Back to all lessons
Awareness Lessons
3 months ago

German Court Allows Rejection of Abusive GDPR Access Requests

A German court ruled that GDPR Article 15 access requests submitted with the abusive intent of manufacturing damages claims can be lawfully rejected, aligning with CJEU precedent. This case highlights that data protection rights, while fundamental, are not absolute and can be denied under the 'manifestly unfounded or excessive' exception in GDPR Article 12(5). Organizations often feel compelled to fulfill every access request without scrutiny, exposing themselves to exploitation by bad-faith actors. The ruling matters because it empowers controllers to push back against abuse while reinforcing the importance of documenting the rationale for any rejection. Failure to properly assess and record decisions around DSARs can leave organizations legally vulnerable in either direction.

Tactical Insight

Immediate actions

  • Establish a formal DSAR intake process that captures contextual metadata (requester location, frequency, nature of request) to support abuse assessments.
  • Train your Data Protection Officer and legal team on the GDPR Article 12(5) 'manifestly unfounded or excessive' exemption and relevant CJEU rulings.

Long-term improvements

  • Implement a DSAR tracking system to detect patterns indicative of coordinated or abusive request campaigns across your organization.
  • Develop and document a risk-based decision framework for evaluating and formally responding to potentially abusive access requests.
  • Establish relationships with legal counsel familiar with cross-border GDPR enforcement trends and evolving case law.

Detection & Evidence measures

  • Maintain detailed audit logs of all DSARs including requester identity, timestamps, stated purpose, and organizational response decisions.
  • Monitor open-source intelligence (OSINT) and legal databases for reports of serial GDPR claimants or abuse patterns targeting your industry.