Laws · GDPR ·art-12-par-5 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Information provided under Articles 13 and 14 and any communication and any actions taken under Articles 15 to 22 and 34 shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either:
How it connects
Cited by
- Guidelines 01/2022 on data subject rights - Right of access
- Company: Insufficient fulfilment of data subjects rights
- One-Stop-Shop case digest on right of access
- Coordinated Enforcement Action, implementation of the right of access by controllers
- Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH
All 30
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- Rb. Den Haag - C/09/689833
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- Coordinated Enforcement Action,
- The Court of Justice on the Excessiveness of Access Requests under the GDPR
- AG Arnsberg - 42 C 434/23
- CJEU - C-526/24 - Brillen Rottler
- Munich Court: §11(8) RBStV validly restricts Art. 15 GDPR access for broadcasting
- Opinion 26/2024 on the draft decision of the DE Bremen Supervisory Authority regarding the “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria
- EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space
- RW v Österreichische Post AG
- APD/GBA (Belgium) - 97/2026
- Rb. Noord-Holland - C/15/376188
- Garante per la protezione dei dati personali (Italy) - 457/2026
- EDPB - Binding Decision 1/2026
- HDPA (Greece) - 33/2020
- Rotterdam court upholds municipality's refusal of excessive GDPR requests
- DSB: No processor access violation under Art. 15 GDPR when controller deleted data
- VG Osnabrück - 7 A 170/24
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- BVwG: Data protection complaint by litigation-funded enforcement association inadmissible
- Den Haag District Court: 51 gamblers sue Unibet operator Risepoint over unanswered GDPR
- Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access