Re-requesting Personal Data Already Held by the Controller
1. GDPR Principles at Play
- Data Minimisation (Art. 5(1)(c)): Only collect what is necessary for the specified purpose.
- Accuracy (Art. 5(1)(d)): Personal data must be accurate and kept up to date.
- Storage Limitation (Art. 5(1)(e)): Data should not be kept longer than necessary for the purpose.
- Transparency (Arts. 12-14): Data subjects must be informed how their data is used.
2. Can a Controller Re-Request Data After Many Years?
Yes — but only if justified. GDPR does not prohibit asking for personal data you already hold; what it prohibits is unnecessary, duplicate, or excessive collection.
If data was collected 10-15 years ago, the controller must consider:
- Is the data still accurate? People may have changed names, addresses, contact details, employment, or even nationality.
- Was the original retention period exceeded? If the data should have been deleted under storage limitation rules, you may need to refresh it anyway.
- Is there a legal obligation to update? For example, financial institutions must update KYC/AML data periodically.
- Is there a risk to data subjects if outdated information is relied upon? (e.g., sending confidential medical records to an outdated address).
3. Practical Compliance Approach
- Justification: Document in your GDPR records why you are requesting updated data (accuracy principle, Art. 5(1)(d)).
- Transparency: In the privacy notice, explain clearly why you are asking for updated data (e.g., “We are required to ensure that your information is accurate and up to date to comply with GDPR and relevant regulations.â€).
- Minimisation: Only re-collect information that could realistically have changed, not everything.
- Alternative method: Instead of requesting full data again, controllers can ask the data subject to confirm or update existing information (“Please check that your address and contact details are still correctâ€).
4. Example
- Insurance Company: A client's policy has been active for 15 years. Re-requesting all personal information again would breach minimisation, but asking the client to confirm/update existing records is justified under accuracy.
- Hospital: A patient last visited 12 years ago. Before treatment resumes, the hospital may re-collect critical information (health conditions, next of kin, contact details) — this is proportionate and lawful.
- Public Authority: A pension fund with records dating back 20 years may request confirmation of beneficiaries' personal details to ensure lawful and accurate payment.
✅ Conclusion
- No, you cannot re-collect data just for the sake of it — that would breach minimisation.
- Yes, you can re-request or update data if you have a lawful justification, particularly to ensure accuracy or compliance with legal obligations.
- The correct approach is usually:
- Do not re-collect everything.
- Ask for confirmation/update of existing data.
- Document the rationale in your GDPR compliance records.