A subject access request under GDPR Art. 15 must be answered without undue delay and within one month at the latest. The deadline can be extended by two months for complex requests. The requester need not give reasons, and the request cannot be refused because it is used in an employment dispute or litigation. Only exceptionally can a request be refused as manifestly unfounded or excessive.
A subject access request often arrives at the worst possible moment. An employee is facing dismissal, a customer has threatened legal action, or a former supplier is looking for evidence. The request looks like a data protection matter, but is being used as a tool in the dispute. The business must nonetheless respond correctly and on time, and there is little scope for refusing the request.
What is a subject access request under the GDPR?
A subject access request is a request from an individual to find out what personal data the business processes about them. The right follows from GDPR Art. 15 of the General Data Protection Regulation, which applies in Norway through the Personal Data Act (personopplysningsloven).
The data subject is entitled to confirmation of whether data is being processed and, if so, a copy of the data. The business must also provide information on the purposes, the categories of data, the recipients, the retention period, where the data came from, the right to lodge a complaint and any automated decision-making.
There are no formal requirements. A subject access request may be made orally, in an email to any employee or in a letter from a lawyer. The deadline runs from when the request is received by the business, not from when it reaches the data protection officer.
What is the deadline for responding to a subject access request?
The deadline is one month from receipt, and the response must be given without undue delay, see GDPR Art. 12(3). If the request is complex, or the business has received a large number of requests, the deadline may be extended by a further two months. The data subject must then be informed of the extension and the reasons for it within the first month.
| Point | Rule |
|---|---|
| Main deadline | One month from receipt, GDPR Art. 12(3) |
| Extension | Up to two further months for complex or numerous requests, with notice and reasons within one month |
| Cost | The first copy is free. A reasonable fee may be charged for further copies, GDPR Art. 15(3) |
| Identity | Where there are reasonable doubts, the business may ask for information confirming identity, GDPR Art. 12(6) |
| Refusal | In writing, with reasons and information on the right to complain |
Where the business processes a large quantity of data about the individual, it may ask for the request to be specified, see Recital 63. In the EDPB’s view such a request does not stop the clock, and the business cannot refuse the request because the data subject does not wish to narrow it.
What exemptions are there from the right of access?
The exemptions are few and are interpreted strictly. The most important in practice are these.
The rights of others. The right to a copy must not adversely affect the rights and freedoms of others, see GDPR Art. 15(4). Recital 63 mentions trade secrets and intellectual property rights. Information about colleagues, customers or other third parties must be assessed case by case and redacted where appropriate. The exemption allows individual items of data to be withheld, not access to be refused altogether.
National exemptions. Personal Data Act § 16 exempts, among other things, information that must be kept secret in the interests of a criminal investigation, information subject to a statutory duty of confidentiality, and text prepared for internal case preparation that has not been shared with others, to the extent necessary to ensure sound internal decision-making. A business that refuses access under § 16 must give written reasons with a precise reference to the exemption.
Manifestly unfounded or excessive requests. Under GDPR Art. 12(5) the business may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive, in particular because of their repetitive character. The burden of proving that the condition is met lies with the business.
The exemption for internal case preparation is particularly relevant in HR matters. Working notes from an ongoing internal investigation may, depending on the circumstances, be withheld as long as they have not been shared outside the business. The exemption does not cover the factual information about the employee held in other systems, and it falls away when the text is shared with, for example, the opposing party or an external adviser who is not the business’s own. The assessment is case-specific, and the boundary has not been drawn in Norwegian practice.
Can a subject access request be refused because it is used in a dispute?
As a rule, no. This is the most important point for employers and businesses in litigation.
In C-307/22 of 26 October 2023, a patient had asked for a copy of their medical records in order to assess a damages claim against their dentist. The Court of Justice of the EU held that the first copy must be free of charge and that the data subject does not need to give reasons for the request. The fact that the request has a purpose other than verifying the lawfulness of the processing is no ground for refusing it. The EDPB has taken the position in its guidelines that the business should not assess why the request is being made, and that access cannot be refused because the data might be used in a dismissal case or a commercial dispute.
A subject access request needs no reasons, and the fact that it is used in a dispute with you is no ground for refusing it.
The line is drawn at abuse. In C-526/24 Brillen Rottler of 19 March 2026, the Court of Justice held that even a first request can be excessive under GDPR Art. 12(5). That requires the business to be able to document that the request was made with abusive intent, for example to create a basis for a damages claim, and not to verify the processing. Publicly available information showing that the individual has made a series of similar requests against other businesses may serve as evidence. The threshold is high, and an ordinary employment dispute is not abuse.
In practice, the subject access request therefore provides a form of access to evidence alongside the rules in the Norwegian Dispute Act (tvisteloven), and without proceedings having to be brought. How the Norwegian courts will view the relationship between the two sets of rules has not, as far as we are aware, been settled by the Supreme Court.
What must the copy contain?
The copy must be a faithful and intelligible reproduction of all the personal data. In C-487/21 of 4 May 2023, the Court of Justice held that this may include extracts from documents, entire documents or extracts from databases, where necessary for the data to be intelligible. An employer therefore cannot make do with a list of categories when the employee asks for emails and notes that refer to them.
Logs of who has viewed the data are also covered. In C-579/21 Pankki S of 22 June 2023, the Court of Justice held that the data subject is entitled to know when and why their data was consulted. The names of the employees who carried out the look-ups need not, as a rule, be disclosed, unless this is necessary for the data subject to exercise their rights.
A subject access request often follows after the employer has accessed the employee’s email. If the business has followed the rules described in the article on employer access to employee email, the documentation is already in place and the request is easier to answer.
What is the risk of responding incorrectly or too late?
Breaches of the right of access may lead to an administrative fine under GDPR Art. 83(5), with an upper limit of EUR 20 million or 4 per cent of global annual turnover. In practice the greatest risk often lies elsewhere. A late or incomplete response gives the other side an additional line of attack, undermines the business’s credibility and may give grounds for compensation.
In C-526/24 the Court of Justice also held that a breach of the right of access may in itself give rise to compensation under GDPR Art. 82, and that loss of control over one’s own data may constitute non-material damage. In Norway, compensation for non-pecuniary loss may also be claimed under Personal Data Act § 30.
Subject access requests also uncover other failings. A response may reveal that data has been kept too long, shared without a legal basis or that a personal data breach has occurred. Separate rules then apply, see the article on personal data breaches.
What should the business do?
- Train employees to recognise a subject access request and pass it on the same day, however it is worded.
- Log the date of receipt and calculate the deadline immediately. Consider an extension early, and give notice within one month.
- Map all sources, such as email, case management systems, the HR system, chat, logs and backups.
- Assess the exemptions case by case, redact information about others, and give written reasons with a legal basis for each exemption.
- Do not refuse because the request is being used in a dispute. Only documented abuse justifies refusal under Art. 12(5).
- Coordinate with the lawyer handling the dispute, so that the response to the subject access request and the litigation strategy are aligned.
- Document the entire process, so that the business can show Datatilsynet and the court what was done, and why.
More articles on the subject are available on the topic page on data protection.
Questions and answers
Can we ask for proof of identity before answering a subject access request?
Yes, if you have reasonable doubts about who is behind the request. You may then ask for the information necessary to confirm their identity, but no more. If the request comes from a known employee via their work address, there is rarely any basis for requiring identification.
Do we have to hand over entire emails and documents?
Not as a starting point. The right concerns personal data, not documents. The Court of Justice of the EU has nevertheless held that the copy may have to include extracts or entire documents where this is necessary for the data to be intelligible. Information about other people must be assessed and redacted where appropriate.
What happens if we do not respond within the deadline?
The data subject may complain to Datatilsynet, which can issue orders and administrative fines. Breaches of the right of access may also give rise to compensation, including for non-material damage, under GDPR Art. 82 and the Norwegian Personal Data Act § 30.
- General Data Protection Regulation (EU) 2016/679 Arts. 12, 15, 82 and 83, Recital 63
- Norwegian Personal Data Act (personopplysningsloven) §§ 16 and 30
- Norwegian Dispute Act (tvisteloven)
- Court of Justice of the EU, C-307/22 FT v DW (26 October 2023)
- Court of Justice of the EU, C-487/21 Österreichische Datenschutzbehörde and CRIF (4 May 2023)
- Court of Justice of the EU, C-579/21 Pankki S (22 June 2023)
- Court of Justice of the EU, C-526/24 Brillen Rottler (19 March 2026)
- EDPB, Guidelines 01/2022 on data subject rights, Right of access (version 2.1)
- Norwegian Data Protection Authority (Datatilsynet), Right of access
Next legal review: 1 April 2027