Skip to content

What is the Right of Access?

    Within the European Union (“EU”), privacy and personal data protection matters are regulated by the General Data Protection Regulation (EU) 2016/679[1] (also known as “GDPR”) as well as by each EU Country’s (hereinafter “Member State”) legislative and regulatory privacy framework. The GDPR, preceded by the Data Protection Directive 95/46/EC[2], identifies the figure of data subject as any identifiable natural person, and they are prone to have ‘personal data’ being processed by other legal or natural persons. 

    In essence, the GDPR is at the core of the EU privacy framework and has the primary objective of protecting natural persons with regard to the processing of their personal Data.

    What are your rights under the General Data Protection Regulation (GDPR)?

    The General Data Protection Regulation Grants Data subjects with a variety of rights with the purpose of protecting their personal data when such information is being processed by a data controller or data processor is processing such information. 

    Such rights include:

    1. The Right to be informed (about the collection and use of their personal data)
    2. The Right of rectification: when they detect that personal data is incorrect or incomplete,
    3. The Right of Access: to know if a controller or processor is processing their personal data, and if so, retrieve it along with supplementary information or documentation

    From this basis, the GDPR establishes, within its article 15 the definition of the Right of access as follows:

    “The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data (…)”.

    Data Subjects have the right to know:

    • Why is the data being processed
    • The categories of personal data being processed
    • Who will be receiving such personal data (particularly if they are in 3rd countries; which are not EU Member States).
    • The Data storage time (or, if this is not known, the criteria to determine that)
    • To know that they can request rectification, erasure or object to processing such personal data
    • To know that they can complain to a supervisory authority
    • To know where that data came from
    • If the Company used any automated decision-making, the logic involved and the consequences or significance of such processing for the data subject
    • If it was transferred to a third country, which safeguards were used

    On top of all of for the above, the data subjects also have the right to receive a copy of the personal data being processed.

    Companies should be ready to effectively execute their obligations under the GDPR and to honour Data Subjects’ Rights as legally requested. Should you need any further information on how to do so, require professional advice, or need Data Protection Officer services, do not hesitate to reach out for further details.