DPA Subject Access Request Template for Germany

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a DPA Subject Access Request?

The DPA Subject Access Request response document is a mandatory compliance requirement under both the GDPR and German Federal Data Protection Act (BDSG). It must be provided when an individual (data subject) exercises their right to access their personal data under Article 15 GDPR. The document must be provided within one month of receipt of the request (with possible extension under specific circumstances) and should contain comprehensive information about all personal data processing activities, including the purposes of processing, categories of data, recipients, retention periods, and data subject rights. This response template is specifically designed to meet German legal requirements while ensuring full GDPR compliance, incorporating necessary elements to address both EU-wide and German-specific data protection obligations.

Frequently Asked Questions

Is a DPA Subject Access Request response legally binding under German law?

Yes, DPA Subject Access Request responses are legally binding in Germany under Article 15 of the GDPR and the German Federal Data Protection Act (BDSG). Data controllers must provide complete and accurate information within one month of receiving the request. Failure to comply can result in administrative fines up to €20 million or 4% of annual global turnover under GDPR Article 83.

What happens if my DPA Subject Access Request response is incomplete or missing information?

Incomplete responses violate GDPR Article 15 and can trigger enforcement action by German data protection authorities. The data subject can file a complaint with their state data protection authority (Landesdatenschutzbehörde), potentially leading to investigation and fines. You may also face civil claims for damages under GDPR Article 82.

How long do I have to respond to a Subject Access Request under German data protection law?

Under GDPR Article 12 and German BDSG implementation, you must respond within one month of receiving a valid Subject Access Request. This period can be extended by two additional months for complex requests, but you must inform the data subject within the first month and explain the reasons for the delay.

How is a DPA Subject Access Request response different from a data breach notification in Germany?

A Subject Access Request response under Article 15 provides an individual with information about their personal data processing upon request. A data breach notification under Articles 33-34 is mandatory reporting to authorities and affected individuals when a security incident occurs. They serve different purposes and have different triggers, timelines, and legal requirements.

How long does it typically take to prepare a comprehensive GDPR Subject Access Request response?

Preparation time varies significantly based on data complexity and organizational size. Simple cases may take 2-5 business days, while complex requests involving multiple systems and data categories can require 2-3 weeks. Large organizations often need additional time to gather information from various departments and ensure completeness.

Can I charge fees for providing a Subject Access Request response in Germany?

Under GDPR Article 12, Subject Access Request responses must generally be provided free of charge. You can only charge a reasonable fee based on administrative costs if the request is manifestly unfounded, excessive, or repetitive. Any fee must be justified and communicated to the data subject before processing the request.

What are the most common mistakes companies make when responding to Subject Access Requests in Germany?

Common mistakes include missing the one-month deadline, providing incomplete information about data sources or recipients, failing to verify the requestor's identity properly, and not explaining data processing purposes clearly. Many companies also forget to include information about automated decision-making or profiling activities as required by GDPR Article 15.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Germany

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the DPA Subject Access Request

When you receive a subject access request from an individual in Germany, you must respond with comprehensive information about how you process their personal data. This response is not optional—it's a fundamental right under Article 15 of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz or BDSG). Your response must be clear, complete, and provided free of charge within one month of receiving the request.

When do you need this document?

You need a DPA Subject Access Request response whenever an individual formally requests information about their personal data that your organization processes. This includes employees asking about their HR records, customers inquiring about their purchase history and account data, website users requesting details about cookies and tracking, or anyone whose personal information you collect, store, or process. The request can come via email, letter, phone call, or through your website, and you must respond regardless of the communication method used. Even if you believe you don't hold any data about the person, you must still provide a formal response confirming this.

Key legal considerations

Your response must include specific information mandated by Article 15 GDPR: confirmation of whether you process their data, the categories of personal data involved, the purposes of processing, recipients or categories of recipients, retention periods, and information about their rights to rectification, erasure, or restriction of processing. You must also disclose the source of the data if not collected directly from the individual, details about any automated decision-making including profiling, and information about international transfers including appropriate safeguards. If you cannot fulfill the request, you must explain why and inform the individual of their right to complain to a supervisory authority. Failure to respond adequately can result in fines up to 4% of annual global turnover or €20 million under GDPR Article 83.

Legal requirements in Germany

Under German law, the BDSG supplements GDPR requirements with additional national provisions. You must verify the requester's identity before disclosing personal data, particularly when the request involves sensitive information or could affect third parties. The German Data Protection Authority (Bundesbeauftragte für den Datenschutz und die Informationsfreiheit) expects responses to be provided in German unless the individual specifically requests another language. If your organization employs a Data Protection Officer (DPO), their contact details must be included in your response. For complex requests involving large amounts of data, German courts have accepted that providing summaries or allowing inspection of records may be sufficient, but this must be justified and the individual must be informed of alternative access methods. You must also consider German civil law principles when handling requests that could reveal information about third parties, balancing transparency rights with privacy protection.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it