GDPR Access Requests Cannot Be Dismissed as Abusive Even in Legal Disputes
An Austrian appellate court (OLG Wien) confirmed that data subjects retain the full right to submit GDPR Article 15 access requests even when their underlying motivation is to gather evidence for litigation, reinforcing CJEU precedent. Controllers cannot unilaterally label such requests as abusive simply because the outcome may be unfavorable to them legally. Additionally, the court rejected the argument that a data subject's own personal data could qualify as a trade secret — a defense that, if accepted, would fundamentally undermine data subjects' rights. This ruling matters because organizations that routinely deflect or delay access requests using pretextual justifications now face heightened legal risk. A proper, timely, and complete response to Article 15 requests is not optional — it is a core compliance obligation.
Tactical Insight
Immediate actions
- Audit all pending and recently rejected GDPR Article 15 access requests to ensure none were improperly denied on grounds of 'abuse' or 'trade secrets' relating to the requester's own data.
- Brief legal and compliance teams on the OLG Wien ruling and relevant CJEU judgments to align internal guidance with current case law.
Process & Policy improvements
- Establish a documented, legally reviewed workflow for handling Subject Access Requests (SARs) that includes clear criteria for what constitutes a genuinely abusive request under GDPR Article 12(5).
- Remove or revise any internal policy language that allows trade-secret claims to be used as a blanket exemption against disclosing a data subject's own personal data.
- Set enforceable SLA timers (maximum 30 days) for SAR responses with escalation paths to a designated Data Protection Officer.
Training & Awareness measures
- Train customer-facing, legal, and HR staff on data subjects' rights so that legitimate access requests are not misclassified as threats or harassment.
- Conduct annual tabletop exercises simulating SAR scenarios — including adversarial or litigation-motivated requests — to validate readiness and reduce response errors.