EU Data Access Rules Tighten
Coverage from Privacy International, Inside Privacy, and others
Articles
9
Active Days
137
The Topic

EU institutions and courts are refining the boundaries of access to regulatory records and personal data. The European Commission has formalized broader confidentiality presumptions for some DMA and DSA documents, while EU court decisions set high but clearer thresholds for refusing abusive requests and limit demands for entire business files where they contain little substantive personal data. These developments matter because they balance public oversight and individual privacy rights against confidentiality, administrative burden and misuse of access mechanisms.
First Article: 02/23/26
Latest Article: 07/09/26
Summary
- European Commission rules adopted in December 2024 place DMA and DSA proceedings within categories presumed confidential, according to civil-society critics.
- The Commission’s approach shifts more of the burden for disclosure onto applicants seeking to demonstrate an overriding public interest.
- EU courts have set a high threshold for treating GDPR access requests as abusive, requiring controllers to establish abusive intent from the circumstances rather than relying on suspicion.
- A first or single access request can still be excessive in exceptional cases, but a pending compensation claim or any single behavioral factor is not enough on its own.
- GDPR Article 15 does not generally entitle employees to entire work mailboxes or business files when the material contains no substantive personal data about them.
- Body-worn camera operators must provide Article 13 information when recording individuals directly, although layered notices may satisfy the obligation proportionately.
- The emerging legal direction distinguishes access to personal data from wholesale discovery of documents while preserving disclosure and compensation rights where legal conditions are met.
History
The main change is a clearer legal framing: the Commission’s access regime is now described as formally placing certain DMA/DSA materials under confidentiality presumptions, while the court side has sharpened the limits on GDPR access requests by specifying when they can be treated as abusive or too broad. The story also narrows slightly from general document-disclosure debates to a more explicit distinction between personal-data access and wholesale document discovery.
The biggest change is that the story now includes a concrete Commission regulatory move: December 2024 rules presumptively keep more DMA and DSA materials confidential, sharpening the transparency fight. At the same time, the GDPR access-rights thread is narrowed further by explicit court guidance that access is for verification and personal data, not document discovery.
