27/02/2025 - The right of access is one of the fundamental rights in the General Data Protection Regulation (GDPR). It allows individuals to find out what personal data is being processed about them. Still, research by the European Data Protection Board (EDPB) shows that many organisations are still struggling to handle requests for access to personal data correctly and efficiently. This can lead to complaints from data subjects, sanctions from the Data Protection Authority and reputational damage for organisations. In this blog, we set out for you the main pitfalls from this research and provide some guidance on how to avoid them. 

Common bottlenecks in right of access requests 

The EDPB survey reveals several shortcomings in organisations' handling of access requests. These are problems observed at both procedural and substantive levels. The most important of these points are briefly outlined below. 

  • Lack of standard procedure: Many organisations do not have an established procedure for handling data subject requests, which means employees do not know how respond to right of access requests. In the Netherlands, 30% of organisations do not have a standard procedure for right of access requests. 
  • Unnecessary barriers: Sometimes organisations ask for a copy of ID when it is not needed, or a request is wrongly refused when it does not come in through the right channel, for example.  
  • Unclear deadlines for processing: organisations do not always apply a clear deadline for processing access requests. In addition, a third of organisations also do not systematically check whether right of access requests are handled correctly and in a timely manner. 
  • Incorrect provision of access: The information about personal data that organisations give to data subjects is often too brief or not focused on the data subject's request for access. For example, little information is usually given about who can access the personal data, even when the data subject has specifically requested it. 

Differences and awareness 

Differences can also be seen between sectors. Highly regulated sectors, such as healthcare and finance, tend to have their processes well in place compared to, for example, commercial sectors (such as retail). The reason behind this is that such sectors are also required by other legislation to give people access to the personal data they process about them. Large organisations that receive many right of access requests also appear to have clearly and effectively set up the necessary procedures for this purpose. 

However, regulators were surprised by the large number of organisations that reported few data subject access requests by 2023, which could indicate that not all access requests are recognised as such. Awareness and knowledge about access requests thus also seems to be a possible problem. 

What can you do as an organisation? 

In addition to examining the bottlenecks, the EDPB also listed a number of practical measures in its report. These should ensure that organisations get their handling of access requests more compliant with the GDPR. The key measures that your organisation can get started with tomorrow are listed below. 

  1. Implement a clear procedure

Provide a standardised process for receiving, reviewing and responding to right of access requests. This prevents ambiguity for both employees and data subjects and reduces the risk of errors. Also ensure that it is clear to whom within the organisation the handling of access requests is assigned (this may not be the Data Protection Officer). 

  1. Ensure convenience and clear communication

Make it easy for data subjects to submit a right of access request, e.g. via an online form or a technical feature that allows them to download their personal data themselves. Communicate clearly about the next steps and keep the data subject informed about the progress. 

  1. Minimise administrative barriers

Ask for additional identification only if there is a justified reason. Make sure employees know when this is necessary and when it is not. In addition, coordinate with them that right of access requests that come in through an incorrect channel (such as a wrong mailbox) are always forwarded to the person in charge of processing. 

  1. 4. Evaluate regularly and train staff

Systematically check whether right of access requests are handled correctly within your organisation. This can be done through periodic audits, internal checks and evaluations of the process. In addition, train employees on how to recognise these requests so that the risk of violating the right of access is minimised.  

In conclusion 

A well-designed process for right of access requests not only helps to be GDPR compliant, but also contributes to transparency and trust among customers and employees. By ensuring a clear process, effective communication and regular review, organisations can improve their right of access procedures and avoid unnecessary risks. 

Want to know more about how your organisation can tackle this efficiently? Contact us for advice and practical support. 

 

 

Do you want to know more?

Handling personal data access requests correctly and efficiently is crucial for GDPR compliance and maintaining trust with your customers and employees. However, many organizations still face challenges in this area, leading to potential complaints, sanctions, and reputational damage. Do you have any questions about improving your processes for handling data access requests? Feel free to contact us for advice and practical support to ensure your organization is compliant and efficient.

Our services orContact