EU Data Access Rules Tighten
Coverage from EFF, Privacy Daily, and others

EU institutions and courts are refining the boundaries of access to regulatory records and personal data.
The European Commission has formalized broader confidentiality presumptions for some DMA and DSA documents, while EU court decisions set high but clearer thresholds for refusing abusive requests and limit demands for entire business files where they contain little substantive personal data. These developments matter because they balance public oversight and individual privacy rights against confidentiality, administrative burden and misuse of access mechanisms.
The main change is a clearer legal framing: the Commission’s access regime is now described as formally placing certain DMA/DSA materials under confidentiality presumptions, while the court side has sharpened the limits on GDPR access requests by specifying when they can be treated as abusive or too broad. The story also narrows slightly from general document-disclosure debates to a more explicit distinction between personal-data access and wholesale document discovery.
The biggest change is that the story now includes a concrete Commission regulatory move: December 2024 rules presumptively keep more DMA and DSA materials confidential, sharpening the transparency fight. At the same time, the GDPR access-rights thread is narrowed further by explicit court guidance that access is for verification and personal data, not document discovery.
- December 2024 Commission rules add presumptions of non-disclosure for some DMA and DSA documents.
- Privacy International is specifically cited as criticizing the confidentiality rules.
- GDPR access is framed as verification of processing, not full document disclosure.
- Bodycam recordings from individuals trigger Article 13 notice duties.
The story has broadened beyond GDPR access-right limits into a wider EU digital-rights and transparency theme, adding AI redress, platform interoperability, and regulatory confidentiality disputes. The core access-request constraints remain, but they are now framed as part of a larger debate over how people can challenge automated and platform-based power.
- GDPR is being treated as a route for redress against harmful AI decisions.
- EU enforcement transparency under the DMA and DSA is now part of the story.
- Interoperability and data portability are newly central themes.
- Privacy groups and civil society are now highlighted as active stakeholders.
Recent EU and French rulings are tightening how GDPR access rights work in practice, especially around excessive or abusive requests, the scope of what must be disclosed, and when compensation is available.
