.