DSARs and the Digital Omnibus: What the Leaked Draft Reveals
The latest version of the proposed Digital Omnibus Regulation that will amend the GDPR (Proposal 2025/0360) (the “Draft Regulation”), which was leaked in September 2026, has already attracted considerable commentary, some of it heated. In this briefing, we focus on the current state of play regarding proposed updates to the circumstances in which a controller may refuse to act on or charge a fee for dealing with a data subject request.
Recap
The initial version of the Draft Regulation that was published on 19 November 2025 included an amendment to Article 12(5) of the GDPR to enable a controller to charge a reasonable fee or refuse to act on a data subject request specifically under Article 15 if “the data subject [abused] the rights conferred by [the GDPR] for purposes other than the protection of their data”. Recital 35 of that version of the Draft Regulation set out non-exhaustive examples of when such abuse might arise. These included “where data subjects make excessive use of the right of access with the only intent of causing damage or harm to the controller or when an individual makes a request, but at the same time offers to withdraw it in return for some form of benefit from the controller”.
In their joint opinion on this initial version, the EDPB and EDPS were critical of this proposed amendment. In particular, they objected to controllers being able to refuse a DSAR merely because it was made for purposes other than the protection of the individual’s personal data. They proposed that narrower wording, referring to an “abusive intention” should be included instead.
Subsequently, in March 2026 the CJEU delivered its decision in the Brillen Rottler case. This related to the interpretation of the current wording of Article 12(5) (which refers to manifestly unfounded or excessive requests and does not make any reference to abusive intention). The CJEU followed the recommendations of Advocate General Szpunar (which were referenced in the EDPB and EDPS’s joint opinion on the Draft Regulation). It held that a request could be construed to be excessive if it could be shown to have been made with abusive intention.
What the Draft Regulation Says
The latest version of the Draft Regulation proposes that Article 12(5) will be amended essentially to incorporate an express reference to “abusive intention” as a third ground for refusing to act or charging a reasonable fee to deal with a data subject request (in addition to “manifestly unfounded” or “excessive”). This will be somewhat helpful to controllers, but it will not move the dial significantly since in the Brillen Rottler decision the CJEU has already recognised that “abusive intention” is implicitly covered in any event by the existing wording of Article 12(5). The latest version does not incorporate the broader concept of ‘abuse’ set out in the initial version of the Draft Regulation that was published in November 2025.
On a slightly more positive note, controllers being plagued by AI-generated DSARs (or at least those in the public sector) will find some grounds for modest encouragement in updates to Recital 35 of the Draft Regulation. The amended Recital 35 sets out the following non-exhaustive examples of where an abusive intention may arise:
- where a data subject submits a request with the sole intent of causing harm to the controller, including by making excessive numbers of identical or largely similar requests;
- where an individual submits a request but simultaneously offers to withdraw it in return for some form of benefit from the controller;
- where a data subject submits a request with the sole purpose of obtaining compensation for an alleged infringement; and
- where a right is exercised with the intention to adversely affect public authorities, for instance by using AI agents for broad and malicious automated requests.
The limited wording regarding the use of “AI agents” is narrower than many organisations might like. However, a reference to the use of AI tools to generate DSARs, as a non-exhaustive example of ‘abusive intention’ is perhaps better than no reference to AI in this context at all.
There is a little more cause for optimism for controllers in relation to proposed amendments to the wording in Article 12(5) regarding the burden of proof. Article 12(5) currently provides that controllers bear the burden of demonstrating that a request is “manifestly unfounded” or “excessive”. In the latest version it is proposed that this will be amended so that controllers bear the burden of demonstrating that “there are reasonable grounds to believe that, in the light of all of the relevant circumstances of the case” the request is “manifestly unfounded” or “excessive” or the data subject has an “abusive intention”.
Commentary
Out of the various potential amendments to the GDPR that were signalled in 2025, a broadening of the grounds for refusing to deal with a DSAR was among the most popular and eagerly anticipated amendments (at least among businesses). It was hoped that this would be one of the more material changes to the administrative burden imposed by the GDPR. Those hopes will be bruised if not entirely dashed by the latest version of the Draft Regulation.
What Organisations Should Do
Although the Digital Omnibus has some distance yet to travel before being finalised, it seems safe to assume that it will not include a silver bullet to make handling DSARs materially easier. Organisations grappling with the burden imposed by DSARs should therefore be considering how best to apply the Brillen Rottler ruling to their processes to deal with DSARs as efficiently as possible, pending the modest improvements that will be introduced when the Digital Omnibus is finalised and becomes applicable.
This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.


Select how you would like to share using the options below