Back to all lessons
Awareness Lessons
3 months ago

Austrian Court Upholds GDPR Access Rights Regardless of Litigation Intent

An Austrian appellate court ruled that a landlord acting as a data controller cannot deny a tenant's GDPR Article 15 access request simply because the tenant may use the data in a legal dispute. The court also rejected the claim that data could be withheld under trade secret protections, reinforcing that data subjects have an unconditional right to verify how their personal data is processed. This case highlights a common misconception among organizations that 'inconvenient' or 'strategically timed' data subject requests can be deflected as abusive. Failure to comply with legitimate access requests exposes controllers to regulatory enforcement, court orders, and reputational damage. Organizations must treat GDPR rights as non-negotiable obligations, not optional courtesies.

Tactical Insight

Immediate actions

  • Establish a documented Subject Access Request (SAR) intake and response procedure with clear ownership and a 30-day response timeline.
  • Train legal, HR, and operations staff to recognize valid GDPR Article 15 requests and avoid reflexively rejecting them based on perceived intent.

Process & Policy improvements

  • Create a legal review checklist to evaluate only the narrow, lawful grounds (e.g., third-party rights, manifestly unfounded requests) before considering any refusal of an access request.
  • Maintain a comprehensive data inventory (Record of Processing Activities) so personal data can be located and compiled quickly in response to SARs.
  • Establish clear internal escalation paths so data protection officers (DPOs) are consulted before any SAR is refused.

Monitoring & Compliance measures

  • Log all incoming SARs, decisions made, and response timelines to demonstrate accountability to supervisory authorities.
  • Conduct annual GDPR compliance audits that specifically test SAR handling procedures against current regulatory guidance and case law.