Article 15
Right of Access
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Enable individuals to confirm processing and receive their personal data plus required context about purposes, recipients, retention, sources, rights, and safeguards.
Points of focus
- Search all systems reasonably likely to contain the requester's data
- Provide intelligible data and processing context
- Protect the rights and data of other people during disclosure
Implementation notes
Build a subject-identity graph across tenants and systems, automate collection where reliable, and retain human review for privilege, third-party data, secure delivery, and understandable explanations. Operationalize search all systems reasonably likely to contain the requester's data in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain system search map and access-request runbook with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the export covers account tables but omits support tickets and event logs Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample system search map and access-request runbook with dates and named reviewers. Be ready to walk through how you detect and correct: the export covers account tables but omits support tickets and event logs
Evidence auditors typically request:
- System search map and access-request runbook
- Completed export with review and redaction record
- Identity verification and secure-delivery evidence
Common gaps
- The export covers account tables but omits support tickets and event logs
- Teams disclose raw records containing another user's personal data
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 15 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 15: Regulation (EU) 2016/679, Article 15 — Right of Access