Sovy
  • Products
    • Data Privacy Essentials℠
    • myConsentChoice CMP
    • Whistleblowing Portal
    • Outsourced DPO
    • EU/UK Representative Services
    • Compliance Spot Check
    • All Products
    • Free GDPR Scan
    • Free GDPR Readiness Survey
  • Sovy Academy℠
    • Introduction to GDPR
    • Introduction to GDPR for Recruitment
    • GDPR for Managers
    • GDPR for DPOs
    • GDPR for IT Professionals
    • Introduction to Cybersecurity
  • Resources
    • Free GDPR Scan
    • Free GDPR Readiness Survey
    • Knowledge Portal
    • Data Privacy Blog
  • Pricing
    • Data Privacy Essentials
    • myConsentChoice CMP
  • About Sovy
    • Mission
    • Team
    • Investor Relations
    • Partnerships
    • Contact Us
  • Products
    • Data Privacy Essentials℠
    • myConsentChoice CMP
    • Whistleblowing Portal
    • Outsourced DPO
    • EU/UK Representative Services
    • Compliance Spot Check
    • All Products
    • Free GDPR Scan
    • Free GDPR Readiness Survey
  • Sovy Academy℠
    • Introduction to GDPR
    • Introduction to GDPR for Recruitment
    • GDPR for Managers
    • GDPR for DPOs
    • GDPR for IT Professionals
    • Introduction to Cybersecurity
  • Resources
    • Free GDPR Scan
    • Free GDPR Readiness Survey
    • Knowledge Portal
    • Data Privacy Blog
  • Pricing
    • Data Privacy Essentials
    • myConsentChoice CMP
  • About Sovy
    • Mission
    • Team
    • Investor Relations
    • Partnerships
    • Contact Us

Data Privacy Blog

February 18, 2022  |  By Camelia Nastasi

New Guidelines on the Right of Access under Article 15 GDPR

article 15 GDPR

The EDPB (European Data Protection Board) issued Guidelines on Article 15 GDPR right of access of data subjects, on January 18th.

What is Article 15 GDPR?

Under Article 15 GDPR data subjects can request confirmation from the controller as to whether or not their personal data is being processed. If such is the case, they have the right to see those records.

Furthermore, they can request additional information about the processing's purposes. They can inquire about the types of personal data, and also if the controller will disclose it to other recipients. As the EDPB points out, this makes it easier for an individual to exercise other rights. For example: the right to be forgotten or corrected.

The Draft guidelines summary

Individuals can use their right of access to check and retrieve their data if the processing is improper. The goal is to make it easier for data subjects to check the 'lawfulness and accuracy of the processed data.'

The Guidelines clarifies, that when a data subject requests access to personal data, controllers shall disclose it in a transparent and straightforward manner.

In addition, if the amount of information requested is too extensive for the data subject to comprehend or handle, controllers may need to adjust the personal data information request to each request.

Individuals do not have to explain why they require access to the information held by the controller. The latter must cooperate and allow full access. There is an exemption if the individual requests the data for reasons other than those under the GDPR.

When the Controller receives the request, it must determine whether it is about personal data. Also to determine if it falls within the scope of Art.15, and provide a "user-friendly channel" for the data subject to utilize.

However, if the controller cannot identify the individual based on the information provided, access may be denied.

Another important concern raised in the Guidelines is the manner in which controllers grant access. Depending on the complexity of the processing and the volume of data, there are several options. For many controllers, this step may be difficult. If the individual has difficulties in understanding, the controller will have to look for personal data across all IT and non-IT systems. Then, offer a brief and comprehensible manner (children, people with special needs).

However, the most common method of granting access to data subjects is by a copy of the requested material.

Conclusions

Even if the controller no longer retains the personal data at the time of the request for access, the controller must inform the data subjects whether he has transferred personal data to other entities and to whom.

If the controller refuses to grant access to a data subject's request the controller will face a GDPR penalty. Read more about gdpr penalties and how to avoid them.

Source: https://edpb.europa.eu/system/files/2022-01/edpb_guidelines_012022_right-of-access_0.pdf

Last updated: February 18, 2022

Article by Camelia Nastasi

Previous StoryGoogle and Facebook, fines of 210m euros for cookie policy
Next StoryMeta Platforms was fined 17 million euros for failing to protect personal data.

SEARCH

CATEGORIES

  • CCPA (1)
  • consent management (2)
  • CPRA (2)
  • Cybersecurity (2)
  • Data Privacy Fines (2)
  • Data Protection Officer (1)
  • Data security and privacy (6)
  • GDPR (67)
  • GDPR fines (8)
  • GDPR guidance (10)

TAG CLOUD

2020 cookie policy data breach data privacy data protection facial recognition fines GDPR tik tok

ARCHIVES

  • October 2023 (1)
  • July 2023 (1)
  • June 2023 (2)
  • May 2023 (1)
  • April 2023 (2)
  • March 2023 (1)
  • February 2023 (1)
  • January 2023 (2)
  • December 2022 (1)
  • November 2022 (1)
  • October 2022 (1)
  • September 2022 (1)
  • August 2022 (1)
  • July 2022 (1)
  • June 2022 (3)
  • May 2022 (2)
  • April 2022 (1)
  • March 2022 (1)
  • February 2022 (1)
  • January 2022 (2)
  • December 2021 (1)
  • November 2021 (1)
  • September 2021 (1)
  • August 2021 (1)
  • July 2021 (2)
  • June 2021 (2)
  • May 2021 (2)
  • February 2021 (1)
  • January 2021 (1)
  • December 2020 (1)
  • November 2020 (4)
  • October 2020 (3)
  • September 2020 (1)
  • August 2020 (1)
  • July 2020 (2)
  • June 2020 (3)
  • May 2020 (2)
  • April 2020 (2)
  • February 2020 (1)
  • January 2020 (3)
  • December 2019 (3)
  • November 2019 (1)
  • July 2019 (3)
  • May 2019 (3)
  • March 2019 (2)
  • January 2019 (2)
  • December 2018 (3)
  • November 2018 (2)
  • September 2018 (1)
  • July 2018 (1)
  • June 2018 (1)

LATEST POSTS

  • tiktok fined
    TikTok Fined €345m, Appeals Data Privacy Fine Imposed by DPC
  • wordpress cookie consent
    WordPress Cookie Consent: Become Compliant with myConsentChoice
  • outsourced dpo
    Outsourced DPO: Improving Business Data Protection
  • how do spear phishing attacks differ from standard phishing attacks
    How Do Spear Phishing Attacks Differ from Standard Phishing Attacks?
  • biggest gdpr fines
    Meta, Facebook’s Parent Company, Hit with Enormous €1.2 Billion Fine for EU Rule Violations: Among the Biggest GDPR Fines Ever Imposed

QUICK LINKS

  • About Us
  • Resources
  • Privacy Policy
  • Terms
  • Manage Consent
  • Contact Us

Sovy GDPR Privacy Essentials

  • Subscription Benefits
  • Pricing
  • Log in
  • GDPR for Small Businesses
  • GDPR for Enterprises
  • GDPR for Sole Traders
  • GDPR for Charities

SOVY LOCATIONS

Ireland HQ

Registered Office
Woods House
Cannon Street, Kells
Co. Meath, A82 RF86
Ph: +353 (4)6 929-3537

Trading Office
St Gall's House
St Gall Gardens South
Milltown, Dublin 14
D14 Y882

Brussels

Rond-Point Schuman 11
1040 Brussels
Belgium

London

Registered Office
Kemp House
152-160 City Road
London EC1V 2N

Trading Office
9-10 Staple Inn
2nd Floor
London WC1V 7QH

New York

NY Metropolitan Area
2037 Lemoine Ave
Suite 452,
Fort Lee, N.J. 07024, USA

ASSOCIATIONS

Copyright © 2023 Sovy Trust Solutions Limited. All Rights Reserved. Registered in Ireland, No. 610835 and No. 605069