Access to personal data: when the controller can refuse - Digital Agenda
Summary
This article explains a new Court of Justice of the EU ruling on when a company can refuse or limit a personal data access request under GDPR. The court says even a first access request can be considered excessive if the company can prove abusive intent. It also clarifies that the burden of proof stays with the controller and that a claimant must show actual damage plus causation to win compensation. For businesses, the key takeaway is to tighten request-triage processes, preserve evidence, and document decisions carefully. The ruling is especially relevant for companies that handle high volumes of access requests and need stronger privacy compliance workflows.
Classifications
industries
No industries detected
applications
No applications detected
AskAI Classifications
Labels
No AI classifications detected