Right of access to personal data

Subject Access Requestright of access
The Right of Access, also referred to as Right to Access and [data] subject access, is one of the most fundamental rights in data protection laws around the world.wikipedia
22 Related Articles

General Data Protection Regulation

GDPRGeneral Data Protection Regulation (GDPR)General Data Protection Regulation 2016
In the GDPR this right is defined in various sections of Article 15.
The right of access (Article 15) is a data subject right.

Max Schrems

Europe v FacebookMaximillian SchremsSchrems'' case.
He later made a request under the European Right of access to personal data provision for the company's records on him and received a CD containing over 1,200 pages of data, which he published at europe-v-facebook.org with personal information redacted.

Facebook–Cambridge Analytica data scandal

Cambridge Analytica data scandalCambridge AnalyticaCambridge Analytica scandal
Facebook director Mark Zuckerberg first apologized for the situation with Cambridge Analytica on CNN, calling it an "issue", a "mistake" and a "breach of trust"; in effect, he reminded them of their Right of access to personal data.

Data access

accessaccessible
* Right of access to personal data

Information privacy

data protectiondata privacyprivacy
The Right of Access, also referred to as Right to Access and [data] subject access, is one of the most fundamental rights in data protection laws around the world.

Charter of Fundamental Rights of the European Union

Charter of Fundamental RightsEU Charter of Fundamental RightsCFREU
The right of access is enshrined as part of the fundamental right to data protection in the Charter of Fundamental Rights of the European Union.

Bundesdatenschutzgesetz

Federal Data Protection ActGerman Data Protection Act (1990)German Federal Data Protection Act
When the EU Directive is transposed into Member State national law, the right of access may be suspended or restricted, as in the case of Germany in Article 34 of its Bundesdatenschutzgesetz.

Member state of the European Union

member statesEU member statesmember states of the European Union
In the current Member State United Kingdom, the website of the Information Commissioner's Office states regarding Subject Access Requests (SARs): "''You have the right to find out if an organisation is using or storing your personal data. This is called the right of access. You exercise this right by asking for a copy of the data, which is commonly known as making a ‘subject access request''".

Information Commissioner's Office

Information CommissionerData Protection RegistrarInformation Commissioner’s Office
In the current Member State United Kingdom, the website of the Information Commissioner's Office states regarding Subject Access Requests (SARs): "''You have the right to find out if an organisation is using or storing your personal data. This is called the right of access. You exercise this right by asking for a copy of the data, which is commonly known as making a ‘subject access request''".

Data Protection Act 1998

Data Protection Actdata protectionData Protection Act 1984
Before the General Data Protection Regulation (GDPR) came into force on 25 May 2018 organisations could charge a specified fee for responding to a SAR, of up to £10 for most requests.

Children's Online Privacy Protection Act

COPPAChildren's Online Privacy Protection Act (COPPA)Children's Online Privacy Protection Act of 1998

Health Insurance Portability and Accountability Act

HIPAAHealth Insurance Portability and Accountability Act of 1996Health Insurance Portability and Accountability Act (HIPAA)

EU–US Privacy Shield

EU-US Privacy ShieldEU-U.S. Privacy ShieldPrivacy Shield
Transatlantic data flows (or at least those going West, towards the US) are governed by the EU–US Privacy Shield.

Microsoft Corp. v. United States

Microsoft Corporation v. United States of AmericaIn re Warrant to Search a Certain E-Mail Account Controlled & Maintained by Microsoft CorpMicrosoft email case
This Privacy Shield practice also shows that the case of civilian data protection (as under GDPR) is quite different from the case of criminal investigation, where a right of access is exercised as a "data request" by a government, not an individual, as in the US Supreme Court case Microsoft Corp. v. United States.

Cifas

Under the Data Protection Act, an individual has the right to make a Subject Access Request to Cifas, who will, in accordance with the Act, disclose data held on the individual for a statutory fee.

Data portability

portable
The data portability right is slightly different from the Right of access to personal data; see GDPR and the seventh item in the list cited immediately above.

Office of the Independent Adjudicator

Office of the Independent Adjudicator for Higher EducationIndependent Adjudicator for Higher EducationOffice of the Independent Adjudicator for Higher Education (OIA)
but is covered by a subject access request.