LinkedInInstagramXTikTok

Data subject access requests: how to handle a GDPR request without getting it wrong

An email arrives from a former employee: “Please send me all the personal data you hold about me.” It is one sentence, it carries a one-month deadline, and it is one of the most common triggers for a data protection complaint in Sweden. Handling it well is a matter of process rather than legal argument – but the process has to exist before the request arrives.

What the right of access actually covers

Article 15 of the GDPR gives individuals the right to obtain confirmation of whether their personal data is being processed and, where it is, access to that data together with a defined set of information.

That information includes the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipient to whom the data has been or will be disclosed, the envisaged retention period or the criteria used to determine it, the existence of the rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, the source of the data where it was not collected from the individual, and the existence of automated decision-making including profiling, with meaningful information about the logic involved.

The European Data Protection Board’s Guidelines 01/2022 on the right of access, adopted in 2022, set out how these obligations are to be interpreted, and they are notably strict on several points that controllers commonly get wrong.

The deadline and when it can be extended

The response must be provided without undue delay and in any event within one month of receipt. The period may be extended by a further two months where necessary, taking into account the complexity and number of requests – but the individual must be informed of the extension and the reasons for it within the first month.

The EDPB is clear that extension is an exception to the general rule and should not be overused. Critically, the mere fact that complying would require a great deal of effort does not make a request complex. If an organisation regularly finds itself extending, that is treated as evidence that its internal procedures need improving rather than as a justification.

Identity, scope and clarification

Where there are reasonable doubts about the identity of the requester, the controller may request additional information to confirm it. This must be proportionate. Demanding a copy of a passport where the person is writing from an email address already held on file, and where the response contains no sensitive material, tends to be excessive – and the time spent verifying does not stop the clock indefinitely.

Where a controller processes a large quantity of data about the individual, it may ask them to specify which data or which processing activities the request relates to. This is a request for clarification, not a condition of the right, and it cannot be used to narrow a request the individual intends to be broad.

Third-party data and other limits

Article 15(4) provides that the right to obtain a copy shall not adversely affect the rights and freedoms of others. This is the provision that governs documents containing information about more than one person – internal emails, meeting notes, investigation files.

It is not a basis for refusing the request. The expected approach is to disclose the individual’s own personal data while redacting information about others where disclosure would adversely affect their rights, and to consider each document rather than applying a blanket exclusion. The Swedish Authority for Privacy Protection has consistently found blanket refusals to be unlawful.

Legal professional privilege, trade secrets and the rights of other individuals may all justify redaction, but each has to be assessed against the specific material.

Fees and refusals

The first copy must be provided free of charge. A reasonable fee based on administrative costs may be charged for further copies. Where a controller intends to charge, the EDPB expects the amount to be indicated in the initial response so that the individual can decide whether to proceed or withdraw the request, and expects controllers to organise their resources so as to keep costs low.

A controller may refuse to act on manifestly unfounded or excessive requests, including where they are repetitive. The threshold is high. Because Article 15 imposes very few prerequisites – essentially that the request concerns the requester’s own personal data – the EDPB regards the scope for concluding that a request is manifestly unfounded as very limited. The burden of demonstrating the character of the request sits with the controller.

Motive is not a valid ground for refusal. A request made in the context of an employment dispute, a commercial disagreement or pending litigation is still a valid request, and the fact that the individual is using it tactically does not make it excessive.

Practical example: the request that arrived during a dispute

A company dismisses a manager. Two weeks later the manager submits an access request seeking all personal data, expressly including internal emails mentioning them.

The instinct is to treat the request as an extension of the dispute and to respond minimally. That instinct produces the worst outcome. The company should acknowledge the request, note the one-month deadline, and search systematically – HR systems, payroll, email archives, messaging platforms, CRM, access logs, CCTV where retained, and any consultant or payroll provider acting as a processor.

It should then review the material document by document, disclosing the manager’s personal data, redacting information about colleagues where their rights would be adversely affected, and withholding genuinely privileged legal advice with an explanation of the basis. Alongside the data it must supply the Article 15(1) information – purposes, recipients, retention, rights, source, automated decision-making.

Handled this way, the request is closed within the deadline and a complaint is unlikely. Handled defensively, it becomes a supervisory authority investigation running alongside the employment claim, with the disclosure eventually happening anyway.

Common mistakes companies make

Not recognising the request. An access request need not mention the GDPR, use the word “access”, or be sent to a designated address. A message to any employee asking what data the company holds starts the clock. Front-line staff need to know how to escalate it.

Searching only the obvious systems. Personal data sits in email, chat, ticketing tools, backups, shared drives and third-party platforms, not only in the HR or CRM system.

Forgetting the accompanying information. Sending a data export without the Article 15(1) details is an incomplete response, and it is a frequent finding in enforcement decisions.

Refusing whole documents because a colleague is mentioned. Redaction is the expected approach; blanket exclusion is not.

Treating verification as a delaying tactic. Disproportionate identity demands are themselves a compliance failure.

Ignoring processors. Data held by payroll bureaux, IT providers and recruitment platforms is still yours to account for, and processor contracts should already require them to assist.

Recommended actions

Write a documented procedure covering recognition, logging, verification, search, review, redaction, response and record-keeping, with named owners and internal deadlines set well inside the one month.

Keep your record of processing activities current. An accurate record is what turns the search from an archaeological exercise into a checklist, and it is the practical difference between organisations that respond in a week and those that need an extension.

Train the people most likely to receive a request first – reception, HR, customer service and sales – to recognise and escalate rather than answer.

Agree a redaction standard in advance so that decisions are consistent, and use tooling where volumes justify it. Review your processor agreements for assistance obligations and response times, and enforce your retention schedule: data deleted in accordance with a documented policy before a request arrives is data you do not have to disclose, whereas deleting it afterwards is a serious matter.

Frequently asked questions

Does an access request have to be in writing?

No. It can be made orally or in writing, through any channel, and does not need to reference the GDPR. This is why staff training on recognition matters more than a request form.

Can we refuse because the person is suing us?

No. The motive behind a request is not a ground for refusal. Genuinely privileged legal advice may be withheld, but that is a document-level assessment, not a reason to decline the request.

Do we have to provide the actual documents?

The right is to a copy of the personal data undergoing processing. Where the data cannot be meaningfully understood in isolation, or where extracting it would strip necessary context, providing the document with redactions is often the appropriate way to give effect to the right.

What happens if we miss the deadline?

The individual may complain to the Swedish Authority for Privacy Protection, which can investigate and impose corrective measures and administrative fines. Late responses are among the most frequent subjects of complaint, and they are also among the easiest failures to avoid.

Conclusion

The right of access is not a legal puzzle. It is an operational test of whether an organisation knows what personal data it holds, where it lives, and who is responsible for finding it. Companies that maintain an accurate record of processing, enforce retention, and have a rehearsed procedure treat access requests as routine administration. Companies that do not discover, under a one-month deadline and often in the middle of a dispute, exactly how little they know about their own data.

Lawgent helps organisations build and stress-test their data subject request procedures, review records of processing and retention schedules, assess redaction and third-party data questions, and respond to supervisory authority enquiries. Get in touch if you would like your process reviewed before the next request arrives.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop