Data Subject Access Requests Abuse Under the Digital Omnibus

29/06/2026Introduced by the European Commission on 19 November 2025, the Digital Omnibus is a broad legislative package that would amend several EU digital laws, including the GDPR, the ePrivacy Directive, the Data Act and the NIS2 Directive. It aims to simplify the increasingly complex EU digital rulebook.  

This blog is part of a series exploring the proposals set out in the European Commission’s Digital Omnibus package. In a previous blog, we examined the Omnibus’ vision regarding the legal framework surrounding cookies. In this blog we will focus on the proposal to amend Article 12(5) GDPR and what it could mean for organizations navigating the fine line between legitimate access requests and the ones that are anything but.  

The current framework  

Most organizations are familiar with data subject access requests. Under the GDPR, any individual can ask an organization to confirm whether they process their personal data and, if so, to provide a copy. This request must be fulfilled free of charge and must be handled within one month. In practice, however, not every access request is submitted in that spirit. A common example is an access request submitted by an (ex-)employee not to verify what data an organization holds, but as a mechanism to obtain documents for use in an employment dispute.  

To deter this, under Article 12(5) GDPR, data controllers can refuse to act on an access request, or charge a reasonable fee, where requests are manifestly unfounded or excessive. In practice, however, this rarely works. The word “manifestly” sets a high bar; you need clear, documented evidence of abuse, and the burden of proof rests entirely with you as the controller. In practice, this has left many organizations caught between the cost of responding to requests that feel tactical or strategic, and the risk of liability if they refuse. And so, we see that controllers seldom succeed in, or even try to, proving that an access request is manifestly unfounded or excessive.  

The proposal by the European Commission  

The Digital Omnibus proposes to make this easier. The proposed amendment to Article 12(5) GDPR would explicitly allow controllers to refuse, or to charge a fee for, an access request where the data subject is abusing their rights. The Omnibus recitals provide concrete examples, such as requests made with the sole intent of causing damage to the controller. The proposal also signals that overly broad and vague requests can be treated as excessive, and that data subjects should be as specific as possible when submitting a request.  

In practice, this means that requests submitted primarily to gather evidence for litigation, or requests made with the sole intent of causing damage to the controller, or cases where an individual offers to withdraw the request in return for monetary benefit, could more clearly fall within the scope of a refusal ground.  

That said, the proposal has its limits. The EDPB and EDPS have pushed back in their joint opinion, recommending that refusal should only be permitted where there is demonstrable intent to cause harm, which is a higher bar than the Commission’s text suggest. Whether that position survives the trilogue negotiations remains to be seen.  

The operational reality: what changes if the proposals hold?  

Whether or not the Omnibus passes in its current form, there are concrete steps your organization can take now.  

  • Get your intake process in order. Every access request should be logged from the moment it arrives, including the date, the channel, the scope of what is being asked, and any context that might be relevant to assessing the request. If you ever need to substantiate or justify a refusal, that paper trail is your first line of defense.  
  • Ask for clarification before considering refusal. If a request feels unusually broad or the timing seems off, do not refuse outright. Instead, go back to the data subject and ask them to specify what they are looking for.  
  • Document everything if you suspect abuse. If the same individual has targeted multiple organizations, or if the request arrives alongside a legal threat, document everything during the decision-making process. The burden of proof is on you, and a well-documented file can justify a defensible refusal.  

Looking forward  

The Omnibus proposal does not fundamentally change the rules, but it does signal where things are heading. The right of access is not absolute, and organizations are not without recourse when it is misused. But what the proposal does not do is reduce the operational burden on organizations. Documenting requests, assessing intent, and substantiating refusal decisions will remain your organization’s responsibility.  

For organizations, the practical takeaway is to invest in the infrastructure that will support any future refusal decision, for example documented intake procedures, clear reasoning trails, and a habit of asking data subjects to specify or narrow broad requests before considering refusal. That approach is consistent with current law, the Omnibus proposal, and defensible before a supervisory authority regardless of the outcome of the trilogue negotiations.   

Emmy Zhang Legal Consultant

Do you want to know more?

Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.

Our services orContact