Access requests are normally free under GDPR. An organisation can charge a reasonable fee based on administrative costs only for further copies of the same information, or for manifestly unfounded or excessive requests. The practical rule is to avoid using fees as a barrier to access, while still allowing recovery of limited administrative costs in exceptional cases.
When fees are allowed, and why free access is still the default
Under GDPR, the default position is free access. That reflects the purpose of access rights: people should be able to understand and verify how their data is used without a price barrier. The exception is narrow, so organisations should treat charging as an administrative control for unusual cases, not as a routine monetisation or deterrence measure.
For the broader governance context around access rights, IAM and IGA Basics is useful because it connects request handling to entitlement oversight, access review, and the practical difference between granting access and managing the right to information.
When a reasonable fee can be charged
A fee is generally only defensible for further copies of the same information, or where a request is manifestly unfounded or excessive. The fee should be limited to reasonable administrative cost recovery, not a punitive amount. In practice, that means the organisation needs a clear internal basis for calculating the cost and for showing why the request falls within an exception.
For request handling that involves data subject rights and consent-related data, Identity Data Privacy and Consent Guide helps frame the privacy obligations that sit behind access-request handling, especially where identity data, retention, and lawful handling of personal data are in scope.
When information must be provided for free
If the request is the first copy or a standard access request, the organisation should provide the information without charge. The same applies where the request is routine, proportionate, and made in good faith. A charge should not be used simply because the request is inconvenient, time-consuming, or likely to disclose sensitive internal process detail.
For the legal baseline, the GDPR framework is the clearest external reference point, and the relevant privacy controls are also reflected in ISO/IEC 27001:2022 Information Security Management, which reinforces controlled handling of personal data, access governance, and documented operational discipline.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Article 12(5) — Manifestly unfounded or excessive requests; administrative fee for further copies | Directly governs when a fee may be charged for access requests. |
| Recommendation — Apply Article 12(5) to charge only for further copies or manifestly unfounded or excessive requests. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | Supports disciplined handling of personal data requests and privacy obligations. |
| A.5.15 — Access control | Relates to governing authorised access to information and request handling boundaries. | |
| Recommendation — Document access-request handling so fees and disclosures follow defined privacy procedures. Set clear rules for who may approve responses and exceptions to access-request charges. | ||
Practitioner Guidance
What to verify: Confirm whether the request is a first copy, a repeat copy, or one that can be evidenced as manifestly unfounded or excessive. If you cannot explain the basis for charging in plain operational terms, treat the request as free.
Decision rule: Use charges only as a narrow exception tied to administrative cost recovery, and keep the amount proportionate to the actual work involved. If the request is borderline, default to free provision and resolve ambiguity through the access-rights process, not by introducing a fee barrier.
Common mistake: Treating inconvenience, volume, or staff workload as enough to justify a fee. Under GDPR, those factors may affect process design, but they do not by themselves convert a normal access request into a chargeable one.
Practitioner takeaway: The safest operating model is to make access free by default, document the exceptional cases tightly, and ensure any fee is clearly justified by the limited administrative cost of an allowed exception.
Related resources from NHI Mgmt Group
- What do organisations get wrong when they treat access requests as a one-time approval instead of an ongoing control?
- What do organisations get wrong when they handle ad hoc access requests manually?
- How should security teams run access reviews for non-human identities?
- How should security teams govern non-human identities that have persistent access?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org