A retailer in Fuerstenfeldbruck, one of our clients, got an email one Friday afternoon. Subject line: "Request for access under Art. 15 GDPR". He read the first two lines, thought "another one of those legal-threat spam mails", and dragged it into the trash. Three weeks later it came back to him, because the sender followed up. By then the one-month deadline was almost gone. Panic. A call to us, Saturday morning. And yet the actual reply took maybe 20 minutes, using a template he still uses today.
That is exactly what this is about. A GDPR data request sounds like lawyers and ring binders. In the vast majority of cases, it is neither. You just need to know what to do before the clock runs out.
What is a request for access under Article 15, really?
Article 15 of the GDPR gives every person the right to find out from you whether, and which, personal data you hold about them. A customer, a newsletter subscriber, a former job applicant, an annoyed ex-employee, anyone can ask. And you have to answer.
The whole thing is informal. There is no mandatory form, no prescribed subject line. A short email is enough, a phone call works in theory, even a single sentence sent over Instagram might count. That is why these requests slip through so easily. They do not look official. They look like an ordinary customer message.
Important: the person does not have to give a reason. They can simply ask. And the first time round, providing the information is free.
Why small businesses often get caught off guard
In larger companies, someone has "data protection" printed on their business card. At the cafe in Olching, the trades business in Maisach, or the two-person online shop in Germering, the owner handles it on the side, somewhere between taking orders and doing the books.
Three things regularly go wrong here. First, people mistake the request for spam, see above. Second, nobody knows where all the customer data actually lives: in the inbox, in the shop system, in the newsletter tool, in the WhatsApp history, in an old Excel sheet on the desktop. And third, people misjudge the deadline, because they assume an informal email like that has no real due date. It does.
In my experience from client projects across the west of Munich, the biggest problem is not the reply itself. It is not realising that the clock is already ticking.
How long do I have? The one-month deadline
You have one month, counted from the day the request arrives. If the email comes in on 4 July, the deadline falls on 4 August. Not "four weeks", not "about 30 days", but the same date in the following month.
This deadline can be extended by another two months if the request is genuinely complex, for example when there is a very large volume of records. But, and this is the catch, you have to inform the person within the first month about the extension and the reason for it. Simply letting the deadline pass in silence and delivering later is not an option.
For most small businesses the extension is unnecessary anyway. A normal customer record is not a complex matter. One month is plenty, with room to spare, as long as you don't sleep through three weeks of it.
Which data do I actually have to hand over?
This is where it gets practical. When someone requests access, you owe them a copy of their data plus some additional information. That typically covers:
- The stored data itself: name, address, email, phone number, order history, and any notes you have made about the person.
- The purpose of processing: why do you have the data? For example, to fulfil orders or to send the newsletter.
- The recipients: who do you pass the data on to? Payment providers, your shipping service, your tax advisor.
- The storage period, or the criteria you use to decide how long you keep it.
- A note about their further rights: rectification, erasure, and the right to complain to a supervisory authority.
What you do not have to hand over: other people's data. If an email exchange also mentions colleagues or third-party customers, redact their details. One person's right to access ends where another person's right to privacy begins.
And here is something that surprises a lot of people. Internal notes, honest little remarks like "customer always pays late", can fall under the scope of the request. That does not mean you are not allowed to make notes. It just means: don't write anything you wouldn't also say to the person's face.
Do I have to check that the person is who they say they are?
Yes, within reason. Where there is genuine doubt about someone's identity, you may and should ask. If someone writes from a completely unknown address and wants the data of one of your customers, caution is warranted. Otherwise you end up handing data to the wrong person, and that is itself a data protection breach.
But don't overdo it. If the email comes from exactly the address stored on the customer account, you don't need an ID in triplicate. A simple confirmation reply is usually enough.
The response plan in five steps
This is how we walk our clients through it when a request comes in:
- Note the date. Record the day it arrived, put the deadline in the calendar. Utterly mundane, but the most important step.
- Check identity briefly. Is the request coming from the known address? If yes, carry on. If not, politely ask for confirmation.
- Gather the data. Go through every location: shop system, inbox, newsletter tool, accounting, notes. Ideally you have drawn up this list once, in advance.
- Write the reply. Using the template below. Attach the copy of the data, redact third parties.
- Document it. Make a short note of when you answered and what you sent. If someone asks later, you have proof.
The copy-and-paste response template
This template covers the standard case. Adapt it to your own business:
Dear [Name],
Thank you for your request of [date]. We are happy to provide you with the information under Article 15 GDPR regarding the data we hold about you.
We process the following data about you: [name, address, email, phone number, order history, etc.]. The purpose of processing is [e.g. fulfilling your orders and meeting statutory record-keeping obligations]. We pass your data on to the following recipients: [e.g. shipping provider, payment provider, tax advisor]. The data is stored for [e.g. the duration of the business relationship and the applicable statutory retention periods].
You have the right to have your data corrected or erased, as well as the right to lodge a complaint with the competent supervisory authority. A copy of your data is attached.
If you have any questions, you can reach us at [contact].
Kind regards
In a normal case, that is all it takes. No lawyer, no ring binder, no sleepless night.
Where your website comes into play
Part of the preparation happens long before the first request ever lands. If you collect customer data online, via a contact form, newsletter, or shop, you need a clean privacy policy anyway. If that policy already states which data you collect, for which purpose, and how long you keep it, you have essentially pre-written half of your response.
On our web design projects this is part of the deal: forms that only collect what is needed, and a privacy page that matches reality instead of coming out of a generator. That makes the request easy later, because you know exactly where everything sits.
If you are unsure whether your website is on solid ground when it comes to data protection, we will take a free look. In our 30-minute audit we check your forms, your privacy policy, and everywhere customer data accumulates. Honest, no sales pressure. Just get in touch through our contact form and we will find a time, gladly in person in Bruck, Puchheim, or Groebenzell.