A customer asks for access: what you must supply within a month

A customer asks for access: what you must supply within a month

7 min read

An access request rarely arrives announced and almost never as a form. It arrives as an email, sometimes as a sentence at the counter — and from that moment a deadline is running.

Customer data in one place, not four lists

With everything in one system an access request takes minutes, and what should go, goes. Hosted in Germany.

See the products

Article 15 GDPR gives every person the right to learn from you whether and what data you process about them. The request is bound to no form, needs no reason and does not have to contain the word “access”. “What have you actually got stored about me?” is a request too, if it is meant seriously.

The effort behind it depends less on the law than on your filing. The list of what belongs in it is manageable and can be put together in an hour — if you know where the data is. If it sits in four systems, that same hour becomes a weekend. This article describes the procedure; it is orientation, and contested individual cases are for your supervisory authority or a lawyer.

1. What belongs in the response

Article 15(1) requires two things that are often confused. First the confirmation of whether data is being processed at all. Second, if so, the access to that data and to eight details about the processing itself:

  • the purposes of the processing,
  • the categories of data concerned,
  • the recipients or categories of recipient — including those in third countries,
  • the envisaged storage period or, if that is not possible, the criteria for it,
  • the existence of the rights to rectification, erasure, restriction and objection,
  • the right to lodge a complaint with a supervisory authority,
  • the source of the data, where you did not collect it from the person,
  • whether there is automated decision-making, including profiling.

In a small business the first seven are the same for every request — they can be written once and reused. Only the actual data differs per person. Which is exactly why a template pays: the fixed part is the larger one.

To that add Article 15(3): you provide a copy of the data undergoing processing. Where the request comes electronically, you provide the information in a commonly used electronic form, unless something else is asked for. For further copies you may charge a reasonable fee based on administrative costs — for the first, you may not.

Giving access is not a legal task. It is a question of how you file.

2. The clock: one month, extendable by two

Article 12(3) sets the deadline: without undue delay and in any event within one month of receipt of the request. The month runs from receipt, not from the day you recognised the request as one — a reason not to leave emails to the general address lying for weeks.

The deadline can be extended by a further two months where that is necessary given the complexity and number of requests. That extension does not happen by itself: you have to inform the person within the first month and give the reasons for the delay. Notify the extension in the third month and you have missed the deadline, not extended it.

If you do not act on a request, the matter does not end in silence. Article 12(4) requires you to state the reasons without delay and at the latest within one month, and to point out two routes: a complaint to a supervisory authority and a judicial remedy. So there is always an answer, including the refusing one.

Access is free of charge under Article 12(5). Only for manifestly unfounded or — particularly where repetitive — excessive requests may you charge a reasonable fee or refuse to act, and the burden of demonstrating that is yours. The same person's second request after six months is not yet excessive.

3. Who is actually asking?

The response goes to the data subject — and to nobody else. Access given to the wrong person is itself a data breach, and one you caused. So the identity check comes before the answer.

Article 12(6) allows you, where you have reasonable doubts, to request additional information to confirm identity. Recital 64 adds that all reasonable measures should be used, particularly with online services. Two limits matter here:

  • Doubts have to be reasonable. If the request comes from the email address that has been in your file for years, you as a rule have no cause to ask for identity documents.
  • The check must not become data collection. Recital 64 says expressly that data should not be retained for the sole purpose of being able to react to potential requests. A copy of an ID document that you keep afterwards inverts the purpose of the provision.

In practice one simple route carries: reply on the channel through which the person is known to you. If the request comes from an unknown address, go back via the number or address on file. That is not obstruction and can be explained in a sentence.

Where somebody asks on another person's behalf — a relative, a law firm, an appointed representative — you need evidence of authority. Without it you do not answer refusing, you answer asking — and the deadline keeps running.

4. What does not belong in the response

The commonest mistake is not the response that is too thin but the one that is too generous. Article 15(4) says: the right to obtain a copy shall not adversely affect the rights and freedoms of others. From which follows a list of exceptions to go through before sending.

CaseWhat you do
Appointment shared with a second personrelease their own data, redact the second person's name
Internal note about a member of staffthe content about the requester yes, the staff appraisal no
Email thread with third parties copied inremove third-party addresses
Referral by another personname the source as far as you can — record the balancing

The direction of the exception matters: it does not let you refuse the response as a whole because somebody else's name appears somewhere. It lets you hold back the part that touches another person's rights. The rest goes out.

And one more thing does not belong in it: justification. Article 12(1) requires a concise, transparent, intelligible and easily accessible form, in clear and plain language. A response that opens with three paragraphs on why the storage is necessary meets that worse than a plain listing does.

5. Four systems, one answer

Now to the real effort. The response covers all the data you process about the person — not the data from one system. In a typical small business it sits in at least four places: the diary, the customer file, the invoices, and the correspondence, meaning emails and messages.

To that add the quiet places: the spreadsheet for the newsletter, the form on the website, the booking tool, the accountant's invoicing program, the notebook at the front desk. Each of those places is harmless on its own. Together they produce the question that makes an access request laborious: are you certain you have not forgotten one?

Here lies the most honest reason to keep appointments, customer file and invoices in one system — not the time saved day to day, but whether that question can be answered. Where everything sits in one place, the response is an export. Where it is spread out, it is a search with an uncertain end. For a salon, digital client records show what bringing it together looks like; for a garage, the workshop software.

Whatever the tool, a list you write beforehand helps: one line per place where customer data sits, with a word on how you search there. The same list later answers the question of what actually comes across when you switch software. It is in any case almost identical to the record under Article 30 GDPR — so you are not writing it twice.

The procedure is short: recognise the request, note the date of receipt, check identity, go through every place, remove other people's data, answer in plain language — within one month, if need be with a reasoned extension of two. The preparation that makes the difference is the list of places. Which data may be in them at all is settled by Which customer data you may store; what happens to it afterwards, by the deletion policy on one page.

Customer data in one place, not four lists

With everything in one system an access request takes minutes, and what should go, goes. Hosted in Germany.