Right to Access
The right to access lets individuals ask an organization for a copy of the personal information it holds about them, along with details about how and why that information is being used. It generally does not extend to information about other people, and organizations may need to balance a person's request against the rights and freedoms of others. This right is a core feature of data protection laws such as the GDPR.
Under Article 15 of the GDPR, the right of access entitles a data subject to obtain confirmation of whether their personal data is being processed and, where it is, access to that data together with supplementary information including the purposes of processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the data has been or will be disclosed. Article 15(3) provides for a copy of the personal data undergoing processing, while Article 15(4) states that the right to obtain such a copy should not adversely affect the rights and freedoms of others. As reflected in ICO guidance, the right applies to an individual's own personal information and does not generally extend to information about third parties except in limited circumstances. Note that this entry addresses the general access right under EU and UK data protection law; specific procedural requirements, exemptions, response timeframes, and equivalent rights under other regimes (such as US state privacy laws) are out of scope here and may differ. The scope of exemptions and the balancing exercise involving others' rights can involve contested, fact-specific assessments.
Why it matters
The right of access is widely regarded as one of the most fundamental rights in data protection law, and it underpins the transparency principle that runs through frameworks such as the GDPR. For individuals, it is often the practical gateway to exercising other rights: before someone can request correction, deletion, or object to processing, they generally need to understand what personal data an organization holds and how it is being used. In the cookie and tracking context, this can extend to data generated through consent management, analytics, advertising identifiers, and similar technologies, though the precise scope depends on whether the data in question qualifies as personal data and on the facts of each case.
For organizations, the right creates a standing obligation to be able to locate, retrieve, and explain the personal data they process, including the purposes of processing, the categories of data, and the recipients or categories of recipients to whom data has been or will be disclosed. This is not a one-off exercise but an operational capability that must be maintained. Handling access requests also requires care, because Article 15(4) provides that supplying a copy of personal data should not adversely affect the rights and freedoms of others, which can require a fact-specific balancing exercise.
Because the right generally applies to an individual's own personal information and does not usually extend to information about third parties, responding well involves judgment as much as process. Getting this wrong in either direction, withholding data people are entitled to, or disclosing information about others, can create both compliance and reputational exposure. The specific exemptions, timeframes, and procedural mechanics are out of scope here and can differ between regimes.
Who it's relevant to
Inside SAR
Common questions
Answers to the questions practitioners most commonly ask about SAR.
