Privacy & Data · European Union

Right of Access Under GDPR: How to Find Out Exactly What Data a Company Has on You

Asking a company what information it holds about you might sound like it would return a basic summary — your name, email, and a simple purchase history. The reality goes considerably deeper. Under Article 15 of the GDPR, you have the legal power to make what's called a Subject Access Request (SAR), and the organisation is legally obligated to hand over a complete, legible copy of essentially all personal data it processes about you.

What a full SAR disclosure actually includes

This can include recordings of your customer service calls, hidden location history, internal notes staff have written about you in their CRM, and the algorithmic classifications or behavioural profiles the company has built to target you with advertising.

It's free — with narrow exceptions

Making a SAR is free of charge. Companies are strictly prohibited from charging administrative fees for processing your first copy. Only if you request additional copies, or make a request that's genuinely manifestly unfounded or excessive, can they charge a reasonable fee based on actual administrative costs — and the burden of proving a request meets that threshold sits with the company, not you.

The response deadline — and the same extension rule that applies to erasure

The legal delivery deadline is one month from identity verification. As with erasure requests, this isn't a hard, non-extendable cutoff: the company can extend it by up to two further months where the request is genuinely complex or numerous, provided they notify you within the first month with their reasons. Don't assume a company using this legitimate extension has broken the law — check whether they gave you proper notice within the first month before assuming non-compliance.

Drafting a request that gets a complete answer

Send your formal request citing Article 15 of the GDPR explicitly. Ask specifically for the purposes of processing, the categories of personal data processed, the recipients your data has been or will be shared with, and the intended retention period.

Reviewing what you receive

Examine the structured data package you're sent (commonly JSON, CSV, or PDF format). If you spot obvious omissions, or the company masks key tracking metadata behind vague claims of "trade secrets," you can report the case directly to your DPA to push for a technical audit of their systems.

Sources