>It isn't clear to me that the GDPR requires disclosure of data that is related to a person but was not created by or provided by that person.It absolutely, positively does require that disclosure. Article 15 states:
"The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data"
"Personal data" is defined in Article 4 as:
"any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;".
If I have any information* that can be related to you by any identifier, directly or indirectly, it is personal data within the scope of GDPR. Server logs, invoices, customer service records, CCTV footage, emails between employees that mention your name or username, the whole kit and caboodle.
The definition of "processing" given in Article 4 includes storage.
The regulations would be a farce if I could hoover up data about you from third parties or through surveillance technology, but you had no rights over that data simply because you didn't provide it to me.
https://gdpr-info.eu/