Procedure
An access request has arrived
An access request needs no reasons, and the motives behind it are in principle irrelevant. Since the judgment of 19 March 2026, however, even a first request can be excessive where the controller demonstrates an abusive intention. The burden of demonstrating that lies with the controller, and the deadline keeps running.
An access request during ongoing litigation
In the general mailbox sits an email with the subject line “Information about my data”. The sender is an employee whose unfair dismissal claim has been running for three weeks. The message is eleven days old. Nobody has read it.
The copy is not a copy of the file and more than a list
What the copy under Art. 15(3) sentence 1 GDPR covers is missed in two directions. What is owed is a copy of the personal data undergoing processing, not of the documents they sit in. Alongside that stand the eight items in paragraph 1.
The eight items in Art. 15(1) GDPR
Purposes and categories
The purposes of the processing and the categories of data concerned, points (a) and (b). Both already appear in the record of processing activities and can be taken from there.
Recipients and third countries
The recipients or categories of recipients, point (c), in particular in third countries. Under paragraph 2 the data subject also has to be informed of the safeguards under Art. 46 GDPR.
Duration and origin
The envisaged storage period or the criteria for determining it, point (d), and, where the data was not collected from the data subject, any available information about its source, point (g).
Rights and automated decisions
The rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, and the existence of automated decision-making together with meaningful information about the logic involved, points (e), (f) and (h).
Two claims in one provision
| Information under paragraph 1 | Merkmal | Copy under paragraph 3 |
|---|---|---|
| Information about the processingPurposes, categories, recipients, duration, rights, origin, automated decisions. | Subject matter | The data itselfIn the form in which it is processed. |
| Exhaustively listedEight points, plus paragraph 2 for third-country transfers. | Extent | All data processedIncluding from emails, notes and free-text fields, in so far as it is personal. |
| Art. 12(5) GDPRManifestly unfounded or excessive requests. | Limit | Additionally Art. 15(4) GDPRRights and freedoms of others. |
| Free of chargeArt. 12(5) sentence 1 GDPR. | Cost | First copy free of chargeFor further copies a reasonable fee based on administrative costs. |
The most common failure is conflating the two claims. A copy of the file without the eight items does not satisfy paragraph 1, and a table of master data does not satisfy paragraph 3.
The rights of others limit the copy, not the information
How to handle other people’s data and trade secrets is answered by Art. 15(4) GDPR only in part. The provision limits the right to obtain a copy and not the information about the processing as such.
Three steps instead of a blanket refusal
Separate
The personal data of the requesting person from that of others. A note about a conversation contains both, and only the first part is the subject of the claim.
Establish the adverse effect
Art. 15(4) GDPR requires an adverse effect in the individual case. The mere fact that a third party is named does not suffice.
Redact as little as possible
A redaction that leaves the copy saying nothing does not satisfy the claim. Where an adverse effect is established, the data subject has to be informed of that.
3 von 3
Trade secrets are not a separate ground for refusal under the regulation. They may enter the balancing under Art. 15(4) GDPR in so far as they concern the rights of another person. Alongside that stand the restrictions national legislatures may enact under Art. 23 GDPR, for Germany in particular section 34 BDSG.
The motive does not count, an abusive intention has since 2026
Whether it makes a difference that the request comes out of a live dispute has been answered by the Court of Justice twice, and the second answer is recent.
Two judgments, three years apart
26 October 2023
The request needs no reasons
In case C-307/22 the Court held that the first copy is owed free of charge even where the request is justified by a purpose other than checking the lawfulness of the processing. The controller may not require reasons.
19 March 2026
Even a first request can be excessive
In case C-526/24 the Court held that a first request can be treated as excessive where the controller demonstrates an abusive intention, such as artificially creating the conditions for obtaining an advantage under the regulation.
The two stand side by side and do not contradict each other. The motive remains in principle irrelevant, and the limit lies at abusive intention. Two consequences follow for practice.
The deadline runs from receipt and not from allocation
How the one-month deadline is organised internally decides the outcome more than the substantive law does. Art. 12(3) GDPR runs it from receipt of the request, and a request is received in a general mailbox too.
What should be settled before the first request
Liste zu erledigender Punkte
- Where requests can arrive, so general mailboxes, forms, telephone and paper post
- Who recognises them and forwards them, and to whom
- Which systems have to be searched, derived from the record of processing activities
- Which processors have to assist, under Art. 28(3)(e) GDPR
- Who decides on an extension and who communicates it
The extension by two months is available where the complexity or number of requests requires it. It has to be communicated within the first month, together with the reasons for the delay.
How we support you in responding to the access request
The preparation costs one morning and pays off with every request. The record of processing activities provides the list of systems and of processors. A template letter carrying the eight items of Art. 15(1) GDPR takes the sting out of the deadline.
Frequently asked questions
Does an access request have to give reasons?
No. The Court of Justice held on 26 October 2023 that neither Art. 12(5) nor Art. 15(1) and (3) GDPR require reasons. The controller may therefore not make them a condition.
Can even a first request be excessive?
Since 19 March 2026, yes. The Court of Justice held that a first request can be treated as excessive where the controller demonstrates an abusive intention. It may be taken into account whether, according to publicly available information, the person has made several access requests followed by damages claims.
What applies to other people's data?
Art. 15(4) GDPR limits the right to obtain a copy where it would adversely affect the rights and freedoms of others. That has to be established case by case and does not justify a blanket refusal. The information about the processing as such remains owed.
How long is the deadline?
One month from receipt of the request, Art. 12(3) GDPR. It may be extended by two months where the complexity or number of requests requires it. The extension has to be communicated within the first month, together with the reasons.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.