Skip to content
compliancebase
GDPRChapter III — Right of Access

Article 15

Right of Access

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Enable individuals to confirm processing and receive their personal data plus required context about purposes, recipients, retention, sources, rights, and safeguards.

Points of focus

  • Search all systems reasonably likely to contain the requester's data
  • Provide intelligible data and processing context
  • Protect the rights and data of other people during disclosure

Implementation notes

Build a subject-identity graph across tenants and systems, automate collection where reliable, and retain human review for privilege, third-party data, secure delivery, and understandable explanations. Operationalize search all systems reasonably likely to contain the requester's data in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain system search map and access-request runbook with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the export covers account tables but omits support tickets and event logs Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample system search map and access-request runbook with dates and named reviewers. Be ready to walk through how you detect and correct: the export covers account tables but omits support tickets and event logs

Evidence auditors typically request:

  • System search map and access-request runbook
  • Completed export with review and redaction record
  • Identity verification and secure-delivery evidence

Common gaps

  • The export covers account tables but omits support tickets and event logs
  • Teams disclose raw records containing another user's personal data

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 15This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Right of Access applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — search all systems reasonably likely to contain the requester's data — with evidence stored where auditors and customers can sample it.

Lead with system search map and access-request runbook and pair it with completed export with review and redaction record. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because the export covers account tables but omits support tickets and event logs Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above