Right of access under the GDPR: the scope of article 15 AVG

A row of archive folders standing side by side

The right of access in article 15 of the General Data Protection Regulation, known in the Netherlands as the Algemene Verordening Gegevensbescherming (AVG), entitles any individual to ask an organisation whether it processes personal data about them, to receive a copy of those data, and to be told the purposes, the recipients, the retention period and the source. The controller must answer within one month, free of charge, and may only limit access where doing so is necessary to protect the rights and freedoms of others. In the Netherlands a refusal can be taken to the district court by petition within six weeks under article 35 of the GDPR Implementation Act (Uitvoeringswet AVG).

The AVG is not a separate Dutch statute: it is the Dutch name for the Regulation itself, which applies directly. What Dutch law adds is the Uitvoeringswet AVG, which fills in the choices the Regulation left to member states and sets out how the right is enforced before the Autoriteit Persoonsgegevens and the courts. This article deals with the scope of article 15, its limits, and the procedure that follows a refusal.

What article 15 actually gives you

Article 15(1) contains two entitlements that are often confused. The first is confirmation: a yes or no answer to the question whether personal data concerning you are being processed. The second, which arises only if the answer is yes, is access to those data together with eight items of supplementary information. Article 15(3) then adds the obligation to provide a copy.

Article 15(1)What the controller must tell you
(a)The purposes of the processing
(b)The categories of personal data concerned
(c)The recipients or categories of recipient, including any outside the EEA
(d)The envisaged storage period, or the criteria used to determine it
(e)The right to request rectification, erasure or restriction, and to object
(f)The right to lodge a complaint with a supervisory authority
(g)Where the data were not collected from you, all available information about their source
(h)The existence of automated decision-making, including profiling, with meaningful information about the logic involved and the consequences

Article 15(2) adds that where personal data are transferred to a third country or an international organisation, you are entitled to be informed of the appropriate safeguards relied on for that transfer. Together these items are the reason a bare data dump is not compliance: the copy without the context does not satisfy article 15.

Personal data is a broad category, and controllers regularly define it too narrowly. It covers far more than a name and an address: behavioural profiles, assessments and opinions recorded about you, camera images, call recordings, device identifiers, log-in timestamps, IP addresses and inferences drawn about you all qualify as soon as they can be linked, directly or indirectly, to you as an identifiable person. The GDPR definition is deliberately wide, and the burden of explaining why something falls outside it rests with the controller.

Who can ask, and who must answer

The right belongs to the data subject: an identified or identifiable living natural person. Age, nationality and residence are irrelevant. A parent or legal guardian can act for a minor, and a court-appointed representative can act for an adult who lacks capacity. Anyone else needs a written authorisation, and a controller is entitled to verify it. The right does not survive death, because the Regulation does not apply to the data of deceased persons, although Dutch rules on professional secrecy and on access to a deceased patient’s medical file may still give relatives a route.

The request goes to the controller: the party that determines the purposes and the means of the processing. A payroll bureau, a hosting company or a software supplier acting on instructions is a processor, and must pass the request on rather than answer it. Where two organisations jointly determine the purposes and means, article 26 makes them joint controllers; they must agree between themselves who handles access requests and make the essence of that arrangement available, but the data subject may exercise the right against either of them.

Geography is rarely an obstacle. The Regulation applies to controllers established in the EU, and also to controllers outside it that offer goods or services to people in the EU or monitor their behaviour. A Dutch resident can therefore address a request to a foreign platform, and the one-month period starts when that controller receives it.

In the employment context the request is made by the employee personally, and it is a right rather than a favour. Employers should expect access requests around dismissal discussions and performance disputes, and should not treat the timing as a reason to answer differently.

What a copy means

The Court of Justice settled this point in Case C-487/21 of 4 May 2023. A copy under article 15(3) must be a faithful and intelligible reproduction of all the personal data being processed. A summary, a table of categories, or a general description of what the organisation holds does not satisfy the obligation.

The same judgment answered the harder question of whether whole documents must be handed over. In principle the obligation concerns the data, not the file they sit in. But the Court held that extracts from documents, entire documents, or extracts from databases must be provided where that is indispensable to enable the data subject to understand the data and to exercise their rights effectively. Context can be part of the meaning: an assessment makes sense only in the document that frames it, and an empty field can itself be informative. The practical test for a controller is therefore not whether a document is convenient to release, but whether the data remain intelligible without it.

A second judgment, Case C-307/22 of 26 October 2023, removed two arguments controllers used to rely on. The data subject does not have to state a reason for the request, and a motive unconnected with data protection, such as preparing a claim, does not make the request abusive. And the first copy must be free, even where national legislation would otherwise allow a charge for producing records.

Redaction remains legitimate where a document also contains other people’s personal data. A meeting note recording several employees can be released with the passages concerning colleagues removed or neutralised, provided what remains is still comprehensible. A document that concerns only you, such as your contract and the general terms and conditions applied to you, does not lend itself to redaction at all.

Deadlines, format and cost

Article 12(3) gives the controller one month from receipt of the request. That period may be extended by up to two further months where the request is complex or where the controller has received a number of requests, but the extension and the reasons for it must be communicated within the first month. Silence is not an extension. If the controller does not act on the request, article 12(4) requires it to say so within one month and to inform the data subject of the right to complain to a supervisory authority and to seek a judicial remedy.

There is no prescribed form. A request by email, by letter, through a web form, or made orally is equally valid, and a controller may not insist on its own template as a condition. Where the request is made electronically, the information should be provided in a commonly used electronic form unless the data subject asks otherwise.

Access is free. Article 15(3) allows a reasonable fee based on administrative costs only for further copies of the same data, and article 12(5) allows a reasonable fee or a refusal where a request is manifestly unfounded or excessive, in particular because of its repetitive character. The controller bears the burden of demonstrating that character, and after the 2023 case law the threshold is high: repetition alone, without more, is not enough.

Identity verification is permitted but bounded. Article 12(6) allows the controller to request additional information where it has reasonable doubts about the identity of the requester, and no more than that. Where the request comes from a known account, matching it against existing account details is usually sufficient. Where an identity document is genuinely necessary, the citizen service number, the photograph and the machine-readable zone should be blacked out, and any copy retained only for as long as the check requires. Requiring a full passport scan as standard is itself a breach, and identity documents that contain biometric data attract stricter rules again.

Transmission must be secure. Sending an unprotected file containing an entire personnel record to a private email address is a data breach waiting to happen; use a protected file with the key shared separately, or a portal with two-factor authentication.

When access may be limited or refused

Article 15 is not absolute. Article 15(4) provides that the right to obtain a copy must not adversely affect the rights and freedoms of others, and recital 63 names business secrets and intellectual property, including software copyright, as interests that may be weighed. The limitation is narrow in two respects: it applies to the copy rather than to the underlying entitlement to information, and it cannot result in a blanket refusal. Where a conflict exists, the controller must look for the least restrictive route, which is normally partial disclosure with redaction.

Third-party data

Correspondence, meeting notes and complaint files usually contain the personal data of more than one person. The controller must balance the interests, not simply withhold. In practice that means removing names and contact details of third parties, replacing an identity with a neutral description where the identity itself is not the point, or supplying an extract rather than the whole chain. What the controller may not do is refuse the entire document because a third party appears in it.

Confidential information and professional privilege

Trade secrets, pricing models and source code can be protected, but the answer is calibration rather than silence. Where an automated decision is involved, the controller owes meaningful information about the logic applied and the consequences for the data subject, which is not the same as disclosing the algorithm. Separately, information covered by legal professional privilege is shielded, and the interaction between disclosure duties and privilege is a recurring issue for advisers, which we discuss in our article on reporting obligations and privilege.

Restrictions in Dutch law

The Uitvoeringswet AVG contains a number of restrictions on data subject rights adopted under article 23 of the Regulation, for purposes such as the prevention and investigation of criminal offences, supervision by public bodies, and the protection of the data subject or the rights of others. A controller relying on one of these must identify it, apply it to the specific request, and be able to justify it. A general statement that disclosure is not in anyone’s interest is not a restriction.

Medical records follow a partly separate track. Alongside article 15, the treatment agreement provisions of the Dutch Civil Code give a patient the right to inspect and obtain a copy of their file, and the two routes coexist rather than compete.

Handling a request as a controller

Most failures are organisational rather than legal. A request that arrives at a sales inbox, a branch office or in a telephone call still starts the clock, so the first requirement is that staff recognise one and route it. The second is that the organisation knows where personal data actually sit: the record of processing activities required by article 30 is the practical foundation for locating them, and a controller that cannot search its own systems will miss the deadline regardless of good intentions.

From there the process is mechanical. Acknowledge receipt and record the date. Verify identity proportionately. Define the scope with the requester where the request is very broad, without using that conversation as a delaying tactic. Search the systems, including archived mailboxes and ticketing tools. Redact third-party data under a second pair of eyes. Send the copy together with the article 15(1) information, in writing, and keep a record of what was disclosed and what was withheld with the reasons. That file is what the Autoriteit Persoonsgegevens will ask for if a complaint follows.

Two habits reduce the volume of work permanently: enforcing retention periods, because data lawfully deleted never has to be disclosed, and writing internal notes on the assumption that the person concerned may read them.

What to do if the controller does not answer

Start with a dated reminder that identifies the original request, states the date it was sent, and notes that the period in article 12(3) has expired. A short deadline of one or two weeks is reasonable. A significant proportion of requests are answered at this stage, and the reminder also creates the paper trail you will need later.

If that fails, two routes are open and they can be used in parallel. The first is a complaint to the Autoriteit Persoonsgegevens under article 77. The supervisory authority can investigate, order the controller to comply, impose an order subject to a penalty payment and, in serious cases, an administrative fine. What it does not do is award you anything personally, and the timescale is that of a regulator rather than of a dispute.

The second route is the court, and in the Netherlands it is unusually accessible. Article 35 of the Uitvoeringswet AVG allows an interested party to apply to the district court by petition for an order that the controller grant or refuse the request. Three features of that provision matter in practice. The petition must be lodged within six weeks of receiving the controller’s answer. Where the controller did not answer within the periods of article 12(3), no time limit applies at all. And article 35(4) provides expressly that the petition need not be lodged by a lawyer, which makes the procedure available to individuals without representation, even though the substance usually benefits from advice.

Urgent cases can also be brought in summary proceedings, and a claim for compensation under article 82 can be joined to a substantive claim. On damages, be realistic: the Court of Justice has held that an infringement does not by itself create an entitlement to compensation, and that the person claiming must show actual damage, although non-material damage can qualify and there is no minimum threshold of seriousness. Awards in access cases are modest, and the value of the procedure lies in obtaining the data. Our overview of how proceedings before a Dutch court are prepared sets out what to expect.

Making a request that works

A request does not have to be elaborate, but a well-scoped one is answered faster and is far harder to stall. Say who you are and in what capacity the organisation knows you, quoting a customer or personnel number. Refer to article 15 explicitly, so that there is no argument later about what you asked for. Where you are interested in a defined issue, name the period and the systems: correspondence with a named department between two dates, or entries in a specific application. Ask expressly for the supplementary information in article 15(1), not just for the data. And state how you want to receive it.

Subject: Request for access under article 15 GDPR / AVG

Dear Sir or Madam,

Under article 15 of the General Data Protection Regulation I request confirmation
whether you process personal data concerning me and, if so, a copy of those data
together with the information listed in article 15(1)(a) to (h) and, where relevant,
article 15(2).

My request concerns the period from [date] to [date] and in particular [systems,
departments or types of record].

I am known to you as [name, date of birth, customer or personnel number]. Please
provide the information electronically, in a secure manner, within the period of
one month laid down in article 12(3).

Yours faithfully,
[Name and contact details]

Keep the sent item, note the date, and diary the deadline. When the answer arrives, read it against the eight items in article 15(1) rather than only looking at the attachments; incomplete supplementary information is the most common defect and the easiest to challenge. If the data turn out to be inaccurate or excessive, the natural next step is a request for rectification or erasure, built on the same evidence.

The right of access is straightforward in principle and technical in application, on both sides of the request. Law & More advises individuals who are not getting answers, including employees and former employees confronting a personnel file, and organisations that need a defensible process for handling requests, redaction and refusals. If you are facing a deadline under article 12(3), or the six-week period under article 35 of the Uitvoeringswet AVG is running, contact Law & More to discuss the position.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Using AI in a Dutch business triggers two regimes at once. Any AI system that

The GDPR and big data are not incompatible, but they force a choice that many

Data breaches happen every day in the Netherlands. When they do, someone must take responsibility.

Discover when Escrow Arrangements for Software Source Code are necessary for legal and business security.

Sharing personal data under the GDPR is lawful only where the organisation that discloses the

Dutch criminal law distinguishes between offences in which a computer is the target and offences

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.