Right of Access in Germany: What Art. 15 DSGVO Requires a Company to Hand Over

Art. 15 DSGVO gives a person the right to ask an organisation what personal data it holds about them, why it holds that data, and who else has seen it. In German this is the Auskunftsrecht, and it is the gateway to the other Betroffenenrechte. A correction, an erasure or an objection is difficult to formulate before anyone can see what actually exists.
Making the request is deliberately simple. There is no form to complete, no reason has to be given, and the answer is free. The harder part is knowing what a complete answer looks like, because a controller that sends back a thin summary and hopes the matter ends there is a common experience rather than an unusual one.
This page sets out what an Auskunft request reaches, the deadline the DSGVO sets and the narrow circumstances in which it stretches, the limits that genuinely apply under Art. 15 Abs. 4 DSGVO and under German national law, and what happens when a controller simply does not answer. It also runs the deadline through a calendar, because a period counted in months is easier to see than to describe.
Information last verified on 20 July 2026. This page provides general legal information and does not constitute legal advice in an individual case.
What an Auskunft request actually reaches
The right works in two layers. The first layer is confirmation: whether personal data concerning the person is being processed at all. A controller that holds nothing still has to say so, and a negative answer is a valid answer.
The second layer applies where data does exist. In that case Art. 15 Abs. 1 DSGVO gives access to the data together with a list of information items about the processing:
- the purposes of the processing
- the categories of personal data concerned
- the recipients or categories of recipients to whom the data has been or will be disclosed
- the envisaged storage period, or where that cannot be given, the criteria used to determine it
- the existence of the rights to rectification, erasure and restriction of processing, and the right to object
- the right to lodge a complaint with a supervisory authority
- where the data was not collected from the person, any available information about its source
- the existence of automated decision making including profiling, with meaningful information about the logic involved and the consequences
Art. 15 Abs. 2 DSGVO adds that where data is transferred to a third country, the person may be informed of the safeguards relied on for that transfer.
The practical significance of that list is that it is not a summary of a customer record. Personal data is a broad concept, and internal notes, ticket histories, call recordings, log data and the free text fields where staff describe a customer can all contain it. A response that reproduces only the name, address and order history has answered a narrower question than the one that was asked.
The copy under Art. 15 Abs. 3 DSGVO
Art. 15 Abs. 3 DSGVO is a separate obligation from the information list. It requires the controller to provide a copy of the personal data undergoing processing.
A copy is not the same as a description. A controller that writes that it processes contact data, order data and payment data for the purpose of fulfilling the contract has described categories, which is the Abs. 1 duty, without producing the data itself, which is the Abs. 3 duty. The two are commonly conflated in the responses people receive, and noticing the difference is the single most useful thing a requester can do with a reply.
Where the request is made electronically, the information is normally provided in a commonly used electronic format unless the person asks otherwise.
The one month clock, and the only way it stretches
Art. 15 DSGVO says what has to be handed over. Art. 12 Abs. 3 DSGVO says when. The controller has to respond without undue delay and in any event within one month of receiving the request.
That period can be extended by two further months where the extension is necessary taking into account the complexity and the number of requests. The extension is not automatic and it is not silent. The controller has to inform the person of the extension, together with the reasons for the delay, within one month of receiving the request.
So the outer limit is three months, but only where the controller actively claimed the extension inside the first month and explained why. A controller that says nothing for six weeks and then announces that it is taking three months has not followed the mechanism the article describes.
| Stage | What Art. 12 Abs. 3 DSGVO requires |
|---|---|
| Standard case | Response without undue delay, at the latest one month after receipt |
| Complex or high volume case | Extension by up to two further months, so three months in total |
| Condition for the extension | Notice to the person, with reasons for the delay, within the first month |
| No response at all | The deadline is simply missed, and the complaint route under Art. 77 DSGVO opens |
A worked timeline
Take a concrete calendar. A customer sends an email to a Berlin based online retailer on Monday 2 March 2026, asking for access under Art. 15 DSGVO.
The one month period runs from receipt, so the response falls due on 2 April 2026. If the retailer considers the request complex, for example because the data sits across a shop system, a support desk and a marketing platform, it can extend. To do so it has to write to the customer by 2 April 2026, say that it is extending and say why. The response then falls due on 2 June 2026.
If 2 April 2026 passes with no answer and no extension notice, the response is late from that date. Nothing further has to happen for the deadline to have been missed, and the complaint route to the competent supervisory authority is open from that point.
One caveat on the arithmetic. The exact way a period expressed in months is counted can move the end date by a day depending on the computation rules applied, so a response that arrives on 3 April rather than 2 April is not usually where a dispute has any substance. A response that arrives in September, or never, plainly is.
No form, no reason, and no fee
The DSGVO does not prescribe a form for the request. An email, a letter or a message through a support channel all work, and a controller cannot make its own web form the only permitted route. It is worth using a channel that leaves a record of the date, because the date is what starts the clock.
No reason has to be given. The right does not depend on a dispute, a suspicion or a purpose, and a controller that asks why the person wants the data is asking a question the regulation does not make a precondition.
Art. 12 Abs. 5 DSGVO makes the response free of charge. A fee, or a refusal to act, becomes possible only where a request is manifestly unfounded or excessive, in particular because of its repetitive character, and the controller bears the burden of demonstrating that character. Excessive in that sense is a high bar. A request that is inconvenient to answer, or that reaches a lot of data because the company holds a lot of data, is not on its own an excessive one.
Identity checks, and where they turn into delay
A controller that hands personal data to the wrong person has created a data breach rather than complied with a request, so a check on identity is legitimate where there is genuine doubt about who is asking. That much is uncontroversial.
What the identity check does not do is reset the clock. The one month period runs from the request, and a controller that spends five weeks asking for successive forms of proof from a person writing from the email address already on the account is using a legitimate step for a different purpose.
Whether a controller may insist on a copy of a Personalausweis is genuinely contested in German practice. The data minimisation principle in Art. 5 DSGVO is the usual reference point in that argument, and the common compromise is that details not needed to confirm identity are blacked out. We could not identify a binding provision that settles the question either way, so it is stated here as unsettled rather than resolved.
The limits that actually exist
The right of access has real limits, and they are narrower than the ones controllers tend to assert.
Art. 15 Abs. 4 DSGVO provides that the right to obtain a copy shall not adversely affect the rights and freedoms of others. In practice that is an argument for redaction rather than for silence. Where a document contains data about the requester and about a third party, removing the third party material leaves the rest disclosable.
§ 29 Abs. 1 Satz 2 BDSG is the German hook usually reached for on trade secrets. It provides that the right of access under Art. 15 der Verordnung (EU) 2016/679 does not exist where the Auskunft would reveal information that has to be kept secret under a legal provision or by its nature, in particular because of the overriding legitimate interests of a third party. The wording is about the information that would be revealed, not about the request as a whole.
§ 34 Abs. 1 BDSG adds two further German exceptions. The right does not exist where the person does not have to be informed under § 33 BDSG, and it does not exist where the data is stored only because legal or statutory retention rules prevent deletion, or serves exclusively data backup or data protection control purposes, provided that giving the Auskunft would require disproportionate effort and that processing for other purposes is excluded by appropriate technical and organisational measures. Those conditions are cumulative, which is why the provision covers far less ground than it is often given credit for.
§ 34 Abs. 2 BDSG then constrains the refusal itself. The reasons for refusing have to be documented, and the refusal has to be reasoned to the person, unless communicating the factual and legal grounds would defeat the purpose the refusal serves. A one line reply asserting a Geschaeftsgeheimnis with no reasons is not the pattern the statute describes.
What a request usually looks like in practice
Requests that work tend to be short. They identify the person clearly enough for the company to find the record, for example by naming the customer or account number the company itself uses. They state plainly that this is a request for access under Art. 15 DSGVO. They ask both for the information under Art. 15 Abs. 1 DSGVO and for the copy under Art. 15 Abs. 3 DSGVO, since those are the two halves that get separated in weak replies. They give a date, and they are sent through a channel that produces a record of that date.
Nothing in that description is required by the regulation. The right does not depend on the words used, and a request that says none of this is still a request. It is set out here as a description of ordinary practice, not as a template and not as a suggestion about what any particular reader should send or demand in their own situation.
If nothing comes back
Art. 77 DSGVO gives every person the right to lodge a complaint with a supervisory authority. In Germany the practical question is which one, and the answer is decided by the type of body being complained about rather than shared between authorities.
§ 40 Abs. 1 BDSG assigns supervision of non public bodies, meaning essentially the entire private economy, to the authorities designated under the law of each Land. § 9 Abs. 1 BDSG gives the Bundesbeauftragte fuer den Datenschutz und die Informationsfreiheit, the BfDI, supervision of federal public bodies and of companies processing data for the commercial provision of telecommunications services, alongside its role for postal services.
For a bank, a retailer, an insurer, a landlord, an employer or a platform, the competent authority is therefore the data protection authority of the Land where that controller is established, not the BfDI. Where a controller has several German establishments, § 40 Abs. 2 BDSG applies the main establishment concept in Art. 4 Nr. 16 DSGVO to work out which authority leads. A complaint costs nothing and does not require a lawyer.
The supervisory route and the court route are separate. Art. 79 DSGVO preserves the judicial remedy, and Art. 82 DSGVO provides for compensation for damage suffered. German courts have differed considerably on whether, and in what amount, non material damages follow from a late or incomplete Auskunft, so that part of the picture is unsettled and no figure should be read as typical.
What a breach can cost the controller
Art. 83 DSGVO has two fine tiers, and the difference matters because they are routinely merged into a single headline figure.
A breach of the data subject rights in Art. 12 to Art. 22 DSGVO, which includes the right of access, sits in the higher tier under Art. 83 Abs. 5 DSGVO: up to twenty million Euro, or up to four percent of the total worldwide annual turnover of the preceding financial year, whichever is higher. The lower tier in Art. 83 Abs. 4 DSGVO, which covers controller and processor obligations such as Art. 28 DSGVO, runs to ten million Euro or two percent on the same alternative basis.
§ 43 BDSG is a separate and much narrower German provision that is often dropped into this discussion incorrectly. It penalises only the mishandling of an Auskunftsverlangen under § 30 Abs. 1 BDSG and the failure to inform a consumer under § 30 Abs. 2 BDSG, both of which concern credit reference agencies and consumer credit. Its ceiling is fifty thousand Euro, and § 43 Abs. 3 BDSG provides that no fines are imposed on authorities and other public bodies. It is not the general penalty for ignoring an Auskunft request.
Access requests against an employer
The employment context is worth separating, because the statutory basis there is unstable. § 26 BDSG on the processing of employee data remains on the books, but the EuGH held on 30 March 2023 in case C-34/21 that a national general clause of that kind is not a more specific rule within the meaning of Art. 88 Abs. 1 DSGVO. The Beschäftigtendatengesetz that was intended to replace it has not been enacted, so it should not be described as imminent.
The result for an access request is comparatively stable even so. An employee asking an employer what it holds is asking under Art. 15 DSGVO directly, and the same one month period, the same copy obligation and the same limits apply. The material an employer holds, including monitoring records, is discussed further at workplace surveillance.
Where the organisation replying is not the one that actually stores the data, the contractual layer behind it matters, and that is the subject of the Auftragsverarbeitungsvertrag. For the wider set of German data protection topics see the data privacy overview, and for German law generally see Germany.
Frequently asked questions
Frequently Asked Questions
How long does a company have to answer an Auskunft request in Germany?
One month from receipt under Art. 12 Abs. 3 DSGVO. That can be extended by two further months where necessary because of the complexity or the number of requests, but only if the controller tells the person about the extension and gives reasons within the first month.
Does a request for access under Art. 15 DSGVO cost anything?
No. Art. 12 Abs. 5 DSGVO makes the response free of charge. A fee or a refusal becomes possible only where the request is manifestly unfounded or excessive, in particular because it is repetitive, and the controller has to demonstrate that.
Do I have to say why I want my data?
No reason has to be given and no particular form has to be used. The right does not depend on a dispute or a stated purpose, and a company cannot make an explanation a precondition for answering.
What exactly does a company have to send?
The information items in Art. 15 Abs. 1 DSGVO, covering purposes, categories of data, recipients, storage period, the other data subject rights, the source of the data and any automated decision making, plus a copy of the personal data itself under Art. 15 Abs. 3 DSGVO. A description of categories alone does not satisfy the copy obligation.
Can a company refuse because of trade secrets?
Only within limits. § 29 Abs. 1 Satz 2 BDSG excludes access where the Auskunft would reveal information that must be kept secret under a legal provision or by its nature, in particular because of overriding legitimate interests of a third party. § 34 Abs. 2 BDSG requires the reasons for a refusal to be documented and communicated, so an unexplained refusal is not what the statute contemplates.
Can a company demand a copy of my ID before answering?
A controller may verify identity where there is genuine doubt, since disclosing data to the wrong person would itself be a breach. Whether a full copy of a Personalausweis can be required is contested in German practice, data minimisation is the usual counter argument, and the verification step does not restart the one month deadline.
Who do I complain to if a German company ignores my request?
The Landesdatenschutzbehoerde of the Land where the company is established. § 40 Abs. 1 BDSG gives the Land authorities supervision over non public bodies, which covers virtually the whole private economy. The BfDI is competent for federal public bodies and for telecommunications and postal providers.
What is the fine for ignoring an access request?
A breach of Art. 15 DSGVO falls in the higher tier of Art. 83 Abs. 5 DSGVO, up to twenty million Euro or four percent of total worldwide annual turnover, whichever is higher. The fifty thousand Euro ceiling in § 43 BDSG is a different and much narrower provision about credit reference agency requests under § 30 BDSG.
Sources and References
- Verordnung (EU) 2016/679 (DSGVO), konsolidierte Fassung(eur-lex.europa.eu).gov
- Datenschutzkonferenz, Kurzpapier Nr. 6, Auskunftsrecht der betroffenen Person, Art. 15 DS-GVO(datenschutzkonferenz-online.de).gov
- § 34 BDSG, Auskunftsrecht der betroffenen Person(gesetze-im-internet.de).gov
- § 33 BDSG, Informationspflicht bei Erhebung von Daten ohne Kenntnis der betroffenen Person(gesetze-im-internet.de).gov
- § 29 BDSG, Rechte der betroffenen Person und aufsichtsbehoerdliche Befugnisse im Fall von Geheimhaltungspflichten(gesetze-im-internet.de).gov
- § 40 BDSG, Aufsichtsbehoerden der Laender(gesetze-im-internet.de).gov
- § 9 BDSG, Zustaendigkeit der oder des Bundesbeauftragten fuer den Datenschutz und die Informationsfreiheit(gesetze-im-internet.de).gov
- § 43 BDSG, Bußgeldvorschriften(gesetze-im-internet.de).gov
- § 30 BDSG, Verbraucherkredite(gesetze-im-internet.de).gov
- § 26 BDSG, Datenverarbeitung fuer Zwecke des Beschäftigungsverhaeltnisses(gesetze-im-internet.de).gov
- BfDI, Beschwerde ueber Datenschutzverstoesse bei den Aufsichtsbehoerden(bfdi.bund.de).gov
- BfDI, Anschriften und Links der Landesdatenschutzbehoerden(bfdi.bund.de).gov