GDPR Requests: A Practical Guide for Companies
This page supports the GDPR request feature of Outlook: Search to Export. It explains what a GDPR data subject access request is, what your response must contain, what you may leave out, who may make a request and how often — and how the export created by the add-in fits into the process.
Disclaimer: This page is general information, not legal advice. GDPR enforcement details vary between EU/EEA member states and situations. When in doubt, consult your data protection officer or legal counsel.
What is a GDPR access request?
Under Article 15 of the EU General Data Protection Regulation (GDPR, Regulation 2016/679), any person (the data subject) has the right to ask an organisation:
- whether the organisation processes personal data about them, and if so,
- to receive a copy of that personal data, together with
- supplementary information about the processing.
This is commonly called a DSAR (data subject access request). E-mail is one of the most common places where personal data about a person accumulates: messages they sent to you, messages you sent to them, and messages that mention them.
A request is valid in any form — e-mail, letter, phone call, even verbally. It does not need to mention the GDPR or use any particular words. The clock starts when the request reaches you.
Deadlines
- You must respond without undue delay and at the latest within one month of receiving the request (Article 12(3)).
- The deadline may be extended by two further months if requests are complex or numerous — but you must tell the requester about the extension, with reasons, within the first month.
- If you refuse to act on a request, you must tell the requester within one month, state the reasons, and inform them of their right to complain to the supervisory authority (see the country notes below for your national authority) and to seek a judicial remedy.
Who may make a request?
- The data subject themselves. You must be able to verify the requester's identity with reasonable certainty (Recital 64). Ask for additional identification only if you have reasonable doubts — do not collect more data than needed for verification.
- An authorised representative (for example a lawyer) with a mandate/power of attorney from the data subject.
- A guardian on behalf of a person they represent, and parents typically on behalf of young children.
- The right is personal: an employer, spouse or journalist cannot demand someone else's data without authorisation.
Important: the right of access covers the requester's own personal data only — never other people's (Article 15(4)).
How often, and what does it cost?
- The first copy is free of charge.
- For further copies, you may charge a reasonable fee based on administrative costs (Article 15(3)).
- If requests are manifestly unfounded or excessive, in particular because of their repetitive character, you may either charge a reasonable fee or refuse to act (Article 12(5)). The burden of demonstrating this is on you, the controller — apply it narrowly. A person asking once a year is normal; asking every week with no change in circumstances may be excessive.
What the response must contain
Your response has two parts:
1. A copy of the personal data
For e-mail this typically means the messages (or relevant extracts) where the requester appears — as sender, as recipient, or discussed in the content. In practice, supervisory authorities and the EDPB Guidelines 01/2022 on the right of access expect you to make a reasonable, documented search of the systems where personal data of the requester can be found, including mailboxes used for business processes.
An access response does not always require handing over full copies of every e-mail. What matters is that the data subject receives the personal data concerning them in an intelligible form. A structured summary — for example a table of date, time, correspondent, subject and the opening lines of each message — is often an appropriate and proportionate format, supplemented with full copies where the content itself is the personal data.
2. Supplementary information (Article 15(1)(a)–(h) and 15(2))
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipients to whom the data has been or will be disclosed (especially recipients in third countries), and the safeguards used for third-country transfers;
- the envisaged retention period, or the criteria used to determine it;
- the existence of the rights to rectification, erasure, restriction and objection;
- the right to lodge a complaint with a supervisory authority;
- where the data was not collected from the data subject: information about its source;
- the existence of automated decision-making, including profiling, and meaningful information about the logic involved.
Much of this can be a standard cover letter that accompanies the data export.
What you may (and must) leave out
The right of access is broad, but not unlimited:
- Personal data of other people. Disclosing the export must not adversely affect the rights and freedoms of others (Article 15(4)). E-mails almost always contain third-party personal data — other senders, recipients, people discussed. Redact or remove what is not the requester's own personal data, rather than refusing the whole request.
- Trade secrets and intellectual property (Recital 63) may justify redacting specific content — but not refusing to provide any information at all.
- Legally privileged material and data whose disclosure is restricted by national law may be withheld — each EU member state has its own derogations (typical examples: danger to health or safety, protection of the rights of others, legal professional secrecy; see the country notes below). Document the reasoning.
- Data that is not personal data of the requester — purely internal business content in a thread is not automatically disclosable just because the requester's name is in the header; conversely, opinions and assessments about the person generally are their personal data.
Never delete data after receiving a request to avoid disclosing it — destroying requested evidence can constitute a GDPR infringement and, in some situations, a criminal offence.
A practical workflow
- Log the request and its date. Verify the requester's identity if in doubt.
- Scope the search: which mailboxes, systems and archives can contain the person's data? Document what you searched.
- Search and export. In Outlook, the GDPR request mode of Outlook: Search to Export finds all messages in the chosen date range where the person appears as sender or recipient, in both received and sent mail, and produces a structured Excel file with date, time, direction, contact, subject and (optionally) the first lines of each message. The summary sheet records the search term, the date range, the scope of the search and the generation time — useful for documenting how you searched.
- Review before disclosure. Go through the export: redact third-party personal data, trade secrets and privileged content. Decide which full messages need to be attached.
- Add the supplementary information (purposes, recipients, retention, rights — see above) in a cover letter.
- Deliver securely — encrypted or via a secure channel, to a verified address. If the request was made electronically, provide the response in a commonly used electronic form.
- Keep a record of what was disclosed, when, and what was redacted and why.
What the add-in does — and what it does not do
The GDPR request checkbox automates step 3: it searches both received and sent mail for the named person and never skips messages (the Skip marketing email option is disabled, because an access response must not silently omit data). The export's summary sheet states the scope of the search.
The add-in searches the default Inbox and Sent Items folders of the current mailbox. If your organisation uses subfolders, archive mailboxes, shared mailboxes or other systems (CRM, ticketing, chat), search those separately. The tool does not redact third-party data and does not generate the supplementary information — those steps remain your responsibility.
All processing happens locally on your computer. The add-in sends nothing to us or anyone else.
EU country notes: authorities and national derogations
The GDPR applies directly and identically in every EU member state: the deadlines, the free first copy, and the core content of Article 15 are the same everywhere. What varies by country is which supervisory authority handles complaints, which national act implements the GDPR, and which national derogations (based on Article 23 GDPR) may allow withholding specific material. Expand your country below. The full contact list is maintained by the EDPB.
Austria
Authority: Österreichische Datenschutzbehörde (DSB). National law: Datenschutzgesetz (DSG).
Access may be refused insofar as it would endanger a business or trade secret of the controller or a third party (§ 4(6) DSG) — a broader formulation than the GDPR baseline; document any reliance on it carefully. Data protection also has constitutional status in Austria (§ 1 DSG).
Belgium
Authority: Autorité de protection des données / Gegevensbeschermingsautoriteit (APD/GBA). National law: Law of 30 July 2018.
National derogations are mainly sector-specific (police, intelligence, certain public bodies). For private employers the GDPR baseline applies unchanged.
Bulgaria
Authority: Commission for Personal Data Protection (CPDP). National law: Personal Data Protection Act (ZZLD).
Derogations exist mainly for journalistic and academic purposes. For business mailboxes the GDPR baseline applies; the CPDP publishes guidance on handling access requests.
Croatia
Authority: Agencija za zaštitu osobnih podataka (AZOP). National law: Act on the Implementation of the GDPR (2018).
No major private-sector derogations to Article 15; follow the GDPR baseline and AZOP guidance.
Cyprus
Authority: Commissioner for Personal Data Protection. National law: Law 125(I)/2018.
Derogations concern mainly public-interest areas. For business mailboxes the GDPR baseline applies.
Czechia
Authority: Office for Personal Data Protection (ÚOOÚ). National law: Act No. 110/2019 Coll. on Personal Data Processing.
The act largely mirrors the GDPR baseline for private controllers; derogations concern journalism, research and public bodies.
Denmark
Authority: Datatilsynet. National law: Data Protection Act (databeskyttelsesloven).
Section 22 allows restricting data subject rights where the data subject's interest is found to be outweighed by essential private interests (including the controller's own) or public interests — a case-by-case balancing that must be documented.
Estonia
Authority: Andmekaitse Inspektsioon (AKI). National law: Personal Data Protection Act (2019).
Derogations exist for journalism and research. For business mailboxes the GDPR baseline applies.
Finland
Authority: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto). National law: Data Protection Act (1050/2018).
Section 34 lists exceptions to the right of access — for example where disclosure could seriously endanger the data subject's health or care, or the rights of the data subject or another person. If you withhold data, you must state the reasons, and the requester can ask the Ombudsman to review the withheld material.
France
Authority: Commission Nationale de l'Informatique et des Libertés (CNIL). National law: Loi Informatique et Libertés.
CNIL has extensive guidance on workplace e-mail: messages marked or identifiable as an employee's personal/private correspondence enjoy special protection and should generally be excluded from employer searches. French law also lets heirs exercise certain post-mortem rights based on the deceased's instructions (arts. 84–86).
Germany
Authority: Federal BfDI plus 16 Länder authorities — for private companies, the authority of the Land where the company is established is competent. National law: Bundesdatenschutzgesetz (BDSG).
§ 34 BDSG excludes access where data are stored only because of statutory retention duties or purely for backup / data-protection-control purposes and access would take disproportionate effort. § 29 BDSG protects material covered by professional secrecy (including legal advice). Works-council (Betriebsrat) processing adds employer-specific nuances.
Greece
Authority: Hellenic Data Protection Authority (HDPA). National law: Law 4624/2019.
The law contains several derogations to Articles 12–22, some of which have been questioned at EU level — check current HDPA guidance before relying on a national exemption.
Hungary
Authority: National Authority for Data Protection and Freedom of Information (NAIH). National law: Act CXII of 2011 (Info Act).
NAIH maintains an active complaint practice on access requests. For business mailboxes the GDPR baseline applies.
Ireland
Authority: Data Protection Commission (DPC). National law: Data Protection Act 2018.
Notable exemptions: legal privilege, opinions given in confidence, and the Section 60 restrictions (e.g. data relating to negotiations with the requester, examination scripts). The DPC publishes detailed DSAR guidance for employers — useful reading even outside Ireland.
Italy
Authority: Garante per la protezione dei dati personali. National law: Personal Data Protection Code (D.Lgs. 196/2003, as amended by D.Lgs. 101/2018).
Special feature: the rights of deceased persons can be exercised by heirs and others with a legitimate interest (art. 2-terdecies). The Garante also has significant case law restricting employer access to and retention of former employees' mailboxes.
Latvia
Authority: Datu valsts inspekcija (DVI). National law: Personal Data Processing Law (2018).
Derogations concern journalism and official secrets; for business mailboxes the GDPR baseline applies.
Lithuania
Authority: Valstybinė duomenų apsaugos inspekcija (VDAI). National law: Law on Legal Protection of Personal Data.
The GDPR baseline applies to private controllers; VDAI publishes guidance in Lithuanian.
Luxembourg
Authority: Commission Nationale pour la Protection des Données (CNPD). National law: Law of 1 August 2018.
The GDPR baseline applies; note that financial-sector professional secrecy interacts with access requests — seek advice in banking and fund contexts.
Malta
Authority: Information and Data Protection Commissioner (IDPC). National law: Data Protection Act (Cap. 586).
Restrictions are set out in subsidiary legislation for specific sectors; the GDPR baseline applies to business mailboxes.
Netherlands
Authority: Autoriteit Persoonsgegevens (AP). National law: GDPR Implementation Act (UAVG).
Article 41 UAVG implements the Article 23 GDPR restrictions (rights and freedoms of others, enforcement interests). Dutch courts have produced significant case law on what "a copy" requires — full documents are not always owed, but work notes about a person can be in scope.
Poland
Authority: Urząd Ochrony Danych Osobowych (UODO). National law: Act of 10 May 2018 on Personal Data Protection.
The GDPR baseline applies to private controllers; sectoral acts add specific exceptions.
Portugal
Authority: Comissão Nacional de Proteção de Dados (CNPD). National law: Law 58/2019.
The CNPD has declined to apply certain provisions of the national law as conflicting with the GDPR — rely primarily on the GDPR text and CNPD guidance.
Romania
Authority: National Supervisory Authority for Personal Data Processing (ANSPDCP). National law: Law 190/2018.
Derogations concern mainly journalism and national security; the GDPR baseline applies to business mailboxes.
Slovakia
Authority: Úrad na ochranu osobných údajov. National law: Act No. 18/2018 Coll.
The act largely restates the GDPR; the baseline applies to private controllers.
Slovenia
Authority: Information Commissioner (Informacijski pooblaščenec) — also the freedom-of-information authority. National law: ZVOP-2 (in force since 2023).
ZVOP-2 adds procedural detail (for example on identity verification) rather than new private-sector exemptions.
Spain
Authority: Agencia Española de Protección de Datos (AEPD). National law: Organic Law 3/2018 (LOPDGDD).
Heirs and relatives may access a deceased person's data (art. 3 LOPDGDD). The law also codifies digital rights in employment — including rules on monitoring employee devices and e-mail — which affect how mailbox searches should be conducted.
Sweden
Authority: Integritetsskyddsmyndigheten (IMY). National law: Data Protection Act (2018:218).
Chapter 5 contains a notable exception: the right of access does not extend to personal data in running text that has not yet been given its final form (drafts) or in memory notes — unless the material has been disclosed to a third party. Confidentiality (sekretess) rules can further restrict disclosure.
The GDPR also applies in the EEA countries Norway, Iceland and Liechtenstein through their own implementing acts and authorities (Datatilsynet, Persónuvernd, Datenschutzstelle).
Sanctions for getting it wrong
Ignoring or mishandling access requests is one of the most common causes of GDPR complaints. Infringements of the data subjects' rights (Articles 12–22) fall in the higher fine bracket: up to 20 million euros or 4 % of worldwide annual turnover, whichever is higher (Article 83(5)) — in addition to reputational damage and orders from the supervisory authority.
Sources and further reading
- Regulation (EU) 2016/679 (GDPR), Articles 12 and 15
- EDPB Guidelines 01/2022 on data subject rights – Right of access
- EDPB – National supervisory authorities (contact list for all member states)
- Your national implementing act and supervisory authority guidance (see the country notes above)