Data Subject Access Requests at Scale: Operational and Legal Limits
By the Legal Cyber Academy editorial team ·
What actually breaks when access requests arrive at volume
Data subject access requests run on a fixed clock: one month under the EU GDPR, extendable by two further months for complexity or number of requests, and 45 days under the California Consumer Privacy Act, extendable once to a maximum total of 90 calendar days. The deadline is rarely what fails. Identity verification, scope definition, and third-party redaction all have to finish inside it, and the grounds for refusing outright are narrow and carry the burden of proof.
The clock starts at receipt, not at verification
Article 12(3) GDPR requires a response "without undue delay and in any event within one month of receipt of the request," extendable "by two further months where necessary, taking into account the complexity and number of the requests" — but only if the data subject is told of the extension, with reasons, inside the first month. Miss the notice and the extension is gone.
California states the same rule expressly, and adds a step. Under 11 CCR § 7021(b), the 45-day period "will begin on the day that the business receives the request, regardless of time required to verify the request," and if the business cannot verify the consumer within those 45 days it may deny the request. Section 7021(a) then requires something most intake workflows omit: within 10 business days of receipt, the business must confirm receipt and describe, in general, its verification process and when the consumer should expect a response — except where it has already granted or denied the request.
Key every calendar entry to the timestamp of receipt: a queue that starts counting when a request reaches a reviewer is already late.
The United Kingdom has now diverged, which matters for any multinational running one global process. Section 76 of the Data (Use and Access) Act 2025, in force 5 February 2026, replaced the fixed month in UK GDPR Article 12(3) with an "applicable time period" defined in a new Article 12A, running from the latest of receipt of the request, receipt of any identity information requested under Article 12(6), and payment of any fee. Article 12A(5) goes further for access requests specifically: where the controller reasonably requires further information to identify the information or processing activities to which an Article 15 request relates, the days between asking and receiving count neither toward the deadline nor toward the month for giving an extension notice. Article 12(6)(b) now lets a UK controller "delay dealing with the request until the identity is confirmed." None of that exists in the EU text.
Verification: California quantifies what the GDPR leaves qualitative
Article 12(6) GDPR permits a controller to request additional identity information only where it "has reasonable doubts" — an exception, not a routine intake step. Article 11(2) covers the narrow case where the controller genuinely cannot identify the person, in which event Articles 15 to 20 do not apply unless the data subject supplies information enabling identification.
The California regulations put numbers on it — but only for consumers who do not have, or cannot access, a password-protected account. Where the consumer has one, § 7061 lets the business verify through its existing authentication practices, subject to § 7060, and requires the consumer to re-authenticate before any disclosure. For everyone else, § 7062 applies on top of § 7060: a request to know categories requires verification to "a reasonable degree of certainty," which "may include matching at least two data points." A request for specific pieces requires "a reasonably high degree of certainty," which may include matching at least three pieces of personal information "together with a signed declaration under penalty of perjury," retained as a record.
Denial is mandatory rather than discretionary where specific pieces are sought and identity cannot be verified: § 7024(a) provides that the business "shall not disclose any specific pieces," and § 7062(f) says it "shall deny" the request. Section 7024(a) then requires the business to evaluate that same request as if it sought categories, rather than simply closing it — though under § 7024(b) an unverified categories request may itself be denied, with the consumer directed to the business's published information practices.
Three further rules trip organizations up: § 7060(c)(1) requires matching against data the business already holds before asking for anything new, § 7060(d) requires deleting verification data as soon as practical after the request is processed, and § 7060(e) forbids charging for verification — a notarized affidavit may be demanded only if the business pays for or compensates the consumer for the notarization.
Scope: what has to come out of the systems
Article 15(1) GDPR entitles the requester to the personal data plus the purposes, categories, recipients, retention period or the criteria setting it, the source where data was not collected from the individual, and the existence of automated decision-making. On recipients, the Court of Justice held in Österreichische Post (C-154/21) that the controller must give the actual identity of recipients on request, falling back to categories only where it is not (yet) possible to identify them or the controller demonstrates the request is manifestly unfounded or excessive.
California's lookback is longer than most intake scripts assume. Under 11 CCR § 7024(h) the default is the 12 months preceding receipt, but a consumer may reach back as far as 1 January 2022, and the business must comply "unless doing so proves impossible or would involve disproportionate effort." A business claiming disproportionate effort must give "enough facts to give a consumer a meaningful understanding" of why; it "shall not simply state that it is impossible or would require disproportionate effort."
Inferences are in scope. In Opinion No. 20-303 (10 March 2022) — an advisory opinion of the California Attorney General, persuasive rather than binding — the AG concluded that internally generated inferences a business holds about a consumer are personal information under the CCPA and "must be disclosed to the consumer on request," unless the business can demonstrate that a statutory exception applies. The opinion accepts that the CCPA will not require disclosure of a genuine trade secret, but holds that "a blanket assertion of 'trade secret' or 'proprietary information' or the like would not suffice," and that a business withholding on that ground "bears the ultimate burden of demonstrating that such inferences are indeed trade secrets under the applicable law."
Two carve-outs belong in the extraction step rather than being discovered late. Section 7024(d) prohibits disclosing, in response to a request to know, Social Security numbers, driver's license or other government-issued identification numbers, financial account numbers, health insurance or medical identification numbers, account passwords, security questions and answers, or unique biometric data — while still requiring the business to inform the consumer "with sufficient particularity" that it holds that type of information. Section 7024(c) excuses searching altogether, but only where all four conditions hold: the data is not maintained in a searchable or reasonably accessible format, is held solely for legal or compliance purposes, is neither sold nor used for any commercial purpose, and the consumer is told which categories of records went unsearched.
No equivalent effort escape exists under the EU GDPR. The European Data Protection Board's Guidelines 01/2022 on the right of access (v2.1, 28 March 2023) state that the right of access is "without any general reservation to proportionality with regard to the efforts the controller has to take," and that "a controller who processes a large quantity of data on a large scale must accept to undertake great efforts" to give effect to it. The UK is again the outlier: Article 15(1A) UK GDPR, inserted by section 78 of the 2025 Act with retrospective effect to 1 January 2024, limits the entitlement to what a "reasonable and proportionate search" yields.
Third-party data is a redaction problem, not a refusal ground
Article 15(4) GDPR provides that the right to obtain a copy "shall not adversely affect the rights and freedoms of others." The EDPB's position is that this cannot become a reason to withhold everything: the result of the balancing "should not be a refusal to provide all information to the data subject," and information concerning others "has to be rendered illegible as far as possible instead of refusing to provide a copy." The EDPB is equally clear that Article 15(4) "is not applicable to the additional information on the processing as stated in Art. 15(1) lit. a.-h. GDPR."
In employment files this is where the review hours go. The EDPB's worked example is an annual performance review containing a colleague's testimony about the requester's professional performance: the review is the requester's personal data, while elements revealing the reviewing colleague's identity may be limited under Article 15(4). California is blunter for personnel files — Labor Code § 1198.5(g) permits an employer to redact the name of any nonsupervisory employee before producing.
Build the redaction log while the review runs, document by document. The review tradeoffs are the ones covered in eDiscovery and AI, and request volume spikes reliably after an incident, alongside the obligations discussed in ransomware response.
"Manifestly unfounded or excessive" is narrower than it sounds
Article 12(5) GDPR permits a fee or a refusal where requests are "manifestly unfounded or excessive, in particular because of their repetitive character," and states plainly that "the controller shall bear the burden of demonstrating" that character. California mirrors this at Civil Code § 1798.145(h)(3), burden included. Virginia adds "repetitive" as a third trigger, caps free responses at twice annually, and — unlike California, which requires only that a business tell a consumer of any right to appeal — mandates a conspicuously available appeal process with a written decision within 60 days and an online mechanism or other method for contacting the Attorney General if the appeal is denied (Va. Code § 59.1-577(B)(3), (C)).
What does not qualify, per the EDPB guidelines, is the more useful list. The fact that it "would take the controller a vast amount of time and effort to provide the information" cannot on its own render a request excessive. Nor can the absence of any stated reason, improper or impolite language, or — importantly for litigators — the fact that "the data subject intends to use the data to file further claims against the controller." What may qualify is an offer to withdraw the request in return for some benefit from the controller, or systematically sending requests as part of a campaign with the intention and effect of causing disruption.
Because the burden sits with the organization, the reasoning must be recorded at the moment of refusal, not assembled once a complaint lands. California requires exactly that: 11 CCR § 7024(e) demands "a detailed explanation of the basis for the denial," including any conflict with federal or state law or exception to the CCPA, plus disclosure of whatever personal information the exception does not cover.
The tactical use in litigation and employment disputes
Access requests are not discovery, and treating them as discovery is the recurring error on both sides. Federal Rule of Civil Procedure 26(b)(1) confines discovery to matter "relevant to any party's claim or defense and proportional to the needs of the case." Neither the EU GDPR nor the CCPA conditions disclosure on relevance to a dispute, and neither imports anything resembling Rule 26's case-specific proportionality balance — the EDPB puts it that the right of access carries no general reservation to proportionality as to the controller's effort. The CCPA's limits are narrower and specific: the four-condition search exception at § 7024(c), and the disproportionate-effort limit on the pre-12-month reach-back. And the EDPB is explicit that a requester "does not have to give reasons for the access request." No meet-and-confer, no protective order, no judicial officer over the exchange — which is why a request often arrives before the complaint does.
California now presents a three-channel problem in employment matters, with three different clocks:
- CCPA. The human-resources exemption at Civil Code § 1798.145(m) became inoperative on 1 January 2023, so employees, former employees, applicants and contractors are consumers. 45 days, extendable to 90.
- Personnel records. Labor Code § 1198.5(b)(1) requires inspection or a copy within 30 calendar days, or up to 35 by written agreement, with a $750 penalty under § 1198.5(k). But § 1198.5(n) provides that if an employee or former employee "files a lawsuit that relates to a personnel matter" against the employer, the right to inspect or copy under that section "ceases during the pendency of the lawsuit in the court with original jurisdiction" — and § 1198.5(o) defines a lawsuit as relating to a personnel matter "if a current or former employee's personnel records are relevant to the lawsuit." Former employees get one request per year under § 1198.5(d).
- Payroll records. Labor Code § 226(c) requires compliance "as soon as practicable, but no later than 21 calendar days from the date of the request."
The asymmetry is the point: the statute that switches off at filing is the personnel-records statute, and the CCPA right to know has no corresponding shut-off. What the CCPA offers is narrower and must be asserted rather than assumed — § 1798.145(a)(1)(E) provides that the title's obligations shall not restrict a business's ability to "exercise or defend legal claims," and § 1798.145(b) disapplies the obligations imposed by §§ 1798.110, 1798.115, 1798.120, 1798.121, 1798.130 and 1798.135 where compliance would violate an evidentiary privilege under California law.
For defence counsel the discipline is consistency: an access-request production is a document opposing counsel will lay alongside your discovery responses and privilege log. For requesting counsel it is a map of the custodians and systems the organization admits it searched. When the scope fight needs a neutral, the mechanics resemble those in working with a discovery special master.
The file that has to survive review
Whatever the jurisdiction, the defensible artifact is the same: date of receipt; acknowledgment sent; verification method and data points matched; search log, including categories deliberately not searched; redaction rationale, document by document; any extension notice and its stated reasons; and, for a denial, the explanation given at the time. None of it can be reconstructed convincingly after the fact.
Learn more
- Gail Gottehrer — Vice President for Global Litigation, Labor & Employment Law, and Government Relations, Fresh Del Monte Produce, Inc.
- Katherine Charonko — Partner and ESI Practice Group Leader, Bailey & Glasser
- David Shonka — Partner and General Counsel, Redgrave LLP
- Aaron Tantleff — Partner, Foley & Lardner LLP
- Michael Kleinman — Special Counsel, Fried Frank LLP
This article is general information about legal and regulatory requirements, not legal advice, and does not create an attorney-client relationship.
Go deeper — courses on this
eDiscoveryUnderstanding Trade Secret Disputes and the Advantage of Resolving Them Through ADR
Panelists explain what trade secrets are, why they lead to disputes, and how the Defend Trade Secrets Act…
Yoav Griver
eDiscoveryAttorney Rulebook for Working with Special Masters in Federal Court
This webinar explains how legal teams engage with special masters in federal court, covering their role…
Daniel B. Garrie · 1h 5m
FreeEmployment LawCode and Ethics: Understanding Attorneys' Ethical Obligations after Data Breaches
Panelists explain the ethical concerns that data breaches create for attorneys, then outline their…
Daniel B. Garrie
Keep reading
- Mobile Device Forensics: What Extraction Can and Cannot RecoverWhat a phone extraction really returns: logical, file-system and physical tiers, deleted-data limits, cloud and encrypted content, and how t…
- Resolving Trade Secret Disputes Without Destroying the SecretHow trade secret cases are sequenced and contained: particularity before discovery, AEO tiers and their limits, neutral source code review,…
- Crypto Assets in Litigation: How Courts Trace, Freeze, and Seize Digital WealthWhen crypto is at the center of a dispute, courts have real tools to freeze wallets and trace funds. Here is what lawyers and executives nee…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.