Implementation of the Right of Access by Controllers (the CEF 2024 Report and its National Annex)
The right of access is, in the EDPB’s own words, one of the most frequently exercised data subject rights — and it is also a task that is rarely benchmarked: everyone runs a process, few ever see anyone else’s. In 2024 the EDPB’s Coordinated Enforcement Framework pointed 30 supervisory authorities across the EEA at the same question — how are controllers actually implementing the right of access? — and 1,185 controllers, from SMEs to large companies and public bodies, answered. This report aggregates what they found: seven named challenges, each paired with non-binding recommendations, with every authority’s national findings annexed.
- Published by
- The European Data Protection Board (EDPB), under its Coordinated Enforcement Framework (CEF); the European Data Protection Supervisor took part for the EU institutions under Regulation (EU) 2018/1725. We have no relationship with the EDPB and inclusion here is not an endorsement in either direction.
- Type
- Report (PDF) plus an Appendix of national reports (PDF) — adopted 16 January 2025, published 20 January 2025. Seven challenge sections (§§4.2.1–4.2.7), each with recommendations.
- Versions & language
- Single version, English. No revision since adoption; the 2025 CEF action moved on to the right to erasure.
- Jurisdiction
- EU / EEA. The recommendations are expressly non-binding and without prejudice to the GDPR. The ICO was not part of the action; the UK GDPR carries the right of access in substantially the same form (Article 15), and the ICO’s right of access guidance remains the UK reference.
- Primary audience
- DPOs, privacy operations teams, and anyone who owns the access-request process end to end.
- Topic tags
- right of access · access requests / DSARs · data subject rights · accountability · enforcement
- Availability
- Free, direct download from the EDPB. No registration.
The part to read first
Section 4.2 — the seven challenges, each with its recommendations: (1) lack of awareness about the scope of access to be provided; (2) indefinite, excessive or inconsistent retention periods for access-request communication; (3) lack of documented internal procedures; (4) barriers to facilitating requests — channels and excessive identity checks; (5) inconsistent or excessive interpretation of the limits; (6) excessive use of requests for specification under recital 63; (7) insufficiently detailed or tailored information in the response. Then the Appendix, for what your own supervisory authority — or the one nearest your estate — reported.
Why it matters
Most guidance on the right of access tells you what the law requires. This report shows where implementation actually breaks, at scale, in the regulators’ own words. The seven challenges will be recognisable to anyone who has run the process: requests arriving through channels nobody monitors for them, and staff who do not recognise an access request unless it says “Article 15”; identity checks demanding more documents than the situation justifies; limits and exemptions applied by reflex rather than case by case; requests for “specification” used beyond what recital 63 contemplates; responses that list categories where the data subject is owed their data.
Two of the findings deserve particular attention because they are easy to get wrong in a well-run function. First, retention of the access-request correspondence itself: the report finds indefinite, excessive or inconsistent periods to be common, and says plainly that statutory retention periods for other records should not be applied to it by default — fix a period on objective criteria and document the reasoning under Article 5(2). Second, the record of processing activities: the EDPB points to the Article 30 record as the map for locating personal data when a request lands, and for naming actual recipients under Article 15(1)(c) — a record that is current turns out to be the difference between a search and a guess.
Throughout, the report keeps returning to Guidelines 01/2022 on the right of access (now at version 2.1): the participating authorities judged awareness of them mixed at best, and most of the recommendations amount to reading the relevant section. The encouraging finding is real too: around two thirds of participating authorities rated the controllers they looked at from average to high — and compliance ran higher where request volumes and organisations were larger, which suggests the process improves with practice. Used honestly, the report is a benchmarking instrument: read the seven challenges against your own process and see which ones you could evidence your way out of.
What’s coming
The CEF is a rolling programme. The 2025 action moved to the right to erasure, and the first sanction we have seen connected to it has already been published: on 11 September 2026 the EDPB published the CNIL’s €300,000 fine against EXTIA, an IT and engineering consultancy, for erasure requests that were not processed, or where the individual was never told the outcome or was told months late (decision of 21 July 2026) — following an April 2025 audit carried out both to investigate complaints and in the context of the 2025 coordinated action. When the erasure report itself is published, this access report is the template for reading it. Read alongside NIST SP 800-88 Rev. 2 from issue #9 — what “erased” means in practice — and the CMS GDPR Enforcement Tracker from issue #2, where right-of-access outcomes surface case by case.
