Right of Access
The right of access, in the data protection context, gives individuals the right to obtain a copy of the personal information an organisation holds about them, along with certain details about how and why that information is being used. It allows a person to find out what data is being processed about them and to check that it is being handled lawfully. The specific scope and procedures depend on the applicable law and jurisdiction, so readers should verify requirements against the current official text.
In data protection law, the right of access (commonly termed subject access) entitles a data subject to obtain confirmation as to whether their personal data is being processed and, where it is, to receive a copy of that personal data together with supplementary information. Based on the evidence, this supplementary information generally includes the purposes of the processing, the categories of personal data processed, and the recipients or categories of recipients to whom the data has been or will be disclosed. This entry addresses the right of access as an individual right under data protection frameworks such as the UK GDPR (as described by the ICO) and the EU GDPR; it does not cover the distinct concepts of 'right of access' in property/easement law or common-law public access to judicial records, which are unrelated legal doctrines. Exact conditions, exemptions, response timeframes, and format requirements are fact-specific, differ across jurisdictions (for example the UK versus the EU), and are periodically amended; practitioners should confirm against the latest authoritative source and apply professional judgment to particular circumstances.
Why it matters
The right of access is one of the foundational individual rights in data protection law because it makes an organisation's processing activities transparent to the people whose data is being used. Without it, individuals would have no reliable way to confirm whether an organisation holds their personal data, what it is doing with that data, or whether the processing is lawful. In this sense, the right of access functions as a gateway to other rights: a person often cannot meaningfully exercise rights such as rectification or erasure until they first understand what data is held and how it is being processed.
For organisations, the right of access carries operational and compliance significance. Under frameworks such as the UK GDPR (as described by the ICO) and the EU GDPR, individuals can require confirmation of processing and a copy of their personal data along with supplementary information about purposes, categories of data, and recipients. Handling these requests requires organisations to locate personal data across their systems and respond within the parameters set by the applicable law. Because exact conditions, exemptions, and response timeframes are fact-specific and differ between jurisdictions such as the UK and the EU, organisations should treat the right of access as an ongoing operational obligation rather than a one-off task.
It is important to distinguish this data protection right from unrelated legal doctrines that share the same name. The 'right of access' in property or easement law and the common-law right of public access to judicial proceedings and records are distinct concepts and are not addressed here. Conflating them can lead to misapplied requirements, so practitioners should confirm that they are working from the correct data protection source for their jurisdiction.
Who it's relevant to
Inside Right of Access
Common questions
Answers to the questions practitioners most commonly ask about Right of Access.
