# Data Subject Rights Exercise Modalities and Procedures — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/data-subject-rights-exercise-modalities
> Sources are cited per item. Verify against the official texts before relying on them.

This content specifically addresses the transparent communication and practical modalities for how data subjects can exercise their GDPR rights, which is not adequately covered by existing topics focused on individual rights in isolation.

## Overview

## Legal Framework

Articles 12 through 15 GDPR form the procedural backbone for data subject rights exercise. Article 12(1) mandates that controllers facilitate rights exercise through transparent, easily accessible, and intelligible means, using clear and plain language. Article 12(2) requires controllers to provide information on action taken without undue delay and within one month of receipt, extendable by two further months where necessary given complexity or volume. Article 12(3) obliges controllers to justify any non-action, informing the data subject of the reasons and the availability of a complaint or judicial remedy. Articles 15 through 22 define the substantive rights themselves—access, rectification, erasure, restriction, portability, and objection—but their practical operability depends entirely on the Article 12 modalities. The rationale is structural: rights without accessible, procedurally sound mechanisms are effectively illusory.

## Key Developments

The CJEU's ruling in *Minister voor Immigrratie v. M* (Case C-553/13) established that compliance with the right of access does not require furnishing a literal copy of documents; providing a full summary in an intelligible form suffices, provided the data subject can verify accuracy and lawfulness of processing. This sets a practical floor for access responses while emphasizing functional adequacy over formal completeness. The Court also confirmed access as a precondition enabling rectification, erasure, and blocking.

In *Jehovah's Witnesses* (Case C-25/17), the Court rejected blanket refusals of access premised on third-party privacy concerns, requiring controllers to conduct case-specific balancing rather than invoking privacy categorically.

Enforcement actions reinforce these standards. The Italian Garante fined Green.mec. s.r.l. €1,000 for failing to adequately respond to a former employee's access request, demonstrating that incomplete or evasive responses trigger sanctions even at modest financial thresholds. The Romanian ANSPDCP fined SC Piramida Trade Invest SRL €3,000 for processing without sufficient legal basis, underscoring that lawful basis deficiencies compound procedural failures when rights requests expose underlying compliance gaps.

The EDPB's February 2026 identification of barriers to full erasure implementation signals continued regulatory scrutiny of how controllers operationalize response obligations, particularly where technical or legal obstacles are invoked.

## Practical Guidance

- Establish a single, documented intake channel for all rights requests and log receipt dates immediately—the one-month Article 12(2) deadline runs from receipt, not internal routing.
- For access requests, prepare intelligible summaries rather than raw document dumps, consistent with *Minister v. M*, but ensure summaries are sufficiently detailed for the data subject to verify accuracy and lawfulness.
- Never refuse access categorically on third-party privacy grounds; conduct individualized balancing per *Jehovah's Witnesses* and document the analysis.
- Implement a two-month extension protocol with documented complexity justifications and notify the data subject within the initial one-month period as required by Article 12(3).
- Train frontline staff to recognize rights requests expressed informally—Article 12 does not require magic words, and misidentification of a request was a factor in the Green.mec. enforcement.

## Case law

### HvJ EU 9 januari 2025, C‑394/23 (Mousse).

*Source: CJEU, 2025-01-09 — https://overview.legal/posts/50377 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0394*

HvJ EU 9 januari 2025, C‑394/23 (Mousse). Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20 (Vyriausioji tarnybinės etikos komisija), maar dat had hier ook heel logisch geweest.

### Österreichische Datenschutzbehörde v CRIF

*Source: CJEU, C-487/21, 2023-10-26 — https://overview.legal/posts/51486 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0487*

Right of access includes obtaining a copy in commonly used electronic form.

### Judgment of the Court (First Chamber) of 12 January 2023.#BE v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Articles 77 to 79 – Remedies – Parallel exercise – Relationship – Procedural autonomy – Effectiveness of the protection rules established by that regulation – Consistent and homo

*Source: Court of Justice of the European Union, C-132/21, 2023-01-12 — https://overview.legal/posts/132298 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0132*

In Case C-132/21, the Court of Justice of the European Union (First Chamber) issued a preliminary ruling responding to a referral from the Budapest High Court concerning the parallel exercise of GDPR remedies under Articles 77, 78, and 79. The underlying dispute involved data subject BE challenging the refusal by the Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian Data Protection Authority) of BE's request to obtain extracts from a sound recording of a shareholders' general meeting. The Court held that data subjects may simultaneously lodge a complaint with a supervisory authority and bring a judicial action against a controller, as Member States may not impose procedural rules that prevent the parallel exercise of these remedies in a manner that undermines the effective protection guaranteed by the GDPR and Article 47 of the EU Charter of Fundamental Rights.

### Judgment of the Court (Grand Chamber) of 2 March 2021.#Criminal proceedings against H. K.#Request for a preliminary ruling from the Riigikohus.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Directive 2002/58/EC – Providers of electronic communications services – Confidentiality of the communications – Limitations – Article 15(1) – Articles 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union – Legisl

*Source: Court of Justice of the European Union, C-746/18, 2021-03-02 — https://overview.legal/posts/132324 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0746*

In Case C-746/18, the CJEU Grand Chamber addressed a preliminary reference from the Estonian Supreme Court (Riigikohus) concerning whether EU law permits national legislation authorizing general and indiscriminate retention of traffic and location data by electronic communications providers and subsequent access by national authorities for criminal investigations. The Court reaffirmed that general and indiscriminate data retention is incompatible with Articles 7, 8, and 11 of the Charter and Article 15(1) of Directive 2002/58/EC, while allowing targeted retention with strict safeguards; it further held that data retained unlawfully may not be used as evidence in criminal proceedings, though national courts must assess whether access was independently justified and proportionate.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### Bundesverband der Verbraucherzentralen v Planet49 GmbH

*Source: CJEU, C-673/17, 2019-10-01 — https://overview.legal/posts/51473 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0673&ref=51473*

Pre-ticked checkboxes do not constitute valid consent. Consent must be active.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Google LLC v CNIL

*Source: CJEU, C-507/17, 2019-09-24 — https://overview.legal/posts/51476 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0507&ref=51476*

Right to delisting does not require global de-referencing under EU law.

### Peter Nowak v Data Protection Commissioner

*Source: CJEU, C-434/16, 2017-12-20 — https://overview.legal/posts/51480 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0434&ref=51480*

Examination scripts constitute personal data of the candidate.

### Google Spain SL and Google Inc. v AEPD and Mario Costeja González

*Source: CJEU, C-131/12, 2014-05-13 — https://overview.legal/posts/51472 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0131&ref=51472*

Established the right to be forgotten (delisting). Search engines are data controllers.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

### CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is

*Source: CJEU, 2010-06-29 — https://overview.legal/posts/6182 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62008CJ0028&ref=6182*

Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69)

## Guidance

### Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom

*Source: EDPB, edpb-opinion-202527-united-kingdom-adequacy-led-en, 2025-10-16 — https://overview.legal/posts/51407 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-272025-regarding-the-european-commission-draft-implementing-decision_en*

Adopted 1 Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom Adopted 16 October 2025 Adopted 2 Executive summary The European Commission endorsed its draft implementing decision on the adequate protection of personal data by the United Kingdom pursuant to the Law Enforcement Directive on 22 July 2025. On the same date, as part of the procedure towards the formal…

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

### Guidelines 07/2022 on certification as a tool for transfers

*Source: EDPB, edpb-guidelines-on-certification-as-a-tool-for-transfers, 2023-02-24 — https://overview.legal/posts/38131 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072022-on-certification-as-a-tool-for-transfers_en*

The GDPR requires in its Article 46 that data exporters shall put in place appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by data exporters under Article 46 for framing transfers to third countries by introducing, amongst others, certification as a new transfer mechanism (Articles 42 (2) and 46 (2) (f) GDPR). These guidelines provide guidance as to the applicati...

### Guidelines 06/2022 on the practical implementation of amicable settlements

*Source: EDPB, edpb-guidelines-on-the-practical-implementation-of-amicable-settlements, 2022-05-12 — https://overview.legal/posts/38072 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062022-on-the-practical-implementation-of-amicable-settlements_en*

The EDPB adopted Guidelines 06/2022 to provide practical guidance on the implementation of amicable settlements between supervisory authorities and controllers or processors under the GDPR. The guidelines address the scope and definition of amicable settlements, the legal basis for this power, and its procedural operation within the one-stop-shop mechanism, including the roles of the complaint-receiving competent supervisory authority and the lead supervisory authority. No fines are imposed as this is a guidance document rather than an enforcement decision.

### Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (LED) under Article 62

*Source: EDPB, contribution-of-the-edpb-to-the-european-commissions-en, 2021-12-14 — https://overview.legal/posts/125973 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/contribution-of-the-edpb-to-the-european-commissions_en*

Adopted Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive ( LED ) under Article 62 Adopted on 14 December 2021 2 3 The European Data Protection Board Having regard to Articles 51(1)(a)(b) and (h) of the Directive ( EU ) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal da ta by competent authorities for the purposes of the…

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

## Enforcement decisions

### CNIL fines energy supplier for mishandling data subject access and objection requests

*Source: CNIL (France), 2026-07-17 — https://overview.legal/posts/125641 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2022-011*

Facts — The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French DPA (CNIL) that they had encountered difficulties in exercising their rights of access to personal information about them, and objection to receiving commercial prospecting telephone calls from the controller. The complaints concerned data subject requests for rectification of personal data, late, erroneous, or no response to access to personal data and access to the origin of personal data, failure to cease processing of personal data after objection to the processing of data for commercial prospecting (marketing) purposes, and request for personal data deletion. The DPA appointed a rapporteur that carried out an audit of the website of the controller and investigated the various complaints of the data subjects. The controller in its defence argued that 1) the data subjects' access requests were not sent by the data subjects to the controller’s dedicated unit and that the person who received the requests did not know how to identify their purpose; 2) the procedures it had put in place were not respected because of human error; 3) there were a large number of requests received in 2020 during the health crisis and this was impeded by the disruptions that followed; 4) there were difficulties in obtaining the necessary information from its business partners, thus unable to properly inform data subjects about the source of their data; 3) It had taken steps to modify its processing activities to comply with the relevant applicable laws; 4) The breach affected barely a fraction of its customers. Beyond the direct complaints made by the data subjects, the DPA in its investigation noted that when subscribing online on the controller's website, the subscription form had no option for users to object to the use of their personal data for marketing purposes. The subscription form informed users that their personal data may be used by the controller to present offers to them at a later date. On this point, the controller argued that 5) the CPCE did not apply to the online subscription form, since the collection of personal data through the form was not intended to promote the company's products or services, but to offer assistance to the user in order to help them finalize the current subscription. Holding — The DPA held that the lack of an option for a user to object to the processing of their personal data for marketing purposes, at the time of collection, constitutes a breach of the provisions of article L. 34-5 of the French Post and Electronic Telecommunications Code (CPCE). The DPA observed that, in certain cases, the data subjects contacted for marketing purposes were not provided with any information required in Article 14 GDPR, such as the purposes of the processing or the existence of the various rights. They were not informed that the call was being recorded, nor of their right to object to it. The DPA observed that the controller had failed to respond, supplied erroneous responses, or responded late to several data subject requests, beyond the deadlines set by Article 12 GDPR, often after several reminders from the data subject. The DPA observed that the controller failed to process the various data subject’s requests for access to personal data, their origin, as well as access to recordings of telephone conversations concerning the data subjects within the time limit set with the obligations of Article 15 GDPR. The DPA finally observed that the controller continued to process the personal data of data subjects after objections from the data subjects to the processing of their personal data in breach of Article 21 GDPR. The DPA held that the controller cannot rely on its difficulties in obtaining information from its commercial partners to justify its failure to provide a response to the applicants in accordance with the applicable provisions. It is the duty of the controller to organize itself in such a way as to be able to ensure that requests for access are processed in accordance with the applicable provisions and, in particular, to provide information on the origin of the data. The DPA further held that although data subjects did not send their access requests directly to the unit in charge of responding to them, it is up to the controller, as long as the requests, one of which was directly addressed to the data protection officer, were received in clear terms by the controller, to process them within the time limits provided for and to ensure that they were transmitted to the competent department responsible for handling such requests. For these violations, the DPA fined the controller €1,000,000. The controller argued against the publication of the penalty decision, on the ground that publication would be disproportionate in light of the limited nature of the alleged breaches and its compliance. It also claimed that publication of the penalty would have a significant impact on the controller’s image and that it would be favorable to its main competitors, in a very competitive market. The DPA also decided to make its decision public on the CNIL website and on the Légifrance website and held that the controller will no longer be identified by name after a period of two years from its publication. The DPA noted that the company has taken measures to bring its processing into compliance with the applicable laws, and the efforts made by the company to comply throughout the procedure. The DPA also noted that the controller’s agents have had to attend awareness training on the subjects of the complaints.

### Greek DPA: Google breached Art. 17 GDPR erasure right over outdated criminal case links

*Source: HDPA (Greece), 2023-06-29 — https://overview.legal/posts/125608 — original: https://gdprhub.eu/index.php?title=HDPA_(Greece)_-_54/2024*

Facts — In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links - referring to criminal charges - appearing in search results based on their name. The data subject argued that these results contained outdated information about a closed criminal case involving them. The controller partially complied with the request but retained one link. The data subject then identified additional publications that required deletion. However, the controller failed to act within the 30-day deadline stipulated by Article 12(3) GDPR. Instead, it responded with an automated message, attributing the delay to the Covid-19 pandemic and claiming that the erasure request was incomplete because it lacked the court judgment clearing the data subject of charges. Before the DPA, the data subject argued that the pandemic is not a valid justification for delays and that the erasure request form does not allow attachments, preventing them from submitting supporting documents. The controller stated that it provides multiple channels for data subjects to request data erasure, including direct email contact with its DPO and the retained link in question referred to a comment, which allegedly did not meet the criteria for erasure or contain any information directly linking it to the data subject. Holding — The DPA found Google LLC to be the controller as it is responsible for the deletion process not Google Hellas/Athens. The DPA found, that contrary to the controller's statement the remaining link could be associated with the data subject’s identity and past criminal cases. Thus, the DPA held, that the erasure request must be fulfilled unless the controller demonstrates compelling and lawful reasons for continuing processing (Article 21(1) GDPR), which the DPA found lacking. The DPA held that the lack of an attachment option hinders the effective exercise of data subjects' rights, as they are forced to seek alternative communication methods. Thus, the controller fails to facilitate the erasure request process. Additionally the court found, that the controller did not comply with Article 12(3) GDPR, as a general, automated response does not meet it’s requirements and the contact link for the controller’s DPO did not include any contact details, making direct communication impossible in breach of Article 37(7) GDPR. Based on these findings, the DPA ordered the controller to: Provide an attachment option in the erasure request submission form. Stop sending automated responses to submitted requests. Publish the contact details of its DPO. Delete the remaining link, as requested by the data subject.

### Vodafone España SAU: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2020-07-31 — https://overview.legal/posts/46497 — original: https://www.enforcementtracker.com/ETid-382*

Unlawfull processing of a telephone number for marketing purposes even after the data subject had exercised its right to erasure

### Italian DPA: Enna Health Authority violated GDPR by publishing judicial data

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-18 — https://overview.legal/posts/109000 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_471/2026*

Facts — The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial records). The data subject contacted the controller and requested the controller to remove or redact the data. The controller responded that it would remove it promptly, however, the data subjects’ data remained in a separate page of the controller’s website. The data subject later brought a complaint to the DPA. The controller stated that it completely removed the data subject’s personal data after the DPA requested it, including data that was accidentally included in its website. Holding — The DPA found a violation of Articles 5, 6 and 10 GDPR. The DPA first clarified that the controller processed data related to the commission of crimes or pending criminal proceedings involving the data subject. This data fell under the scope of Article 10 GDPR, meaning the controller had specific obligations for the processing activity to be lawful. The DPA considered that the controller had processed this data unlawfully by publishing it, and had failed to comply with the principle of lawfulness (Article 5(1)(a) GDPR) and data minimisation (Article 5(1)(c) GDPR). The DPA also found a violation of Article 17 GDPR. The DPA stated that the controller failed to adequately respond to the data subject’s request for erasure by not recognising that the data remained visible in a different section of its website. The DPA fined the controller €20,000.

### NAIH (Hungary) - NAIH-4667-10/2022

*Source: NAIH (Hungary), 2022-09-22 — https://overview.legal/posts/122837 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-4667-10/2022*

Facts — A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested access to his personal data contained in the eKRÉTA (Public Education Registration and Study Fund) system. This system was used by the school (the controller) to record and capture the grade history of pupils, including the data subject. The controller failed to provide the requested personal data. However, it did ask KRÉTA (the processor) whether additional information regarding manipulation of grades can be exracted from the system and informed the parent that no such possibility existed. Consequently, the parent of the data subject filed a complaint with the Hungarian DPA. The parent submitted that the overwriting and deletion of the data subject's grades could not be tracked on the eKRÉTA administrative interface accessible to parents. The parent proved their right of representation before the DPA with the child's birth certificate. The DPA initiated an investigation into the matter. Holding — The DPA reitarrated, based on the definitions of the GDPR, that a subject grade is data related to the data subject's academic evaluation and should be considered personal data. Hence, any operation performed on the data is considered data processing. In the present case, the personal data was allegedly modified or overwritten at a time other than when the semester grade notice was issued to pupils. With regard to the personal data of a minor, the parent is not considered to be the data subject pursuant to Article 4(1) GDPR. At the same time, the parent can submit a data subject request to the controller on behalf of the minor data subject. The parent wanted to exercise this right in order to have access to the information related to the management of the grade, regarding the overwriting and deletion of the grade, based on Article 15(1) GDPR. The purpose was to establish the legality of the data management on behalf of the controller. The DPA confirmed that the processor (the KRÉTA system) provided information on of the date on which the grades were entered, following a request from the controller. However, the processor could not track whether a certain grade entry was overwritten or deleted form the system. This request was in compliance with Article 28(3) GDPR since the data controller validated the data subject's request by asking for the information in question from the data processor. The DPA found that the allegation that the personal data in question had been manipulated was not substantiated and that the controller had not committed any infringement in the course of complying with the data subject's request to access the data in question. The DPA noted that the accessed data was not provided to the data subject, not in an attempt to conceal any manipulated merits, but rather due to the fact that the requested data was not in the controller's possession yet. The DPA concluded that the general data processing of the controller did not directly affect the rights or legitimate interest of the data subject. In view of this, the DPA rejected the complaint.

### SC Piramida Trade Invest SRL: Non-compliance with general data processing principles

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2025-06-26 — https://overview.legal/posts/48839 — original: https://www.enforcementtracker.com/ETid-2724*

The Romanian DPA has imposed a fine of EUR 3,000 on SC Piramida Trade Invest SRL. The controller processed personal data without a sufficient legal basis and without sufficient technical and organisational measures to ensure data security. The controller also failed to properly react to a request to exercise data subject rights.

### KUGELCHEN PROPIERTIES, S.L.: Insufficient legal basis for data processing

*Source: Spanish Data Protection Authority (aepd), 2023-07-07 — https://overview.legal/posts/48058 — original: https://www.enforcementtracker.com/ETid-1943*

The Spanish DPA has imposed a fine of EUR 2,000 on KUGELCHEN PROPIERTIES, S.L.. The controller had continued to process data of the data subject, despite exercising their right to erasure.

### Modaone SRL: Insufficient fulfilment of information obligations

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2023-03-13 — https://overview.legal/posts/47797 — original: https://www.enforcementtracker.com/ETid-1682*

The Romanian DPA has imposed a fine of EUR 2,000 on Modaone SRL. An individual had filed a complaint with the DPA for having received advertising messages by e-mail, although they had objected to receiving such messages and this had been confirmed to them by the controller. In the course of its investigation, the DPA also found that the controller had not provided data subjects with sufficient, correct and up-to-date information about the processing of their personal data. In addition, the DPA f

## Recent developments

### EDPB identifies challenges hindering the full implementation of the right to erasure

*Source: European Data Protection Board, 2026-02-18 — https://overview.legal/posts/52724 — original: https://www.edpb.europa.eu/news/news/2026/edpb-identifies-challenges-hindering-full-implementation-right-erasure_en*

Brussels, 18 February - The European Data Protection Board (EDPB) has adopted a report on its Coordinated Enforcement Framework (CEF) action on the right to be forgotten (Art.17 GDPR). The Board selected this topic as it is one of the most frequently exercised GDPR rights and one about which DPAs frequently receive complaints from individuals. The main objectives of this coordinated action are to ensure that the right to erasure is effectively exercised by individuals in Europe and understand ho

### Greek SA fines Clearview AI for EUR 20M

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/6252 — original: https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data#entry-1098*

A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

### Dirkzwager: ABRvS geeft uitleg aan het AVG-begrip "de instelling, uitoefening of onderbouwing van een rechtsvordering"

*Source: Dirkzwager, 2022-10-05 — https://overview.legal/posts/6332 — original: https://www.dirkzwager.nl/kennis/artikelen/abrvs-geeft-uitleg-aan-het-avg-begrip-de-instelling-uitoefening-of-onderbouwing-van-een-rechtsvordering/#entry-968*

> Privacybescherming is niet absoluut. Dat staat zelfs letterlijk zo in de privacywetgeving. De AVG bevat daarom ook allerlei uitzonderingen. Een van de uitzonderingen die enkele keren terugkomt in de AVG ziet op de verwerking van persoonsgegevens in het kader van "de instelling, uitoefening of onderbouwing van een rechtsvordering". Tot op heden was echter niet heel erg duidelijk wat die woorden nu precies betekenen. Een recente uitspraak van de Afdeling bestuursrechtspraak van de Raad van State

### What Happened to the Risk-Based Approach to Data Transfers?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/6271 — original: https://fpf.org/blog/what-happened-to-the-risk-based-approach-to-data-transfers/#entry-912*

The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute principles), the RBA of Article 24 therefore applies. Other than the DPAs assume, this is not contradicted by the ECJ in Schrems II nor by the EDPB recommendations on additional measures following the Schrems II judgment, according to Lokke Moerel, Professor of Global ICT Law at Tilburg University and a Dutch Cyber Security

### De Griekse toezichthouder heeft Clearview AI een boete van 20 miljoen euro opgelegd.

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/51829*

Een overzicht van de boete die aan IAPP is opgelegd: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

## Literature

### The Court of Justice on the Excessiveness of Access Requests under the GDPR

*Source: European Journal of Risk Regulation, 2026-07-09 — https://overview.legal/posts/83502 — original: https://doi.org/10.1017/err.2026.10117*

Abstract This case note comments on the preliminary ruling of the Court of Justice of the EU in Case C-526/24 Brillen Rottler v TC of 19 March 2026, which addresses the abuse of rights under the General Data Protection Regulation (GDPR), specifically in the context of requests for access to personal data under Article 15 GDPR and compensation under Article 82 GDPR. First, the Court held that even a first access request may be regarded as “excessive” where the controller demonstrates that it was

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data

---
Generated by overview.legal · https://overview.legal/topics/data-subject-rights-exercise-modalities · 2026-08-22
