Data subject access rights (“DSARs”) are increasingly testing the legal limits of access rights in contentious disputes across the EU, the UK and France. Although they are not a form of pre-action disclosure, they are a popular tool in litigation, providing cheap and easy access to information that would otherwise be sought through litigation procedures. In commercial, public authority and employment disputes, access requests now frequently require courts to determine whether the controller’s obligation extends beyond the basic data file to internal assessments, contextual extracts, professional correspondence, metadata, or material sought in parallel with compensation or litigation objectives. As a requester does not need to explain why they are making a DSAR, under the GDPR/UK GDPR, the legal difficulty is in identifying where the controller’s obligation ends when the request is made in an adversarial context.
Three main legal points emerge from the recent case law in Europe. First, the controller’s ability to demonstrate that a DSAR is motivated by abusive intent may matter where a DSAR is used not to verify processing, but to artificially create the conditions for a claim. Secondly, controllers cannot redefine the scope of a DSAR in accordance with internal operational and administrative boundaries. Thirdly, personal data may have to be provided with enough context to be intelligible, but the right of access remains a right to personal data, not a general right to documents, mailbox inspection or litigation disclosure.
The limits to DSAR obligations are being established differently in recent cases across jurisdictions in Europe. In the EU, the Court of Justice of the European Union (“CJEU”) has addressed the circumstances in which an access request may be refused where it is made with abusive intent and driven by a compensation strategy. In the UK, the High Court has examined the scope of a controller’s search obligations when receiving a DSAR, the distinction between personal data and documents, and the requirement that access be intelligible. In France, the Cour de cassation and the Paris Court of Appeal have considered whether professional emails sent or received through a work mailbox, fall within the right of access and how far that right may be relied on in employment litigation.
This article examines those developments through three decisions: the landmark judgment in Brillen Rottler GmbH & Co. KG v TC (Case C-526/24) handed down on 19 March 2026, Michael Ashley v The Commissioners for His Majesty’s Revenue and Customs [2025] EWHC 134 decided on 24 January 2025, and the French decisions in relation to professional emails of the Paris Court of Appeal, Cour d’appel de Paris, Pôle 6 Chambre 2, 18 December 2025, no. 25/04270 which built upon the prior Cour de cassation ruling of 18 June 2025 (no. 23-19.022).
For each decision, we consider the legal issue before the court, the reasoning adopted, and the practical implications for controllers handling contentious DSARs.
1. EU: Abusive access requests and compensation-driven DSARs after CJEU Brillen Rottler
a. Legal issue
In Brillen Rottler, the CJEU considered whether a first access request may be treated as excessive under Article 12(5) GDPR where it is made with abusive intent. The case arose from a DSAR made to a German optician following the data subject’s subscription to its newsletter. The controller refused to act on the request, arguing that it was abusive because evidence indicated that the claimant had deliberately created the circumstances for an access request and subsequent compensation claim. The allegation was not simply that the request was inconvenient or contentious, but that it formed part of a wider pattern of targeting businesses to provoke data protection infringements and seek monetary damages. The data subject challenged that refusal and sought non-material damages of €1,000 under Article 82 GDPR.
The reference raised two linked issues. Article 12(5) GDPR expressly allows controllers to charge a reasonable fee or refuse to act where requests are “manifestly unfounded or excessive”, in particular because of their repetitive character. The question was whether repetition is merely an example of excessiveness, or whether a first request can also be excessive where the request is made with an abusive intention to artificially create the conditions for a compensation claim. The CJEU also had to consider whether an alleged breach of the right of access could found a claim for compensation under Article 82 GDPR, and whether the data subject’s own conduct was relevant to damage and causation.
b. Court’s reasoning
The CJEU confirmed that manifestly unfounded or excessive requests, under Article 12(5) GDPR are not confined to repeated requests. A first access request may be “excessive” where the controller establishes, by reference to all relevant circumstances, that the request was made with abusive intent. The Court’s analysis is important because it shifts the focus under Article 12(5) from the frequency of submissions to whether the request was made for the proper purpose of enabling the data subject to be aware of the processing and verify its lawfulness, or whether it was made with an “abusive intention”, including by “artificially creating” the conditions for obtaining an advantage under the GDPR.
That does not give controllers a broad discretion to refuse difficult DSARs. The burden of proof remains on the controller. A request is not abusive simply because it is hostile, inconvenient, linked to a dispute or accompanied by a complaint. The controller must be able to demonstrate that the request does not seek to exercise the right of access for its statutory purpose, but that it is submitted for an artificial or abusive objective. The CJEU’s approach therefore extends the legal doctrine of abuse of rights to the right of access under Article 12(5), while keeping the exception strictly narrow.
The judgment also matters for compensation under Article 82 GDPR. The CJEU confirmed that a breach of Article 15 GDPR does not create an automatic right to damages. Therefore, the CJEU rejected a purely automatic link between a GDPR infringement and damages under Article 82 GDPR. A breach of access rights may nevertheless fall within the scope of Article 82 GDPR, but to successfully claim compensation, the data subject must still prove a distinct material or non-material damage, an actual infringement, and a direct causal link between that specific breach and the damage suffered. That distinction is critical where the factual matrix suggests that the data subject engineered the circumstances of the alleged harm. In that situation, the controller may have arguments not only on excessiveness under Article 12(5) GDPR, but also on causation under Article 82 GDPR.
c. Practical implications
For controllers, Brillen Rottler is useful but limited in practice. It is not a permission slip to treat contentious DSARs as abusive. It is a narrow route for cases which may be deemed excessive where the controller can prove, by objective circumstances, that it was made with abusive intent and for a purpose outside the proper exercise of the right of access. Data controllers can now legally reject tactical, bad-faith first requests, but they bear a heavy burden of proof to demonstrate an objective abuse of the right of access.
In practice, controllers considering reliance on manifestly unfounded or excessive grounds under Article 12(5) GDPR should document the basis for that position carefully. Relevant factors may include the sequence of events, the timing of the request, any standardised or repetitive pattern of conduct, the immediate assertion of compensation claims, and correspondence showing that the request is being used to create rather than vindicate a data protection claim. A refusal should explain why the request is excessive or abusive, why the evidence meets the threshold under Article 12(5) GDPR, and why refusal rather than a fee is justified on the facts.
Controllers facing speculative GDPR claims should challenge the claim for compensation under Article 82 GDPR as a separate issue. Even if a procedural breach has occurred, the claimant must still prove they suffered actual damage as a direct result of that breach. Brillen Rottler therefore assists controllers in two ways: it narrows the circumstances in which abusive access requests must be answered, and it confirms that a claimant cannot win compensation simply by proving a rule was broken.
2. UK: Scope of search and intelligibility of personal data after Ashley v HMRC
a. Legal issue
Ashley v HMRC concerned a DSAR made by Mike Ashley in the context of a high-stakes tax enquiry and tax dispute with HMRC. The request sought personal data processed by HMRC in relation to its enquiry into his tax affairs. HMRC initially adopted a narrow approach and relied on exemptions. During the proceedings, it accepted that it had breached aspects of Article 15 UK GDPR.
The High Court had to determine whether HMRC had construed the request too narrowly; whether the information in issue “related to” Mr Ashley for the purposes of Article 4(1) UK GDPR; the scope of HMRC’s search obligations; the lawfulness of reliance on statutory exemptions, including the tax exemption under Schedule 2, Part 1, Paragraph 2 of the Data Protection Act 2018; and whether the information provided met the standard of intelligibility required by Article 15(1) UK GDPR read alongside the transparency principles of Article 12(1) UK GDPR.
The case is significant because it addresses several recurring problems in contentious DSARs: how the scope of the request is to be interpreted, how far the controller must search, what counts as personal data, and whether providing isolated extracts is sufficient where context is needed to make the data intelligible. It also illustrates a frequent error in contentious DSARs, which is to treat the request as if it were simply a demand for documents, rather than first identifying the personal data contained in the material and then assessing what must be provided to comply with Article 15 UK GDPR.
b. Court’s reasoning
The High Court confirmed the orthodox starting point: the right of access is a right to personal data, not a general right to receive copies of underlying documents. A data subject is not entitled to obtain every document in which their name appears. The relevant question is whether the information is personal data within the meaning of the UK GDPR and whether it falls within the scope of the request.
The Court therefore had to consider the “relating to” limb of the personal data definition, under Article 4(1) UK GDPR. The issue was not only whether Mr Ashley was identifiable, but whether the information was sufficiently connected to him, by reason of its content, purpose, or effect, to constitute personal data. That point is central to the judgment. A controller may get it wrong by focusing on the document as a whole, rather than on whether information within it relates to the data subject.
That distinction matters in contentious disputes. A DSAR cannot be converted into standard disclosure or civil litigation discovery merely because the data subject is interested in the controller’s internal reasoning or wishes to understand the evidential basis for a position taken against them. However, the opposite is also true. A controller cannot avoid its access obligations by taking an artificially narrow approach to personal data or by confining the request to the department that first handled the matter.
The High Court ruled that HMRC had adopted an impermissibly narrow approach to the definition of personal data under Articles 15(1) and 15(3) UK GDPR. It concluded that HMRC had not properly identified all personal data falling within the request. The Court clarified that personal data extends to information within internal tax or regulatory assessments if it relates to an identifiable individual, even if contained within broader corporate or institutional files.
Crucially, the Court held that a data controller cannot artificially restrict the scope of its search by drawing the boundary around a particular internal department, unit or operational team if the relevant data logically resides elsewhere. The request was not limited to personal data processed by HMRC’s Wealthy and Mid-Size Business Compliance department. It extended to relevant personal data processed more widely by HMRC, including material held by the Valuation Office Agency. Furthermore, the Court rejected HMRC’s overbroad reliance on exemptions and redactions where the evidential basis for withholding the material had not been properly established.
One of the central points in Ashley v HMRC is that internal organisational structures do not define the legal scope of the right. Where a controller processes personal data falling within the request, the controller must take a legally compliant approach to identifying and searching relevant repositories. It cannot simply draw the boundary around the team, department or function most closely associated with the dispute.
The judgment is also important on intelligibility. Article 15 UK GDPR does not always require disclosure of full documents. But the personal data supplied must be meaningful. Where an extract is so narrow that the data subject cannot understand the personal data or the processing to which it relates, further context may be required. The Court’s approach is that additional contextual material may be required where it is necessary to make the personal data intelligible and to enable the data subject to exercise their UK GDPR rights effectively. Extracts consisting only of names, initials or decontextualised fragments may not be enough where context is needed to understand what is being disclosed.
c. Practical implications
For UK controllers, Ashley v HMRC is a warning against under-scoped DSAR responses. Large organisations, public authorities, banks, insurers and professional services firms should not treat the receiving department as the outer boundary of the request. Controllers must identify the repositories, systems, departments and agencies that may contain responsive personal data. They should not assume that the team handling the underlying dispute defines the limits of the DSAR.
A compliant DSAR response should record the interpretation of the request, the systems and business areas searched, the reasons for excluding other repositories, the search methodology applied, and the basis on which extracts rather than documents were provided. Where exemptions are relied on, the legal basis should be recorded with care. Where context is withheld, the controller should be able to explain why the personal data remains intelligible without it. Broad-brush redactions under the guise of statutory exemptions will not stand. Redactions must be specific, justified, and applied sparingly to preserve the contextual intelligibility of the data. The analysis of the applicable exemptions must be specific and evidence based. A broad reliance on statutory exemptions or the application of heavy redaction without explaining how the relevant legal threshold is met is unlikely to be sufficient or legally compliant.
The wider point is that Ashley v HMRC preserves the distinction between personal data and documents, but it does not allow controllers to use that distinction mechanically. The response must be legally reasoned. While the right of access is a right to data rather than the underlying documents, controllers must provide enough surrounding context to make the data intelligible in the sense of Article 15 UK GDPR, interpreted in light of the transparency obligations under Article 12(1) UK GDPR.
3. France: Professional emails and the limits of workplace DSARs after the decision of the Paris Court of Appeal
a. Legal issue
The two French decisions concern a question which has become central to DSARs in the employment context: whether emails sent or received by an employee through a professional mailbox constitute personal data, and whether the right of access extends to the content and metadata of those emails.
First, the Cour de cassation, in its decision of 18 June 2025, (Chambre sociale, n° 23-19.022) adopted a broad approach. It held that emails sent or received by an employee through a professional mailbox may constitute personal data and may fall within the right of access. However, the Paris Court of Appeal, in its decision of 18 December 2025, introduced a more limiting analysis where the request was used in an employment litigation context. These two interconnected decisions focused on employment law disputes. The Courts had to decide whether an employee’s right of access under Article 15 GDPR extends to professional emails sent or received via an employer-provided mailbox, and whether data controllers can limit or refuse such requests to protect business security or the rights and freedoms of third parties. The two decisions should be read together. The Cour de cassation addresses classification: professional emails may be personal data. The Paris Court of Appeal addresses limitation: Article 15 GDPR does not provide an unlimited route to gather workplace evidence. They expose the boundary between professional correspondence as personal data and professional correspondence as litigation material.
b. Court’s reasoning
The Cour de cassation adopted a broad approach to the classification of professional emails as personal data. The Court held that emails sent or received by an employee through a professional mailbox may constitute personal data. It ruled that an employer’s total failure to communicate professional emails and associated metadata containing an employee’s personal data constituted a clear violation of the GDPR, establishing that professional mailboxes are inherently within the scope of a DSAR, and confirming that professional emails cannot be excluded from the scope of a DSAR merely because they were sent or received through a work mailbox. The fact that the mailbox is professional does not remove the data from the scope of the GDPR. The Court’s approach aligns with the view that access may extend not only to the existence of the emails, but also to metadata, such as timestamps and recipients, and to content, subject to the rights and freedoms of others.
That is a significant burden for employers. It means that employee DSARs cannot be answered by disclosing only HR records, payroll data and formal personnel documents. In appropriate cases, the employer must search and consider professional correspondence, including email content and metadata.
The Paris Court of Appeal tempered this position and supplied a limiting principle. The Court clarified that because the objective of the right of access is strictly to enable the data subject to verify the lawfulness of processing, check the accuracy of personal data, and, where appropriate, exercise rights of rectification or erasure, it does not authorise a general and exhaustive review of a professional mailbox or work folders where the request is pursued for evidential purposes. Reviewing and disclosing entire mailboxes must be strictly limited to protect business confidentiality, trade secrets, and the privacy rights and freedoms of other employees and third parties.
On that analysis, Article 15 GDPR is not meant to be a mechanism for an exhaustive review of a professional mailbox or work folders where the real purpose is to obtain evidence for employment litigation.
The French position is therefore more nuanced than simply asserting that professional emails are disclosable. The first question is whether the emails contain personal data relating to the employee. The second is whether the content or metadata must be supplied to satisfy the right of access. The third is whether disclosure would adversely affect the rights and freedoms of others, confidentiality, business secrecy (secret des affaires), or the principle of litigation fairness.
c. Practical implications
For employers operating in France, the key point is that professional emails require a dedicated DSAR analysis. They should not be dismissed as business records outside the scope of access. Metadata and content are potentially disclosable where they contain personal data relating to the employee and disclosure is not limited by the rights and freedoms of others. Nor should they be disclosed wholesale merely because the employee sent or received them.
Controllers must carry out a balanced, step-by-step review of email systems, filtering out third-party personal data, confidential business information, legally privileged material, and material sought for evidential purposes before disclosure. A proper response should identify whether the request seeks personal data contained in emails or copies of emails as documents. It should consider metadata separately from content. It should assess whether the content is necessary to provide access to the employee’s personal data. It should also address third-party personal data, confidentiality, legal privilege, business information, and the purpose for which the request is being pursued.
For multinational organisations, these three distinct rulings highlight why a uniform global DSAR playbook creates significant compliance risks. A controller’s search obligations vary fundamentally by jurisdiction and context, ranging from navigating narrow public authority tax exemptions in the UK to managing wide-ranging mailbox reviews in French employment disputes. Consequently, the right of access demands strict, jurisdiction-specific handling.