Skip to main content
DSAR Rejection Is Not a Compliance FailureLaws and Regulations
5 min readFor Legal Counsel

DSAR Rejection Is Not a Compliance Failure

The Conventional Wisdom

Many privacy teams follow a simple rule: never reject a Data Subject Access Request (DSAR). This approach seems logical because Article 15 of the GDPR grants individuals the right to access their personal data. Refusing a request could lead to regulatory scrutiny, complaints to supervisory authorities, and reputational damage. It's often seen as safer to process every DSAR, even the burdensome ones, than risk accusations of violating data subject rights.

This defensive stance has become common. Your team likely has a policy stating, "Process all DSARs within 30 days unless an extension is necessary for complexity." You've built workflows, assigned staff, and accepted that some requests will consume significant resources. Rejecting a request feels like admitting non-compliance.

Why We Disagree

This blanket acceptance misinterprets both the regulation and recent case law. The CJEU has acknowledged that organizations can reject DSARs when they are "manifestly unfounded or excessive" under Article 12(5) GDPR. You're not required to process every request, and treating rejection as taboo leaves your team open to strategic abuse.

The regulation itself anticipates this situation. Article 12(5) allows controllers to refuse requests that are "manifestly unfounded or excessive, in particular because of their repetitive character." It doesn't specify "after the third request" or "only in extreme cases." You may refuse when the request meets that threshold, even if it's the first time that particular data subject has contacted you.

The CJEU's position supports this interpretation. The court clarifies that the "manifestly unfounded or excessive" standard applies to the request itself, not the requester's history. A first-time DSAR can be rejected if it meets the criteria, if it's clearly made in bad faith, imposes an unreasonable burden, or is part of a pattern designed to harass rather than exercise legitimate rights.

The Evidence

Consider what Article 12(5) actually requires. The controller must show that the request is "manifestly unfounded or excessive." This is a high bar but a specific one. Manifestly unfounded means the request has no legitimate purpose, it's not seeking information the data subject needs for any recognizable right or interest. Excessive means the burden imposed is disproportionate to any legitimate objective.

The CJEU's framework gives you three paths to justify rejection:

Repetitive requests with no changed circumstances. If a data subject submits identical or substantially similar requests within a short timeframe, and you've already provided the information, subsequent requests may be excessive. The regulation explicitly names repetitive character as a factor.

Requests designed to disrupt operations. A DSAR that requires you to search years of archives, involve dozens of employees, and compile hundreds of pages of documents may be excessive if the data subject has shown no genuine interest in the information or has made clear their intent is to burden your organization.

Requests that contradict their stated purpose. Article 15 exists to let individuals understand what data you hold and how you process it. If the request's scope or framing makes clear it's serving a different purpose, litigation strategy, competitive intelligence, harassment, you can challenge its legitimacy.

The key phrase is "manifestly." You must be able to show, without extensive investigation, that the request fails the legitimacy test. If you need to conduct discovery to determine whether rejection is justified, the request probably isn't manifestly unfounded.

What to Do Instead

Develop a DSAR triage process that evaluates requests against Article 12(5) criteria before committing resources. This isn't about finding excuses to reject requests; it's about identifying the small subset that genuinely meet the manifestly unfounded or excessive threshold.

Document your assessment. When you receive a DSAR, record the scope of the request, any previous requests from the same data subject, the estimated effort required to fulfill it, and any indicators suggesting bad faith or disproportionate burden. If you decide to process the request despite concerns, note why. If you reject it, your documentation must show you applied the Article 12(5) standard.

Communicate your reasoning. Article 12(5) requires you to inform the data subject of your refusal and their right to lodge a complaint with a supervisory authority or seek judicial remedy. Don't just cite the article number. Explain specifically why this request is manifestly unfounded or excessive: "Your request seeks all communications mentioning your name across seven years of email archives, instant messages, and internal documents. Given that you've indicated your sole purpose is to identify material for pending litigation, and you've made three similar requests in the past two months, we've determined this request is excessive under Article 12(5) GDPR."

Charge reasonable fees for excessive requests. Article 12(5) also permits you to charge a reasonable fee based on administrative costs instead of outright rejection. For borderline cases, requests that are burdensome but not clearly abusive, this middle path lets you fulfill the request while signaling that the burden is recognized.

Prepare for challenge. The data subject can complain to a supervisory authority or file suit. Your Article 12(5) assessment must be defensible. Vague claims that a request is "too much work" won't survive scrutiny. Specific evidence that the request is repetitive, made in bad faith, or disproportionate to any legitimate interest will.

When the Conventional Wisdom Is Right

Most DSARs don't meet the Article 12(5) threshold, and you should process them. A request is not excessive simply because it's inconvenient or time-consuming. Individuals have a fundamental right to access their personal data, and that right doesn't disappear because fulfillment requires effort.

Reject a DSAR only when you can clearly articulate why it's manifestly unfounded or excessive, and only after documenting that assessment. If you're uncertain, process the request. The risk of incorrectly rejecting a legitimate DSAR, regulatory action, litigation, reputational harm, far outweighs the cost of processing one more request.

The CJEU's position doesn't give you license to reject DSARs you find annoying. It confirms that the regulation already contains a mechanism to address abuse, and it's your responsibility to apply that mechanism correctly. Use Article 12(5) when it applies. Ignore it when it doesn't.

You Might Also Like