This code of practice explains the rights of individuals to access their personal data. It also clarifies what you must do in this regard to comply with your duties as a data controller. These rights and duties are set out in sections 7–9A of the Data Protection Act 1998 (DPA) and are often referred to as ‘the right of subject access’, a phrase this code also uses. The code refers to a request made under section 7 of the DPA as a ‘subject access request’ (SAR).
GDPR Right of Access Under EDPB’s Enforcement Spotlight in 2024
The EDPB initiates a 2024 action focusing on GDPR's right of access to ensure compliance across the EU.