Practical guide

How to draft a GDPR data access request with AI

4 min read · Updated May 2026 · Editorial oversight: Avv. Federico Papa

The data access request is the primary tool through which the data subject exercises control over their personal information pursuant to Art. 15 GDPR. This request allows the individual to obtain confirmation from the data controller as to whether personal data concerning them are being processed, as well as access to and a copy of such data. The right of access is essential for verifying the lawfulness of processing and for the potential exercise of rights such as rectification or erasure. It constitutes a fundamental document in litigation concerning privacy, employment relationships, or contractual liability.

In brief

The data access request under Article 15 GDPR enables data subjects to obtain processing confirmation and copies of personal data. Drafted also via AI, this procedure facilitates the verification of processing lawfulness and the exercise of rectification or erasure rights. Requests must specify purposes, data categories, and recipients. Pursuant to Article 12 GDPR, controllers must respond within one month, extendable for complex cases. Transmission via Certified Email or registered mail ensures proof of receipt for potential complaints to the Data Protection Authority or legal actions before ordinary courts.

The steps

  1. 1.

    Identification of the Data Controller and DPO

    Ensure the request is correctly addressed to the data controller by verifying the contact details provided in the privacy notice. If a Data Protection Officer (DPO) has been appointed, the data subject may contact them to facilitate internal handling, provided that the legal obligation to respond lies with the controller. Accuracy in identifying the recipient prevents administrative delays and ensures the request reaches the relevant department.

  2. 2.

    Detailed formulation of the request

    Clearly express the intention to exercise the right of access, specifically requesting confirmation as to whether personal data are being processed. Pursuant to Art. 15 GDPR, the applicant is entitled to obtain information regarding the processing purposes, the categories of personal data concerned, and the recipients or categories of recipients to whom the data have been or will be disclosed. Vague wording could justify the controller's request for clarification, thereby extending the duration of the procedure.

  3. 3.

    Defining the scope of the request

    Define the scope of the request by specifying whether access concerns all personal data or particular categories, such as profiling data or system logs. If the request is submitted by electronic means, the information shall be provided in a commonly used electronic format, unless otherwise indicated by the data subject. Specifying the relevant timeframe allows the controller to conduct a targeted search across both electronic and physical archives.

  4. 4.

    Indication of response deadlines

    Explicitly reference Art. 12 GDPR, which mandates the controller to provide a response without undue delay and at the latest within one month of receipt. Specify that, in the event of an extension by up to two months due to the complexity or number of requests, the controller must still inform the data subject within the first month, stating the reasons for the delay. Including this formal deadline serves as a legal notice and establishes a foundation for any subsequent proceedings before the Data Protection Authority or the courts.

  5. 5.

    Transmission methods and proof of receipt

    Transmit the request using methods that guarantee proof of receipt and time-stamping, such as Certified Email (PEC) or registered mail with return receipt. Proof of delivery is essential to establish the commencement of the one-month deadline and to demonstrate the controller's inaction during administrative or judicial proceedings. It is advisable to retain a signed copy of the request and to attach a valid identity document.

Legal basis: art. 12 GDPRart. 15 GDPR

The template structure

The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.

  1. Sender

    Identification and contact details of the data subject requesting access to their personal data.

  2. Data Controller

    Details of the public or private entity determining the purposes and means of personal data processing.

  3. Subject: right of access

    Brief indication of the exercise of rights under Art. 15 GDPR for immediate identification of the request.

  4. Content of the request

    Detailed request for confirmation of processing, provision of data copies, and information on purposes, storage, and origin.

  5. Response methods and deadlines

    Indication of the contact address for the response and reference to the mandatory one-month deadline.

  6. Place, date, signature

    Formal closing elements of the document including the applicant's handwritten or digital signature.

Mistakes to avoid

  • Forgetting to attach a copy of the identity document, which may justify the controller requesting additional information to confirm the applicant's identity pursuant to Art. 12(6) GDPR.
  • Addressing the request to a data processor rather than the controller, resulting in delays or rejection due to the recipient's lack of passive standing.
  • Confusing the right of access (Art. 15 GDPR) with the right to data portability (Art. 20 GDPR), thereby erroneously restricting the request only to data directly provided by the data subject.
  • Omitting the request for information regarding the logic involved in automated decision-making when personal data are used for profiling or scoring systems.

Frequently asked questions

Does providing a copy of the data involve paying a fee?

No, exercising the right of access is free of charge under Art. 12 GDPR. The controller may charge a reasonable administrative fee only in cases of manifestly unfounded, excessive, or repetitive requests.

What is the deadline for receiving a response from the controller?

The controller must respond without undue delay and at the latest within one month of receiving the request. This period may be extended by two further months where necessary, taking into account the complexity of the request, provided that a reasoned notice is sent to the data subject within the first month.

What actions can be taken if the controller fails to respond or unjustifiably refuses access?

In the event of non-response or unjustified refusal, the data subject may lodge a complaint with the Data Protection Authority or institute judicial proceedings before the ordinary courts. Both remedies aim to enforce data disclosure and establish the controller's breach.

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAM

What edit.legal automates

  • Automatic verification of legal references to Articles 12 and 15 GDPR to ensure the legal soundness of the document.
  • Intelligent population of Data Controller and DPO details using professional databases integrated into the AI editor.
  • Suggestion of specific clauses to request the logic involved in automated decision-making and profiling processes.

Put edit.legal to the test on actual cases

Try edit.legal for free on an active case. No credit card required.

Try edit.legal for free