Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

GDPR's "Right of access by the data subject" (Article 15) is here: https://gdpr-info.eu/art-15-gdpr/

The right can only be enforced against a "controller," which is the entity that "determines the purposes and means of the processing of personal data."

It's worth noting that GDPR does not give the data subject the right to request everything in the letter. Only a more limited set of things.

The practical effect for SaaS companies is that they should keep track of data and the systems and services where data is processed. With good preparation and a system of record for security/privacy management data, you can prepare for this kind of request very well. My company does just that - helps others prepare.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: