# Right of Access Procedures — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/article-15-gdpr-access-procedures
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because Article 15 GDPR deserves dedicated coverage for its specific procedures, requirements, timelines, formats, and exceptions related to the right of access by data subjects.

## Overview

## Legal Framework

The right of access is enshrined in [Article 8(2) of the EU Charter](/laws/eu/art-8-38440#point-2-38442) and operationalised by [Article 15 GDPR](/laws/gdpr/art-15). Article 15 grants data subjects a two-tier right: first, confirmation of whether their personal data are being processed, and second, where processing is occurring, access to the data together with a prescribed catalogue of supplementary information — including processing purposes, categories of data, recipients, retention periods, and the existence of automated decision-making.

> "The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:"
> — [GDPR Art. 15(1)](/laws/gdpr/art-15)

Recital 63 frames the right's purpose: enabling data subjects to verify the lawfulness of processing. It also signals limits — the right must not unduly prejudice trade secrets or intellectual property — while warning that such considerations "should not be a refusal to provide all information." Where personal data are transferred to third countries, Article 15(2) adds a discrete obligation to inform the data subject of the appropriate safeguards under Article 46. Article 15(3) entitles the data subject to a copy of the processed data.

## Key Developments

The CJEU's ruling in *Minister voor Immigratie v. M* (2014) established foundational parameters for access scope. The Court held that access extends to all personal data processed by the controller but does not encompass legal analysis or administrative reasoning beyond what constitutes personal data. Critically, the Court confirmed that compliance can be achieved through a summary, provided it is intelligible and enables the data subject to verify accuracy and exercise downstream rights.

> "an applicant for a residence permit has a right of access to all personal data concerning him which are processed by the national administrative authorities"
> — [Minister v. M ¶60](/posts/5962#seg-60)

The earlier *X* judgment (2013) set procedural benchmarks, requiring that access be provided without constraint, excessive delay, or excessive expense — a standard carried forward into Article 12(3) GDPR. Enforcement actions confirm these are not merely aspirational: the Irish DPA fined Permanent TSB €277,500 for insufficient measures to fulfil access requests, and the Estonian DPA acted against a dental clinic that failed to properly respond to a data subject's access complaint.

## Status of the Debate

This topic is actively contested. While the core entitlement under Article 15 is well-established, courts and regulators continue to grapple with boundary questions: what constitutes "personal data" in mixed legal-factual records (per *Minister v. M*), how to balance trade-secret protection against the access right (Recital 63's tension), and what format satisfies the "intelligible form" standard. National derogations under Article 89(2)–(3) for archival and research purposes further fragment the landscape, as Member States may restrict access rights in those contexts. The EDPB's ongoing guidelines on right of access signal that regulator-level clarification is still evolving. Resolution will likely require further CJEU guidance on the precise scope of "copy" under Article 15(3) and the proportionality test when third-party rights intersect with access requests.

## Practical Guidance

- **Verify identity proportionately**: Before responding, confirm the requester's identity using reasonable means — do not demand excessive documentation that would itself constitute a barrier to access, consistent with the *X* standard of access "without constraint."
- **Distinguish personal data from legal analysis**: Following *Minister v. M*, provide access to all personal data but exclude purely legal reasoning or administrative analysis that does not itself constitute personal data, unless it contains personal data embedded within it.
- **Deliver in intelligible form**: A full summary may satisfy the obligation if it allows the data subject to become aware of the data and verify accuracy — but ensure the summary is complete and comprehensible, not merely a data dump in raw format.
- **Include all Article 15(1) supplementary information**: Beyond the data itself, provide processing purposes, recipient categories, retention periods, source information (where data were not collected from the subject), and details of any automated decision-making.
- **Document third-party and trade-secret redactions**: Where redactions are applied to protect others' rights, record the specific legal basis and ensure the data subject still receives meaningful information — a blanket refusal will not survive scrutiny.

## Legislation (full text of key provisions)

### Right of access by the data subject

*Source: GDPR, gdpr-art-15-en, 2016-04-27 — https://overview.legal/posts/90406*

### Recital 63 — data subject right of access

*Source: GDPR, gdpr-rec-63-en, 2016-04-27 — https://overview.legal/posts/91641*

A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing. This includes the right for data subjects to have access to data concerning their health, for example the data in their medical records containing information such as diagnoses, examination results, assessments by treating physicians and any treatment or interventions provided. Every data subject should therefore have the right to know and obtain communication in particular with regard to the purposes for which the personal data are processed, where possible the period for which the personal data are processed, the recipients of the personal data, the logic involved in any automatic personal data processing and, at least when based on profiling, the consequences of such processing. Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data. That right should not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software. However, the result of those considerations should not be a refusal to provide all information to the data subject. Where the controller processes a large quantity of information concerning the data subject, the controller should be able to request that, before the information is delivered, the data subject specify the information or processing activities to which the request relates.

### Recital 146 — Commission decision procedural rights and confidentiality

*Source: DSA, dsa-rec-146-en, 2022-10-19 — https://overview.legal/posts/95689*

The provider of the very large online platform or of the very large online search engine concerned and other persons subject to the exercise of the Commission’s powers whose interests may be affected by a decision should be given the opportunity of submitting their observations beforehand, and the decisions taken should be widely publicised. While ensuring the rights of defence of the parties concerned, in particular, the right of access to the file, it is essential that confidential information be protected. Furthermore, while respecting the confidentiality of the information, the Commission should ensure that any information relied on for the purpose of its decision is disclosed to an extent that allows the addressee of the decision to understand the facts and considerations that led up to the decision.

### Recital 110 — lawful domain registration data access

*Source: NIS2, nis2-rec-110-en, 2022-12-14 — https://overview.legal/posts/96748*

The availability and timely accessibility of domain name registration data to legitimate access seekers is essential for the prevention and combating of DNS abuse, and for the prevention and detection of and response to incidents. Legitimate access seekers are to be understood as any natural or legal person making a request pursuant to Union or national law. They can include authorities that are competent under this Directive and those that are competent under Union or national law for the prevention, investigation, detection or prosecution of criminal offences, and CERTs or CSIRTs. TLD name registries and entities providing domain name registration services should be required to enable lawful access to specific domain name registration data, which are necessary for the purposes of the access request, to legitimate access seekers in accordance with Union and national law. The request of legitimate access seekers should be accompanied by a statement of reasons permitting the assessment of the necessity of access to the data.

## Case law

### Council of State: Tax Authority satisfied GDPR access request on FSV fraud registration

*Source: Council of State, 2026-08-05 — https://overview.legal/posts/187482 — original: https://gdprhub.eu/index.php?title=RVS_-_202307578/1/A3*

Facts — The personal data of an individual was stored in the Fraud Detection System (FSV), an application used by the Dutch Tax Authority between 2012 and 2020 to record potential indicators of tax fraud. The Minister of Finance was the controller. The data subject submitted an access request under Article 15 GDPR. In particular, she requested information about the personal data processed, the purposes of the processing, the recipients of the data, its source and retention period, and any automated decision-making concerning her. The controller provided an overview of the personal data stored in the FSV and answered the data subject’s questions. The data subject objected to the decision, claiming that the controller had not disclosed all information relating to her registration. The controller rejected the objection. It explained that the data subject had been selected for a manual review of her tax return under Project 1043, an anti-fraud initiative launched by the Dutch Tax, and was consequently registered in the FSV. It also stated that the data was accessible only to employees of the Tax Authority and had not been disclosed to other organisations. The District Court of Amsterdam dismissed the data subject’s appeal. It held that the proceedings concerned compliance with the GDPR access request and not the lawfulness of her inclusion in the FSV or any alleged resulting damage. The data subject appealed this judgment before the Council of State. Holding — The Council of State dismissed the appeal and upheld the judgment of the District Court. The Court held that there was no evidence that the controller had incorrectly applied Article 15 GDPR. The controller had provided an overview of all personal data concerning the data subject processed in the FSV, explained the purposes of the processing and clarified the circumstances of her registration under Project 1043. Although the data subject suspected that the controller held additional information, she did not provide concrete evidence supporting this claim. The Court also found no indication that she had been classified as a fraudster or that her personal data had been disclosed to other organisations. The Court further clarified that the lawfulness of the data subject’s registration in the FSV, the deletion of her data and any claim for compensation fell outside the scope of the access proceedings. Consequently, the Court confirmed the contested judgment and did not award litigation costs.

### Rb. Overijssel: Police access request wrongly assessed under GDPR instead of Wpg

*Source: District Court Overijssel, 2026-07-24 — https://overview.legal/posts/187481 — original: https://gdprhub.eu/index.php?title=Rb._Overijssel_-_ZWO_25/2142*

Facts — On 5 January 2025, the data subject submitted an access request to the Chief of Police, the controller, concerning her personal data for the period between 1 January 2016 and 31 December 2017. In particular, she requested information about searches carried out using her Citizen Service Number in a Basic Register of Persons. On 10 February 2025, the controller extended the deadline for deciding on the request by eight weeks. Since the controller considered it unclear whether the request had been submitted under Article 15 GDPR or Article 25 of the Police Data Act (Wet politiegegevens (Wpg)), it contacted the data subject by telephone. On 14 April 2025, the controller assessed the request under Article 15 GDPR and rejected it on the ground that it had not processed the data subject’s personal data during the relevant period. The data subject lodged an objection against this decision. On 13 June 2025, the controller rejected the objection and upheld its initial decision. Since the decision did not contain information on the available legal remedies, the controller sent it again on 18 June 2025 with the relevant appeal clause. On 29 July 2025, the data subject appealed to the District Court of Overijssel. She argued that the controller should have understood from the content and context of her request that it had been submitted under Article 25 Wpg rather than Article 15 GDPR. In particular, the request referred to an earlier access request that the controller had processed under the Wpg. Holding — The Court held that the controller should have assessed the access request under Article 25 Wpg rather than Article 15 GDPR. The content and context of a request determine its legal classification, irrespective of the legal basis identified by the applicant. The request referred to an earlier request processed under the Wpg and sought a similar overview for a different period. Moreover, the Wpg constitutes the specific legal framework applicable to personal data processed by the police for public-security purposes and therefore takes precedence over the GDPR. The Court declared the appeal well-founded and annulled the contested decision. Since decisions under Article 25 Wpg are not subject to an administrative objection procedure, it ordered the controller to issue a new primary decision under the Wpg. No fine was imposed.

### EWCA - Dawson-Damer v Taylor Wessing LLP

*Source: EWCA, 2026-07-17 — https://overview.legal/posts/125652 — original: https://gdprhub.eu/index.php?title=EWCA_-_Dawson-Damer_v_Taylor_Wessing_LLP*

Facts — This case concerns a data subject access request (SAR) under the Data Protection Act (DPA) 1998. The data subjects were beneficiaries under a trust. The data controller was a firm of solicitors, holding trust money as trustees. Following the appointment of further trustees and transfer of trust money into a new trust for other discretionary beneficiaries, the data subjects challenged the validity of these appointments and served the data controller with a SAR under section 7(2) DPA 1998. The data controller refused to make the disclosure, stating that the personal data was covered by Legal Professional Privilege (LPP), and therefore exempted from disclosure under Schedule 7 para. 10 DPA 1998. Furthermore, the data controller asserted that the supply of information required a disproportionate effort. The data subjects contended that many categories of personal data held by the data controller were not privileged and that, if any, the only privilege on which the data controller could rely was litigation privilege. The data subjects applied to the court for a declaration under section 7(9) DPA 1998 that the data controller had not complied with the request and to oblige the data controller to comply with the SAR. At trial, the court agreed with the data controller and refused to make such an order. The appellate court had to determine: whether, taking a narrow view, the LLP exception is limited to documents subject only to legal professional privilege under English law; whether, if the narrow view is correct, any further search would involve "disproportionate effort" for the purposes of section 8(2) DPA 1998 so that the data controller is excused from doing so; whether the exercise of the court’s discretion under section 7(9) DPA 1998 can be refused because the data subject's real motive was to use the information in legal proceedings against the data controller. Holding — The Court of Appeal held that 'privilege' in the LLP exception is limited to legal professional privilege. It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort. The High Court judge was wrong not to exercise its discretion under section 7(9) DPA 1998 to order the data controller to comply with the request. On Issue 1 - Extent of the Legal Professional Privilege Exception: The purpose of Directive 95/46/EC (the Directive) was to regulate the activities of data controllers on a territorial basis. Therefore, the words "legal proceedings" in sched. 7 para. 10 DPA 1998 refer to legal proceedings in any part of the UK. If Parliament had intended to legislate for events which occur outside the territory of the UK, it would have introduced provisions specifying which parts of the world were relevant for this purpose and under which conditions the privilege applied. The LPP exception is expressly limited to legal professional privilege. Documents not disclosable to a beneficiary of a trust under trust law principles are not within the LPP exception. Insofar as the exception was interpreted purposively as also including documents covered by the trustees' right of non-disclosure, the Directive would have to name appropriate objectives which could support an interpretation along these lines. However, the DPA does not contain such exceptions. The court concluded at para. 45 that the LPP exception “relieves the data controller from complying with a SAR only if there is relevant privilege according to the law of any part of the UK.” Since the data in question is not covered by the LPP under English law and no other exemption under the DPA 1998 applies, the SAR must be granted. On Issue 2 - Whether compliance with the request would involve disproportionate effort: The public interest reasons set out in the Directive for giving people control over the data held about them require that SARs should be enforced so far as possible. Under section 8(2) DPA 1998 the data controller is obliged to supply copies of information constituting personal information to the data subject, "unless …the supply of such a copy is not possible or would involve disproportionate effort." The effort, the data controller undertakes must be weighed in a proportionality exercise against the potential benefits that the provision of the information could bring to the data subject. That includes the possibility that there may be limits to a search in certain circumstances, see Ezsias v Welsh Ministers [2007] EWHC B15 (QB). The court held at para. 75 ff, that “It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort”. However, “disproportionate effort must involve more than an assertion that it is too difficult to search through voluminous papers”. The data controller “must produce evidence to show what it has done to identify the material and to work out a plan of action.” On Issue 3 - Whether the request can be declined because the data subject intended to use the information against the data controller: The purpose of the Directive is to protect fundamental rights conferred by EU law. The court found that nothing in Directive or the DPA 1998 limits the purpose for which data subjects may request their data or allows data controllers not to provide data based solely on the on the basis of the purpose of the data subject. Also, Parliament has not expressly required data subjects to show that they have no other purpose. The court distinguished Dunn v Durham County Council [2003] 1 WLR 2305, Lin & Anor v Commissioner of Police of the Metropolis [2015] EWHC 2484 and Kololo v Metropolitan Police Commissioner [2015] 1 WLR 3702. Durant v Financial Services Authority [2004] FSR 573 at para. 27 also does not establish a “no other purpose rule” and should only be interpreted to mean that “a person could not claim that something was personal data because it would assist him in obtaining discovery or in litigation or complaints against third parties.” (para. 111) The court found that the trial judge had wrongly refused to enforce the request just because the appellants intended to use the information obtained in other proceedings. The section 7(9) DPA 1998 discretion must be applied with a view to fulfilling the purposes of the DPA.

### Rb. Noord-Holland - C/15/376188

*Source: District Court Noord-Holland, 2026-07-13 — https://overview.legal/posts/144035 — original: https://gdprhub.eu/index.php?title=Rb._Noord-Holland_-_C/15/376188*

Facts — Rydo Telecom (the controller) is a telecommunications provider. In 2023, a data subject made an access request following a dispute with the controller on whether the data subject received two phones they had purchased from the controller. The data subject informed the controller in a letter that they intended to claim costs in the event that it did not respond to the request. The controller began investigating the data subject and found a similar claim against PostNL (one of the controller’s suppliers). According to PostNL, the data subject had made a similar claim that it had failed to deliver the two phones. The data subject later filed a case with the Amsterdam sub district court after the controller refused to respond to the request. The court dismissed the data subject’s claim for reimbursement of €2,908, on the grounds that the data subject had accused both companies of the same issue, and had left the hearing early. The data subject continued to reiterate their access request in 2024, and received a response from the controller in 2025. The controller stated that it no longer had data related to them beyond their email address in connection to the previous lawsuit. The data subject filed a case with the sub district court in 2026, who later referred the case to the court. The data subject requested the court to order the controller to provide full access to their data, subject to a penalty for noncompliance. Holding — The court first noted that the data subject had filed approximately 20 GDPR request cases with the sub district court within one year against different controllers. The court then assessed whether the data subject’s request was abusive within the meaning of Article 12(5) GDPR. This includes an objective and subjective element following CJEU case law (Brillen Rottler). According to the CJEU, the subjective element requires the data subject to intend to obtain a benefit by artificially creating the conditions to receive said benefit. Publicly available information can be used for this assessment. The court considered that the data subject had abused their right. The court took into consideration other cases the data subject had initiated, and considered that the data subject had a financial motive for their requests rather than a genuine concern to assess their personal data or verify the lawfulness of its processing. The court gave as an example the fact that the data subject had insisted that the controller reach a settlement in the form of paying compensation or damages. The court dismissed the case. Since there was an established abuse of rights, the court saw no need to assess the merits of the data subject’s claim.

### CJEU - C-526/24 - Brillen Rottler

*Source: GDPRhub, C-526/24, 2026-07-13 — https://overview.legal/posts/96819 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-526/24_-_Brillen_Rottler*

Facts — On 16 March 2023, the data subject (a private individual living in Vienna) subscribed to the ‘newsletter’ on the website of the controller (a family run optician company established in North Rhine-Westphalia) by entering his personal data in the registration form, confirming his consent to data processing by ticking a box and submitting the form. On 29 March 2023, the data subject sent by fax an information request pursuant to Article 15 GDPR. The controller acknowledged receipt of the request and stated that it would respond to it within the one-month period. However, by letter of 26 April 2023, the controller refused to provide the information since it classified the information request as an abuse of right for the purposes of the second sentence of Article 12(5)(b) GDPR. The controller sought a declaration from the referring court that the data subject is not entitled to compensation in the amount of €1000. The court decided to refer the following questions set out in point I. to the CJEU for a preliminary ruling pursuant to Article 267 TFEU: Is the second sentence of Article 12(5) GDPR to be interpreted as meaning there cannot be an excessive information request from the data subject when the first request is made to the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that the controller can refuse an information request from the data subject if the data subject intends to use the information request to provoke claims for damages against the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that grounds for refusing to provide information can be provided by publicly available information about the data subject which suggests that the data subject is asserting claims for damages against the controller in a large number of cases of infringement of the law relating to the protection of personal data? Is Article 4(2) GDPR to be interpreted as meaning that an information request from a data subject to the controller pursuant to Article 15(1) GDPR and/or a response to that request constitutes processing within the meaning of Article 4(2) GDPR? In view of the first sentence of recital 146 GDPR, is Article 82(1) GDPR to be interpreted as meaning that only damage which the data subject suffers or has suffered as a result of processing is eligible for compensation? Does this mean that for there to be a claim for damages under Article 82(1) GDPR – assuming causal damage to the data subject exists – there must necessarily have been processing of the data subject’s personal data? If the answer to Question 5 is in the affirmative: Does this mean that the data subject – assuming causal damage exists – has no claim for compensation under Article 82(1) GDPR solely on the basis of an infringement of his or her right to information under Article 15(1) GDPR? Is Article 82(1) GDPR to be interpreted as meaning that the controller’s objection relating to an abuse of right in relation to an information request from the data subject cannot, in view of EU law, consist in the fact that the data subject brought about processing of his or her personal data solely or inter alia in order to assert claims for damages? If the answers to Questions 5 and 6 are in the negative: Does the mere loss of control and/or uncertainty about the processing of the data subject’s personal data associated with an infringement of Article 15(1) GDPR constitute non-material damage to the data subject within the meaning of Article 82(1) GDPR or does it also require a further (objective or subjective) restriction and/or (significant) damage to the data subject? Advocate General Opinion — In addressing the first, second, third, and seventh questions referred by the national court: — The excessive character of an initial access request Advocate General emphasized that while an initial access request can, in theory, be considered "excessive," this must be limited to exceptional circumstances since the right of access is fundamental and linked to other GDPR rights. The circumstances that allow a request to be characterized as ‘excessive’ The Advocate General analyzed when a data access request under Article 15 GDPR could be considered excessive under Article 12(5) GDPR . He concluded that such a request may only be treated as excessive if the controller can demonstrate an abusive intention. However, merely having a pattern of making similar claims in many cases does not, on its own, prove abuse, and strict criteria must be applied to ensure that the fundamental right of access is not unduly restricted. In addressing the the fourth, fifth and sixth questions referred by the national court : — The event giving rise to the damage within the meaning of Article 82 of the GDPR The Advocate General analyzed whether only data processing that violates the GDPR can give rise to compensation under Article 82 GDPR. He concluded that not just unlawful processing, but any infringement of the GDPR can be a basis for compensation, provided that damage and a causal link are proven. The concept of ‘processing’ for the purposes of the right to compensation The Advocate General explains that although sending an access request is not "processing" under the GDPR, a controller’s act of responding to such personal data , which can fall under the scope of the GDPR. However, the actual damage arises not from this technical processing, but from the unjustified refusal to fulfill the access request. To ensure the effectiveness of Article 15 GDPR and the right to compensation under Article 82, the concept of “processing that caused the damage” should be interpreted broadly. The existence of non-material damage The Advocate General clarifies that a violation of Article 15 GDPR alone does not automatically entitle a data subject to compensation; the individual must prove actual non-material harm resulting from the infringement. The Court has recognized that even temporary loss of control over personal data may qualify as non-material damage, without requiring a minimum severity threshold. Conclusion — In the Advocate General’s view, an initial access request under Article 15 GDPR can only be considered “excessive” where the data controller can clearly demonstrate, based on all relevant circumstances, that the data subject acted with abusive intent, specifically, where the individual consented to the processing of their personal data solely to submit an access request and subsequently claim compensation. Importantly, the mere fact that a data subject has frequently exercised their right to compensation in similar cases does not, in itself, justify classifying the request as excessive. Moreover, under Article 82(1) GDPR, a data subject is entitled to compensation for damage resulting from a violation of the Regulation, even if that damage was not directly caused by the processing of personal data. Holding — Is a first access request excessive in accordance with Article 12(5) GDPR, and under what circumstances is it possible to establish such an excessive nature? (Questions 1, 2, 3 and 7) — The court first noted that the GDPR guarantees the right to access in Article 15(1) GDPR. However, Article 12(5) GDPR allows the controller to charge a reasonable fee or refuse the request if it is “manifestly unfounded or excessive”. Given the fact that the GDPR does not define these terms, the concept must be understood through its wording and objectives pursued . The court stated that Article 12(5) GDPR does not rule out the possibility that a first request may be considered excessive. This is because the repetitive character referred to in this article is an example, meaning “excessive” is not necessarily limited to the number of requests. However, this must be interpreted strictly; therefore, the controller may only rely on this in exceptional cases, and the controller bears the burden of demonstrating the excessive nature of the request. In terms of circumstances, the court noted that proof of an abusive practice must meet objective and subjective requirements. The court noted that the data subject’s access request met the formal requirements, as the data subject exercised the right to access to be aware of the processing and verify its lawfulness in accordance with the aim of Article 15 GDPR. The subjective element, on the other hand, concerns the intention of the data subject; in this case the controller must unequivocally demonstrate that the data subject has made the request for a purpose other than being aware of the processing and verifying its lawfulness (such as artificially creating conditions to obtain compensation). The court stated that it is necessary to take into consideration all the circumstances of the case, including the fact that the data subject provided the data voluntarily, or the time elapsed between providing the data and requesting access. The court noted that the controller may use publicly available information, provided that it is supported by other material. The court concluded that it was for the referring court to determine whether the controller demonstrated that the data subject made the access request with abusive intentions. Does Article 82(1) confer the right to compensation for damages resulting from an infringement of the right to access? (questions 5 and 6) — The court first noted that under Article 82(1) GDPR data subjects that have suffered (non)material damages as a result of an infringement of the GDPR are entitled to compensation. Since the Article does not refer to “processing”, the right to compensation is not limited to damage resulting from the processing of personal data. In this case, an infringement is liable for damages from the refusal to act, rather than from the actual processing of personal data as such. The court also noted that the right of access would be significantly weakened if Article 82(1) GDPR was limited solely to unlawful acts involving data processing. In light of the answer to these questions, the court saw no need to answer question 4. Does non-material damage for data subjects include loss of control or uncertainty over how their data is processed? (question 8) — The court noted that the GDPR does not define “(non)material damages” or “compensation for damages suffered”. Therefore, they must be considered autonomous concepts of EU law, and interpreted in a uniform manner . The court referred to previous case law, and highlighted the fact that “non material damage” cannot be limited by the degree of seriousness. However, an infringement on its own does not give data subjects the right to compensation, as it is one of the three conditions that must be met cumulatively. Therefore, the data subject must also establish that the infringement caused them harm, and that there is a causal link between the damage and the infringement. This applies to loss of control, as well as data subjects’ fears regarding the misuse of their data. Finally, the court stated that the causal link may be broken by the behaviour of the data subject; this means a data subject may not receive compensation for damages when the loss of control or fears over misuse of data were caused by the data subject submitting this data to the controller with the aim of artificially creating conditions to obtain compensation).

### AG Arnsberg - 42 C 434/23

*Source: Local Court Arnsberg, 2026-07-01 — https://overview.legal/posts/90173 — original: https://gdprhub.eu/index.php?title=AG_Arnsberg_-_42_C_434/23*

Facts — An Austrian citizen residing in Vienna (the data subject) subscribed to the newsletter of a family-run optician company (the controller) mainly operating in the German states of North Rhine-Westphalia and Lower Saxony in March 2023. During the registration process, he provided his email address as well as his first and last name and consented to the processing of his personal data. He then made an access request under Article 15 GDPR by fax, using letterhead that included his full home address, email address, and fax number. The controller refused to provide the requested information in April 2023 as it considered the request to constitute abuse of rights. It cited newspaper reports indicating that the defendant had subscribed to numerous newsletters solely for the purpose of asserting claims for damages. The controller brought proceedings concerning the legality of its rejection of the access request. The data subject demanded access to the information required by in Article 15 GDPR and the payment of monetary compensation of €1,000 in a counter-lawsuit. The court referred the case to the CJEU for a preliminary ruling in July 2024. The CJEU rendered its judgment in the case C-526/24 Brillen Rottler on 19 March 2026. It held that even an initial access request could be rejected on the grounds of an abuse of rights. According to the CJEU, the assessment of abusive conduct is based on all circumstances of the individual case. Both objective circumstances and the subjective intent of the data subject need to be taken into account. An abusive intent always exists if the access request is made in order to artificially create a claim for damages. Holding — The court held that the lawsuit had originally been well-founded and ruled that the counterclaims were without merit. According to the court, the controller could reject the data subject’s access request as excessive under Article 12(5)(b) GDPR. The data subject also had no right to damages under Article 82 GDPR due to the absence of a GDPR violation. The court referred to the preliminary ruling in the case C-526/24 and based its decision on an overall assessment of the objective and subjective circumstances of the present case as required by the CJEU decision. It held that the data subject’s conduct had been abusive. To the conviction of the court, there were numerous indications of abusive conduct: first, the data subject had voluntarily disclosed more personal data than was needed to subscribe to the newsletter. Second, the court could not identify any personal interest in a regional newsletter concerning operations in Nordrhein-Westfalen, as the data subject was an Austrian resident. In addition, the court took into account that the data subject had made the access request only nine days after subscribing to the newsletter and had not filed a complaint with the competent DPA before raising a claim for damages. Finally, information on the internet about numerous cease-and-desist letters sent by the data subject pointed to abusive conduct.

### Rb. Den Haag - C/09/689833

*Source: District Court Den Haag, 2026-05-27 — https://overview.legal/posts/53095 — original: https://gdprhub.eu/index.php?title=Rb._Den_Haag_-_C/09/689833*

Facts — Kindred Group PLC and Risepoint Limited (the controllers) are companies that provide online gambling products. Several companies within Kindred Group PLC (Risepoint was initially in this group) offered online gambling products before a national law requiring a license entered into force. In response, several lawsuits were filed before courts regarding the validity of the gambling agreements between players and unlicensed online gambling providers. Several data subjects later requested access (Article 15 GDPR, or in the alternative, the right to portability under Article 20 GDPR) to the controller to receive information on specific transaction data and the types of games they participated in. The data subjects did not receive access and brought a claim to the court. The data subjects requested the court to hold both companies liable (jointly or separately) The court initially dismissed the claim based on the code of civil procedure, but allowed the data subjects to amend their arguments regarding the GDPR. Both companies argued that they were not controllers, and that the requests made by the data subjects were abusive. According to the companies, the data subjects requested access for the sole purpose of bringing legal actions against them. Finally, the companies argued that they did not have the obligation to comply with the requests under Article 15(4) GDPR. Holding — The court first clarified that both Kindred Group PLC and Risepoint Limited were controllers. Kindred Group PLC argued that it did not exercise any decisive influence over the purpose and means of processing. The court took into consideration the functional definition of “controller” under Article 4(7) GDPR and CJEU case law, rather than a formal definition. The court found that Kindred Group PLC was a controller for access made between May and October 2024, but not for requests made after October 2024. This is because Kindred had a unified privacy policy for companies under its group, and answered the access request from an email address containing its name. However, after October 2024, Risepoint was no longer a part of the group, and the data from Kindred had been transferred to Risepoint. The court then dismissed the controllers’ arguments, and stated that the access requests were not abusive under Article 12(5) GDPR. Under Article 12(5) GDPR, a controller may refuse a request for access if it is manifestly unfounded or excessive. However, the CJEU has clarified that a data subject does not need to justify an access request, and a controller cannot refuse a request for access on the sole ground that it serves a purpose other than obtaining information about the processing of personal data and verifying its lawfulness. In any case, the court stated that the controller bears the burden in proving that a request is manifestly unfounded or excessive. Similarly, the controllers could not rely on Article 15(4) GDPR to refuse the data subjects’ requests. The court stated that the controllers’ interest in not granting information that data subjects could use against them in court is not recognised under EU law as a basis to refuse access. While the GDPR allows for national law to restrict specific rights under Article 23 GDPR, the court stated that the restriction must be necessary and proportionate. This, however, does not apply for hypothetical situations. The court upheld the data subjects’ claim, and ordered the controllers to provide them with a copy of their transaction data. The court specified that the controllers had the obligation to provide a complete copy, in accordance with CJEU case law.

### VG München - M 26a K 25.5210

*Source: Administrative Court Munich, 2026-05-18 — https://overview.legal/posts/108991 — original: https://gdprhub.eu/index.php?title=VG_München_-_M_26a_K_25.5210*

Facts — The data subject had been liable to pay broadcasting contributions to the Controller, a German regional public broadcasting authority, since 2007. Following objections to several contribution assessment notices, the data subject submitted a request under Article 15 GDPR seeking a copy of all personal data processed about him by the Controller. The Controller responded by providing the categories of personal data and related information specified under § 11(8) of the German Broadcasting Contribution Treaty (RBStV), which governs data subject access requests relating to broadcasting contribution records, together with general privacy information. The data subject argued that the response was incomplete because it did not include copies of all documents containing his personal data, including correspondence with him and third parties. The Controller maintained that it had fully complied with its obligations under the RBStV. After the Controller declined to provide additional information, the data subject brought proceedings seeking disclosure of all personal data concerning him processed by the Controller. Holding — The Court held that § 11(8) of the German Broadcasting Contribution Treaty (RBStV) constituted a lawful restriction of the broader right of access under Article 15 GDPR pursuant to Article 23(1)(e) GDPR. It found that the national provision was a valid legislative measure, respected the essence of the fundamental right to data protection, and pursued an important public interest by ensuring the effective financing and administration of the public broadcasting system. The Court further held that the restriction was necessary and proportionate, noting that requiring the Controller to comply with the full scope of Article 15 GDPR across more than 44 million broadcasting contribution accounts would impose a disproportionate administrative and financial burden capable of undermining that public interest. The Court also held that § 11(8) RBStV satisfied the safeguards required under Article 23(2) GDPR by specifying the purposes of processing, categories of personal data, scope of the restriction, safeguards against misuse and unlawful access, the identity of the Controller, applicable storage periods and other statutory protections. Accordingly, while the Controller was required to disclose the categories of information specified under § 11(8) RBStV, it was not required to provide a copy of all personal data processed under Article 15(3) GDPR. As the Controller had already provided all information required under the national provision, the court dismissed the action.

### GC - T-318/24

*Source: Gereral Court, T-318/24, 2025-12-03 — https://overview.legal/posts/122878 — original: https://gdprhub.eu/index.php?title=GC_-_T-318/24*

Facts — An applicant (the data subject) participated in several EU staff selection procedures administered by the European Personnel Selection Office (EPSO), acting as controller, and created an EPSO account in the Talent system. After he successfully passed one selection procedure, EPSO also stored his data in its recruitment portal. EPSO managed recruitment through two IT systems, both of which generated access logs, although those logs contained limited technical information regarding the purpose of each access. Between 2022 and 2024, the data subject submitted several requests to EPSO under Article 17 of Regulation (EU) 2018/1725, seeking access to all personal data concerning him. He requested, in particular, full access logs, minutes of meetings, internal and external communications containing his personal data, information on data recipients, and the restoration of personal data deleted after the expiry of retention periods. EPSO stated that certain data did not exist, that it could not restore lawfully deleted data, and that it had already disclosed all available log data. After the data subject lodged a complaint, the European Data Protection Supervisor (EDPS) reconsidered the matter in light of the CJEU’s judgment in Pankki. The EDPS ordered EPSO to provide all available log data relating to consultations of the data subject’s profile. EPSO complied with that order by disclosing the available logs but withheld the identities of individual staff members who had accessed the data. EPSO later rejected further access requests submitted by the data subject. As a result, the data subject brought two actions before the General Court (Cases T-318/24 and T-362/24), seeking the annulment of EPSO’s decisions. The General Court joined the two cases and examined together all the pleas in law raised by the data subject. Holding — The General Court dismissed both actions in their entirety. It held that the controller did not infringe Article 17(1) or (3) of Regulation 2018/1725, as the right of access concerns personal data undergoing processing and not documents as such, nor does it require the controller to restore lawfully deleted data. The Court confirmed that Regulation 2018/1725 contains no obligation for a controller to reinstate personal data once deleted in compliance with applicable retention rules. The Court further held that the controller had no obligation to disclose additional log data, meeting minutes, or communications where it credibly asserted that no such personal data existed. The data subject failed to rebut the presumption of legality attaching to the controller’s statements regarding the non-existence of further data. Moreover , The Court held that access logs constitute personal data to which a data subject is entitled, as they reveal the existence, frequency and purpose of processing. However, employees of a controller acting under its authority are not “recipients” within the meaning of the GDPR or Regulation 2018/1725, and controllers are not required to log or disclose their identities. Disclosure of such identities is only required if strictly necessary for the effective exercise of data protection rights and subject to safeguarding employees’ rights. Since the data subject had already been informed of the purposes and recipients of processing, the absence of staff identities or detailed purposes in the logs did not infringe the right of access. It is not further apparent from the Pankki that Article 15 GDPR requires the controller to set up a logging mechanism containing information on the identity of employees who have carried out consultation operations in respect of the personal data of a person. In addition, the Court found no infringement of the principles of lawfulness, fairness, transparency, accuracy, integrity, confidentiality, or accountability under Article 4 of Regulation 2018/1725. The deletion of the data subject’s data after the expiry of retention periods was lawful and the data subject’s rights to restriction of processing and objection under Articles 20 and 23 were not applicable, as the deletion was based on a legal obligation rather than consent or legitimate interests.

### OLG Wien - 13R70/25x

*Source: Higher Regional Court Vienna, 2025-12-01 — https://overview.legal/posts/53664 — original: https://gdprhub.eu/index.php?title=OLG_Wien_-_13R70/25x*

Facts — A data subject brought proceedings against a controller after it refused to provide, free of charge, digital copies of invoices and transaction data following an access request. The data subject argued that Article 15(3) GDPR entitled them to receive a complete copy of the personal data processed by the controller, including the copies of invoices and transaction data. The controller argued that it had complied with both of the data subject's requests for information in a timely and complete manner. It argued that Article 15(3) GDPR entitled the data subject to a copy of their personal data, rather than to copies of documents as such. The controller alleged that it had disclosed the payment details provided by the data subject, thereby enabling them to clearly identify which bank account had been debited. The first-instance court dismissed the data subject’s action. It acknowledged that, according to the CJEU in judgement C-487/21, copies of whole documents must be provided only where they are indispensable for the data subject to understand the processing of their personal data or to effectively exercise their GDPR rights. The court considered that the data subject had not proved such necessity. It noted that they had already received the relevant invoices during the contractual relationship following the respective billing periods and the information disclosed by the controller was sufficient to understand the processing at issue. The therefore found that the controller could make any re-sending of invoices conditional upon payment of a fee. The data subject appealed to the Higher Regional Court of Vienna (OLG WIEN) and argued that in accordance with the case law of the CJEU (CJEU judgment C-307/22) a data subject need not provide reasons for requesting a copy of their personal data from the controller, and that the right to obtain a copy of personal data applies even where the request serves purposes unrelated to GDPR. They further argued that the first-instance court had incorrectly imposed on them the burden of proving that the copies were necessary for the exercise of their GDPR rights. Holding — The court acknowledged that according to C-307/22, an access request does not need to be justified and is not manifestly unfounded or abusive merely because the data subject pursues objectives unrelated to data protection. It nevertheless stated that motives unrelated to data protection may become relevant when it comes to the scope of the right to access data. The court referred to C-487/21 and held that the right to a copy under Article 15(3) GDPR means that the data subject must be provided with a faithful and intelligible reproduction of the personal data where this is indispensable for understanding the processing at issue and enabling the data subject to effectively exercise their GDPR rights. The court considered that the data subject bears the burden of proving why copies of the requested documents are indispensable. It emphasized that a general assertion that the documents are needed to ensure the completeness of the response is insufficient. It further stated that this requirement also applies where the request pursues objectives unrelated to data protection. The court upheld the legal assessment of the first-instance court and dismissed the appeal.

### OVG Saarlouis - 2 A 165/24

*Source: Superior Administrative Court Saarlouis, 2025-05-13 — https://overview.legal/posts/125590 — original: https://gdprhub.eu/index.php?title=OVG_Saarlouis_-_2_A_165/24*

Facts — The data subject was an employee, the controller was the employer. On 14 January 2022, the data subject requested access to personal data from the controller under Article 15 GDPR. They did not respond. On 28 January 2022, the controller terminated the employment. On 17 February 2022, the data subject lodged a complaint with the Data Protection Authority (DPA) under Article 77 GDPR. The data subject alleged that the controller had failed to answer the access request, had taken unauthorised photographs, and had a copy of their vaccination certificate. On 24 February 2022, the employment relationship ended by a court settlement before the Labour Court. The settlement stated that all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, were settled, except for employment documents. By entering the settlement, the data subject agreed to not pursue further claims. After the settlement, the controller informed the DPA that it had not received an access request from the data subject, had not taken photographs, and had destroyed the vaccination certificate after the employee left. The data subject continued to raise issues with the DPA, including access to time-tracking data and alleged inaccuracies in the controller’s provided documents. The controller later provided partially redacted time-tracking data. On 26 July 2022, the DPA closed the administrative procedure, as it considered that the data subject no longer had a right of access under Article 15 GDPR because the settlement didn't allow for this claim. The data subject challenged the DPA’s decision before the Administrative Court. On 10 July 2024, the court dismissed the action. The data subject appealed. Holding — First, the court held that the right of access under Article 15 GDPR was, in principle, waivable. Although Article 8(2) CFR protects the right of access, the court noted that data protection law is based on self-determination, including the possibility to consent to processing under Article 7 GDPR. From this, the court inferred that a data subject could also waive the exercise of the right of access. Second, the court clarified that a waiver could not generally cover unknown future data processing. However, a waiver relating to past processing was permissible, especially after the end of an employment relationship, where the imbalance between employee and employer no longer existed. Third, the court held that the specific settlement covered the right of access under Article 15 GDPR. The clause settling all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, also included secondary claims linked to the employment relationship, such as access rights concerning employee data. The court considered the wording sufficiently clear and found no requirement to explicitly mention data protection rights. Fourth, the court noted that the data subject already knew about the access request and had raised it before concluding the settlement. Any internal intention not to waive data protection rights was legally irrelevant. Finally, the court upheld the DPA’s decision to close the procedure. Since the data subject had waived the right of access under Article 15 GDPR for past processing through the settlement, the DPA had no obligation to continue enforcement action against the employer.

### Judgment of the Court (First Chamber) of 3 April 2025.#L. H. v Ministerstvo zdravotnictví.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4 – Definitions – Article 6 – Lawfulness of processing – Article 86 – Public access to official documents – Data concerning the representative of a legal person – Case-law of a national court imposing an obligation to inform and consult the data subject prio

*Source: Court of Justice of the European Union, C-710/23, 2025-04-03 — https://overview.legal/posts/132145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0710*

In Case C-710/23, the Court of Justice of the European Union (First Chamber) addressed a preliminary reference from the Czech Supreme Administrative Court concerning whether personal data of individuals acting as representatives of legal persons, contained in official documents related to COVID-19 screening test contracts, may be disclosed under GDPR Article 86 and the lawfulness of processing under Article 6. The case arose from a dispute between L.H. and the Czech Minister of Health, who had refused to disclose certain information about representatives of legal persons named in those contracts and related certificates. The Court held that data concerning a representative of a legal person constitutes personal data within the meaning of the GDPR when it allows the natural person to be identified, and that Member States may provide for public access to official documents containing such personal data, provided that the disclosure is reconciled with the right to data protection; however, a national court cannot impose a general obligation to inform and consult the data subject prior to every disclosure of official documents, as this would undermine the public's right of access to official documents.

## Guidance

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Coordinated Enforcement Action, implementation of the right of access by controllers

*Source: EDPB, edpb-cef-report-2024-20250116-rightofaccess-en, 2025-01-20 — https://overview.legal/posts/50412 — original: https://www.edpb.europa.eu/documents/coordinated-enforcement-framework/coordinated-enforcement-action-implementation-of-the_en*

EDPB 20 jan 2025, Coordinated Enforcement Action, implementation of the right of access by controllers.

### EDPB Annual Report 2025

*Source: EDPB, edpb-annual-report-2025-en, 2026-04-09 — https://overview.legal/posts/125683 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2025_en*

Clarity in action: Supporting stakeholders through guidance and dialogue Annual Report 2025 Foreword 3 Highlights 4 1. The EDPB Secretariat 6 1.1 Mission And Activities 8 2. European Data Protection Board – Activities in 2025 12 2.1 Bridging Fundamental Rights and Digital Innovation Through GDPR Compliance 12 2.1.1 Helsinki high-level meeting: enhanced clarity, support and engagement 12 2.1.2 Regulation on procedural rules and Omnibus regulation on the record of processing 14 2.1.3 Cross…

### Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom

*Source: EDPB, edpb-opinion-202527-united-kingdom-adequacy-led-en, 2025-10-16 — https://overview.legal/posts/51407 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-272025-regarding-the-european-commission-draft-implementing-decision_en*

Adopted 1 Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom Adopted 16 October 2025 Adopted 2 Executive summary The European Commission endorsed its draft implementing decision on the adequate protection of personal data by the United Kingdom pursuant to the Law Enforcement Directive on 22 July 2025. On the same date, as part of the procedure towards the formal…

### Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation

*Source: EDPB, joint-guidelines-interplay-between-digital-en, 2025-10-13 — https://overview.legal/posts/51268 — original: https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/joint-guidelines-interplay-between-digital_en*

Executive summary The Digital Markets Act (DMA) and the General Data Protection Regulation (GDPR) pursue different purposes and objectives and have different scopes. While the GDPR aims to protect natural persons with regard to the processing of personal data and ensure the free flow of personal data in the U nion covering all data controllers and processors, the DMA aims to tackle unfair prac tices, and their potential harmful effects for business users, by laying down harmonised rules…

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

## Enforcement decisions

### AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage

*Source: AEPD (Spain), 2026-07-21 — https://overview.legal/posts/144029 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00159-2025*

Facts — On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The data subject’s vehicle had allegedly been damaged while parked in a facility operated by the controller. On 23 February 2024, the data subject’s legal representative requested access to the footage recorded between 12 and 19 February 2024. The request sought the images showing the collision or, alternatively, the licence plate of the vehicle responsible. The data subject also expressly requested that the controller preserve the relevant footage because it was required for the establishment, exercise or defence of legal claims. The controller acknowledged receipt of the request but did not provide a substantive response until 4 April 2024, after the one-month period under the GDPR had expired. It stated that the footage could only be disclosed to the police or a judge and instructed the data subject to file a police report. After the data subject challenged that requirement and reiterated both the access and preservation requests, the controller responded that it would not provide the recordings and that the footage had already been deleted. During the proceedings, the controller argued that the request was excessive because it covered footage from 16 cameras over several days, amounting to approximately 3,072 hours of recordings. It also maintained that the footage contained personal data relating to numerous third parties and that it was not established that the damage had occurred inside the car park. The controller acknowledged, however, that it had not explained these considerations to the data subject, asked the data subject to narrow the request or notified an extension of the response period. Holding — The DPA held that the controller infringed Articles 15 and 18 GDPR. Regarding Article 15 GDPR, the DPA found that the controller failed to respond to the access request within the one-month period required under Article 12(3) GDPR. Although the controller considered the request complex and excessive, it neither informed the data subject of an extension within the initial one-month period nor explained why it considered the request excessive. The DPA noted that the controller could have asked the data subject to provide additional information to narrow the search. It could also have reviewed the recordings and provided only the footage necessary for the specific incident, applying measures such as blurring or limiting the disclosed extract to protect third parties. The DPA rejected the controller’s position that the footage could only be provided following a request from the police or a court. The exercise of the right of access was not conditional on the prior filing of a police report. The controller was required to assess the request under the GDPR and provide a reasoned and timely response. The failure to respond in time resulted in the deletion of the requested footage. Consequently, the data subject was prevented from obtaining information that could have been relevant to identifying the person responsible for the damage and pursuing a legal claim. Regarding Article 18 GDPR, the DPA held that the data subject had expressly requested the preservation of the recordings for the establishment, exercise or defence of legal claims. Under Article 18(1)(c) GDPR, processing must be restricted where the controller no longer needs the data for its original purposes but the data subject requires it for legal claims. The controller did not address this request and deleted the footage under its ordinary retention schedule. The DPA considered that Article 22(3) Spanish Data Protection Act (LOPDGDD), which generally requires video surveillance images to be erased within one month, did not justify disregarding a valid restriction request. Once the data subject requested preservation for potential legal proceedings, the controller was required to retain the relevant images rather than erase them. The DPA also linked the preservation of the evidence to the data subject’s right to effective judicial protection under Article 24(1) of the Spanish Constitution. Deleting the footage made it more difficult for the data subject to identify the responsible party and exercise their rights before a court. The DPA initially imposed two fines of €75,000: one for the infringement of Article 15 GDPR and one for the infringement of Article 18 GDPR, amounting to €150,000 in total. The controller acknowledged liability and voluntarily paid the fine. Under Article 85 of Spanish Administrative (Law 39/2015), it received a 20% reduction for acknowledging liability and a further 20% reduction for voluntary payment. Consequently, the initial fine of €150,000 was reduced by 40% to a final amount of €90,000. The DPA also ordered the controller to adopt the compliance measures specified in the decision initiating the proceedings and to report their implementation to the DPA within three months after the decision became final and enforceable.

### Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023

*Source: Tietosuojavaltuutetun toimisto (Finland), 2026-07-22 — https://overview.legal/posts/184713 — original: https://gdprhub.eu/index.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV/4630/2023*

Facts — A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022. The data subject made an access request in November 2022 – they suspected the misuse of their personal data as they had not submitted the loan application themselves. The data subject provided their name, phone number, and email address as identifying information in connection with the access request. The controller did not provide the requested information; instead, it asked the data subject to disclose their residential address and personal identification number as well as to sign the access request electronically using strong authentication in order to verify their identity. The data subject refused to comply with this request and filed a complaint with the DPA, stating that the controller’s procedure for verifying the identity of the data subject in connection with an access request violated Articles 5(1)(c), 12(2) and (6), and 25(2) GDPR. The controller considered the additional information necessary to identify the correct individual and avoid providing the data subject’s information to an unauthorised third party. Holding — The DPA found no GDPR violation and held that the controller was entitled to request the data subject to provide additional information necessary to verify their identity pursuant to Article 12(6) GDPR. The controller’s procedure was also in line with the principle of data minimisation laid down in Article 5(1)(c) GDPR. According to the DPA, the personal data originally provided by the data subject when making the access request could not be considered sufficient identifying information since several people might have the same name and the email address and the phone number of the data subject could also be known to third parties. The DPA considered that the controller had a legitimate reason to request that the data subject provide additional information to verify their identity, as the controller processes personal data concerning the financial status of its customers.

### APD/GBA: Controller failed to provide copies of service sheets for GDPR access request

*Source: APD/GBA (Belgium), 2026-05-06 — https://overview.legal/posts/144020 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_97/2026*

Facts — The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed and the clients visited. On 10 May 2021, the data subject requested copies of their service sheets covering the previous five years in order to verify whether the hours they had reported corresponded to those recorded by the controller. The controller provided only the sheet concerning the week of 3 May 2021 to 9 May 2021 and subsequently proposed that the data subject arrange an appointment to consult the records at its premises. The data subject reiterated the request on 17 January 2022 and again in 2023, but never received the requested copies. On 27 July 2023, the data subject lodged a complaint with the Belgian DPA. The DPA issued the prima facie Decision 14/2025, where it ordered the controller to comply with the data subject’s access request and warned it of potential violations of Article 15(3) GDPR and Article 12(3) GDPR. The controller requested an examination on the merits. The controller argued that the data subject’s request had not clearly distinguished between the handwritten service sheets and a computer-generated statement. It further claimed that the request was excessive under Article 12(5) GDPR because the documents were stored by date rather than by employee in several dozen binders. Locating, copying and scanning the relevant records would therefore require considerable workload. For that reason, it had invited the data subject to inspect the binders in its premises and identify the relevant documents to be copied. The data subject maintained that their request had always been clear, that the computer-generated statement was incomplete and unintelligible and that the practical difficulties relied upon by the controller resulted from its own archiving practices. Holding — The DPA ruled that the data subject had made a sufficiently clear request for access and a copy under Article 15(1) GDPR and Article 15(3) GDPR. It further pointed out that the controller’s response demonstrated that it had understood that the data subject sought copies of the service sheets themselves. The DPA further held that the computer-generated statement did not satisfy the request. It noted that the data subject needed the handwritten records in order to compare the hours they had reported with those subsequently recorded by the controller. It referred to C-487/21 (Österreichische Datenschutzbehörde) and recalled that the copy provided must constitute a faithful and intelligible reproduction of the personal data and may require copies of documents where this is necessary for the effective exercise of the data subject’s rights. The DPA therefore determined that the controller’s invitation to inspect the documents at its premises therefore did not constitute an adequate response to the data subject’s request for a copy. It stated that if the controller had genuinely been uncertain about the scope of the request, it should have sought clarification in accordance with Article 12(2) GDPR. Moreover, it rejected the controller’s reliance on Article 12(5) GDPR. The DPA held that the request was neither manifestly unfounded nor excessive as was clearly expressed and properly understood by the controller. It found that the controller did not demonstrate the excessiveness but relied exclusively on the workload resulting from its own archiving system. The DPA also relied on C-526/24 (Brillen Rottler) and applied the abuse of rights test. It found that neither its objective nor its subjective element was established. It reasoned that the request pursued the purpose of Article 15 GDPR, since the data subject sought to access and verify the accuracy of personal data concerning them, nor was there any evidence that the data subject had artificially created the conditions for obtaining an advantage under the GDPR. It further referred to EDPB Guidelines 01/2022 on the right of access, emphasizing that the time and effort required for a controller to fulfil an access request cannot, in itself, make the request excessive, particularly since the burden resulted from organisational choices made by the controller. It also emphasized that the data subject was also not required to justify the reasons for the request. The right of access under Article 15 GDPR does not include any general proportionality reservation regarding the controller’s efforts. Additionally, the term "appropriate" in Article 12(1) GDPR should not be used to limit the scope of data covered by the right of access. The DPA concluded that the alleged burden could not justify a refusal, especially since it stemmed from self-imposed organizational and administrative constraints related to the controller’s archiving system. A refusal may only apply if there is proven abusive intent, as defined by applicable requirements. Any other interpretation would undermine Article 15 GDPR and conflict with Article 12(2) GDPR and Article 25 GDPR, which require controllers to facilitate access requests and implement technical and organizational measures from the outset to ensure effective exercise of this right. The DPA further held that the controller had violated Article 12(2) GDPR, Article 12(3) GDPR and Article 12(4) GDPR. It had neither responded within the applicable time limit nor formally notified the data subject of a reasoned refusal. It further emphasized that the controller by requiring the data subject to attend its premises and identify the relevant records, it improperly transferred to them a task that belonged to it. Moreover, it noted that on-site consultation of the records could have exposed the data subject to personal data relating to the controller’s clients. The DPA held that under Article 15(4) GDPR, the controller was required to assess whether measures, such as partial anonymisation of third-party information, were necessary and that provision could not justify a blanket refusal to provide a copy. The DPA reprimanded the controller for violating Article 12(2) GDPR, Article 12(3) GDPR, Article 12(4) GDPR, Article 15(1) GDPR and Article 15(3) GDPR and ordered it to provide copies of the timesheets within one month.

### AEPD (Spain) - EXP202203606

*Source: AEPD (Spain), 2022-04-22 — https://overview.legal/posts/125657 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202203606*

Facts — Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against the respondent party for not having been duly attended to his right of access and deletion enshrined in Articles 15 to 22 GDPR, Articles 13 to 18 LOPDGDD and Article 17 GDPR respectively. The conflict of law arose in this case when a sufficiently legally established response was not generated by the respondent to the claimants request. Furthermore, the claim was transferred to the respondent so that the entity could proceed with its analysis and provide a response to the claimant within a period of one month. The Director of the Spanish Data Protection Agency agreed to admit the claim for processing and the parties concerned were informed of the maximum term for resolution, that being six months. The competence of the Spanish Data Protection Agency is refined by Article 55 GDPR in the promotion of an obligation between controllers and processors to deal with complaints issued by data subjects. The result of the said transfer did not allow the claimants issues to be understood as satisfied. Consequently, due to the lack of attention delegated to the claimants rights further set forth in Article 15 GDPR, Article 16 GDPR, Article 17 GDPR, Article 18 GDPR, Article 19 GDPR, Article 20 GDPR, Article 21 GDPR and Article 22 GDPR, an agreement to admit for processing was initiated. Holding — The Director of the Spanish Data Protection Agency went on to note that considering the purpose of the outlined procedure was to ensure that the rights of affected parties were fully restored, the complaint that gave rise to this procedure should be upheld on formal grounds due to the fact that the right of access had been complied with and the right of erasure had been duly denied (on the applicable grounds of Article 17 GDPR).

### CNIL fines energy supplier for mishandling data subject access and objection requests

*Source: CNIL (France), 2026-07-17 — https://overview.legal/posts/125641 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2022-011*

Facts — The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French DPA (CNIL) that they had encountered difficulties in exercising their rights of access to personal information about them, and objection to receiving commercial prospecting telephone calls from the controller. The complaints concerned data subject requests for rectification of personal data, late, erroneous, or no response to access to personal data and access to the origin of personal data, failure to cease processing of personal data after objection to the processing of data for commercial prospecting (marketing) purposes, and request for personal data deletion. The DPA appointed a rapporteur that carried out an audit of the website of the controller and investigated the various complaints of the data subjects. The controller in its defence argued that 1) the data subjects' access requests were not sent by the data subjects to the controller’s dedicated unit and that the person who received the requests did not know how to identify their purpose; 2) the procedures it had put in place were not respected because of human error; 3) there were a large number of requests received in 2020 during the health crisis and this was impeded by the disruptions that followed; 4) there were difficulties in obtaining the necessary information from its business partners, thus unable to properly inform data subjects about the source of their data; 3) It had taken steps to modify its processing activities to comply with the relevant applicable laws; 4) The breach affected barely a fraction of its customers. Beyond the direct complaints made by the data subjects, the DPA in its investigation noted that when subscribing online on the controller's website, the subscription form had no option for users to object to the use of their personal data for marketing purposes. The subscription form informed users that their personal data may be used by the controller to present offers to them at a later date. On this point, the controller argued that 5) the CPCE did not apply to the online subscription form, since the collection of personal data through the form was not intended to promote the company's products or services, but to offer assistance to the user in order to help them finalize the current subscription. Holding — The DPA held that the lack of an option for a user to object to the processing of their personal data for marketing purposes, at the time of collection, constitutes a breach of the provisions of article L. 34-5 of the French Post and Electronic Telecommunications Code (CPCE). The DPA observed that, in certain cases, the data subjects contacted for marketing purposes were not provided with any information required in Article 14 GDPR, such as the purposes of the processing or the existence of the various rights. They were not informed that the call was being recorded, nor of their right to object to it. The DPA observed that the controller had failed to respond, supplied erroneous responses, or responded late to several data subject requests, beyond the deadlines set by Article 12 GDPR, often after several reminders from the data subject. The DPA observed that the controller failed to process the various data subject’s requests for access to personal data, their origin, as well as access to recordings of telephone conversations concerning the data subjects within the time limit set with the obligations of Article 15 GDPR. The DPA finally observed that the controller continued to process the personal data of data subjects after objections from the data subjects to the processing of their personal data in breach of Article 21 GDPR. The DPA held that the controller cannot rely on its difficulties in obtaining information from its commercial partners to justify its failure to provide a response to the applicants in accordance with the applicable provisions. It is the duty of the controller to organize itself in such a way as to be able to ensure that requests for access are processed in accordance with the applicable provisions and, in particular, to provide information on the origin of the data. The DPA further held that although data subjects did not send their access requests directly to the unit in charge of responding to them, it is up to the controller, as long as the requests, one of which was directly addressed to the data protection officer, were received in clear terms by the controller, to process them within the time limits provided for and to ensure that they were transmitted to the competent department responsible for handling such requests. For these violations, the DPA fined the controller €1,000,000. The controller argued against the publication of the penalty decision, on the ground that publication would be disproportionate in light of the limited nature of the alleged breaches and its compliance. It also claimed that publication of the penalty would have a significant impact on the controller’s image and that it would be favorable to its main competitors, in a very competitive market. The DPA also decided to make its decision public on the CNIL website and on the Légifrance website and held that the controller will no longer be identified by name after a period of two years from its publication. The DPA noted that the company has taken measures to bring its processing into compliance with the applicable laws, and the efforts made by the company to comply throughout the procedure. The DPA also noted that the controller’s agents have had to attend awareness training on the subjects of the complaints.

### Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/184565 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_484/2026*

Facts — EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller assessed the creditworthiness of potential customers through an internal and an external credit check. The internal assessment involved verifying whether potential customers had outstanding debts not only with the controller but also with Hera Comm S.p.A (hereinafter, the corporate group). The assessment was conducted on behalf of the controller by Hera S.p.A. (hereinafter, the processor), which returned an “OK” or “KO” result. Where the internal assessment returned an “OK”, the controller conducted an external assessment using credit information supplied by Experian Italia S.p.A. and commercial information provided by Cerved Group S.p.A. This information was combined using the “CGS-X” software provided by Major 1 S.r.l. (hereinafter, the software provider and processor). The software generated an integrated creditworthiness score and several underlying sub-scores. On the basis of the result, the controller could refuse to enter into an energy supply contract. The DPA received several complaints from data subjects whose requests for energy supply had been rejected on the basis of their risk profiles. However, when the data subjects contacted the credit and commercial information providers, they were informed that the relevant databases did not contain negative information or adverse events concerning them. The data subjects also submitted access requests under Article 15 GDPR. Although the controller responded within the applicable time limits, it did not provide the CGS-X score, the underlying sub-scores or meaningful information about the logic and criteria used to calculate the profiles. Instead, the controller referred the data subjects to the credit and commercial information providers. Following the complaints, the DPA consolidated the proceedings and initiated an ex officio investigation. It conducted inspections at the premises of the processor, the software provider and processor, and the credit and commercial information providers. The investigation also established that the controller retained the information obtained through the credit checks. Through the processor, the controller subsequently analysed this information to potentially refine the corporate group’s customer rating system. Between 2022 and March 2024, this processing concerned more than one million data subjects. Holding — The DPA held that the controller’s creditworthiness assessment infringed Articles 5(1)(a), (b), (d) and (e), 12, 13, 14, 15 and 28 GDPR. First, the controller failed to provide transparent information about the internal assessment of customers’ previous debts and the sharing of such information within the corporate group. The instructions given to the processor also did not adequately cover these processing operations. The DPA therefore found violations of Articles 5(1)(a), 13, 14 and 28 GDPR. Second, the controller provided incomplete responses to access requests. It did not disclose the CGS-X score, the underlying sub-scores or meaningful information on the logic and criteria used to generate the creditworthiness profile. Referring the data subjects to the credit and commercial information providers did not discharge the controller’s obligations under Articles 12 and 15 GDPR. Third, the controller had not established a justified retention period for the data collected during the external assessment. Applying a general ten-year retention period for accounting records was not shown to be necessary for the creditworthiness assessment, in violation of Article 5(1)(e) GDPR. The DPA also found that reusing credit and commercial information to refine the corporate group’s rating system was incompatible with the original purpose for which the data had been collected. Since the retained information could become outdated, this processing also violated the purpose limitation and accuracy principles under Articles 5(1)(b) and (d) GDPR. The DPA ordered the controller to adopt a compliant access-response template, provide the relevant information to the data subjects involved and establish procedures enabling rectification, human intervention and the possibility to challenge decisions. The controller had six months to demonstrate compliance. Finally, the DPA imposed a €1,400,000 fine, taking into account the seriousness and scale of the infringements, the impact on approximately one million data subjects and the risk of refusal of essential energy services. It also considered the controller’s cooperation, lack of previous relevant infringements and remedial measures as mitigating factors.

### HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens

*Source: HDPA (Greece), 2026-05-13 — https://overview.legal/posts/144044 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_12/2026*

Facts — The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of Undesirable Aliens. In response to the Authority's request for clarifications, the competent Directorate of the Ministry of Citizen Protection informed the DPA that: • By a decision dated 27-07-2017, an entry ban and registration in the National Registry of Undesirable Aliens were imposed on the complainant for reasons of national security. • Following temporary 48-hour lifts of the measure for humanitarian reasons in 2019, the entry ban was re-imposed. • Subsequent decisions in 2020, 2023, and 2025 maintained the entry ban and renewed his registration in the National Registry of Undesirable Aliens for successive three-year periods, as the grounds for registration remained active. • The explicit grounds and documentation behind the registration were not disclosed to the complainant because the competent Directorate classified the file as restricted/classified service material. The complainant and his attorney attended a DPA hearing on 22-04-2026, arguing that the registration lacked specific, adequate, or definitive justification regarding any threat to public order or national security. They noted that the complainant has no criminal convictions, poses no threat, and possesses strong ties, residency, and business operations in the region of Northern Epirus and Greece, meaning the entry ban severely disrupts his professional and family life. Holding — According to the provisions of Article 82(1) of Law 3386/2005, foreign nationals whose presence in Greek territory constitutes a threat to national security, public safety, or public order can be registered in the National Registry of Undesirable Aliens, with registrations subject to an ex officio review every three years. Furthermore, pursuant to the provisions of Article 54(2) and Article 55(4) of Law 4624/2019 (the Greek law implementing the GDPR), the data controller is legally empowered to restrict or omit the provision of information and to deny a data subject access to their personal data when dictated by reasons of national security or public order. These national provisions are explicitly anchored in Article 23 GDPR (specifically Article 23(1)(a)GDPR and Article 23(1)(c) GDPR), which permits Member State law to restrict the scope of the obligations and data subject rights (such as the right to be informed under Article 13 GDPR - Article 14 GDPR and the right of access under Article 15 GDPR) to safeguard national security and public security. In the present case, the evidence demonstrated that the complainant's initial registration and subsequent renewals in the National Registry of Undesirable Aliens were executed lawfully for reasons of national security. The Ministry of Citizen Protection, acting as the data controller, exercised its legal discretion under these frameworks to weigh these interests and correctly determined that the underlying operational decision constitutes classified material that cannot be disclosed to the data subject. Consequently, the fundamental principles of data protection law were not breached, and the Hellenic DPA rejected the complaint as unfounded.

### AKI (Estonia) - No. 2.1-1/24/397-890-38

*Source: AKI (Estonia), 2026-04-16 — https://overview.legal/posts/53882 — original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38*

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

## Recent developments

### Datatilsynet (Denmark) - 2023-31-0321

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291258 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2023-31-0321*

Holding Holding. Holding The DPA, following CJEU precedent, maintained that the information appearing within the logs concerning employees access to a customer’s account are covered by the right of access in Article 15 GDPR.1 Nonetheless, considering the bank informed complainant that the requested log information is no longer available, and that the requested logs do not fall under the retention obligation pursuant to Article 30 Anti-Money Laundering Act, the DPA found no grounds to set these e

### LinkedIn locks your GDPR rights behind a paywall

*Source: noyb - European Center for Digital Rights, 2026-05-05 — https://overview.legal/posts/53127 — original: https://noyb.eu/en/linkedin-locks-your-gdpr-rights-behind-paywall*

Data Subject Rights LinkedIn tracks the visits to profile pages. However, if you want to see who has visited your own profile, you have to pay. The Microsoft subsidiary uses these and other ‘insights’ as an incentive for people to sign up for its paid Premium membership. It is unclear whether this tracking of visitors is legal. What is clear, however, is that if this data is displayed as part of a premium membership, it should also be accessible in response to an access request under Article 15

### Digital Omnibus reality check: 83.5% of access requests not properly answered

*Source: noyb - European Center for Digital Rights, 2026-04-16 — https://overview.legal/posts/53129 — original: https://noyb.eu/en/digital-omnibus-reality-check-835-access-requests-not-properly-answered*

Data Subject Rights The most commonly exercised right under the GDPR is the right of access to one’s personal data that is being processed by companies. After all, it’s often the prerequisite to know if there is inaccurate or unlawful personal data that needs to be corrected or deleted. However, a new analysis of noyb cases shows: Only 16.5% of all access requests noyb has sent to companies in the past 8 years received a satisfactory reply, while 53.7% of replies were incomplete – and almost 30%

### GDPR Omnibus: EU “simplification” far removed from real business needs

*Source: noyb - European Center for Digital Rights, 2026-03-05 — https://overview.legal/posts/53131 — original: https://noyb.eu/en/gdpr-omnibus-eu-simplification-far-removed-real-business-needs*

GDPR Policy Ever since the European Commission has published its Digital Omnibus proposal, discussions about the workload the GDPR creates for businesses in Europe have intensified. Among other things, the Commission wants to restrict the Right of Access, allegedly to reduce the regulatory burden. But do these changes actually reflect the needs of privacy professionals working at companies? To find out more, noyb conducted a survey asking Data Protection Officers (DPOs) which elements of the GDP

### Digital Omnibus: EU DPAs reject many proposed changes to the GDPR

*Source: noyb - European Center for Digital Rights, 2026-02-11 — https://overview.legal/posts/52485 — original: https://noyb.eu/en/digital-omnibus-eu-dpas-reject-many-proposed-changes-gdpr*

GDPR Policy The EDPB (combining all independent data protection authorities) and the European Data Protection Supervisor (EDPS) published a joint opinion expressing serious concerns about key elements of the proposed GDPR and ePrivacy changes in the so-called “Digital Omnibus” proposed by the European Commission. Specifically, the authorities strongly oppose the proposed narrowing of the definition of personal data. The opinion also question the need for various key proposals, such as the legal

## Literature

### The Court of Justice on the Excessiveness of Access Requests under the GDPR

*Source: European Journal of Risk Regulation, 2026-07-09 — https://overview.legal/posts/83502 — original: https://doi.org/10.1017/err.2026.10117*

Abstract This case note comments on the preliminary ruling of the Court of Justice of the EU in Case C-526/24 Brillen Rottler v TC of 19 March 2026, which addresses the abuse of rights under the General Data Protection Regulation (GDPR), specifically in the context of requests for access to personal data under Article 15 GDPR and compensation under Article 82 GDPR. First, the Court held that even a first access request may be regarded as “excessive” where the controller demonstrates that it was

### HOW GDPR TREATS AUTOMATED DECISION-MAKING

*Source: Journal Scientific and Applied Research, 2025-11-14 — https://overview.legal/posts/132599 — original: https://doi.org/10.46687/jsar.v28i1.435*

This article examines how the General Data Protection Regulation (GDPR) regulates automated decision-making, including profiling, in the context of personal data processing. It analyzes the main provisions of Article 22 of the Regulation, as well as the conditions under which fully automated decisions that produce legal effects or significantly affect data subjects are permitted. The article highlights the rights of data subjects – the right to human intervention, the right to express their poin

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### Article 22 GDPR on Automated Individual Decision-Making: Prohibition or Data Subject Right?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132543 — original: https://doi.org/10.21552/edpl/2022/2/6*

### Practitioner’s Corner ∙ Exercising GDPR Data Subjects’ Rights: Empirical Research on the Right to Explanation of News Recommender Systems

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132544 — original: https://doi.org/10.21552/edpl/2020/4/17*

## Related topics

- **Right of Access** — https://overview.legal/topics/inzagerecht
  Data subject right to access their personal data
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/article-15-gdpr-access-procedures · 2026-08-22
