Skip to main content
Praxikon

Legislation in motion

Proposal: refusing requests that abuse the right of access (Article 12(5) GDPR)

Date
Status
proposal
Body
Europese Commissie
Reference
COM(2025) 837 final, 2025/0360(COD), artikel 3, punt 4 (vervanging artikel 12, lid 5 AVG) en overweging 35; Raadsdocument ST 15698/25 van 20 november 2025; EDPB-EDPS Joint Opinion 2/2026, par. 53 t/m 59

What it is about

The proposal adds to the existing rule on manifestly unfounded or excessive requests. A controller could refuse, or charge a reasonable fee for, an access request under Article 15 where the data subject abuses the rights conferred by the GDPR for purposes other than protecting their data. The burden of proof stays with the controller. For a manifestly unfounded request the controller must demonstrate it. For an excessive request, reasonable grounds to believe it is excessive would suffice. Recital 35 gives examples of abuse. A data subject provokes a refusal in order to claim compensation. A data subject makes requests only to harm the controller. Or a data subject offers to withdraw the request in return for a benefit. According to that recital, overly broad and undifferentiated requests are also excessive. In Joint Opinion 2/2026 the EDPB and EDPS want abuse tied to an abusive intention, such as an evident intention to cause harm, rather than to the purpose of the request, since the Court of Justice has confirmed that access may be sought for other purposes. They also recommend removing the lower burden of proof threshold and the statement on overly broad requests.

What this means in practice

If adopted, you would gain an express ground to refuse access requests that do not serve to protect personal data, such as requests designed to provoke a damages claim. Your evidence of excessiveness would face a lower threshold. You would still need to substantiate and document the abuse case by case. The wording may still change before adoption, particularly if the EDPB and EDPS criticism is taken on board. Until then the current GDPR applies as interpreted by the Court. The purpose of a request does not in principle make it invalid (C-307/22). Since Brillen Rottler (C-526/24, 19 March 2026), however, you may refuse a request as excessive, even a first one, if you show it was made solely to artificially create a compensation claim. As of 15 September 2026 the European Parliament has not voted in committee. The ITRE and LIBE draft report dates from 22 June 2026.

The GDPR articles concerned

Source: Raad van de EU, register (COM(2025) 837 final als ST 15698/25); EDPB-EDPS Joint Opinion 2/2026checked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Case law

Guidelines

Legislation in motion6 of 17