Skip to main content
Promotional banner for the pentest readiness checklist
Category: Consumer Privacy Rights

Right to Know

Also known as: RTK, Right-to-Know
Simply put

The right to know is a general principle giving people access to certain information, though its meaning depends heavily on context. In some settings it refers to the public's right to access government records or information about workplace hazards and chemical exposures, while in data protection contexts it is often used to describe an individual's right to learn what personal information an organization holds about them and how it is used. Because the term spans very different legal regimes, its scope and requirements vary significantly by jurisdiction and subject matter.

Formal definition

"Right to know" is not a single defined term but a label applied across multiple legal domains. In its traditional uses it describes statutory rights of public and worker access to information: for example, occupational safety frameworks (such as those associated with OSHA in the United States) require employers to disclose information about hazardous substances and workplace chemical exposures, and open-records or freedom-of-information laws (such as Pennsylvania's Right-to-Know Law) presume that government agency records are public unless a specific exemption applies. UNESCO characterizes a broader right to know as a human right enabling people to participate in an informed way in decisions affecting them. In privacy and data protection practice the phrase is frequently used to describe a consumer or data subject's right to obtain disclosure of the personal information an organization has collected, used, or shared, but the precise mechanics, scope, and exemptions of any such right depend on the specific governing law and jurisdiction. The evidence provided does not establish the parameters of any particular data protection right-to-know provision, so practitioners should consult the applicable statute or regulatory guidance before relying on a specific formulation.

Why it matters

The phrase "right to know" carries meaningfully different legal weight depending on the context in which it appears, and conflating those meanings can lead compliance teams astray. In occupational safety law it refers to an employer's duty to disclose information about hazardous substances and chemical exposures that workers may encounter, while in open-records or freedom-of-information law, such as Pennsylvania's Right-to-Know Law, it describes the presumption that government agency records are publicly accessible unless a specific exemption applies. In privacy and data protection practice, the same phrase is often borrowed to describe a consumer's or data subject's ability to learn what personal information an organization holds about them and how it is used. Because these regimes serve distinct purposes and impose distinct obligations, practitioners cannot assume that guidance developed for one domain transfers to another.

For cookie consent and data protection teams, this ambiguity matters because a data subject's ability to obtain disclosure about collected personal information can intersect with the tracking technologies deployed on a website. However, the specific mechanics, scope, and exemptions of any data protection right-to-know provision depend entirely on the governing statute and jurisdiction, and requirements differ significantly across the EU, the UK, and individual US states. The evidence available here does not establish the parameters of any particular data protection right-to-know provision, so treating the term as a single, uniform right would overstate what can reliably be said.

Given this variability, the practical value of the term lies less in a fixed set of obligations and more in prompting the right question: which legal regime and jurisdiction actually applies to a given request or record? Answering that question correctly is a prerequisite to responding appropriately, and getting it wrong can create both compliance exposure and unmet expectations.

Who it's relevant to

Privacy officers and data protection professionals
Because the term is applied across multiple legal domains, privacy officers should first identify which regime and jurisdiction governs a given request before responding. The specific mechanics, scope, and exemptions of any data protection right-to-know provision depend on the applicable statute, and requirements can differ across the EU, the UK, and individual US states.
Legal counsel
Counsel advising on data subject or consumer requests should be alert to the risk of conflating the privacy-context use of "right to know" with its occupational safety or open-records meanings. The evidence here does not establish the parameters of any particular data protection right-to-know provision, so counsel should consult the governing law and regulatory guidance rather than relying on a generic formulation.
Compliance and records management teams in public sector organizations
Teams handling government agency records may encounter right-to-know in its open-records sense, such as under Pennsylvania's Right-to-Know Law, where records are presumed public unless a specific exemption applies. This is distinct from any data protection right and follows its own procedures.
Employers and workplace safety personnel
In the occupational safety context, right-to-know refers to an employer's obligation to disclose information about hazardous substances and chemical exposures that workers may encounter. This traditional usage, associated in the United States with frameworks such as OSHA, is separate from any privacy or data protection interpretation of the term.

Inside RTK

Categories of Personal Data Collected
The right to know typically enables an individual to request disclosure of the categories of personal data a business has collected about them. In the cookie context this may include identifiers set through cookies, pixels, SDKs, or similar technologies, as well as inferences drawn from browsing behavior. The precise scope of what must be disclosed depends on the applicable regime, such as the CCPA/CPRA in California.
Sources of Collection
Under several US state privacy laws, a right-to-know request may cover the sources from which personal data was obtained, which can include first-party cookies, third-party trackers, and data received from advertising or analytics partners. The exact obligation varies by jurisdiction.
Purposes of Processing
The right to know generally includes disclosure of the business or commercial purposes for collecting or sharing personal data, for example analytics, advertising personalization, or measurement carried out through tracking technologies. This overlaps conceptually with the transparency obligations found in the GDPR, though the GDPR frames access and information rights differently.
Recipients or Third Parties
Many frameworks require disclosure of the categories of third parties with whom personal data is shared or, in some regimes, sold. In the cookie context this often relates to advertising networks and other vendors receiving data via trackers. The terminology (sharing, selling, disclosing for business purposes) differs across US state laws.
Specific Pieces of Information
Some laws, such as those in certain US states, allow individuals to request the specific pieces of personal data held about them, not only categories. Whether specific data must be provided, and any exceptions, depends on the applicable statute.
Relationship to GDPR Access Rights
In the EU and UK, the analogous mechanism is the GDPR right of access rather than a distinct right to know. It allows data subjects to obtain confirmation of and access to personal data being processed, along with related information. This is a separate legal construct from the US state-law right to know, even though the concepts overlap.

Common questions

Answers to the questions practitioners most commonly ask about RTK.

Is the right to know the same as the GDPR's right of access?
Not exactly, and the two should not be treated as interchangeable. The right to know is a term associated primarily with US state privacy laws such as the California Consumer Privacy Act (CCPA) as amended by the CPRA, whereas the right of access is the corresponding concept under the EU and UK GDPR. While both allow individuals to learn what personal information an organization holds about them, they arise under different legal regimes with distinct scopes, definitions, exemptions, and procedural requirements. Treating a process built for one as automatically sufficient for the other may leave gaps, so you should generally map your obligations under each applicable framework separately rather than assuming a single workflow satisfies all of them.
Does responding to a right to know request mean I have to hand over the actual cookies or tracking files on a person's device?
Not in the way that phrasing suggests. The right to know generally concerns the categories and, in some cases, specific pieces of personal information an organization has collected, used, disclosed, or sold or shared, rather than the technical cookie files themselves. Where cookies, pixels, SDKs, or similar technologies are used to collect personal information, the information derived from or associated with them may fall within the scope of a request, but the obligation is typically framed around disclosing categories and details of personal information as defined by the applicable statute. The precise scope depends on the specific law involved and its definitions, so this entry should not be read as a substitute for reviewing those requirements.
How do I verify the identity of someone making a right to know request?
Verification requirements vary by jurisdiction and by the sensitivity and volume of information involved, so there is no single universal standard. In general, applicable frameworks expect you to take reasonable steps to confirm the requester is the individual they claim to be, or an authorized agent acting on their behalf, before disclosing personal information. The appropriate level of verification typically scales with the risk of harm from wrongful disclosure. Because over-collecting identifying data for verification can itself raise privacy concerns, you should generally align your verification process with the specific guidance and rules applicable to the laws you are subject to, and document the approach you take.
What is the timeframe for responding to a right to know request?
Response deadlines differ between legal regimes, and you should confirm the specific timeframe under each law that applies to your organization rather than assuming a common deadline. Many frameworks also permit extensions in certain circumstances, and some require you to acknowledge a request within a set period even if the full substantive response follows later. Because these periods and any extension conditions are defined by the applicable statute and may be clarified through regulatory guidance, this entry does not state a specific number of days; verify the exact requirements for your jurisdictions.
How should consent and cookie data be organized to make right to know responses easier?
In practice, organizations often find it easier to respond when they maintain a data inventory or mapping that records what personal information is collected through cookies and similar technologies, the categories involved, the sources, the purposes, and any parties to whom information is disclosed, sold, or shared. Consent logs and records maintained through a consent management platform (CMP) may support this by documenting choices and preferences, though a CMP supports compliance rather than guaranteeing it and does not replace legal judgment. Aligning your record-keeping with the disclosure categories your applicable laws require can reduce the effort needed to compile an accurate response, but the adequacy of any approach depends on the specific facts and frameworks involved.
Can I charge a fee or refuse a right to know request?
Whether you may charge a fee, and whether and when you may decline or limit a response, depends on the specific law that applies. Many frameworks provide that responses to individual requests are to be handled without charge in ordinary circumstances, while some allow reasonable fees or refusal where requests are manifestly unfounded, excessive, or repetitive, and various exemptions may apply. Because the availability of these grounds and their precise conditions are defined by each applicable statute and can be shaped by regulatory guidance, you should evaluate any decision to charge or refuse against the requirements of the relevant jurisdiction and document your reasoning. This entry does not resolve contested interpretations of when refusal is permitted.

Common misconceptions

The right to know is a single universal right that applies everywhere in the same way.
The right to know is primarily a feature of certain US state privacy laws, such as the CCPA/CPRA in California, and its scope varies between states. In the EU and UK the comparable mechanism is the GDPR right of access, which is structured differently. Obligations should always be assessed against the specific applicable regime rather than assumed to be uniform.
The right to know only covers data collected through literal cookies.
Where the right applies, it generally concerns personal data regardless of the technology used to collect it. This can include identifiers gathered through pixels, local storage, SDKs, or fingerprinting techniques, not only browser cookies. The relevant question is whether personal data was collected, not which specific technology was used.
Responding to a right-to-know request satisfies all other cookie compliance obligations.
Fulfilling a right-to-know or access request addresses only that particular individual right. It does not by itself satisfy separate obligations, such as obtaining valid prior consent for non-essential cookies under EU ePrivacy rules, honoring opt-out signals under US state laws, or meeting record-keeping duties. These are distinct requirements.

Best practices

Map the applicable legal regimes before designing your response process, distinguishing US state-law rights to know (such as under the CCPA/CPRA) from the GDPR right of access in the EU and UK, since scope and terminology differ.
Maintain an up-to-date inventory of the tracking technologies in use, including cookies, pixels, local storage, SDKs, and fingerprinting, so that requests can be answered accurately regardless of the technology involved.
Document the categories of personal data collected, the sources, the purposes of processing, and the categories of third parties receiving data, so this information can be surfaced when a valid request is made.
Establish a verifiable identity-verification and intake procedure for requests, and keep records of requests received and responses provided to support accountability and any record-keeping obligations.
Treat right-to-know or access responses as separate from consent and opt-out obligations, and confirm that consent management, signal handling, and disclosure workflows are each addressed independently.
Involve legal counsel or a qualified privacy professional to interpret which specific disclosures are required in each jurisdiction, as tools and CMPs support these processes but do not replace legal judgment.
Application Security Isn’t Optional Anymore.