Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 4 Council drafts · 15 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Recital 35
Commission proposal
Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 35
May Presidency compromise
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
Recital 35
June Presidency compromise · 10 June
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
Recital 35
June Presidency compromise · 18 June
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller . For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities .
Recital 35
September Presidency compromise
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller . For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities .
Recital 35 4 Council drafts
Recital 35
21 May 2026 · May Presidency compromise
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
Recital 35
10 June 2026 · June Presidency compromise · 10 June
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
Recital 35
18 June 2026 · June Presidency compromise · 18 June
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller . For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities .
Recital 35
3 September 2026 · September Presidency compromise
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller . For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities .
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Alternative wordingAmendment 5 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or herthem are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or herthem to exercise his or hertheir other rights under Regulation (EU) 2016/679. ByWherecontrast,aitrequest is manifestly unfounded or excessive a controller should be clarified in Article 12 ofgive the Regulationchoicethatto a data subject to either pay a defined fee or have the rightrequestof access, which is from the outset favourablerefused to dataensuresubjects,ashouldproportionatenotresponsebeandabusedavoidinunexpectedthe sense that the data subjects abuse themcosts for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject.intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentiallyRights under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 may be used as an enabler of other rights or in the public interest. The use of rights under that Regulation as an enabler of other rights or other legitimate aims should not be deemed abusive, unfounded or excessive. The broad nature of a request should not render a request unfounded or excessive. The data subject, in the exercise of their data subject rights, should be presumed to act for reasonable purposes, unless the controller unequivocally demonstrates abusive intent on the part of the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Remove proposed wordingAmendment 123 · Arash Saeidi JURI
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Remove proposed wordingAmendment 124 · David Cormand JURI
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Remove proposed wordingAmendment 171 · David Cormand on behalf of the Verts/ALE Group IMCO
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Remove proposed wordingAmendment 326 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Alternative wordingAmendment 327 · João Oliveira ITRE · LIBE
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. ByGivencontrast,theitlargeshould be clarified in Article 12number of thependingRegulationorthatunresolved access requests before controllers since the rightentryofintoaccess, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15force of Regulation (EU) 2016/679 the, data subjectsubjects should be asdeemedspecificbyasdefaultpossibleto be acting in their legitimate interest of defending their fundamental right to data protection. OverlyBurdenbroadof proof to the effect that a request is unfair, disproportionate or devoid of a legitimate purpose should always reside with the controller, who should justify their decision on the basis of objective, concrete and undifferentiatedverifiablerequests should also be regarded as excessiveevidence.
Alternative wordingAmendment 328 · Diana Iovanovici Şoşoacă ITRE · LIBE
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, the period of access to the personal data and certain additional information. The right of access shouldmust allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. OtherThereexamplesisofno such thing as abuse includewhensituationsitwhere data subjects make excessive use of the right of access with the only intent of causing damage or harmcomes to thefundamentalcontrollerhumanorrightswhenandanfreedoms,individualinformedmakesconsent is determined solely by a requestcourt, butbecauseatourtheprimarysame time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reasonconcern is thatprotectingthe manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influencepeople, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broadtechnology and undifferentiatedAIrequestscomeshouldafteralso be regarded as excessivethat.
Alternative wordingAmendment 329 · Pernando Barrena Arza ITRE · LIBE
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or herthem are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allowallows the data subject to be aware of, and to verify, the lawfulness of the processing and enableenableshim or her tothe exercise his or herof other rights under Regulation (EU) 2016/679. ByItcontrastmay also enable the exercise of other fundamental rights, itconsumer protection rights, employment rights, rights to non-discrimination, rights of defence, or other legitimate public-interest aims, including research, journalism, collective redress, regulatory oversight or civil society monitoring. The fact that an access request may serve such purposes should be clarifiednot, in Articleitself,12 ofmake the Regulationrequestthatmanifestlytheunfoundedrightorofexcessive.access,Awhich is from the outset favourable to data subjects,request should not be abusedconsideredinexcessivethemerelysensebecausethatittheconcernsdataasubjectslongabuse them for purposes other than the protectionperiod of their data. For exampletime, suchcomplexanprocessing,abuseprofiling, automated decision-making, multiple recipients or categories of the right of access would arise where the data subject intends to cause the controller to refuse an access requestrecipients, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harmpossibletosystemictherights concerns. The controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lowerthe burden of proof regardingdemonstrating the manifestly unfounded or excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Alternative wordingAmendment 330 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay ITRE · LIBE
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse themthe means at their disposal to enforce the rights conferred by this Regulation for purposes otherunrelatedthanto the protection of their data. A request may in particular be regarded as excessive where those means are used for the purpose of obtaining commercially sensitive information or gaining insight into the internal processes of the controller, including for the benefit of an undertaking competing with the controller, of exerting pressure in unrelated proceedings, or of disrupting the administrative operations of the controller by imposing a manifestly disproportionate burden. Conversely, the exercise of the rights conferred by this Regulation for the purpose of verifying, in good faith, whether a controller complies with this Regulation shall not be regarded as unfounded or excessive, irrespective of whether those rights are exercised individually or with the assistance of, or through, a body referred to in Article 80. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Justification
The notion of 'abuse of rights' is an autonomous concept of Union law which the Court applies with extreme caution; invoking it against a fundamental right would be disproportionate and legally exposed. What is targeted is the instrumental use of the procedural means, not the right itself. The good-faith compliance-verification safeguard, anchored in Article 80, expressly protects citizen and non-profit scrutiny.
Alternative wordingAmendment 331 · Nadine Morano ITRE · LIBE
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In anythiseventregard, whilewhenrequestingexercising his or her right of access under Article 15 of Regulation (EU) 2016/679, the data subject must specify the precise scope of his or her request, as well as the specific justification for it, to allow the controller to assess whether it is reasonable. In any event, the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Alternative wordingAmendment 332 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For the purpose of mitigating the harms of abusive requests on controllers, requests should be considered excessive where the controller can demonstrate abusive intention, taking into account the relevant circumstances. For example, such an abuseabusive intention of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuseabusive intention include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conductintent of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuseabusive intent only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Alternative wordingAmendment 333 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that theThe right of access, which is froma free-standing fundamental right that acts as an enabler of other rights, including journalistic oversight, litigation support, collective redress, and the outsetverificationfavourableof academic or workplace fairness. A request shall never be deemed excessive or abusive solely based on its broad, exploratory, or comprehensive nature, nor due to the subjective motivation of the individual. The data subjects,subject should not be abusedrequiredinto provide a justification for the sense that the data subjects abuse them for purposes other than the protectionexercise of their data. For examplerights, suchandantheyabuseshallofbethe right of access would arise where the data subject intendspresumed to causeact for reasonable purposes, unless the controller tounequivocallyrefusedemonstratesanbad-faithaccessabusive intent. Where a request,inisorderproven to subsequentlybedemandgenuinelythe payment of compensationrepetitive, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller ormustwhengiveanthe individual makesa clear choice between paying a request,standardizedbutadministrativeatfee or having the samerequesttime offers to withdraw it in return for some form of benefit from the controllerrefused. MoreoverNevertheless, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 35
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. ByArticlecontrast12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, itthe controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be clarifiedconsideredinexcessiveArticlewhere12an abusive intention on the part of the Regulationdatathatsubject submitting those requests can be demonstrated by the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their datacontroller. For example, such an abuseabusiveof the right of accessintention would arise where the data subject intendssubmitstoexcessivecause the controller to refuse an access request, in order to subsequently demand the paymentnumbers of compensation,identicalpotentiallyorunderlargelythesimilarthreat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of accessrequests with the onlysole intent of causing damage or harm to the controller.orRepeatedwhenrequests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual makessubmits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller.Moreover, inwhenorderantosubjectkeep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character ofsubmits a request than regardingwith the manifestlysoleunfounded characterpurpose of aobtainingrequest.compensationTheforreasonan alleged infringement which is thatdeliberatelytheprovokedmanifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679by the data subject should,beoraswhenspecifictheasexercisepossible.ofOverlyabroadright is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and undifferentiatedburdenrequestspublicshould also be regarded as excessiveauthorities.
RemovedAdded
Both texts in full
European Commission proposal
Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Council Presidency text · ST 9547/26
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
Recital 35
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
Council Presidency text · ST 10426/26
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
Recital 35
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller. For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject , or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities.
Council Presidency text · ST 10677/26
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller . For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities .
Recital 35
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller . For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities .
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller . For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities .
Council Presidency text · ST 12535/26
Chapter III of Regulation (EU) 2016/679 sets out rights of the data subject and corresponding obligations of the controller. Inter alia, Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Article 12 (5) of that Regulation already provides that where the request to exercise a right under Regulation 2016/679 is manifestly unfounded or excessive, the controller may either charge a reasonable fee or refuse to act on the request. The controller should provide the data subject with the reason thereof. A request is also to be considered excessive where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller . For example, such an abusive intention would arise where the data subject submits excessive numbers of identical or largely similar requests with the sole intent of causing damage or harm to the controller. Repeated requests are not automatically excessive in nature but may indicate an abusive intent on the part of the data subject. Other examples include situations where an individual submits a request, but at the same time offers to withdraw it in return for some form of benefit from the controller , when an subject submits a request with the sole purpose of obtaining compensation for an alleged infringement which is deliberately provoked by the data subject, or when the exercise of a right is made with the intention to adversely affect a judicial procedure or with deliberate intention to adversely affect and burden public authorities .
Recital 35
Wording reproduced in the amendment → Amendment 323 · ITRE–LIBE amendments 251–400 to the draft report: removal
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 323 · ITRE–LIBE amendments 251–400 to the draft report: removal
Wording reproduced in the amendment → Amendment 324 · ITRE–LIBE amendments 251–400 to the draft report: removal
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 324 · ITRE–LIBE amendments 251–400 to the draft report: removal
Wording reproduced in the amendment → Amendment 325 · ITRE–LIBE amendments 251–400 to the draft report: removal
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 325 · ITRE–LIBE amendments 251–400 to the draft report: removal
Wording reproduced in the amendment → Amendment 326 · ITRE–LIBE amendments 251–400 to the draft report: removal
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 326 · ITRE–LIBE amendments 251–400 to the draft report: removal
Wording reproduced in the amendment → Amendment 327 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. ByGivencontrast,theitlargeshould be clarified in Article 12number of thependingRegulationorthatunresolved access requests before controllers since the rightentryofintoaccess, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15force of Regulation (EU) 2016/679 the, data subjectsubjects should be asdeemedspecificbyasdefaultpossibleto be acting in their legitimate interest of defending their fundamental right to data protection. OverlyBurdenbroadof proof to the effect that a request is unfair, disproportionate or devoid of a legitimate purpose should always reside with the controller, who should justify their decision on the basis of objective, concrete and undifferentiatedverifiablerequests should also be regarded as excessiveevidence.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 327 · ITRE–LIBE amendments 251–400 to the draft report
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. Given the large number of pending or unresolved access requests before controllers since the entry into force of Regulation (EU) 2016/679, data subjects should be deemed by default to be acting in their legitimate interest of defending their fundamental right to data protection. Burden of proof to the effect that a request is unfair, disproportionate or devoid of a legitimate purpose should always reside with the controller, who should justify their decision on the basis of objective, concrete and verifiable evidence.
Wording reproduced in the amendment → Amendment 328 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, the period of access to the personal data and certain additional information. The right of access shouldmust allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. OtherThereexamplesisofno such thing as abuse includewhensituationsitwhere data subjects make excessive use of the right of access with the only intent of causing damage or harmcomes to thefundamentalcontrollerhumanorrightswhenandanfreedoms,individualinformedmakesconsent is determined solely by a requestcourt, butbecauseatourtheprimarysame time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reasonconcern is thatprotectingthe manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influencepeople, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broadtechnology and undifferentiatedAIrequestscomeshouldafteralso be regarded as excessivethat.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 328 · ITRE–LIBE amendments 251–400 to the draft report
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, the period of access to the personal data and certain additional information. The right of access must allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. There is no such thing as abuse when it comes to fundamental human rights and freedoms, informed consent is determined solely by a court, because our primary concern is protecting people, and technology and AI come after that.
Wording reproduced in the amendment → Amendment 329 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or herthem are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allowallows the data subject to be aware of, and to verify, the lawfulness of the processing and enableenableshim or her tothe exercise his or herof other rights under Regulation (EU) 2016/679. ByItcontrastmay also enable the exercise of other fundamental rights, itconsumer protection rights, employment rights, rights to non-discrimination, rights of defence, or other legitimate public-interest aims, including research, journalism, collective redress, regulatory oversight or civil society monitoring. The fact that an access request may serve such purposes should be clarifiednot, in Articleitself,12 ofmake the Regulationrequestthatmanifestlytheunfoundedrightorofexcessive.access,Awhich is from the outset favourable to data subjects,request should not be abusedconsideredinexcessivethemerelysensebecausethatittheconcernsdataasubjectslongabuse them for purposes other than the protectionperiod of their data. For exampletime, suchcomplexanprocessing,abuseprofiling, automated decision-making, multiple recipients or categories of the right of access would arise where the data subject intends to cause the controller to refuse an access requestrecipients, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harmpossibletosystemictherights concerns. The controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lowerthe burden of proof regardingdemonstrating the manifestly unfounded or excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 329 · ITRE–LIBE amendments 251–400 to the draft report
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether personal data concerning them are being processed and, where that is the case, access to the personal data and certain additional information. The right of access allows the data subject to be aware of, and to verify, the lawfulness of the processing and enables the exercise of other rights under Regulation (EU) 2016/679. It may also enable the exercise of other fundamental rights, consumer protection rights, employment rights, rights to non-discrimination, rights of defence, or other legitimate public-interest aims, including research, journalism, collective redress, regulatory oversight or civil society monitoring. The fact that an access request may serve such purposes should not, in itself, make the request manifestly unfounded or excessive. A request should not be considered excessive merely because it concerns a long period of time, complex processing, profiling, automated decision-making, multiple recipients or categories of recipients, or possible systemic rights concerns. The controller should bear the burden of demonstrating the manifestly unfounded or excessive character of the request.
Wording reproduced in the amendment → Amendment 330 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse themthe means at their disposal to enforce the rights conferred by this Regulation for purposes otherunrelatedthanto the protection of their data. A request may in particular be regarded as excessive where those means are used for the purpose of obtaining commercially sensitive information or gaining insight into the internal processes of the controller, including for the benefit of an undertaking competing with the controller, of exerting pressure in unrelated proceedings, or of disrupting the administrative operations of the controller by imposing a manifestly disproportionate burden. Conversely, the exercise of the rights conferred by this Regulation for the purpose of verifying, in good faith, whether a controller complies with this Regulation shall not be regarded as unfounded or excessive, irrespective of whether those rights are exercised individually or with the assistance of, or through, a body referred to in Article 80. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 330 · ITRE–LIBE amendments 251–400 to the draft report
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse the means at their disposal to enforce the rights conferred by this Regulation for purposes unrelated to the protection of their data. A request may in particular be regarded as excessive where those means are used for the purpose of obtaining commercially sensitive information or gaining insight into the internal processes of the controller, including for the benefit of an undertaking competing with the controller, of exerting pressure in unrelated proceedings, or of disrupting the administrative operations of the controller by imposing a manifestly disproportionate burden. Conversely, the exercise of the rights conferred by this Regulation for the purpose of verifying, in good faith, whether a controller complies with this Regulation shall not be regarded as unfounded or excessive, irrespective of whether those rights are exercised individually or with the assistance of, or through, a body referred to in Article 80. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Wording reproduced in the amendment → Amendment 331 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In anythiseventregard, whilewhenrequestingexercising his or her right of access under Article 15 of Regulation (EU) 2016/679, the data subject must specify the precise scope of his or her request, as well as the specific justification for it, to allow the controller to assess whether it is reasonable. In any event, the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 331 · ITRE–LIBE amendments 251–400 to the draft report
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In this regard, when exercising his or her right of access under Article 15 of Regulation (EU) 2016/679, the data subject must specify the precise scope of his or her request, as well as the specific justification for it, to allow the controller to assess whether it is reasonable. In any event, the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Wording reproduced in the amendment → Amendment 332 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For the purpose of mitigating the harms of abusive requests on controllers, requests should be considered excessive where the controller can demonstrate abusive intention, taking into account the relevant circumstances. For example, such an abuseabusive intention of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuseabusive intention include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conductintent of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuseabusive intent only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 332 · ITRE–LIBE amendments 251–400 to the draft report
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For the purpose of mitigating the harms of abusive requests on controllers, requests should be considered excessive where the controller can demonstrate abusive intention, taking into account the relevant circumstances. For example, such an abusive intention of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abusive intention include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive intent of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abusive intent only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Wording reproduced in the amendment → Amendment 333 · ITRE–LIBE amendments 251–400 to the draft report
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that theThe right of access, which is froma free-standing fundamental right that acts as an enabler of other rights, including journalistic oversight, litigation support, collective redress, and the outsetverificationfavourableof academic or workplace fairness. A request shall never be deemed excessive or abusive solely based on its broad, exploratory, or comprehensive nature, nor due to the subjective motivation of the individual. The data subjects,subject should not be abusedrequiredinto provide a justification for the sense that the data subjects abuse them for purposes other than the protectionexercise of their data. For examplerights, suchandantheyabuseshallofbethe right of access would arise where the data subject intendspresumed to causeact for reasonable purposes, unless the controller tounequivocallyrefusedemonstratesanbad-faithaccessabusive intent. Where a request,inisorderproven to subsequentlybedemandgenuinelythe payment of compensationrepetitive, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller ormustwhengiveanthe individual makesa clear choice between paying a request,standardizedbutadministrativeatfee or having the samerequesttime offers to withdraw it in return for some form of benefit from the controllerrefused. MoreoverNevertheless, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 333 · ITRE–LIBE amendments 251–400 to the draft report
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. The right of access is a free-standing fundamental right that acts as an enabler of other rights, including journalistic oversight, litigation support, collective redress, and the verification of academic or workplace fairness. A request shall never be deemed excessive or abusive solely based on its broad, exploratory, or comprehensive nature, nor due to the subjective motivation of the individual. The data subject should not be required to provide a justification for the exercise of their rights, and they shall be presumed to act for reasonable purposes, unless the controller unequivocally demonstrates bad-faith abusive intent. Where a request is proven to be genuinely repetitive, the controller must give the individual a clear choice between paying a standardized administrative fee or having the request refused. Nevertheless, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level.
Wording reproduced in the amendment → Amendment 5 · ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or herthem are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or herthem to exercise his or hertheir other rights under Regulation (EU) 2016/679. ByWherecontrast,aitrequest is manifestly unfounded or excessive a controller should be clarified in Article 12 ofgive the Regulationchoicethatto a data subject to either pay a defined fee or have the rightrequestof access, which is from the outset favourablerefused to dataensuresubjects,ashouldproportionatenotresponsebeandabusedavoidinunexpectedthe sense that the data subjects abuse themcosts for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject.intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentiallyRights under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 may be used as an enabler of other rights or in the public interest. The use of rights under that Regulation as an enabler of other rights or other legitimate aims should not be deemed abusive, unfounded or excessive. The broad nature of a request should not render a request unfounded or excessive. The data subject, in the exercise of their data subject rights, should be presumed to act for reasonable purposes, unless the controller unequivocally demonstrates abusive intent on the part of the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning them are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable them to exercise their other rights under Regulation (EU) 2016/679. Where a request is manifestly unfounded or excessive a controller should give the choice to a data subject to either pay a defined fee or have the request refused to ensure a proportionate response and avoid unexpected costs for the data subject. Rights under Regulation (EU) 2016/679 may be used as an enabler of other rights or in the public interest. The use of rights under that Regulation as an enabler of other rights or other legitimate aims should not be deemed abusive, unfounded or excessive. The broad nature of a request should not render a request unfounded or excessive. The data subject, in the exercise of their data subject rights, should be presumed to act for reasonable purposes, unless the controller unequivocally demonstrates abusive intent on the part of the data subject.
Wording reproduced in the amendment → Amendment 171 · IMCO amendments 125–328 to the draft opinion: removal
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 171 · IMCO amendments 125–328 to the draft opinion: removal
Wording reproduced in the amendment → Amendment 123 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 123 · JURI amendments 69–296 to the draft opinion: removal
Wording reproduced in the amendment → Amendment 124 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(35) Article 15 of Regulation (EU) 2016/679 provides data subjects with the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and certain additional information. The right of access should allow the data subject to be aware of, and to verify, the lawfulness of the processing and enable him or her to exercise his or her other rights under Regulation (EU) 2016/679. By contrast, it should be clarified in Article 12 of the Regulation that the right of access, which is from the outset favourable to data subjects, should not be abused in the sense that the data subjects abuse them for purposes other than the protection of their data. For example, such an abuse of the right of access would arise where the data subject intends to cause the controller to refuse an access request, in order to subsequently demand the payment of compensation, potentially under the threat of bringing a claim for damages. Other examples of abuse include situations where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller. Moreover, in order to keep their burden to a reasonable extent, controllers should bear a lower burden of proof regarding the excessive character of a request than regarding the manifestly unfounded character of a request. The reason is that the manifestly unfounded character of a request depends on facts that lie principally within the controller’s sphere of responsibility, whereas the excessive character of a request concerns the possibly abusive conduct of a data subject, which lies primarily outside the controller’s sphere of influence, and therefore the controller may be able to prove such abuse only to a reasonable level. In any event, while requesting access under Article 15 of Regulation (EU) 2016/679 the data subject should be as specific as possible. Overly broad and undifferentiated requests should also be regarded as excessive.
Amendment 124 · JURI amendments 69–296 to the draft opinion: removal