Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Consumer Privacy Rights

Right to Access

Also known as: SAR, Right of Access, Subject Access Request, Data Subject Access, Right of Access to Personal Data
Simply put

The right to access lets individuals ask an organization for a copy of the personal information it holds about them, along with details about how and why that information is being used. It generally does not extend to information about other people, and organizations may need to balance a person's request against the rights and freedoms of others. This right is a core feature of data protection laws such as the GDPR.

Formal definition

Under Article 15 of the GDPR, the right of access entitles a data subject to obtain confirmation of whether their personal data is being processed and, where it is, access to that data together with supplementary information including the purposes of processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the data has been or will be disclosed. Article 15(3) provides for a copy of the personal data undergoing processing, while Article 15(4) states that the right to obtain such a copy should not adversely affect the rights and freedoms of others. As reflected in ICO guidance, the right applies to an individual's own personal information and does not generally extend to information about third parties except in limited circumstances. Note that this entry addresses the general access right under EU and UK data protection law; specific procedural requirements, exemptions, response timeframes, and equivalent rights under other regimes (such as US state privacy laws) are out of scope here and may differ. The scope of exemptions and the balancing exercise involving others' rights can involve contested, fact-specific assessments.

Why it matters

The right of access is widely regarded as one of the most fundamental rights in data protection law, and it underpins the transparency principle that runs through frameworks such as the GDPR. For individuals, it is often the practical gateway to exercising other rights: before someone can request correction, deletion, or object to processing, they generally need to understand what personal data an organization holds and how it is being used. In the cookie and tracking context, this can extend to data generated through consent management, analytics, advertising identifiers, and similar technologies, though the precise scope depends on whether the data in question qualifies as personal data and on the facts of each case.

For organizations, the right creates a standing obligation to be able to locate, retrieve, and explain the personal data they process, including the purposes of processing, the categories of data, and the recipients or categories of recipients to whom data has been or will be disclosed. This is not a one-off exercise but an operational capability that must be maintained. Handling access requests also requires care, because Article 15(4) provides that supplying a copy of personal data should not adversely affect the rights and freedoms of others, which can require a fact-specific balancing exercise.

Because the right generally applies to an individual's own personal information and does not usually extend to information about third parties, responding well involves judgment as much as process. Getting this wrong in either direction, withholding data people are entitled to, or disclosing information about others, can create both compliance and reputational exposure. The specific exemptions, timeframes, and procedural mechanics are out of scope here and can differ between regimes.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for handling data subject requests need reliable processes to confirm whether personal data is processed, retrieve it, and provide the required supplementary information such as processing purposes, categories of data, and recipients. They also need to apply the Article 15(4) balancing exercise where a request may reveal information about other people, recognizing that this can be fact-specific and contested.
Legal counsel and compliance teams
Legal advisors assess how the general access right applies to their organization, including where the boundary lies between an individual's own data and information about third parties. They should note that specific exemptions and procedural requirements are out of scope of this general definition and can differ between the EU, the UK, and other regimes such as US state privacy laws.
Web developers and engineers handling tracking data
Teams building and maintaining cookie consent, analytics, and tracking infrastructure may need to help locate and export data associated with an individual where it constitutes personal data. Designing systems so relevant records can be identified and retrieved supports the organization's ability to respond to access requests, though whether particular data falls in scope depends on the facts.
Marketing and analytics teams
Because access requests can reach data generated through advertising identifiers, analytics, and similar technologies, marketing teams should understand what personal data their tools collect and to which recipients or categories of recipients it is disclosed. This awareness helps the organization respond accurately when individuals exercise their right of access.

Inside SAR

Scope of the right
Under the GDPR (Article 15), the right of access allows a data subject to obtain confirmation of whether their personal data is being processed and, where it is, access to that data along with supplementary information. In the cookie context, this may extend to personal data collected through cookies, pixels, SDKs, and similar tracking technologies where that data relates to an identifiable individual.
Information to be provided
Typically includes the purposes of processing, the categories of personal data concerned, the recipients or categories of recipients, the envisaged retention period or criteria for it, the existence of other data subject rights, the source of the data where not collected directly, and information about any automated decision-making or profiling. Cookie-derived data may implicate profiling and advertising recipients.
Relationship to the ePrivacy Directive
The right of access is a GDPR right governing the processing of personal data. It is distinct from the ePrivacy Directive rules that govern the placing of and access to information on a user's device. An access request concerns the personal data resulting from tracking, not the lawfulness of setting the cookie itself, though the two may overlap in practice.
Format and delivery of the response
The response is generally expected to be provided in a concise, transparent, intelligible, and easily accessible form, using clear language. Where requested electronically, information is commonly provided in a commonly used electronic format unless otherwise requested. A copy of the personal data undergoing processing is typically provided.
Timeframes and conditions
Access requests under the GDPR are generally subject to defined response timeframes and may be extended in certain circumstances involving complexity or volume. Controllers must typically verify the identity of the requester and may refuse or charge for manifestly unfounded or excessive requests, subject to conditions.
Geographic and legal scope
The GDPR right of access applies within the EU, with a comparable right under the UK GDPR. US state privacy frameworks such as the CCPA and CPRA in California provide their own access or 'right to know' rights, which differ in scope, thresholds, and mechanics. Obligations vary by jurisdiction and should not be assumed to be universal.

Common questions

Answers to the questions practitioners most commonly ask about SAR.

Does the right to access mean a user can obtain a copy of the cookie consent record we hold about them?
Not exactly, and it is important to separate two distinct obligations. The right to access under the GDPR concerns the personal data an organisation processes about a data subject, and where consent-related information (such as a logged consent record tied to an identifier) constitutes personal data, it may fall within the scope of an access request. However, the right to access is not itself a cookie-specific mechanism, and it does not replace the separate ePrivacy and consent-logging obligations that govern how consent is obtained and recorded. Whether a particular consent log must be disclosed depends on whether it relates to an identifiable person and on the applicable exemptions, which vary by jurisdiction.
If we already provide a consent management platform where users can review their cookie choices, have we satisfied the right to access?
Generally no. A CMP interface that lets users view or change their cookie preferences supports transparency and consent management, but it should not be assumed to discharge the GDPR right to access. The right to access is a broader data subject right that may require disclosing categories of personal data, purposes of processing, recipients, and other prescribed information, not only the state of a user's cookie toggles. Tools such as CMPs can help operationalise responses, but they do not by themselves guarantee compliance with an access request, and legal judgment is still required to determine what must be provided.
How do we verify the identity of someone making an access request relating to cookie data?
Identity verification is often challenging where the underlying data is tied only to pseudonymous identifiers such as cookie IDs rather than to a named individual. Where an organisation cannot link a request to identifiable data without disproportionate additional information, the position on what must be done can differ, and some regimes do not require an organisation to acquire extra data solely to identify a data subject. Any verification approach should be proportionate and should avoid collecting more personal data than necessary. Because guidance from data protection authorities on this point evolves, the specific steps should be confirmed against current requirements in the relevant jurisdiction.
What information should we be prepared to include when responding to an access request that touches cookie-related processing?
Where cookie-related data constitutes personal data, a response may need to address the categories of data processed, the purposes of processing, the recipients or categories of recipients, and other information prescribed by the applicable law. This can extend beyond literal cookies to similar technologies such as pixels, local storage, SDKs, and identifiers used for analytics or advertising, where these process personal data. The precise content required varies between the EU, the UK, and other regimes, so the scope of a response should be assessed against the specific legal framework that applies.
How should access requests be handled where cookie data is shared with or held by third parties such as advertising vendors?
Where personal data derived from cookies or similar technologies is shared with third parties, an access response may need to identify recipients or categories of recipients, and the organisation's role (for example as controller or joint controller) will affect its obligations. Contractual arrangements with vendors and, where relevant, frameworks such as the IAB Transparency and Consent Framework may influence how information flows are documented. Because responsibilities depend on the specific relationships and the applicable jurisdiction, this typically requires case-by-case assessment rather than a single fixed approach.
How does consent logging and record-keeping support our ability to respond to access requests?
Maintaining records of consent and of the processing carried out through cookies and similar technologies can make it easier to locate and disclose relevant personal data when an access request is received. Consent logs, records of processing activities, and clear documentation of purposes and recipients are organisational measures that support responsiveness. That said, keeping such records does not by itself determine what must be disclosed in any given case, and the disclosure obligations remain a matter of applying the relevant law to the specific facts.

Common misconceptions

The right of access is governed by the ePrivacy Directive because it involves cookies.
The right of access is a GDPR right concerning the processing of personal data. The ePrivacy Directive governs the placing of and access to information on a user's device, which is a separate matter. Cookie-related access requests concern the personal data that results from tracking, not the act of setting the cookie itself.
A right of access request only covers data stored in literal HTTP cookies.
Where personal data relates to an identifiable individual, the right may extend to data collected through similar technologies such as pixels, local storage, SDKs, and fingerprinting, not only cookies in the strict sense. The relevant question is generally whether personal data is being processed, not the specific technical method used.
The same access rules and mechanics apply everywhere.
Access rights differ across jurisdictions. The GDPR applies in the EU, the UK GDPR provides a comparable right in the UK, and US state laws such as the CCPA and CPRA offer distinct 'right to know' mechanisms that often differ in thresholds, exemptions, and procedures. Scope and obligations should be assessed against the applicable regime.

Best practices

Maintain an inventory mapping cookies, pixels, SDKs, and similar technologies to the personal data they generate, so access requests can be answered accurately across all tracking technologies rather than only literal cookies.
Verify the identity of the requester using proportionate methods before disclosing personal data, and document the verification steps taken.
Prepare responses in a concise, transparent, and intelligible form, and where requests are made electronically provide the information in a commonly used electronic format unless the requester asks otherwise.
Track applicable response timeframes for each jurisdiction and document any grounds for extension or refusal, since GDPR, UK GDPR, and US state frameworks differ in their mechanics.
Coordinate access request handling with consent records and CMP logs, while recognising that such tools support the response process but do not by themselves determine what must legally be disclosed.
Seek legal review for edge cases such as profiling, automated decision-making, or third-party recipients of advertising data, and flag where interpretations are unsettled rather than assuming a single correct answer.
Promotional banner for the Penetration Report Template Kit