Skip to content
+370 5 212 1506 info@dat.lt

Subject access requests: the deadline and the answer

24 September 2026 · Good to know

A request for access to personal data must be answered without undue delay, and within one month of receipt at the latest (Article 12(3) GDPR). The answer has three parts: confirmation of whether the person’s data is processed, a copy of it, and information about the processing (Article 15(1) and Article 15(3) GDPR). The first copy is provided at no cost. A fee may be charged only for further copies or where a request is manifestly unfounded or excessive, and the controller must prove that (Article 12(5) and Article 15(3) GDPR). Additional information to confirm identity may be requested only where there are reasonable doubts (Article 12(6) GDPR).

This article is about requests for access to data. If the person is demanding erasure, see our article personal data published without consent: what to do. Where CCTV footage is requested, additional rules apply to the other people in the frame. When an erasure request must be met and when you may refuse is covered in Erasure requests: when you must erase and when you may refuse.

What the answer must include

Article 15(1) GDPR lists what the person is entitled to know: the purposes of processing, the categories of data, the recipients, the retention period or the criteria for it, their rights, the right to lodge a complaint, the source of the data if it was not collected from them, and any automated decision-making. If data is transferred to a third country, the person is also entitled to know about the safeguards (Article 15(2) GDPR). A link to the privacy policy alone usually does not fulfil this duty: it provides no copy of the data, and the general information may need to be tailored to that specific person.

The European Data Protection Board (EDPB), in its Guidelines 01/2022 on the right of access (version 2.1, adopted on 28 March 2023), clarifies several points where mistakes are most common:

  • the controller must search for data in all IT systems and paper filing systems, not in a single database;
  • the right must not be interpreted too narrowly and can cover data that also relates to other people, such as correspondence;
  • the person does not have to say why they are asking;
  • what counts is the situation on the day the request is received, and even inaccurate or unlawfully processed data must be provided.

Where the request is made by electronic means, the information is provided in a commonly used electronic form, unless the person asks otherwise (Article 15(3) GDPR).

The deadline: when it starts and when it can be extended

The month runs from receipt of the request. The EDPB says the period starts when the request reaches the controller through one of its official channels, and the controller does not actually need to be aware of it (01/2022, paragraph 159). A request that arrives in a shared organisational inbox that is published as a contact address, but that nobody reads during the holidays, has already started the clock. The EDPB’s example (Example 32): a request received on 5 March must be answered by 5 April at the latest. If the last day falls on a weekend or a public holiday, the answer is due by the next working day (paragraph 161).

The deadline can be extended by two further months where necessary, taking into account the complexity and number of requests. The person is informed of the extension and the reasons within the first month (Article 12(3) GDPR). The EDPB stresses that this is an exception (paragraph 162), and that a large effort alone does not make a request complex (paragraph 164).

If you decide not to act on the request, within the same month you must give the reasons and tell the person they can complain to the supervisory authority and go to court (Article 12(4) GDPR).

One organisation was receiving repeated questions from a former employee and asked us to help draft a formal answer. Our first question was whether the organisation had at least one document setting how quickly data subjects are answered. It had none. In that situation the deadline is unknown not only to the person, but to the organisation itself.

Identity checks

If the controller has reasonable doubts about the identity of the person making the request, it may ask for additional information (Article 12(6) GDPR). This is an option, not the first step for every request. The EDPB says the information requested must be proportionate to the type of data processed and the possible harm (01/2022, paragraph 70). If the person is already identified, for example logged into their account, demanding a copy of an identity document is disproportionate (paragraph 73). In general, a copy of an identity document should not normally be considered an appropriate way of confirming identity (paragraphs 74–75). If you do check a document, the EDPB suggests not copying it but making a note such as “ID card was checked” (paragraph 79).

If additional information was requested without delay, handling of the request may be paused until it arrives (01/2022, paragraph 159). If identity remains unconfirmed and the controller does not act on the request, it must give the reasons within the month and tell the person they can complain to the supervisory authority and go to court (Article 12(4) GDPR).

Other people’s data and other restrictions

The right to a copy must not adversely affect the rights and freedoms of others (Article 15(4) GDPR). But this is not a ground for rejecting a request altogether. The EDPB says only the parts that could harm others should be removed or made illegible, and the controller must be able to prove that harm. This exception does not apply to the information about processing under Article 15(1) GDPR.

One institution recorded its meetings as audio. When an employee asked for the recording, it offered only his own contributions. That answer may be too narrow. Data about a person can also include what was said about them or in reply to them. Parts unrelated to him need not be given, but parts containing his data may be withheld only to the extent the controller can show concrete harm to others (Article 15(4) GDPR; EDPB 01/2022, executive summary). Who must get what when CCTV footage is requested is covered in Requests for CCTV footage: who must get what.

Other restrictions can be set only by Union or Member State law under Article 23(1) GDPR. They must be in a specific legislative measure, not in the controller’s internal rules.

Fees and manifestly unfounded requests

Under Article 12(5) GDPR, the controller may charge a reasonable fee or refuse to act where requests are manifestly unfounded or excessive, in particular because of their repetitive character. In addition, a reasonable fee based on administrative costs may be charged for further copies (Article 15(3) GDPR).

The EDPB asks for these exceptions to be interpreted narrowly. A request is not excessive merely because the person gives no reasons, uses impolite language or intends to use the data for claims against the controller (01/2022, paragraph 189). It may be excessive where the person offers to withdraw the request in return for some benefit, or where requests are sent systematically, for example every week, to disrupt the controller’s work (paragraph 190).

In one case an access request arrived together with accusations and threats to complain to several authorities. That does not make the request unfounded. It had to be answered on the merits and on time, and identity confirmation could be requested only to the extent genuinely needed to remove a doubt.

What happens when the answer is late or incomplete

Once a month has passed without a proper answer, the person can complain to the State Data Protection Inspectorate (VDAI). The VDAI does not examine a complaint about the exercise of rights lodged before that month has passed (Article 27(2)(3) ADTAĮ). How such a complaint is handled is described in our article complaint to VDAI: how long it takes and what happens next.

Breaches of data subjects’ rights (Article 83(5)(b) GDPR) fall into the highest fine tier: up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5) GDPR). A person who has suffered damage can claim compensation (Article 82(1) GDPR).

The most common mistakes:

  • a link to the privacy policy is sent instead of a copy of the data;
  • the deadline is counted from when the responsible person saw the request;
  • a refusal does not mention the right to complain and to go to court;
  • a copy of an identity document is demanded from everyone;
  • the request is rejected because the person is in a dispute with the organisation;
  • after the request arrives, data that still existed on that day is deleted.

When to call a lawyer

  • when the request comes from a (former) employee, a customer or another party to a dispute;
  • when the request covers emails, call recordings or a large volume of data;
  • when the answer would include other people’s data or trade secrets;
  • when you are considering rejecting the request as manifestly unfounded or excessive;
  • when the VDAI has already asked for explanations.

Frequently asked questions

May we ask for a copy of an identity document?

Only where you have reasonable doubts about identity (Article 12(6) GDPR) and a less intrusive measure is not enough (EDPB 01/2022, paragraphs 70 and 74). The EDPB says a copy of an identity document is not normally an appropriate way of confirming identity, and demanding one is disproportionate if the person is already identified. Confirmation from the same email address or account is often enough.

Does the person have to explain why they want their data?

No. The EDPB Guidelines 01/2022 state that the data subject does not have to give reasons for the request, and the controller does not have to assess whether the request will actually help them. Giving no reasons does not make a request excessive either.

May we refuse if the person intends to take us to court?

No. The EDPB says a request is not excessive merely because the person intends to use the data for claims against the controller. You may refuse only a manifestly unfounded or excessive request, and you must prove it (Article 12(5) GDPR).

What should we answer if we hold no data about the person?

That is an answer too, and it must be given within the same month. The person has the right to confirmation of whether their data is processed (Article 15(1) GDPR). Before writing “we hold none”, check all systems, including email and paper archives.

How to start

Check whether your organisation has written down who receives requests, who searches for the data and who signs the answer. If you have received a request, send it to us with the date it arrived. We will tell you what you must answer and by when.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles