Legislation in motion
Proposal: refusing requests that abuse the right of access (Article 12(5) GDPR)
- Date
- Status
- proposal
- Body
- Europese Commissie
- Reference
- COM(2025) 837 final, 2025/0360(COD), artikel 3, punt 4 (vervanging artikel 12, lid 5 AVG) en overweging 35; Raadsdocument ST 15698/25 van 20 november 2025; EDPB-EDPS Joint Opinion 2/2026, par. 53 t/m 59
What it is about
The proposal adds to the existing rule on manifestly unfounded or excessive requests. A controller could refuse, or charge a reasonable fee for, an access request under Article 15 where the data subject abuses the rights conferred by the GDPR for purposes other than protecting their data. The burden of proof stays with the controller. For a manifestly unfounded request the controller must demonstrate it. For an excessive request, reasonable grounds to believe it is excessive would suffice. Recital 35 gives examples of abuse. A data subject provokes a refusal in order to claim compensation. A data subject makes requests only to harm the controller. Or a data subject offers to withdraw the request in return for a benefit. According to that recital, overly broad and undifferentiated requests are also excessive. In Joint Opinion 2/2026 the EDPB and EDPS want abuse tied to an abusive intention, such as an evident intention to cause harm, rather than to the purpose of the request, since the Court of Justice has confirmed that access may be sought for other purposes. They also recommend removing the lower burden of proof threshold and the statement on overly broad requests.
What this means in practice
If adopted, you would gain an express ground to refuse access requests that do not serve to protect personal data, such as requests designed to provoke a damages claim. Your evidence of excessiveness would face a lower threshold. You would still need to substantiate and document the abuse case by case. The wording may still change before adoption, particularly if the EDPB and EDPS criticism is taken on board. Until then the current GDPR applies as interpreted by the Court. The purpose of a request does not in principle make it invalid (C-307/22). Since Brillen Rottler (C-526/24, 19 March 2026), however, you may refuse a request as excessive, even a first one, if you show it was made solely to artificially create a compensation claim. As of 15 September 2026 the European Parliament has not voted in committee. The ITRE and LIBE draft report dates from 22 June 2026.
The GDPR articles concerned
Source: Raad van de EU, register (COM(2025) 837 final als ST 15698/25); EDPB-EDPS Joint Opinion 2/2026checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Part of the file
Themes where this returns
The counterpart in the other law
Case law
- Brillen Rottler: even a first access request can be abusive if made solely to claim compensation
2026-03-19 · final, Hof van Justitie van de EU (Vierde kamer), Brillen Rottler GmbH & Co. KG tegen TC
- Dun & Bradstreet: right to an intelligible explanation of an automated decision, trade secrets are no absolute ground for refusal
2025-02-27 · final, Hof van Justitie van de EU (Eerste kamer), CK tegen Magistrat der Stadt Wien, met Dun & Bradstreet Austria GmbH als andere partij
- Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
2025-09-24 · final, Raad van State, Afdeling bestuursrechtspraak
- Council of State upholds 6,000 euro DPA fine for recruitment firm
2024-05-29 · final, Raad van State, Afdeling bestuursrechtspraak
- SCHUFA: a credit score on which third parties draw strongly is automated decision-making
2023-12-07 · final, Hof van Justitie van de EU (Eerste kamer), OQ tegen Land Hessen, met SCHUFA Holding AG als interveniënt
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
Guidelines
- Guidelines on transparency under Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
- European Economic and Social Committee adopts opinion on the Digital Omnibus
2026-03-18 · final, Europees Economisch en Sociaal Comité
- European Central Bank issues opinion on the Digital Omnibus
2026-03-10 · final, Europese Centrale Bank
Enforcement and fines
- Netflix fined 4.75 million euros for failing to properly inform customers
2024-11-26 · under appeal, Autoriteit Persoonsgegevens
- 10 million euro fine for Uber over unclear retention and transfer information, objection rejected
2023-12-11 · under appeal, Autoriteit Persoonsgegevens
- 6,000 euro fine for Ambitious People Group for ignoring erasure requests
2020-07-30 · final, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
2024-05-16 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 17
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Committee of the Regions adopts opinion on the Digital Omnibus
2026-05-07 · final, Europees Comité van de Regio's
- Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
2025-11-19 · proposal, Europese Commissie