# Right of Access — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/inzagerecht
> Sources are cited per item. Verify against the official texts before relying on them.

Data subject right to access their personal data

## Overview

## Legal Framework

The right of access is anchored at both the constitutional and statutory levels. [Article 8 of the EU Charter](/laws/eu/art-8-38440) establishes the fundamental right, providing that "[e]veryone has the right of access to data which has been collected concerning him or her." [Article 15 GDPR](/laws/gdpr/art-15) operationalises this right in detail, requiring controllers to confirm whether personal data are being processed and, where so, to provide access to the data together with a specified catalogue of supplementary information — purposes, categories of data, recipients, retention periods, and the existence of other data-subject rights.

> "The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information"
> — GDPR Art. 15(1)

Where data are transferred to third countries, Article 15(2) adds a right to be informed of appropriate safeguards. Article 15(3) obliges the controller to provide a copy of the personal data. Supporting obligations under [Article 32](/laws/gdpr/art-32) (security of processing) and [Article 38](/laws/gdpr/art-38) (DPO involvement) ensure that controllers can retrieve and disclose data in a structured, secure manner.

## Key Developments

The CJEU's ruling in *Minister v. M* (2014) remains the leading authority on the scope of access. The Court held that the right of access exists to enable the data subject to verify accuracy and lawfulness of processing — not to obtain administrative documents more broadly. Crucially, the Court drew a line between personal data and legal analysis contained in administrative minutes:

The Court confirmed that providing "a full summary of those data in an intelligible form" satisfies the access obligation — controllers need not hand over raw documents if a comprehensive, intelligible summary allows the data subject to check accuracy and exercise downstream rights.

The earlier *X* judgment (2013) established the procedural baseline: access must be provided without constraint, excessive delay, or excessive expense. The *Bara* decision (2015) reinforced that where data are not obtained from the data subject, the controller must still inform the individual of the categories of data concerned and the existence of the right of access and rectification.

## Status of the Debate

This topic is actively contested in court. The core fault line concerns the boundary between personal data and administrative or legal analysis — the *Minister v. M* distinction is repeatedly tested in national litigation, and courts diverge on how far the access right reaches into internal deliberations, profiling logic, and automated decision-making outputs. The EDPB's 2025 coordinated enforcement action on right-of-access implementation signals that regulators are also pushing to define practical thresholds. What would resolve the open question is a further CJEU reference clarifying whether the "intelligible summary" standard from *Minister v. M* survives under the GDPR's expanded Article 15(1)(h) requirements for meaningful information about profiling logic.

## Practical Guidance

- **Confirm and disclose**: On receipt of an access request, confirm whether processing is underway and provide the data plus all Article 15(1)(a)–(h) information, including sources and automated decision-making logic where applicable.
- **Provide an intelligible summary**: Following *Minister v. M*, a full, intelligible summary of personal data satisfies the access right; raw administrative documents need not be disclosed where they contain legal analysis beyond the personal data.
- **Respond without excessive delay**: Per the *X* judgment, ensure responses are provided without constraint, excessive delay, or excessive expense — align internal SLAs with the one-month GDPR deadline.
- **Involve the DPO early**: [Article 38(1)](/laws/gdpr/art-38#par-2) requires DPO involvement in access requests; ensure the DPO has resources and access to processing operations to validate completeness.
- **Secure the retrieval process**: [Article 32](/laws/gdpr/art-32#par-1-pnt-c) requires technical measures ensuring data can be restored and accessed in a timely manner — maintain retrieval capabilities that support access-request deadlines.

## Legislation (full text of key provisions)

### Right of access by the data subject

*Source: GDPR, gdpr-art-15-en, 2016-04-27 — https://overview.legal/posts/90406*

### Processing under the authority of the controller or processor

*Source: GDPR, gdpr-art-29-en, 2016-04-27 — https://overview.legal/posts/90592*

The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.

### Recital 63 — data subject right of access

*Source: GDPR, gdpr-rec-63-en, 2016-04-27 — https://overview.legal/posts/91641*

A data subject should have the right of access to personal data which have been collected concerning him or her, and to exercise that right easily and at reasonable intervals, in order to be aware of, and verify, the lawfulness of the processing. This includes the right for data subjects to have access to data concerning their health, for example the data in their medical records containing information such as diagnoses, examination results, assessments by treating physicians and any treatment or interventions provided. Every data subject should therefore have the right to know and obtain communication in particular with regard to the purposes for which the personal data are processed, where possible the period for which the personal data are processed, the recipients of the personal data, the logic involved in any automatic personal data processing and, at least when based on profiling, the consequences of such processing. Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data. That right should not adversely affect the rights or freedoms of others, including trade secrets or intellectual property and in particular the copyright protecting the software. However, the result of those considerations should not be a refusal to provide all information to the data subject. Where the controller processes a large quantity of information concerning the data subject, the controller should be able to request that, before the information is delivered, the data subject specify the information or processing activities to which the request relates.

### Recital 146 — Commission decision procedural rights and confidentiality

*Source: DSA, dsa-rec-146-en, 2022-10-19 — https://overview.legal/posts/95689*

The provider of the very large online platform or of the very large online search engine concerned and other persons subject to the exercise of the Commission’s powers whose interests may be affected by a decision should be given the opportunity of submitting their observations beforehand, and the decisions taken should be widely publicised. While ensuring the rights of defence of the parties concerned, in particular, the right of access to the file, it is essential that confidential information be protected. Furthermore, while respecting the confidentiality of the information, the Commission should ensure that any information relied on for the purpose of its decision is disclosed to an extent that allows the addressee of the decision to understand the facts and considerations that led up to the decision.

### Recital 164 — supervisory authority access and professional secrecy

*Source: GDPR, gdpr-rec-164-en, 2016-04-27 — https://overview.legal/posts/91843*

As regards the powers of the supervisory authorities to obtain from the controller or processor access to personal data and access to their premises, Member States may adopt by law, within the limits of this Regulation, specific rules in order to safeguard the professional or other equivalent secrecy obligations, in so far as necessary to reconcile the right to the protection of personal data with an obligation of professional secrecy. This is without prejudice to existing Member State obligations to adopt rules on professional secrecy where required by Union law.

## Case law

### Council of State: Tax Authority satisfied GDPR access request on FSV fraud registration

*Source: Council of State, 2026-08-05 — https://overview.legal/posts/187482 — original: https://gdprhub.eu/index.php?title=RVS_-_202307578/1/A3*

Facts — The personal data of an individual was stored in the Fraud Detection System (FSV), an application used by the Dutch Tax Authority between 2012 and 2020 to record potential indicators of tax fraud. The Minister of Finance was the controller. The data subject submitted an access request under Article 15 GDPR. In particular, she requested information about the personal data processed, the purposes of the processing, the recipients of the data, its source and retention period, and any automated decision-making concerning her. The controller provided an overview of the personal data stored in the FSV and answered the data subject’s questions. The data subject objected to the decision, claiming that the controller had not disclosed all information relating to her registration. The controller rejected the objection. It explained that the data subject had been selected for a manual review of her tax return under Project 1043, an anti-fraud initiative launched by the Dutch Tax, and was consequently registered in the FSV. It also stated that the data was accessible only to employees of the Tax Authority and had not been disclosed to other organisations. The District Court of Amsterdam dismissed the data subject’s appeal. It held that the proceedings concerned compliance with the GDPR access request and not the lawfulness of her inclusion in the FSV or any alleged resulting damage. The data subject appealed this judgment before the Council of State. Holding — The Council of State dismissed the appeal and upheld the judgment of the District Court. The Court held that there was no evidence that the controller had incorrectly applied Article 15 GDPR. The controller had provided an overview of all personal data concerning the data subject processed in the FSV, explained the purposes of the processing and clarified the circumstances of her registration under Project 1043. Although the data subject suspected that the controller held additional information, she did not provide concrete evidence supporting this claim. The Court also found no indication that she had been classified as a fraudster or that her personal data had been disclosed to other organisations. The Court further clarified that the lawfulness of the data subject’s registration in the FSV, the deletion of her data and any claim for compensation fell outside the scope of the access proceedings. Consequently, the Court confirmed the contested judgment and did not award litigation costs.

### EWCA - Dawson-Damer v Taylor Wessing LLP

*Source: EWCA, 2026-07-17 — https://overview.legal/posts/125652 — original: https://gdprhub.eu/index.php?title=EWCA_-_Dawson-Damer_v_Taylor_Wessing_LLP*

Facts — This case concerns a data subject access request (SAR) under the Data Protection Act (DPA) 1998. The data subjects were beneficiaries under a trust. The data controller was a firm of solicitors, holding trust money as trustees. Following the appointment of further trustees and transfer of trust money into a new trust for other discretionary beneficiaries, the data subjects challenged the validity of these appointments and served the data controller with a SAR under section 7(2) DPA 1998. The data controller refused to make the disclosure, stating that the personal data was covered by Legal Professional Privilege (LPP), and therefore exempted from disclosure under Schedule 7 para. 10 DPA 1998. Furthermore, the data controller asserted that the supply of information required a disproportionate effort. The data subjects contended that many categories of personal data held by the data controller were not privileged and that, if any, the only privilege on which the data controller could rely was litigation privilege. The data subjects applied to the court for a declaration under section 7(9) DPA 1998 that the data controller had not complied with the request and to oblige the data controller to comply with the SAR. At trial, the court agreed with the data controller and refused to make such an order. The appellate court had to determine: whether, taking a narrow view, the LLP exception is limited to documents subject only to legal professional privilege under English law; whether, if the narrow view is correct, any further search would involve "disproportionate effort" for the purposes of section 8(2) DPA 1998 so that the data controller is excused from doing so; whether the exercise of the court’s discretion under section 7(9) DPA 1998 can be refused because the data subject's real motive was to use the information in legal proceedings against the data controller. Holding — The Court of Appeal held that 'privilege' in the LLP exception is limited to legal professional privilege. It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort. The High Court judge was wrong not to exercise its discretion under section 7(9) DPA 1998 to order the data controller to comply with the request. On Issue 1 - Extent of the Legal Professional Privilege Exception: The purpose of Directive 95/46/EC (the Directive) was to regulate the activities of data controllers on a territorial basis. Therefore, the words "legal proceedings" in sched. 7 para. 10 DPA 1998 refer to legal proceedings in any part of the UK. If Parliament had intended to legislate for events which occur outside the territory of the UK, it would have introduced provisions specifying which parts of the world were relevant for this purpose and under which conditions the privilege applied. The LPP exception is expressly limited to legal professional privilege. Documents not disclosable to a beneficiary of a trust under trust law principles are not within the LPP exception. Insofar as the exception was interpreted purposively as also including documents covered by the trustees' right of non-disclosure, the Directive would have to name appropriate objectives which could support an interpretation along these lines. However, the DPA does not contain such exceptions. The court concluded at para. 45 that the LPP exception “relieves the data controller from complying with a SAR only if there is relevant privilege according to the law of any part of the UK.” Since the data in question is not covered by the LPP under English law and no other exemption under the DPA 1998 applies, the SAR must be granted. On Issue 2 - Whether compliance with the request would involve disproportionate effort: The public interest reasons set out in the Directive for giving people control over the data held about them require that SARs should be enforced so far as possible. Under section 8(2) DPA 1998 the data controller is obliged to supply copies of information constituting personal information to the data subject, "unless …the supply of such a copy is not possible or would involve disproportionate effort." The effort, the data controller undertakes must be weighed in a proportionality exercise against the potential benefits that the provision of the information could bring to the data subject. That includes the possibility that there may be limits to a search in certain circumstances, see Ezsias v Welsh Ministers [2007] EWHC B15 (QB). The court held at para. 75 ff, that “It falls to the data controller to show that the supply of a copy of the information in permanent form would involve disproportionate effort”. However, “disproportionate effort must involve more than an assertion that it is too difficult to search through voluminous papers”. The data controller “must produce evidence to show what it has done to identify the material and to work out a plan of action.” On Issue 3 - Whether the request can be declined because the data subject intended to use the information against the data controller: The purpose of the Directive is to protect fundamental rights conferred by EU law. The court found that nothing in Directive or the DPA 1998 limits the purpose for which data subjects may request their data or allows data controllers not to provide data based solely on the on the basis of the purpose of the data subject. Also, Parliament has not expressly required data subjects to show that they have no other purpose. The court distinguished Dunn v Durham County Council [2003] 1 WLR 2305, Lin & Anor v Commissioner of Police of the Metropolis [2015] EWHC 2484 and Kololo v Metropolitan Police Commissioner [2015] 1 WLR 3702. Durant v Financial Services Authority [2004] FSR 573 at para. 27 also does not establish a “no other purpose rule” and should only be interpreted to mean that “a person could not claim that something was personal data because it would assist him in obtaining discovery or in litigation or complaints against third parties.” (para. 111) The court found that the trial judge had wrongly refused to enforce the request just because the appellants intended to use the information obtained in other proceedings. The section 7(9) DPA 1998 discretion must be applied with a view to fulfilling the purposes of the DPA.

### Spanish court reviews DPA decision on KFC Spain website privacy information and DPO

*Source: National Court, 2026-07-16 — https://overview.legal/posts/184690 — original: https://gdprhub.eu/index.php?title=AN_-_SAN_3154/2026*

Facts — In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website. The data subject claimed that the privacy information applicable to users in the EEA was not easily accessible, as the main privacy link led to a global policy. The data subject also alleged that users could not create an account without apparently accepting promotional communications, that the registration form did not correctly link to the privacy policy and that the controller had not appointed a data protection officer. The complaint further identified deficiencies in the privacy information, including insufficient details about the identity of the controller, recipients, international transfers and retention periods. During the investigation, the controller acknowledged that certain links and checkbox descriptions had been incorrectly configured and undertook to correct them. It maintained, however, that its privacy information was provided through several interconnected documents and that it was not required to appoint a DPO. According to the controller, it did not engage in profiling, its marketing communications were based on opt-in consent and the processing of personal data was ancillary to its restaurant business. The DPA found that the information provided on the website was excessively generic and did not comply with Article 13 GDPR. It imposed a €5,000 fine and ordered the controller to bring its website into compliance. The DPA also concluded that the controller’s processing activities required the appointment of a DPO under Article 37(1)(b) GDPR. It imposed a further €20,000 fine and ordered the controller to appoint a DPO. The controller appealed both the sanctioning decision and a subsequent resolution requiring it to demonstrate that it had implemented corrective measures. Holding — The Court dismissed the appeal and upheld the total fine of €25,000. Regarding Article 13 GDPR, the Court found that the controller’s privacy information was excessively generic and did not clearly explain the purposes, legal bases and relevant circumstances of the processing. It also held that the DPA was not limited to investigating only the exact issues identified in the initial complaint. The €5,000 fine was proportionate despite the controller’s subsequent corrective action. Regarding Article 37(1)(b) GDPR, the Court held that the controller was required to appoint a DPO. Although its primary business was the provision of restaurant services, the processing of customer data was inseparable from its online ordering, marketing, loyalty and customer-management activities. The processing also involved regular and systematic monitoring, as the controller continuously collected data such as customer preferences, browsing history, IP addresses, cookies and geolocation for commercial and operational purposes. Considering the number of data subjects, the volume and variety of data, the duration of the processing and its nationwide scope, the Court concluded that the processing was carried out on a large scale.

### CJEU - C-526/24 - Brillen Rottler

*Source: GDPRhub, C-526/24, 2026-07-13 — https://overview.legal/posts/96819 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-526/24_-_Brillen_Rottler*

Facts — On 16 March 2023, the data subject (a private individual living in Vienna) subscribed to the ‘newsletter’ on the website of the controller (a family run optician company established in North Rhine-Westphalia) by entering his personal data in the registration form, confirming his consent to data processing by ticking a box and submitting the form. On 29 March 2023, the data subject sent by fax an information request pursuant to Article 15 GDPR. The controller acknowledged receipt of the request and stated that it would respond to it within the one-month period. However, by letter of 26 April 2023, the controller refused to provide the information since it classified the information request as an abuse of right for the purposes of the second sentence of Article 12(5)(b) GDPR. The controller sought a declaration from the referring court that the data subject is not entitled to compensation in the amount of €1000. The court decided to refer the following questions set out in point I. to the CJEU for a preliminary ruling pursuant to Article 267 TFEU: Is the second sentence of Article 12(5) GDPR to be interpreted as meaning there cannot be an excessive information request from the data subject when the first request is made to the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that the controller can refuse an information request from the data subject if the data subject intends to use the information request to provoke claims for damages against the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that grounds for refusing to provide information can be provided by publicly available information about the data subject which suggests that the data subject is asserting claims for damages against the controller in a large number of cases of infringement of the law relating to the protection of personal data? Is Article 4(2) GDPR to be interpreted as meaning that an information request from a data subject to the controller pursuant to Article 15(1) GDPR and/or a response to that request constitutes processing within the meaning of Article 4(2) GDPR? In view of the first sentence of recital 146 GDPR, is Article 82(1) GDPR to be interpreted as meaning that only damage which the data subject suffers or has suffered as a result of processing is eligible for compensation? Does this mean that for there to be a claim for damages under Article 82(1) GDPR – assuming causal damage to the data subject exists – there must necessarily have been processing of the data subject’s personal data? If the answer to Question 5 is in the affirmative: Does this mean that the data subject – assuming causal damage exists – has no claim for compensation under Article 82(1) GDPR solely on the basis of an infringement of his or her right to information under Article 15(1) GDPR? Is Article 82(1) GDPR to be interpreted as meaning that the controller’s objection relating to an abuse of right in relation to an information request from the data subject cannot, in view of EU law, consist in the fact that the data subject brought about processing of his or her personal data solely or inter alia in order to assert claims for damages? If the answers to Questions 5 and 6 are in the negative: Does the mere loss of control and/or uncertainty about the processing of the data subject’s personal data associated with an infringement of Article 15(1) GDPR constitute non-material damage to the data subject within the meaning of Article 82(1) GDPR or does it also require a further (objective or subjective) restriction and/or (significant) damage to the data subject? Advocate General Opinion — In addressing the first, second, third, and seventh questions referred by the national court: — The excessive character of an initial access request Advocate General emphasized that while an initial access request can, in theory, be considered "excessive," this must be limited to exceptional circumstances since the right of access is fundamental and linked to other GDPR rights. The circumstances that allow a request to be characterized as ‘excessive’ The Advocate General analyzed when a data access request under Article 15 GDPR could be considered excessive under Article 12(5) GDPR . He concluded that such a request may only be treated as excessive if the controller can demonstrate an abusive intention. However, merely having a pattern of making similar claims in many cases does not, on its own, prove abuse, and strict criteria must be applied to ensure that the fundamental right of access is not unduly restricted. In addressing the the fourth, fifth and sixth questions referred by the national court : — The event giving rise to the damage within the meaning of Article 82 of the GDPR The Advocate General analyzed whether only data processing that violates the GDPR can give rise to compensation under Article 82 GDPR. He concluded that not just unlawful processing, but any infringement of the GDPR can be a basis for compensation, provided that damage and a causal link are proven. The concept of ‘processing’ for the purposes of the right to compensation The Advocate General explains that although sending an access request is not "processing" under the GDPR, a controller’s act of responding to such personal data , which can fall under the scope of the GDPR. However, the actual damage arises not from this technical processing, but from the unjustified refusal to fulfill the access request. To ensure the effectiveness of Article 15 GDPR and the right to compensation under Article 82, the concept of “processing that caused the damage” should be interpreted broadly. The existence of non-material damage The Advocate General clarifies that a violation of Article 15 GDPR alone does not automatically entitle a data subject to compensation; the individual must prove actual non-material harm resulting from the infringement. The Court has recognized that even temporary loss of control over personal data may qualify as non-material damage, without requiring a minimum severity threshold. Conclusion — In the Advocate General’s view, an initial access request under Article 15 GDPR can only be considered “excessive” where the data controller can clearly demonstrate, based on all relevant circumstances, that the data subject acted with abusive intent, specifically, where the individual consented to the processing of their personal data solely to submit an access request and subsequently claim compensation. Importantly, the mere fact that a data subject has frequently exercised their right to compensation in similar cases does not, in itself, justify classifying the request as excessive. Moreover, under Article 82(1) GDPR, a data subject is entitled to compensation for damage resulting from a violation of the Regulation, even if that damage was not directly caused by the processing of personal data. Holding — Is a first access request excessive in accordance with Article 12(5) GDPR, and under what circumstances is it possible to establish such an excessive nature? (Questions 1, 2, 3 and 7) — The court first noted that the GDPR guarantees the right to access in Article 15(1) GDPR. However, Article 12(5) GDPR allows the controller to charge a reasonable fee or refuse the request if it is “manifestly unfounded or excessive”. Given the fact that the GDPR does not define these terms, the concept must be understood through its wording and objectives pursued . The court stated that Article 12(5) GDPR does not rule out the possibility that a first request may be considered excessive. This is because the repetitive character referred to in this article is an example, meaning “excessive” is not necessarily limited to the number of requests. However, this must be interpreted strictly; therefore, the controller may only rely on this in exceptional cases, and the controller bears the burden of demonstrating the excessive nature of the request. In terms of circumstances, the court noted that proof of an abusive practice must meet objective and subjective requirements. The court noted that the data subject’s access request met the formal requirements, as the data subject exercised the right to access to be aware of the processing and verify its lawfulness in accordance with the aim of Article 15 GDPR. The subjective element, on the other hand, concerns the intention of the data subject; in this case the controller must unequivocally demonstrate that the data subject has made the request for a purpose other than being aware of the processing and verifying its lawfulness (such as artificially creating conditions to obtain compensation). The court stated that it is necessary to take into consideration all the circumstances of the case, including the fact that the data subject provided the data voluntarily, or the time elapsed between providing the data and requesting access. The court noted that the controller may use publicly available information, provided that it is supported by other material. The court concluded that it was for the referring court to determine whether the controller demonstrated that the data subject made the access request with abusive intentions. Does Article 82(1) confer the right to compensation for damages resulting from an infringement of the right to access? (questions 5 and 6) — The court first noted that under Article 82(1) GDPR data subjects that have suffered (non)material damages as a result of an infringement of the GDPR are entitled to compensation. Since the Article does not refer to “processing”, the right to compensation is not limited to damage resulting from the processing of personal data. In this case, an infringement is liable for damages from the refusal to act, rather than from the actual processing of personal data as such. The court also noted that the right of access would be significantly weakened if Article 82(1) GDPR was limited solely to unlawful acts involving data processing. In light of the answer to these questions, the court saw no need to answer question 4. Does non-material damage for data subjects include loss of control or uncertainty over how their data is processed? (question 8) — The court noted that the GDPR does not define “(non)material damages” or “compensation for damages suffered”. Therefore, they must be considered autonomous concepts of EU law, and interpreted in a uniform manner . The court referred to previous case law, and highlighted the fact that “non material damage” cannot be limited by the degree of seriousness. However, an infringement on its own does not give data subjects the right to compensation, as it is one of the three conditions that must be met cumulatively. Therefore, the data subject must also establish that the infringement caused them harm, and that there is a causal link between the damage and the infringement. This applies to loss of control, as well as data subjects’ fears regarding the misuse of their data. Finally, the court stated that the causal link may be broken by the behaviour of the data subject; this means a data subject may not receive compensation for damages when the loss of control or fears over misuse of data were caused by the data subject submitting this data to the controller with the aim of artificially creating conditions to obtain compensation).

### Rb. Den Haag - C/09/689833

*Source: District Court Den Haag, 2026-05-27 — https://overview.legal/posts/53095 — original: https://gdprhub.eu/index.php?title=Rb._Den_Haag_-_C/09/689833*

Facts — Kindred Group PLC and Risepoint Limited (the controllers) are companies that provide online gambling products. Several companies within Kindred Group PLC (Risepoint was initially in this group) offered online gambling products before a national law requiring a license entered into force. In response, several lawsuits were filed before courts regarding the validity of the gambling agreements between players and unlicensed online gambling providers. Several data subjects later requested access (Article 15 GDPR, or in the alternative, the right to portability under Article 20 GDPR) to the controller to receive information on specific transaction data and the types of games they participated in. The data subjects did not receive access and brought a claim to the court. The data subjects requested the court to hold both companies liable (jointly or separately) The court initially dismissed the claim based on the code of civil procedure, but allowed the data subjects to amend their arguments regarding the GDPR. Both companies argued that they were not controllers, and that the requests made by the data subjects were abusive. According to the companies, the data subjects requested access for the sole purpose of bringing legal actions against them. Finally, the companies argued that they did not have the obligation to comply with the requests under Article 15(4) GDPR. Holding — The court first clarified that both Kindred Group PLC and Risepoint Limited were controllers. Kindred Group PLC argued that it did not exercise any decisive influence over the purpose and means of processing. The court took into consideration the functional definition of “controller” under Article 4(7) GDPR and CJEU case law, rather than a formal definition. The court found that Kindred Group PLC was a controller for access made between May and October 2024, but not for requests made after October 2024. This is because Kindred had a unified privacy policy for companies under its group, and answered the access request from an email address containing its name. However, after October 2024, Risepoint was no longer a part of the group, and the data from Kindred had been transferred to Risepoint. The court then dismissed the controllers’ arguments, and stated that the access requests were not abusive under Article 12(5) GDPR. Under Article 12(5) GDPR, a controller may refuse a request for access if it is manifestly unfounded or excessive. However, the CJEU has clarified that a data subject does not need to justify an access request, and a controller cannot refuse a request for access on the sole ground that it serves a purpose other than obtaining information about the processing of personal data and verifying its lawfulness. In any case, the court stated that the controller bears the burden in proving that a request is manifestly unfounded or excessive. Similarly, the controllers could not rely on Article 15(4) GDPR to refuse the data subjects’ requests. The court stated that the controllers’ interest in not granting information that data subjects could use against them in court is not recognised under EU law as a basis to refuse access. While the GDPR allows for national law to restrict specific rights under Article 23 GDPR, the court stated that the restriction must be necessary and proportionate. This, however, does not apply for hypothetical situations. The court upheld the data subjects’ claim, and ordered the controllers to provide them with a copy of their transaction data. The court specified that the controllers had the obligation to provide a complete copy, in accordance with CJEU case law.

### VG München - M 26a K 25.5210

*Source: Administrative Court Munich, 2026-05-18 — https://overview.legal/posts/108991 — original: https://gdprhub.eu/index.php?title=VG_München_-_M_26a_K_25.5210*

Facts — The data subject had been liable to pay broadcasting contributions to the Controller, a German regional public broadcasting authority, since 2007. Following objections to several contribution assessment notices, the data subject submitted a request under Article 15 GDPR seeking a copy of all personal data processed about him by the Controller. The Controller responded by providing the categories of personal data and related information specified under § 11(8) of the German Broadcasting Contribution Treaty (RBStV), which governs data subject access requests relating to broadcasting contribution records, together with general privacy information. The data subject argued that the response was incomplete because it did not include copies of all documents containing his personal data, including correspondence with him and third parties. The Controller maintained that it had fully complied with its obligations under the RBStV. After the Controller declined to provide additional information, the data subject brought proceedings seeking disclosure of all personal data concerning him processed by the Controller. Holding — The Court held that § 11(8) of the German Broadcasting Contribution Treaty (RBStV) constituted a lawful restriction of the broader right of access under Article 15 GDPR pursuant to Article 23(1)(e) GDPR. It found that the national provision was a valid legislative measure, respected the essence of the fundamental right to data protection, and pursued an important public interest by ensuring the effective financing and administration of the public broadcasting system. The Court further held that the restriction was necessary and proportionate, noting that requiring the Controller to comply with the full scope of Article 15 GDPR across more than 44 million broadcasting contribution accounts would impose a disproportionate administrative and financial burden capable of undermining that public interest. The Court also held that § 11(8) RBStV satisfied the safeguards required under Article 23(2) GDPR by specifying the purposes of processing, categories of personal data, scope of the restriction, safeguards against misuse and unlawful access, the identity of the Controller, applicable storage periods and other statutory protections. Accordingly, while the Controller was required to disclose the categories of information specified under § 11(8) RBStV, it was not required to provide a copy of all personal data processed under Article 15(3) GDPR. As the Controller had already provided all information required under the national provision, the court dismissed the action.

### GC - T-318/24

*Source: Gereral Court, T-318/24, 2025-12-03 — https://overview.legal/posts/122878 — original: https://gdprhub.eu/index.php?title=GC_-_T-318/24*

Facts — An applicant (the data subject) participated in several EU staff selection procedures administered by the European Personnel Selection Office (EPSO), acting as controller, and created an EPSO account in the Talent system. After he successfully passed one selection procedure, EPSO also stored his data in its recruitment portal. EPSO managed recruitment through two IT systems, both of which generated access logs, although those logs contained limited technical information regarding the purpose of each access. Between 2022 and 2024, the data subject submitted several requests to EPSO under Article 17 of Regulation (EU) 2018/1725, seeking access to all personal data concerning him. He requested, in particular, full access logs, minutes of meetings, internal and external communications containing his personal data, information on data recipients, and the restoration of personal data deleted after the expiry of retention periods. EPSO stated that certain data did not exist, that it could not restore lawfully deleted data, and that it had already disclosed all available log data. After the data subject lodged a complaint, the European Data Protection Supervisor (EDPS) reconsidered the matter in light of the CJEU’s judgment in Pankki. The EDPS ordered EPSO to provide all available log data relating to consultations of the data subject’s profile. EPSO complied with that order by disclosing the available logs but withheld the identities of individual staff members who had accessed the data. EPSO later rejected further access requests submitted by the data subject. As a result, the data subject brought two actions before the General Court (Cases T-318/24 and T-362/24), seeking the annulment of EPSO’s decisions. The General Court joined the two cases and examined together all the pleas in law raised by the data subject. Holding — The General Court dismissed both actions in their entirety. It held that the controller did not infringe Article 17(1) or (3) of Regulation 2018/1725, as the right of access concerns personal data undergoing processing and not documents as such, nor does it require the controller to restore lawfully deleted data. The Court confirmed that Regulation 2018/1725 contains no obligation for a controller to reinstate personal data once deleted in compliance with applicable retention rules. The Court further held that the controller had no obligation to disclose additional log data, meeting minutes, or communications where it credibly asserted that no such personal data existed. The data subject failed to rebut the presumption of legality attaching to the controller’s statements regarding the non-existence of further data. Moreover , The Court held that access logs constitute personal data to which a data subject is entitled, as they reveal the existence, frequency and purpose of processing. However, employees of a controller acting under its authority are not “recipients” within the meaning of the GDPR or Regulation 2018/1725, and controllers are not required to log or disclose their identities. Disclosure of such identities is only required if strictly necessary for the effective exercise of data protection rights and subject to safeguarding employees’ rights. Since the data subject had already been informed of the purposes and recipients of processing, the absence of staff identities or detailed purposes in the logs did not infringe the right of access. It is not further apparent from the Pankki that Article 15 GDPR requires the controller to set up a logging mechanism containing information on the identity of employees who have carried out consultation operations in respect of the personal data of a person. In addition, the Court found no infringement of the principles of lawfulness, fairness, transparency, accuracy, integrity, confidentiality, or accountability under Article 4 of Regulation 2018/1725. The deletion of the data subject’s data after the expiry of retention periods was lawful and the data subject’s rights to restriction of processing and objection under Articles 20 and 23 were not applicable, as the deletion was based on a legal obligation rather than consent or legitimate interests.

### OLG Wien - 13R70/25x

*Source: Higher Regional Court Vienna, 2025-12-01 — https://overview.legal/posts/53664 — original: https://gdprhub.eu/index.php?title=OLG_Wien_-_13R70/25x*

Facts — A data subject brought proceedings against a controller after it refused to provide, free of charge, digital copies of invoices and transaction data following an access request. The data subject argued that Article 15(3) GDPR entitled them to receive a complete copy of the personal data processed by the controller, including the copies of invoices and transaction data. The controller argued that it had complied with both of the data subject's requests for information in a timely and complete manner. It argued that Article 15(3) GDPR entitled the data subject to a copy of their personal data, rather than to copies of documents as such. The controller alleged that it had disclosed the payment details provided by the data subject, thereby enabling them to clearly identify which bank account had been debited. The first-instance court dismissed the data subject’s action. It acknowledged that, according to the CJEU in judgement C-487/21, copies of whole documents must be provided only where they are indispensable for the data subject to understand the processing of their personal data or to effectively exercise their GDPR rights. The court considered that the data subject had not proved such necessity. It noted that they had already received the relevant invoices during the contractual relationship following the respective billing periods and the information disclosed by the controller was sufficient to understand the processing at issue. The therefore found that the controller could make any re-sending of invoices conditional upon payment of a fee. The data subject appealed to the Higher Regional Court of Vienna (OLG WIEN) and argued that in accordance with the case law of the CJEU (CJEU judgment C-307/22) a data subject need not provide reasons for requesting a copy of their personal data from the controller, and that the right to obtain a copy of personal data applies even where the request serves purposes unrelated to GDPR. They further argued that the first-instance court had incorrectly imposed on them the burden of proving that the copies were necessary for the exercise of their GDPR rights. Holding — The court acknowledged that according to C-307/22, an access request does not need to be justified and is not manifestly unfounded or abusive merely because the data subject pursues objectives unrelated to data protection. It nevertheless stated that motives unrelated to data protection may become relevant when it comes to the scope of the right to access data. The court referred to C-487/21 and held that the right to a copy under Article 15(3) GDPR means that the data subject must be provided with a faithful and intelligible reproduction of the personal data where this is indispensable for understanding the processing at issue and enabling the data subject to effectively exercise their GDPR rights. The court considered that the data subject bears the burden of proving why copies of the requested documents are indispensable. It emphasized that a general assertion that the documents are needed to ensure the completeness of the response is insufficient. It further stated that this requirement also applies where the request pursues objectives unrelated to data protection. The court upheld the legal assessment of the first-instance court and dismissed the appeal.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 16 July 2025.#Lisa Ballmann v European Data Protection Board.#Protection of personal data – Complaint against the controller of personal data of users of an online social network in the European Union – Article 65(1)(a) of Regulation (EU) 2016/679 – Binding decision of the European Data Protection Board – Complainant’s request for access to the file prepared for the purposes of the binding decision – Refusal to grant access –

*Source: General Court, T-183/23, 2025-07-16 — https://overview.legal/posts/132139 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0183*

In Case T-183/23, Lisa Ballmann sought annulment of the European Data Protection Board's decision refusing her request for access to the file prepared for Binding Decision 3/2022, which concerned Meta Platforms Ireland's processing of personal data on Facebook. The core issue was whether the EDPB's refusal to grant the complainant access to that file—thereby limiting her ability to be heard in the Article 65(1)(a) GDPR dispute resolution procedure—was actionable and compatible with Article 41(2)(b) of the EU Charter of Fundamental Rights. The General Court ruled on the admissibility of the action and the scope of a complainant's procedural rights before the EDPB, with Meta Platforms Ireland intervening in support of the EDPB; no fine was imposed.

### OVG Saarlouis - 2 A 165/24

*Source: Superior Administrative Court Saarlouis, 2025-05-13 — https://overview.legal/posts/125590 — original: https://gdprhub.eu/index.php?title=OVG_Saarlouis_-_2_A_165/24*

Facts — The data subject was an employee, the controller was the employer. On 14 January 2022, the data subject requested access to personal data from the controller under Article 15 GDPR. They did not respond. On 28 January 2022, the controller terminated the employment. On 17 February 2022, the data subject lodged a complaint with the Data Protection Authority (DPA) under Article 77 GDPR. The data subject alleged that the controller had failed to answer the access request, had taken unauthorised photographs, and had a copy of their vaccination certificate. On 24 February 2022, the employment relationship ended by a court settlement before the Labour Court. The settlement stated that all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, were settled, except for employment documents. By entering the settlement, the data subject agreed to not pursue further claims. After the settlement, the controller informed the DPA that it had not received an access request from the data subject, had not taken photographs, and had destroyed the vaccination certificate after the employee left. The data subject continued to raise issues with the DPA, including access to time-tracking data and alleged inaccuracies in the controller’s provided documents. The controller later provided partially redacted time-tracking data. On 26 July 2022, the DPA closed the administrative procedure, as it considered that the data subject no longer had a right of access under Article 15 GDPR because the settlement didn't allow for this claim. The data subject challenged the DPA’s decision before the Administrative Court. On 10 July 2024, the court dismissed the action. The data subject appealed. Holding — First, the court held that the right of access under Article 15 GDPR was, in principle, waivable. Although Article 8(2) CFR protects the right of access, the court noted that data protection law is based on self-determination, including the possibility to consent to processing under Article 7 GDPR. From this, the court inferred that a data subject could also waive the exercise of the right of access. Second, the court clarified that a waiver could not generally cover unknown future data processing. However, a waiver relating to past processing was permissible, especially after the end of an employment relationship, where the imbalance between employee and employer no longer existed. Third, the court held that the specific settlement covered the right of access under Article 15 GDPR. The clause settling all claims arising from the employment relationship and its termination, whether known or unknown and regardless of their legal basis, also included secondary claims linked to the employment relationship, such as access rights concerning employee data. The court considered the wording sufficiently clear and found no requirement to explicitly mention data protection rights. Fourth, the court noted that the data subject already knew about the access request and had raised it before concluding the settlement. Any internal intention not to waive data protection rights was legally irrelevant. Finally, the court upheld the DPA’s decision to close the procedure. Since the data subject had waived the right of access under Article 15 GDPR for past processing through the settlement, the DPA had no obligation to continue enforcement action against the employer.

### Judgment of the Court (First Chamber) of 3 April 2025.#L. H. v Ministerstvo zdravotnictví.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4 – Definitions – Article 6 – Lawfulness of processing – Article 86 – Public access to official documents – Data concerning the representative of a legal person – Case-law of a national court imposing an obligation to inform and consult the data subject prio

*Source: Court of Justice of the European Union, C-710/23, 2025-04-03 — https://overview.legal/posts/132145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0710*

In Case C-710/23, the Court of Justice of the European Union (First Chamber) addressed a preliminary reference from the Czech Supreme Administrative Court concerning whether personal data of individuals acting as representatives of legal persons, contained in official documents related to COVID-19 screening test contracts, may be disclosed under GDPR Article 86 and the lawfulness of processing under Article 6. The case arose from a dispute between L.H. and the Czech Minister of Health, who had refused to disclose certain information about representatives of legal persons named in those contracts and related certificates. The Court held that data concerning a representative of a legal person constitutes personal data within the meaning of the GDPR when it allows the natural person to be identified, and that Member States may provide for public access to official documents containing such personal data, provided that the disclosure is reconciled with the right to data protection; however, a national court cannot impose a general obligation to inform and consult the data subject prior to every disclosure of official documents, as this would undermine the public's right of access to official documents.

### Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor

*Source: Court of Justice of the European Union, C-203/22, 2025-02-27 — https://overview.legal/posts/132146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0203*

In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien concerning an individual's request for meaningful information about the logic of creditworthiness scoring conducted by Dun & Bradstreet Austria GmbH. The Court held that data subjects must receive sufficiently detailed explanations of the logic involved in automated profiling to understand how the decision was reached, while controllers may withhold information protected by trade secrets under Directive (EU) 2016/943 only insofar as such withholding does not render the information provided meaningless. The Court further clarified that data subjects may not use access rights to obtain personal data of third parties or to verify the absolute accuracy of the underlying information processed.

## Guidance

### Coordinated Enforcement Action, implementation of the right of access by controllers

*Source: EDPB, edpb-cef-report-2024-20250116-rightofaccess-en, 2025-01-20 — https://overview.legal/posts/50412 — original: https://www.edpb.europa.eu/documents/coordinated-enforcement-framework/coordinated-enforcement-action-implementation-of-the_en*

EDPB 20 jan 2025, Coordinated Enforcement Action, implementation of the right of access by controllers.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Statement on restrictions on data subject rights in connection to the state of emergency in Member States

*Source: EDPB, statement-on-restrictions-on-data-subject-rights-in-connection-to-the-state-of-en, 2020-06-02 — https://overview.legal/posts/126146 — original: https://www.edpb.europa.eu/documents/statement/statement-on-restrictions-on-data-subject-rights-in-connection-to-the-state-of_en*

1 Statement on restrictions on data subject rights in connection to the state of emergency 1 in Member States Adopted on 2 June 2020 The European Data Protection Board has adopted the following statement: 1. The EDPB has been informed of the adoption by the Hungarian government of the Decree 179/2020 of 4 May 2020 on the derogations from certain data protection and access to information provisions during the state of danger 2 . Under Article 1, this Decree provides that, with respect to…

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

### Statement 05/2021 on the Data Governance Act in light of the legislative developments

*Source: EDPB, statement-052021-on-the-data-governance-act-in-light-of-en, 2021-05-20 — https://overview.legal/posts/126024 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-052021-on-the-data-governance-act-in-light-of_en*

1 Statement 05/2021 on the Data Governance Act in light of the legislative developments Adopted on 19 May 2021 The European Data Protection Board has adopted the following statement: On 9 March 2021 the EDPS and the EDPB adopted the Joint Opinion on the Proposal for a Data Governance Act (DGA) 1 , which has also been presented at the European Parliament at the hearing of the LIBE Committee of 16 March 2021 2 . The EDPB is closely followin g the work of the co - legislators on this important…

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### EU - U.S. Privacy Shield - Third Annual Joint Review report – 12/11/2019

*Source: EDPB, eu-us-privacy-shield-third-annual-joint-review-report-en, 2019-11-12 — https://overview.legal/posts/126199 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/eu-us-privacy-shield-third-annual-joint-review-report_en*

1 Adopted EU - U.S. Privacy Shield - Third Annual Joint Review Adopted on 12 November 2019 2 Adopted 4 Adopted The European Data Protection Board Having regard to Article 4 and Recitals 145 to 149 of the Commis sion Implementing Decision (EU) 2016/1250 of 12 July 2016 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the pro tection provided by the EU - U.S. Pri vacy Shield (“EU - U.S. Privacy Shield), HAS ADOPTED THE FOLL OWING REPORT: 1 EXECUTIVE…

## Enforcement decisions

### Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023

*Source: Tietosuojavaltuutetun toimisto (Finland), 2026-07-22 — https://overview.legal/posts/184713 — original: https://gdprhub.eu/index.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV/4630/2023*

Facts — A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022. The data subject made an access request in November 2022 – they suspected the misuse of their personal data as they had not submitted the loan application themselves. The data subject provided their name, phone number, and email address as identifying information in connection with the access request. The controller did not provide the requested information; instead, it asked the data subject to disclose their residential address and personal identification number as well as to sign the access request electronically using strong authentication in order to verify their identity. The data subject refused to comply with this request and filed a complaint with the DPA, stating that the controller’s procedure for verifying the identity of the data subject in connection with an access request violated Articles 5(1)(c), 12(2) and (6), and 25(2) GDPR. The controller considered the additional information necessary to identify the correct individual and avoid providing the data subject’s information to an unauthorised third party. Holding — The DPA found no GDPR violation and held that the controller was entitled to request the data subject to provide additional information necessary to verify their identity pursuant to Article 12(6) GDPR. The controller’s procedure was also in line with the principle of data minimisation laid down in Article 5(1)(c) GDPR. According to the DPA, the personal data originally provided by the data subject when making the access request could not be considered sufficient identifying information since several people might have the same name and the email address and the phone number of the data subject could also be known to third parties. The DPA considered that the controller had a legitimate reason to request that the data subject provide additional information to verify their identity, as the controller processes personal data concerning the financial status of its customers.

### CNIL fines energy supplier for mishandling data subject access and objection requests

*Source: CNIL (France), 2026-07-17 — https://overview.legal/posts/125641 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2022-011*

Facts — The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French DPA (CNIL) that they had encountered difficulties in exercising their rights of access to personal information about them, and objection to receiving commercial prospecting telephone calls from the controller. The complaints concerned data subject requests for rectification of personal data, late, erroneous, or no response to access to personal data and access to the origin of personal data, failure to cease processing of personal data after objection to the processing of data for commercial prospecting (marketing) purposes, and request for personal data deletion. The DPA appointed a rapporteur that carried out an audit of the website of the controller and investigated the various complaints of the data subjects. The controller in its defence argued that 1) the data subjects' access requests were not sent by the data subjects to the controller’s dedicated unit and that the person who received the requests did not know how to identify their purpose; 2) the procedures it had put in place were not respected because of human error; 3) there were a large number of requests received in 2020 during the health crisis and this was impeded by the disruptions that followed; 4) there were difficulties in obtaining the necessary information from its business partners, thus unable to properly inform data subjects about the source of their data; 3) It had taken steps to modify its processing activities to comply with the relevant applicable laws; 4) The breach affected barely a fraction of its customers. Beyond the direct complaints made by the data subjects, the DPA in its investigation noted that when subscribing online on the controller's website, the subscription form had no option for users to object to the use of their personal data for marketing purposes. The subscription form informed users that their personal data may be used by the controller to present offers to them at a later date. On this point, the controller argued that 5) the CPCE did not apply to the online subscription form, since the collection of personal data through the form was not intended to promote the company's products or services, but to offer assistance to the user in order to help them finalize the current subscription. Holding — The DPA held that the lack of an option for a user to object to the processing of their personal data for marketing purposes, at the time of collection, constitutes a breach of the provisions of article L. 34-5 of the French Post and Electronic Telecommunications Code (CPCE). The DPA observed that, in certain cases, the data subjects contacted for marketing purposes were not provided with any information required in Article 14 GDPR, such as the purposes of the processing or the existence of the various rights. They were not informed that the call was being recorded, nor of their right to object to it. The DPA observed that the controller had failed to respond, supplied erroneous responses, or responded late to several data subject requests, beyond the deadlines set by Article 12 GDPR, often after several reminders from the data subject. The DPA observed that the controller failed to process the various data subject’s requests for access to personal data, their origin, as well as access to recordings of telephone conversations concerning the data subjects within the time limit set with the obligations of Article 15 GDPR. The DPA finally observed that the controller continued to process the personal data of data subjects after objections from the data subjects to the processing of their personal data in breach of Article 21 GDPR. The DPA held that the controller cannot rely on its difficulties in obtaining information from its commercial partners to justify its failure to provide a response to the applicants in accordance with the applicable provisions. It is the duty of the controller to organize itself in such a way as to be able to ensure that requests for access are processed in accordance with the applicable provisions and, in particular, to provide information on the origin of the data. The DPA further held that although data subjects did not send their access requests directly to the unit in charge of responding to them, it is up to the controller, as long as the requests, one of which was directly addressed to the data protection officer, were received in clear terms by the controller, to process them within the time limits provided for and to ensure that they were transmitted to the competent department responsible for handling such requests. For these violations, the DPA fined the controller €1,000,000. The controller argued against the publication of the penalty decision, on the ground that publication would be disproportionate in light of the limited nature of the alleged breaches and its compliance. It also claimed that publication of the penalty would have a significant impact on the controller’s image and that it would be favorable to its main competitors, in a very competitive market. The DPA also decided to make its decision public on the CNIL website and on the Légifrance website and held that the controller will no longer be identified by name after a period of two years from its publication. The DPA noted that the company has taken measures to bring its processing into compliance with the applicable laws, and the efforts made by the company to comply throughout the procedure. The DPA also noted that the controller’s agents have had to attend awareness training on the subjects of the complaints.

### NAIH (Hungary) - NAIH-4667-10/2022

*Source: NAIH (Hungary), 2022-09-22 — https://overview.legal/posts/122837 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-4667-10/2022*

Facts — A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested access to his personal data contained in the eKRÉTA (Public Education Registration and Study Fund) system. This system was used by the school (the controller) to record and capture the grade history of pupils, including the data subject. The controller failed to provide the requested personal data. However, it did ask KRÉTA (the processor) whether additional information regarding manipulation of grades can be exracted from the system and informed the parent that no such possibility existed. Consequently, the parent of the data subject filed a complaint with the Hungarian DPA. The parent submitted that the overwriting and deletion of the data subject's grades could not be tracked on the eKRÉTA administrative interface accessible to parents. The parent proved their right of representation before the DPA with the child's birth certificate. The DPA initiated an investigation into the matter. Holding — The DPA reitarrated, based on the definitions of the GDPR, that a subject grade is data related to the data subject's academic evaluation and should be considered personal data. Hence, any operation performed on the data is considered data processing. In the present case, the personal data was allegedly modified or overwritten at a time other than when the semester grade notice was issued to pupils. With regard to the personal data of a minor, the parent is not considered to be the data subject pursuant to Article 4(1) GDPR. At the same time, the parent can submit a data subject request to the controller on behalf of the minor data subject. The parent wanted to exercise this right in order to have access to the information related to the management of the grade, regarding the overwriting and deletion of the grade, based on Article 15(1) GDPR. The purpose was to establish the legality of the data management on behalf of the controller. The DPA confirmed that the processor (the KRÉTA system) provided information on of the date on which the grades were entered, following a request from the controller. However, the processor could not track whether a certain grade entry was overwritten or deleted form the system. This request was in compliance with Article 28(3) GDPR since the data controller validated the data subject's request by asking for the information in question from the data processor. The DPA found that the allegation that the personal data in question had been manipulated was not substantiated and that the controller had not committed any infringement in the course of complying with the data subject's request to access the data in question. The DPA noted that the accessed data was not provided to the data subject, not in an attempt to conceal any manipulated merits, but rather due to the fact that the requested data was not in the controller's possession yet. The DPA concluded that the general data processing of the controller did not directly affect the rights or legitimate interest of the data subject. In view of this, the DPA rejected the complaint.

### AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage

*Source: AEPD (Spain), 2026-07-21 — https://overview.legal/posts/144029 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00159-2025*

Facts — On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The data subject’s vehicle had allegedly been damaged while parked in a facility operated by the controller. On 23 February 2024, the data subject’s legal representative requested access to the footage recorded between 12 and 19 February 2024. The request sought the images showing the collision or, alternatively, the licence plate of the vehicle responsible. The data subject also expressly requested that the controller preserve the relevant footage because it was required for the establishment, exercise or defence of legal claims. The controller acknowledged receipt of the request but did not provide a substantive response until 4 April 2024, after the one-month period under the GDPR had expired. It stated that the footage could only be disclosed to the police or a judge and instructed the data subject to file a police report. After the data subject challenged that requirement and reiterated both the access and preservation requests, the controller responded that it would not provide the recordings and that the footage had already been deleted. During the proceedings, the controller argued that the request was excessive because it covered footage from 16 cameras over several days, amounting to approximately 3,072 hours of recordings. It also maintained that the footage contained personal data relating to numerous third parties and that it was not established that the damage had occurred inside the car park. The controller acknowledged, however, that it had not explained these considerations to the data subject, asked the data subject to narrow the request or notified an extension of the response period. Holding — The DPA held that the controller infringed Articles 15 and 18 GDPR. Regarding Article 15 GDPR, the DPA found that the controller failed to respond to the access request within the one-month period required under Article 12(3) GDPR. Although the controller considered the request complex and excessive, it neither informed the data subject of an extension within the initial one-month period nor explained why it considered the request excessive. The DPA noted that the controller could have asked the data subject to provide additional information to narrow the search. It could also have reviewed the recordings and provided only the footage necessary for the specific incident, applying measures such as blurring or limiting the disclosed extract to protect third parties. The DPA rejected the controller’s position that the footage could only be provided following a request from the police or a court. The exercise of the right of access was not conditional on the prior filing of a police report. The controller was required to assess the request under the GDPR and provide a reasoned and timely response. The failure to respond in time resulted in the deletion of the requested footage. Consequently, the data subject was prevented from obtaining information that could have been relevant to identifying the person responsible for the damage and pursuing a legal claim. Regarding Article 18 GDPR, the DPA held that the data subject had expressly requested the preservation of the recordings for the establishment, exercise or defence of legal claims. Under Article 18(1)(c) GDPR, processing must be restricted where the controller no longer needs the data for its original purposes but the data subject requires it for legal claims. The controller did not address this request and deleted the footage under its ordinary retention schedule. The DPA considered that Article 22(3) Spanish Data Protection Act (LOPDGDD), which generally requires video surveillance images to be erased within one month, did not justify disregarding a valid restriction request. Once the data subject requested preservation for potential legal proceedings, the controller was required to retain the relevant images rather than erase them. The DPA also linked the preservation of the evidence to the data subject’s right to effective judicial protection under Article 24(1) of the Spanish Constitution. Deleting the footage made it more difficult for the data subject to identify the responsible party and exercise their rights before a court. The DPA initially imposed two fines of €75,000: one for the infringement of Article 15 GDPR and one for the infringement of Article 18 GDPR, amounting to €150,000 in total. The controller acknowledged liability and voluntarily paid the fine. Under Article 85 of Spanish Administrative (Law 39/2015), it received a 20% reduction for acknowledging liability and a further 20% reduction for voluntary payment. Consequently, the initial fine of €150,000 was reduced by 40% to a final amount of €90,000. The DPA also ordered the controller to adopt the compliance measures specified in the decision initiating the proceedings and to report their implementation to the DPA within three months after the decision became final and enforceable.

### UODO (Poland) - DKN.5131.34.2023

*Source: UODO (Poland), 2026-06-13 — https://overview.legal/posts/53104 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.34.2023*

Facts — An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained personal data of clients, their employees, and their children (the data subjects), including their names, dates of birth, salary information, and tax declarations. The controller notified the supervisory authority of a data breach in January 2021. The DPA initiated administrative proceedings regarding possible GDPR violations in December 2023. The controller argued that no personal data breach within the meaning of Article 4(12) GDPR had occurred as the unauthorised entity had only accessed and not obtained the personal data in question. Holding — The DPA held that the controller had violated Articles 5(1)(f) and 5(2), 24(1), 25(1), 32(1), and 32(2) GDPR and issued it a fine of € 2,760. First, it pointed out that mere unauthorised access to personal data processed via email constitutes a data breach under Article 4(12) GDPR. Second, the DPA held that the controller had failed to implement appropriate technical and organisational measures to ensure the security of this personal data – it had only taken measures to comply with the aforementioned provisions of the GDPR after the data breach had been notified to the DPA. The controller had not previously conducted a risk assessment. In addition, it had failed to regularly test, measure, and evaluate the effectiveness of the technical and organisational measures implemented. Finally, the DPA found that the processing posed a high risk to the rights and freedoms of data subjects: it affected a large number of individuals and concerned a broad scope of personal data. When determining the amount of the fine, the DPA took into account that there was a clear imbalance between the data subjects and the controller – the data subjects were required to provide personal data to the controller to fulfil obligations under labour law, social security law, and tax law and could not independently control the data. Consequently, the DPA considered the GDPR infringements to be of significant gravity.

### APD/GBA: Controller failed to provide copies of service sheets for GDPR access request

*Source: APD/GBA (Belgium), 2026-05-06 — https://overview.legal/posts/144020 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_97/2026*

Facts — The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed and the clients visited. On 10 May 2021, the data subject requested copies of their service sheets covering the previous five years in order to verify whether the hours they had reported corresponded to those recorded by the controller. The controller provided only the sheet concerning the week of 3 May 2021 to 9 May 2021 and subsequently proposed that the data subject arrange an appointment to consult the records at its premises. The data subject reiterated the request on 17 January 2022 and again in 2023, but never received the requested copies. On 27 July 2023, the data subject lodged a complaint with the Belgian DPA. The DPA issued the prima facie Decision 14/2025, where it ordered the controller to comply with the data subject’s access request and warned it of potential violations of Article 15(3) GDPR and Article 12(3) GDPR. The controller requested an examination on the merits. The controller argued that the data subject’s request had not clearly distinguished between the handwritten service sheets and a computer-generated statement. It further claimed that the request was excessive under Article 12(5) GDPR because the documents were stored by date rather than by employee in several dozen binders. Locating, copying and scanning the relevant records would therefore require considerable workload. For that reason, it had invited the data subject to inspect the binders in its premises and identify the relevant documents to be copied. The data subject maintained that their request had always been clear, that the computer-generated statement was incomplete and unintelligible and that the practical difficulties relied upon by the controller resulted from its own archiving practices. Holding — The DPA ruled that the data subject had made a sufficiently clear request for access and a copy under Article 15(1) GDPR and Article 15(3) GDPR. It further pointed out that the controller’s response demonstrated that it had understood that the data subject sought copies of the service sheets themselves. The DPA further held that the computer-generated statement did not satisfy the request. It noted that the data subject needed the handwritten records in order to compare the hours they had reported with those subsequently recorded by the controller. It referred to C-487/21 (Österreichische Datenschutzbehörde) and recalled that the copy provided must constitute a faithful and intelligible reproduction of the personal data and may require copies of documents where this is necessary for the effective exercise of the data subject’s rights. The DPA therefore determined that the controller’s invitation to inspect the documents at its premises therefore did not constitute an adequate response to the data subject’s request for a copy. It stated that if the controller had genuinely been uncertain about the scope of the request, it should have sought clarification in accordance with Article 12(2) GDPR. Moreover, it rejected the controller’s reliance on Article 12(5) GDPR. The DPA held that the request was neither manifestly unfounded nor excessive as was clearly expressed and properly understood by the controller. It found that the controller did not demonstrate the excessiveness but relied exclusively on the workload resulting from its own archiving system. The DPA also relied on C-526/24 (Brillen Rottler) and applied the abuse of rights test. It found that neither its objective nor its subjective element was established. It reasoned that the request pursued the purpose of Article 15 GDPR, since the data subject sought to access and verify the accuracy of personal data concerning them, nor was there any evidence that the data subject had artificially created the conditions for obtaining an advantage under the GDPR. It further referred to EDPB Guidelines 01/2022 on the right of access, emphasizing that the time and effort required for a controller to fulfil an access request cannot, in itself, make the request excessive, particularly since the burden resulted from organisational choices made by the controller. It also emphasized that the data subject was also not required to justify the reasons for the request. The right of access under Article 15 GDPR does not include any general proportionality reservation regarding the controller’s efforts. Additionally, the term "appropriate" in Article 12(1) GDPR should not be used to limit the scope of data covered by the right of access. The DPA concluded that the alleged burden could not justify a refusal, especially since it stemmed from self-imposed organizational and administrative constraints related to the controller’s archiving system. A refusal may only apply if there is proven abusive intent, as defined by applicable requirements. Any other interpretation would undermine Article 15 GDPR and conflict with Article 12(2) GDPR and Article 25 GDPR, which require controllers to facilitate access requests and implement technical and organizational measures from the outset to ensure effective exercise of this right. The DPA further held that the controller had violated Article 12(2) GDPR, Article 12(3) GDPR and Article 12(4) GDPR. It had neither responded within the applicable time limit nor formally notified the data subject of a reasoned refusal. It further emphasized that the controller by requiring the data subject to attend its premises and identify the relevant records, it improperly transferred to them a task that belonged to it. Moreover, it noted that on-site consultation of the records could have exposed the data subject to personal data relating to the controller’s clients. The DPA held that under Article 15(4) GDPR, the controller was required to assess whether measures, such as partial anonymisation of third-party information, were necessary and that provision could not justify a blanket refusal to provide a copy. The DPA reprimanded the controller for violating Article 12(2) GDPR, Article 12(3) GDPR, Article 12(4) GDPR, Article 15(1) GDPR and Article 15(3) GDPR and ordered it to provide copies of the timesheets within one month.

### AEPD (Spain) - EXP202203606

*Source: AEPD (Spain), 2022-04-22 — https://overview.legal/posts/125657 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202203606*

Facts — Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against the respondent party for not having been duly attended to his right of access and deletion enshrined in Articles 15 to 22 GDPR, Articles 13 to 18 LOPDGDD and Article 17 GDPR respectively. The conflict of law arose in this case when a sufficiently legally established response was not generated by the respondent to the claimants request. Furthermore, the claim was transferred to the respondent so that the entity could proceed with its analysis and provide a response to the claimant within a period of one month. The Director of the Spanish Data Protection Agency agreed to admit the claim for processing and the parties concerned were informed of the maximum term for resolution, that being six months. The competence of the Spanish Data Protection Agency is refined by Article 55 GDPR in the promotion of an obligation between controllers and processors to deal with complaints issued by data subjects. The result of the said transfer did not allow the claimants issues to be understood as satisfied. Consequently, due to the lack of attention delegated to the claimants rights further set forth in Article 15 GDPR, Article 16 GDPR, Article 17 GDPR, Article 18 GDPR, Article 19 GDPR, Article 20 GDPR, Article 21 GDPR and Article 22 GDPR, an agreement to admit for processing was initiated. Holding — The Director of the Spanish Data Protection Agency went on to note that considering the purpose of the outlined procedure was to ensure that the rights of affected parties were fully restored, the complaint that gave rise to this procedure should be upheld on formal grounds due to the fact that the right of access had been complied with and the right of erasure had been duly denied (on the applicable grounds of Article 17 GDPR).

### BfDI (Germany) - 24-191 II

*Source: BfDI (Germany), 2022-01-27 — https://overview.legal/posts/125601 — original: https://gdprhub.eu/index.php?title=BfDI_(Germany)_-_24-191_II*

Facts — The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject requested access from the controller to all of his data under Article 15 GDPR. He also requested to have his data transmitted in a portable format under Article 20 GDPR. The controller responded to both requests. The data subject, however, considered that both responses were not complete. He argued that information about his traffic data, his contracts with the controller and his requests to the controller's customer service were missing. Furthermore, the data subject criticised that the controller did not list all recipients in its answer, but only the "most important" ones, that the origin of the data was not specified and that the storage duration was not mentioned. He, therefore, lodged a complaint with the German Federal Data Protection Authority (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit - BfDI). Holding — The BfDI partially upheld the complaint. It confirmed the data subject's view that the controller is obligated under Article 15 GDPR to name all recipients and not only the "most important" ones, to specify the origin of the data and to mention the deletion date. However, the DPA found it was not necessary to list each and every individual transfer to a recipient. With regard to the contract documents, the DPA found that it was sufficient that the controller referred the data subject to the online customer portal where the data subject could retrieve those documents. Regarding the data subject’s requests to the customer service of the controller, the DPA found that these requests are usually handled manually by phone or by paper and not automatically. Accordingly, the DPA concluded that Article 20(1)(b) GDPR was not met. Furthermore, the DPA held that the data collected in the course of service requests must be deleted immediately after the purpose has been achieved, that means after the request has been resolved, or, if the data is to be used for other purposes, it must be anonymised. Consequently, the DPA reasoned that the controller could not have provided this data in its answer to the request under Article 15 GDPR. Regarding the traffic data, the DPA reasoned that a data subject has no right to access traffic data under Article 15 GDPR because § 11 TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz), which is an implementation of Article 7 ePrivacy Directive and lays down the right to receive itemized bills, takes precedence according to Article 95 GDPR. In the case at hand, the DPA concluded that the data subject did not invoke § 11 TTDSG since the data subject blackened this part of his submissions. Furthermore, the DPA held that by taking the principle of dataminimisation and Article 11 GDPR into account, the controller is only allowed to store IP addresses seven days. Since the IP addresses which were stored at the time of the request have already been deleted, the controller can no longer provide information about them. The DPA also determined that the controller was not obliged to give the data subject access to location data (Cell-ID) because the data subject did not sufficiently demonstrate that he was the sole user of the mobile phone in question. The DPA took the view that, since location data is very sensitive, the data subject must show that no one else was using the cellphone. Lastly, the DPA clarified that the controller is not allowed to record the content transmitted in an online session. Therefore, it found that it was impossible for the the controller to provide information on the visited websites under Articles 15 and 20 GDPR.

## Recent developments

### Datatilsynet (Denmark) - 2023-31-0321

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291258 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Denmark)_-_2023-31-0321*

Holding Holding. Holding The DPA, following CJEU precedent, maintained that the information appearing within the logs concerning employees access to a customer’s account are covered by the right of access in Article 15 GDPR.1 Nonetheless, considering the bank informed complainant that the requested log information is no longer available, and that the requested logs do not fall under the retention obligation pursuant to Article 30 Anti-Money Laundering Act, the DPA found no grounds to set these e

### Digital Omnibus reality check: 83.5% of access requests not properly answered

*Source: noyb - European Center for Digital Rights, 2026-04-16 — https://overview.legal/posts/53129 — original: https://noyb.eu/en/digital-omnibus-reality-check-835-access-requests-not-properly-answered*

Data Subject Rights The most commonly exercised right under the GDPR is the right of access to one’s personal data that is being processed by companies. After all, it’s often the prerequisite to know if there is inaccurate or unlawful personal data that needs to be corrected or deleted. However, a new analysis of noyb cases shows: Only 16.5% of all access requests noyb has sent to companies in the past 8 years received a satisfactory reply, while 53.7% of replies were incomplete – and almost 30%

### GDPR Omnibus: EU “simplification” far removed from real business needs

*Source: noyb - European Center for Digital Rights, 2026-03-05 — https://overview.legal/posts/53131 — original: https://noyb.eu/en/gdpr-omnibus-eu-simplification-far-removed-real-business-needs*

GDPR Policy Ever since the European Commission has published its Digital Omnibus proposal, discussions about the workload the GDPR creates for businesses in Europe have intensified. Among other things, the Commission wants to restrict the Right of Access, allegedly to reduce the regulatory burden. But do these changes actually reflect the needs of privacy professionals working at companies? To find out more, noyb conducted a survey asking Data Protection Officers (DPOs) which elements of the GDP

### Digital Omnibus: EU DPAs reject many proposed changes to the GDPR

*Source: noyb - European Center for Digital Rights, 2026-02-11 — https://overview.legal/posts/52485 — original: https://noyb.eu/en/digital-omnibus-eu-dpas-reject-many-proposed-changes-gdpr*

GDPR Policy The EDPB (combining all independent data protection authorities) and the European Data Protection Supervisor (EDPS) published a joint opinion expressing serious concerns about key elements of the proposed GDPR and ePrivacy changes in the so-called “Digital Omnibus” proposed by the European Commission. Specifically, the authorities strongly oppose the proposed narrowing of the definition of personal data. The opinion also question the need for various key proposals, such as the legal

### noyb win: Microsoft ordered to stop tracking school children

*Source: noyb - European Center for Digital Rights, 2026-01-27 — https://overview.legal/posts/52487 — original: https://noyb.eu/en/noyb-win-microsoft-ordered-stop-tracking-school-children*

Data Subject Rights noyb has scored another win in its proceedings against Microsoft 365 Education: The Austrian data protection authority (DSB) has decided that the company illegally installed cookies on the devices of a pupil without consent. According to Microsoft’s own documentation, these cookies analyse user behaviour, collect browser data and are used for advertising. Microsoft now has four weeks to comply and cease the use of tracking cookies. Decision by the Austrian DSB (DE)PR for prev

## Literature

### The Court of Justice on the Excessiveness of Access Requests under the GDPR

*Source: European Journal of Risk Regulation, 2026-07-09 — https://overview.legal/posts/83502 — original: https://doi.org/10.1017/err.2026.10117*

Abstract This case note comments on the preliminary ruling of the Court of Justice of the EU in Case C-526/24 Brillen Rottler v TC of 19 March 2026, which addresses the abuse of rights under the General Data Protection Regulation (GDPR), specifically in the context of requests for access to personal data under Article 15 GDPR and compensation under Article 82 GDPR. First, the Court held that even a first access request may be regarded as “excessive” where the controller demonstrates that it was

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how

*Source: Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza, 2023-12-30 — https://overview.legal/posts/132546 — original: https://doi.org/10.14746/ppuam.2023.15.09*

The data subject’s right to access information on data processing has a very broad meaning. Considering the latest developments in this field (mainly the CJEU ruling on Austrian posts and EDPB guidelines) one can draw the conclusion that the controller’s right to protect its confidential in-formation is limited and less valuable than the data subject’s rights. However, this may lead to unfair and unequal treatment of companies and data subjects. When looking at this right in a more systematic pe

### Article 22 GDPR on Automated Individual Decision-Making: Prohibition or Data Subject Right?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132543 — original: https://doi.org/10.21552/edpl/2022/2/6*

### Practitioner’s Corner ∙ Exercising GDPR Data Subjects’ Rights: Empirical Research on the Right to Explanation of News Recommender Systems

*Source: European Data Protection Law Review, 2020-01-01 — https://overview.legal/posts/132544 — original: https://doi.org/10.21552/edpl/2020/4/17*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Right of Access Procedures** — https://overview.legal/topics/article-15-gdpr-access-procedures
  This new topic is needed because Article 15 GDPR deserves dedicated coverage for its specific procedures, requirements, timelines, formats, and exceptions relat
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Data Controller** — https://overview.legal/topics/verwerkingsverantwoordelijke
  The entity that determines purposes and means of processing personal data

---
Generated by overview.legal · https://overview.legal/topics/inzagerecht · 2026-08-22
