An employee requests a copy of his own performance records based on his right of access. The employer does not explicitly refuse, but invites him to come view the documents on-site by appointment. Is that sufficient? In a decision dated May 6, 2026 (No. 97/2026) The Dispute Chamber of the Data Protection Authority (GBA) ruled otherwise: an invitation to view the documents at the office is not a valid response to a request for a copy, nor could the employer rely on the alleged excessive nature of the request.
The facts
The complainant is a technician at a company. Starting on May 10, 2021, he repeatedly requested a copy of his timesheets for the period from May 10, 2016, to May 10, 2021—handwritten weekly sheets detailing his travel, service calls, and hours worked. He wanted to verify whether the hours he had entered himself matched what his employer had ultimately recorded and paid.
On that day, the employer provided him with a single form and, for the rest, referred him to a procedure: make an appointment, at least seven business days in advance, to review the forms on-site at the company’s headquarters. The complainant repeated his request, including by registered letter on January 17, 2022, with explicit reference to the General Data Protection Regulation (GDPR). The employer stood by his position and never provided the requested copies.
On July 27, 2023, the complainant filed a complaint with the GBA. Following an adversarial proceeding, a prima facie decision, and a hearing on the merits, the Dispute Resolution Chamber issued its decision.
The decision
The Dispute Chamber finds that the company has violated Articles 12.2, 12.3, 12.4, 15.1, and 15.3 of the GDPR, issues a reprimand, and orders the company to submit a copy of all performance records within one month. No fine. Three separate questions underpin that conclusion.
Was the request for access clear enough?
The employer argued that the request was never specific enough to be acted upon. The Dispute Resolution Chamber rejects this argument. The very first request of May 10, 2021, could be interpreted as a request for access and a copy within the meaning of Articles 15.1 and 15.3 of the GDPR. The fact that the employer responded immediately by providing one corrected record and proposing a procedure demonstrates that it had understood the intent of the request. The subsequent request of January 17, 2022, formulated by counsel with reference to the GDPR, removed any remaining ambiguity.
The Dispute Chamber concludes that the actual reason for the failure to respond was not a lack of clarity, but rather the workload the employer feared. Had there truly been any doubt regarding the scope, the employer would have been required to clarify it pursuant to its duty to facilitate under Article 12.2 of the GDPR.
Could the employer have refused the request on the grounds that it was unreasonable?
The employer invoked the manifestly unfounded or excessive nature of the request (Article 12.5 of the GDPR), citing the significant workload involved: the files were organized by date rather than by employee and spread across dozens of folders. The Dispute Chamber rejected this argument. Article 12.5 of the GDPR is an exception that must be interpreted restrictively; the burden of proof rests with the data controller.
She refers to the judgment Rottler Eyewear (ECJ, March 19, 2026, C-526/24 – See also our blog post about this ruling): even an initial request can be excessive, but only in cases of proven abuse of rights, which requires both an objective and a subjective element. Neither of these conditions is met here. The records were created in the normal course of the employment relationship, and the request was intended precisely to verify the accuracy of the data. Referring to the judgment Austrian Data Protection Authority (ECJ, January 9, 2025, C-416/23) and the judgment FT (ECJ, October 26, 2023, C-307/22) The Dispute Chamber further confirms that the person concerned is not required to provide grounds for their request. The volume—approximately 250 files, clearly identifiable—was limited, and a mere workload resulting from the institution’s own archiving system does not render a request excessive.
Was an invitation to inspect the property on-site a valid response?
No. The request concerned the provision of a copy within the meaning of Article 15(3) of the GDPR, not temporary access. Referring to the judgment CRIF (ECJ, May 4, 2023, C-487/21) the Dispute Resolution Chamber reiterates that the right to a copy presupposes a faithful and intelligible reproduction of all data, in a form that the data subject can freely and permanently access. By requiring the complainant to come in person to identify and copy the files, the employer shifted a burden that rested with it onto the data subject, in violation of the duty to facilitate under Article 12(2) of the GDPR. Furthermore, the employer had never communicated a formal, reasoned refusal as required by Article 12.4 of the GDPR, nor had it invoked the extension of the deadline permitted by Article 12.3 of the GDPR.
Legal analysis and interpretation
No general right to a copy of all documents
The crux of this decision lies in the distinction between viewing data and obtaining a copy of it. Since the CRIFThe judgment establishes that Article 15(3) of the GDPR is not an autonomous right, but rather the procedure by which the right of access is exercised. In this regard, it is important to emphasize what that judgment does not say: it does not grant a general right to a copy of complete documents. The data subject has the right to an accurate and comprehensible reproduction of their personal data; the provision of extracts or even complete documents is only mandatory to the extent that it is indispensable for the data subject to effectively exercise their rights.
This necessity test explains why, in many cases, a data controller may simply provide a list of the personal data being processed. The Administrative Law Division of the Dutch Council of State has established in its case law that providing a copy of the document containing the personal data is not always necessary, as long as the chosen format achieves the supervisory objective of Article 15(3) of the GDPR (ECLI:NL:RVS:2020:2559). The Paris Court of Appeal took this reasoning even further: an employee cannot invoke the right of access to compel the release of a complete copy of their work email account if the disclosure of those documents is not essential (CA Paris (Pôle 6, ch. 2) December 18, 2025, No. 25/04270).
Against this backdrop, this decision is not a departure from precedent, but rather an application of the same standard to facts that represent the opposite extreme. The Dispute Chamber correctly finds that only the handwritten source documents allowed the complainant to verify the recording of his hours, so that their provision was indeed indispensable in this case. A mere on-site consultation or a computerized overview was not sufficient, precisely because those source documents were the very subject of the audit.
The same standard, but a different outcome than in the banking case
The fact that the indispensability test works both ways is evident from a comparison with an earlier decision by the Dispute Resolution Chamber. In its decision 08/2026 of January 26, 2026, a bank had responded to a request for access with an overview of the processed personal data, but refused to provide copies of the account opening agreements. There, too, the Dispute Chamber applied the CRIF logic: in principle, an overview is sufficient, unless the source document is indispensable for verifying the lawfulness of the processing—which was the case with a contract that itself constitutes the basis for processing. We discussed that decision in detail earlier in our article on whether you are required to provide and retain copies of contracts. The parallel is illuminating: it is not the nature of the document that is decisive, but whether the person concerned can effectively exercise their right of inspection without that document.
In practice, this means that the principle “whoever requests a copy receives a copy” must be qualified. The correct starting point is that the data controller is obligated to provide a faithful reproduction of the personal data, and the source documents only in addition to that when they are indispensable. The fact that the Dispute Chamber decided in this case6 to order the release of all files is therefore not automatic, but rather the result of the special evidentiary function of those files.
Workload as a defense: judged strictly, but not irrelevant
It is striking how the Dispute Chamber considers the workload twice, and in different ways. When assessing whether the workload is excessive, it does not take this into account: referring to EDPB Guidelines 01/2022 The Dispute Resolution Chamber confirms that time and effort alone do not render a request unreasonable, especially when the burden arises from a self-chosen method of archiving. The right of access is not subject to a general proportionality requirement.
However, when selecting the corrective measure, that same workload resurfaces, this time to the employer’s advantage: according to the Dispute Resolution Chamber, an administrative fine on top of a compliance order would be disproportionate, given the internal resources that enforcement will already require. This is a defensible, but not self-evident, line of reasoning. A circumstance that is irrelevant to the existence of the infringement thus becomes relevant to the sanction. It demonstrates that the proportionality test in selecting a sanction is broader than the strict test under Article 12.5 of the GDPR.
We adopted Rottler's glasses, but used them upside down
It is interesting to note that the Dispute Resolution Chamber cites the very recent Brillen Rottler ruling—a decision in which the Court of Justice opens the door to refusing even an initial request for access on grounds of abuse. While that ruling is generally interpreted as strengthening the position of the data controller, the Dispute Chamber uses it here precisely to underscore the strict burden of proof. The abuse criterion requires both an objective and a subjective element, and the mere fear of a future claim is not sufficient. The decision illustrates that Brillen Rottler is not a free pass: it shifts the discussion to the data subject’s intent, an element that the controller must demonstrate unequivocally.
Specifically, what does this mean?
For employers and other data controllers. Responding to a request for access with an invitation to consult the data on-site is not a safe course of action. Anyone who is unable or unwilling to provide a copy within one month has clear alternatives provided by the GDPR itself: extend the response period by two months, provided that a reasoned notification is issued within one month (Article 12.3 GDPR), issue a formally reasoned refusal stating the right to lodge a complaint (Article 12.4 GDPR), or invoke the rights of third parties (Article 15.4 GDPR). Doing nothing or shifting the burden to the data subject is the only option that is certain to lead to a violation. Anyone wishing to invoke the ground of disproportionate burden would be well advised to do so in a timely and reasoned manner—not only during the proceedings before the Dispute Chamber.
Please note the information provided by third parties. The performance reports also contain customer data. The Dispute Resolution Board points out that simply allowing the complainant to view the files would expose them to third-party personal data, in violation of Article 15.4 of the GDPR. It is precisely the controller’s responsibility to redact the relevant documents in advance and, where necessary, to anonymize third-party data—not to shift that responsibility onto the data subject. Anyone providing a copy should therefore consider targeted anonymization in advance.
For employees and other stakeholders. The right of access is a powerful tool, even in an employment context and even when a dispute is ongoing. You do not need to justify your request, and the employer cannot require you to review the documents only on-site. Submit your request in writing, stating that you wish to receive a copy pursuant to Article 15.3 of the GDPR, specify the time period and the documents in question, and keep a record of your correspondence—which serves as proof of both the date and the clarity of your request.
Frequently asked questions (FAQ)
Can my employer refuse to provide a copy because it’s too much work?
As a general rule, no. The fact that locating and copying documents takes time and effort does not, in and of itself, make a request for access excessive within the meaning of Article 12.5 of the GDPR, especially not when that burden results from the way the employer has organized its own files. A request may be refused only in cases of proven abuse of rights, and the burden of proof in this regard rests heavily with the employer.
Do I need to explain why I’m requesting my personal data?
No. The Court of Justice has repeatedly ruled that a data subject is not required to provide a reason for their request for access. Even if you wish to use the data for another purpose—for example, a dispute with your employer—the right to receive an initial copy remains intact.
Is it sufficient for me to be allowed to review the documents on site?
No, unless you have specifically requested a copy. The right to a copy means that you are entitled to receive an accurate reproduction of your data in a format that you can freely and permanently access. A mere invitation to view the data at the office does not satisfy that request.
Conclusion
The decision reaffirms a simple yet often overlooked principle: anyone who requests a copy of their personal data is entitled to a copy—not to an invitation to visit in person. The workload involved in processing the data and the manner in which documents are stored are the responsibility of the data controller, not the data subject. At the same time, the case demonstrates that an employer does have valid options available, provided that they are exercised in a timely manner and with proper justification.



