Copy of the Employee File: Trade Secrets Do Not Justify a Blanket Refusal
8 min read
A dismissed employee writes to HR and asks, under Article 15 GDPR, for a full copy of their personal file. There is no button in the company that exports the file: there is the HR system, the badge access logs, the mailbox assigned to the person, the performance reviews written by the line manager, the productivity tools used every day, and the systems run by one or more external vendors that process data on the company’s behalf. None of them holds the file whole. And for each one, within a deadline the Regulation sets precisely, someone has to decide what is the requester’s personal data, what concerns other employees, and what — if anything — is a trade secret.
Article 15, read in full
The right of access is not exhausted by confirming that processing is taking place. Article 15(3) is blunt: “The controller shall provide a copy of the personal data undergoing processing.” By electronic means, “and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form” — a file, not a summary drafted by whoever answers. Paragraph 4 is not a footnote: “The right to obtain a copy referred to in paragraph 3 shall not adversely affect the rights and freedoms of others.” A limit exists, but the article alone does not say how to apply it: the recital that accompanies it does.
Recital 63 explains, it does not add an exception
A recital carries no independent legal force: it creates no obligations or exceptions of its own, it guides the reading of the article it refers to. Recital 63 does this for Article 15 with a sentence that looks like an opening for refusal: that right “should not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software.” The next sentence closes it back: “However, the result of those considerations should not be a refusal to provide all information to the data subject.” Trade secrets are not, on this reading, a ground for refusing access: they are an interest to weigh item by item, never a gate closing the whole file.
The same recital hands the controller two practical, conditional levers. Where it processes “a large quantity of information”, it “should be able to request that… the data subject specify the information or processing activities to which the request relates” — narrowing the scope, not refusing it. And, “where possible”, it “should be able to provide remote access to a secure system” instead of a static export: useful with a single system, less so with a file split across systems that do not talk to each other.
What “a copy” means: the Court of Justice says so
On the practical meaning of “copy”, the Court of Justice ruled in the judgment of the First Chamber of 4 May 2023, Case C‑487/21, F.F. v Österreichische Datenschutzbehörde, intervening party CRIF GmbH — a reference for a preliminary ruling from the Austrian Bundesverwaltungsgericht, language of the case German. The operative part:
“the right to obtain from the controller a copy of the personal data undergoing processing means that the data subject must be given a faithful and intelligible reproduction of all those data. That right entails the right to obtain copies of extracts from documents or even entire documents or extracts from databases which contain, inter alia, those data, if the provision of such a copy is essential in order to enable the data subject to exercise effectively the rights conferred on him or her by that regulation, bearing in mind that account must be taken, in that regard, of the rights and freedoms of others.”
Two thresholds, not one. The copy must be “faithful and intelligible” — a summary list drafted by whoever answers does not suffice, as the case below shows. And the extract or the whole document is owed only where “essential” to exercise the rights effectively: neither an automatic right to every file bearing one’s name, nor one exhausted by the bare data field.
The file lives in several systems, never in one
For each place, the question comes up three times: is it the requester’s personal data? does it touch third-party data to be redacted, not withheld wholesale? does it hold a method that deserves the label of trade secret — and if so, does that label hold on its own, or does it need to be shown?
- The HR system: personal record, contract, payslips, disciplinary measures.
- Access logs and badges: hours, movements between sites, sometimes the location of a company device.
- Email: the person’s own communications, but also exchanges involving colleagues or clients — third-party data, not only the requester’s.
- Performance reviews: the requester’s own evaluative data, often drafted with reference to internal processes.
- Productivity tools: document history, internal messaging, usage logs.
- Vendor systems, acting as processors: outsourced payroll, recruitment platforms, monitoring tools.
Two decisions that answer the same question
The Garante has already had to untangle this knot, with consistent outcomes. In decision no. 137 of 7 March 2024 (doc-web 10007853) it fined a bank €20,000 for responding to a former employee’s request for her disciplinary file with only communication and a list, moreover incomplete, of the correspondence alone, and for withholding further documentation by citing the protection of a third party — reasons never communicated to the requester, as Article 12(4) requires. The Garante invoked Recital 63 to restate that access serves “to be aware of, and verify, the lawfulness of the processing”, unchanged where the purpose is, as there, defending oneself in a disciplinary proceeding: reading Articles 12 and 15 of the Regulation together shows no requirement for data subjects to state a reason… to justify their requests.
In decision no. 165 of 12 March 2026 (doc-web 10233328) — a complaint against ITAS Mutua, the order issued against LT S.p.A., based in Trento — the Garante fined a company €50,000 for denying a former employee part of their company mailbox by invoking trade secrets contained in the emails. The decision cites Recital 63 and the EDPB Guidelines 01/2022, point 172, on the burden of proof: “The general concern that rights and freedoms of others might be affected by complying with the request for access, is not enough to rely on Art. 15 (4) GDPR. The controller must be able to demonstrate that in the concrete situation, rights or freedoms of others would, in fact, be impacted.” The company had produced no factual element to demonstrate that harm: the label alone does not hold.
The deadline, and when it genuinely stretches
Article 12(3) sets the time to respond: “without undue delay and in any event within one month of receipt of the request.” It can be extended, not at will: “by two further months where necessary, taking into account the complexity and number of the requests” — unpacking a file across several systems is, in practice, the condition that most often justifies it. It must be communicated within the first month, reasons included: “The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.” Never a month of silence: it is exactly the combination that got the bank in decision 137/2024 fined.
See the service · Talk to an engineer
What we could not verify
We do not offer legal advice. We have not checked other Garante decisions on the topic, nor Case C-307/22 (not retrieved), cited in decision 137/2024. We verified point 172 of the EDPB Guidelines 01/2022 both in decision 165/2026 and, independently, in the official English EDPB text — we found no downloadable official Italian version. Of the sanctioned company we know only the operative part: LT S.p.A., based in Trento; we did not reconstruct its corporate relationship with ITAS Mutua, named in the complaint.
The two axes, applied to the file
Compliance. The Article 15 request becomes, in our system, a check across the client’s systems: for each place listed above, which data belongs to the requester, which touches third parties to redact, which carries a trade secret that can be demonstrated rather than merely claimed. Ready within one month, extendable by two if the complexity is real and put in writing, not discovered on day thirty.
Decision-making. The same system holds the HR platform, mail, logs and vendor systems together in a single operating model, on which AI agents execute decisions with a human operator in command. Always on-premises, on autonomous machines without deep integration into the client’s network, or on our dedicated cloud, with a dedicated VPN and a data centre in Italy. It is the method behind how we build the platform.
Could you say today, for one worker’s access request, how many systems you would need to open before answering within a month? Half an hour with one of our experts is enough for the first map.
Sources
- Regulation (EU) 2016/679 (GDPR) — official text, Articles 12 and 15 and Recital 63 (EUR-Lex)
- Court of Justice of the European Union, judgment of 4 May 2023, Case C-487/21, F.F. v Österreichische Datenschutzbehörde (EUR-Lex)
- Garante per la protezione dei dati personali, decision no. 137 of 7 March 2024 (doc-web 10007853, in Italian)
- Garante per la protezione dei dati personali, decision no. 165 of 12 March 2026 (doc-web 10233328, in Italian)
- EDPB, Guidelines 01/2022 on data subject rights — Right of access, adopted version (edpb.europa.eu)