EU Data Access Rules Tighten
Coverage from EFF, Privacy Daily, and others

EU institutions and courts are refining the boundaries of access to regulatory records and personal data.
The European Commission has formalized broader confidentiality presumptions for some DMA and DSA documents, while EU court decisions set high but clearer thresholds for refusing abusive requests and limit demands for entire business files where they contain little substantive personal data. These developments matter because they balance public oversight and individual privacy rights against confidentiality, administrative burden and misuse of access mechanisms.
The main change is a clearer legal framing: the Commission’s access regime is now described as formally placing certain DMA/DSA materials under confidentiality presumptions, while the court side has sharpened the limits on GDPR access requests by specifying when they can be treated as abusive or too broad. The story also narrows slightly from general document-disclosure debates to a more explicit distinction between personal-data access and wholesale document discovery.
The biggest change is that the story now includes a concrete Commission regulatory move: December 2024 rules presumptively keep more DMA and DSA materials confidential, sharpening the transparency fight. At the same time, the GDPR access-rights thread is narrowed further by explicit court guidance that access is for verification and personal data, not document discovery.
