[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fK4hLTN_1CUCEH-EYC3aPlIcioaKsQ4Q6dOs_VORzuW4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"18ba657e-f3e7-4115-9c19-14e91041c4b1","austrian-court-litigation-risk-cannot-block-gdpr-data-access-rights","745eb651-97b5-4981-adf1-42a7ff3ebfe2","Austrian Court: Litigation Risk Cannot Block GDPR Data Access Rights","The OLG Wien ruling (11R86\u002F25k) confirms that data controllers cannot deny data subject access requests (DSARs) simply because the requester may use the information in legal proceedings. Controllers also cannot claim that a data subject's own personal data constitutes a protectable trade secret to justify withholding it. This matters because organizations routinely misuse 'abuse of rights' or 'trade secret' arguments as procedural shields against legitimate GDPR Article 15 requests. Failing to honor valid DSARs exposes organizations to regulatory fines, adverse court rulings, and reputational damage. Compliance teams must understand that the right of access is near-absolute and that restrictions are narrowly defined in law.","**Immediate actions:**\n- Audit all pending or recently rejected DSAR responses to ensure none were denied solely on litigation-risk or trade-secret grounds.\n- Train legal, compliance, and customer-service teams on the narrow, exhaustive list of lawful DSAR refusal grounds under GDPR Article 12(5) and Recital 63.\n\n**Process & Policy improvements:**\n- Establish a documented DSAR handling procedure that includes a legal-review checklist before any rejection is issued.\n- Separate internal trade-secret assessments from personal data disclosures, ensuring only third-party data or genuinely proprietary algorithms—not the data subject's own data—may be redacted.\n- Set SLA monitoring for DSAR response deadlines (30-day statutory limit) with escalation triggers for contested requests.\n\n**Long-term governance:**\n- Conduct annual mock-DSAR exercises to stress-test the organization's ability to locate, compile, and deliver personal data across all systems.\n- Engage Data Protection Officers proactively when legal disputes are anticipated, so DSAR strategy is aligned with litigation counsel without compromising compliance obligations.\n- Document all DSAR decisions with written legal rationale to demonstrate accountability to supervisory authorities.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 15 – Right of access by the data subject","GDPR Article 12(5) – Manifestly unfounded or excessive requests","GDPR Article 12(3) – Response timelines","GDPR Recital 63 – Purpose of the right of access","GDPR Article 23 – Restrictions (exhaustive list of lawful limitations)","NIST Privacy Framework PR.AC-P1 – Identities and credentials managed for authorized individuals","NIST SP 800-53 IP-1 – Consent \u002F Access and Amendment","CIS Control 3 – Data Protection (data governance and classification)","ISO\u002FIEC 27701:2019 – 7.3.2 Obligations to data subjects (access rights)","ITIL Service Operation – Request Fulfilment (handling formal data requests as service requests)","published","2026-07-07T12:20:40.933602+00:00","2026-07-07T12:20:40.6+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=OLG_Wien_-_11R86\u002F25k&diff=52078&oldid=52046","olg-wien-11r86-25k-da4610","OLG Wien - 11R86\u002F25k",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]