The General Data Protection Regulation (GDPR), under Article 15, gives individuals or ‘data subjects’ the right to request a copy of any of their personal data which are being ‘processed’(i.e. used in any way) by ‘controllers’(i.e. those who decide how and why data are processed, e.g. SMEs), as well as other relevant information (as detailed below). These requests are often referred to as ‘data subject access requests’, or ‘access requests’.
These requests must be responded to free of charge and in an accessible form, and SMEs should seek to facilitate access requests being both made and responded to easily, including electronically where appropriate and where the individual wishes. The following guidance should answer some of the most frequently asked questions by SMEs who are struggling to deal with the access requests they are receiving: