Last Update: 08/01/2026 at 2:00 PM EST

EU Data Access Rules Tighten

Coverage from Privacy International, Inside Privacy, and others

Articles

9

Active Days

137

The Topic

EU Data Access Rules Tighten topic image

EU institutions and courts are refining the boundaries of access to regulatory records and personal data. The European Commission has formalized broader confidentiality presumptions for some DMA and DSA documents, while EU court decisions set high but clearer thresholds for refusing abusive requests and limit demands for entire business files where they contain little substantive personal data. These developments matter because they balance public oversight and individual privacy rights against confidentiality, administrative burden and misuse of access mechanisms.

First Article: 02/23/26

Latest Article: 07/09/26

Summary

  • European Commission rules adopted in December 2024 place DMA and DSA proceedings within categories presumed confidential, according to civil-society critics.
  • The Commission’s approach shifts more of the burden for disclosure onto applicants seeking to demonstrate an overriding public interest.
  • EU courts have set a high threshold for treating GDPR access requests as abusive, requiring controllers to establish abusive intent from the circumstances rather than relying on suspicion.
  • A first or single access request can still be excessive in exceptional cases, but a pending compensation claim or any single behavioral factor is not enough on its own.
  • GDPR Article 15 does not generally entitle employees to entire work mailboxes or business files when the material contains no substantive personal data about them.
  • Body-worn camera operators must provide Article 13 information when recording individuals directly, although layered notices may satisfy the obligation proportionately.
  • The emerging legal direction distinguishes access to personal data from wholesale discovery of documents while preserving disclosure and compensation rights where legal conditions are met.

History

07/23/2026

The main change is a clearer legal framing: the Commission’s access regime is now described as formally placing certain DMA/DSA materials under confidentiality presumptions, while the court side has sharpened the limits on GDPR access requests by specifying when they can be treated as abusive or too broad. The story also narrows slightly from general document-disclosure debates to a more explicit distinction between personal-data access and wholesale document discovery.

07/23/2026

The biggest change is that the story now includes a concrete Commission regulatory move: December 2024 rules presumptively keep more DMA and DSA materials confidential, sharpening the transparency fight. At the same time, the GDPR access-rights thread is narrowed further by explicit court guidance that access is for verification and personal data, not document discovery.

Full History

Featured

Timeline: 137 Days

Feb 23Mar 23Apr 20May 4Jun 1Jun 29

Additional Articles

⭐⭐⭐⭐⭐

ICTRecht / Paul Bex02-23-2026
EU Court rules that bodycam data collection triggers GDPR Article 13 notices in Swedish public transport case.
Lewis Silkin / Michael Charalambous02-25-2026
france court of appeal clarifies gdpr article 15 dsar scope restricting access to substantive personal data in work emails.
Ropesgray03-19-2026
On 19 March 2026, the CJEU ruled that GDPR Article 12(5) can justify refusing even a first subject access request when controllers demonstrate abusive intent and break causation for Article 82 claims.
EFF / Karen Gullo07-09-2026
Analysis highlights EU Digital Markets Act interoperability scope after the European Commission declined to require social networking interoperability, citing privacy and lock-in impacts.
Privacy Daily06-29-2026
Cabrera and Maier argue GDPR automated decision safeguards and the CJEU explanation right support redress for AI-driven decisions affecting people across the EU.

⭐⭐⭐

Courthouse News Service / Eunseo Hong03-18-2026
Closing Arguments
An EU court ruled in a GDPR case involving a German optician and a customer that refusal of data access requests requires proof of abusive intent.