Privacy Rights & Requests
What is Right to Access (Right to Know)?
The right to access — GDPR Article 15's access right and the CCPA's 'right to know' — entitles an individual to obtain confirmation that an organization processes their personal data, a copy of that data, and information about how and why it is used.
Access is the gateway right: without seeing what an organization holds, an individual cannot meaningfully correct, delete, or object. Under GDPR Article 15, the response must include not just a copy of the personal data but its context — purposes of processing, categories of data, recipients or categories of recipients (including third countries), retention periods or criteria, the existence of other rights, the data's source if not collected directly, and the existence and logic of any automated decision-making.
The CCPA's right to know parallels this: consumers may request the categories of personal information collected, the sources, the business or commercial purposes, the categories of third parties it is disclosed to, and the specific pieces of personal information — generally covering the preceding 12 months, delivered within 45 days. The CCPA also grants portability by requiring the data in a usable, transferable format; GDPR splits portability into its own right (Article 20) covering machine-readable transfer of data the individual provided.
Two operational tensions define access handling. Verification versus friction: releasing a person's full profile to an impostor is itself a breach, so identity must be confirmed proportionately to sensitivity — but demanding excessive proof unlawfully obstructs the right. Completeness versus third parties: the response must cover data across all systems, yet redact other individuals' personal data and protect trade secrets, without using those carve-outs to withhold the requester's own information.
Access responses are also discovery: plaintiffs' counsel and regulators use them to map an organization's data practices, so inconsistencies between the access response, the privacy policy, and reality are themselves evidence.
Why it matters for eCommerce
An access response for one shopper means assembling their profile from your commerce platform, email tool, analytics, support desk, and ad audiences — accurately and within the deadline. Brands discover during their first real access request that no one can actually enumerate where customer data lives; a maintained data map turns a two-week scramble into a queryable answer.
Frequently asked questions
- What must be included in an access response?
- Under GDPR: a copy of the personal data plus processing purposes, data categories, recipients, retention, source, other rights, and any automated decision-making logic. Under CCPA: categories collected, sources, purposes, third-party disclosures, and the specific pieces of personal information, generally for the prior 12 months.
- How is the right to access different from data portability?
- Access is about transparency — seeing the data and how it is used. Portability is about transfer — receiving data you provided in a structured, machine-readable format to move it elsewhere. GDPR treats them as separate rights (Articles 15 and 20); the CCPA folds a portability requirement into the right to know.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Handle access requests with PieEye