Skip to main content
Category: Data Subject Rights

Manifestly Unfounded or Excessive Request

Also known as: Manifestly Unfounded Request, Manifestly Excessive Request, Manifestly Unfounded and Excessive Request
Simply put

This describes a request made by an individual to exercise their data protection rights (such as a subject access request) that is clearly baseless or unreasonable in nature or scope. Where a request meets this threshold, an organisation may, subject to assessment, be able to charge a reasonable fee or refuse to act on it. The bar is generally high, and an organisation should assess each request individually rather than applying the label routinely.

Formal definition

A characterisation applied to a data subject rights request that permits a controller, in certain circumstances, to charge a reasonable fee or to refuse to act on the request. According to ICO guidance, a request may be 'manifestly unfounded' where the individual clearly has no intention to exercise the right in question, or where the request is malicious in intent; a request may be 'manifestly excessive' following an assessment of whether it is clearly or obviously unreasonable, taking account of relevant circumstances. The word 'manifestly' signals that the unfounded or excessive character must be obvious or clear, and the assessment is made on a case-by-case basis rather than as a blanket policy. The controller generally bears the burden of demonstrating that a request meets this threshold. This entry reflects UK GDPR guidance from the ICO and comparable framing referenced by the Irish Data Protection Commission; practitioners should verify the applicable provisions and thresholds against the current official text of the relevant regime, as national implementing law and regulator guidance may vary, and specific article references should be confirmed against the current Regulation text.

Why it matters

The right of access and other data subject rights are cornerstones of data protection, and the default position is that organisations must respond to valid requests without charge and within the applicable statutory timeframe. The 'manifestly unfounded or excessive' provision is one of the few recognised routes by which a controller may depart from that default, either by charging a reasonable fee or by declining to act. Because it functions as an exception to a fundamental right, the threshold is generally high, and misapplying the label carries real compliance risk, including complaints to the supervisory authority and potential enforcement action.

The practical significance lies in the discipline it demands. According to ICO guidance, a request may be manifestly unfounded where the individual clearly has no intention to exercise the right in question or where the request is malicious in intent, and a request may be manifestly excessive following an assessment of whether it is clearly or obviously unreasonable in the circumstances. The word 'manifestly' signals that the unfounded or excessive character must be obvious. Organisations that treat the provision as a routine filter, or that apply it as a blanket policy to burdensome requests, risk unlawfully refusing legitimate requests.

The controller generally bears the burden of demonstrating that a request meets the threshold, so contemporaneous reasoning and record-keeping matter. Practitioners should also be aware that this framing reflects UK GDPR guidance from the ICO, with comparable framing referenced by the Irish Data Protection Commission; national implementing law and regulator guidance may vary, and specific provisions and thresholds should be verified against the current official text of the applicable regime.

Who it's relevant to

Data Protection Officers and Privacy Teams
DPOs and privacy teams operationalise how requests are triaged and are often the point of accountability when a request is refused or charged for. They should ensure that any decision to treat a request as manifestly unfounded or excessive is made on a case-by-case basis, is documented with clear reasoning, and is not applied as a blanket policy, given that the controller generally bears the burden of justification.
Compliance and Legal Advisers
Lawyers and compliance leads advise on where the threshold sits and on the risk of refusing or charging for a request. Because 'manifestly' sets a generally high bar and the framing here reflects ICO guidance with comparable framing from the Irish DPC, advisers should confirm the applicable provisions and thresholds against the current official text of the relevant regime and account for possible divergence between regulators and national implementing law.
Front-line and Customer-facing Staff
Staff who receive and log rights requests, such as subject access requests, need to understand that refusal is an exception rather than a default. They should escalate rather than decide unilaterally, and should recognise indicators such as an apparent absence of any intention to exercise the right or malicious intent, while leaving the formal assessment to the appropriate team.
Individuals Exercising Their Rights
Data subjects benefit from understanding that organisations may, subject to assessment, charge a reasonable fee or refuse to act only where a request is clearly baseless or unreasonable, and that the organisation must be able to justify that characterisation. This helps individuals frame requests that clearly reflect a genuine intention to exercise a right.

Inside Manifestly Unfounded or Excessive Request

Manifestly Unfounded Request
A data subject request that, on its face, has no legitimate basis or evident purpose connected to exercising the rights the Regulation confers. Under Article 12(5) GDPR, where a request is manifestly unfounded, the controller may either charge a reasonable fee or refuse to act. The threshold is high, and the controller bears the burden of demonstrating the manifestly unfounded character of the request.
Excessive Request
A request that goes beyond what is reasonable, typically assessed by reference to its repetitive character. Article 12(5) GDPR expressly references repetitive requests as an example, though excessiveness is assessed case by case rather than by a fixed numeric rule. Excessiveness relates to the volume, frequency, or nature of the request rather than the legitimacy of its underlying purpose.
Controller's Two Options
Where a request is manifestly unfounded or excessive, Article 12(5) GDPR generally permits the controller to take one of two courses: charge a reasonable fee taking account of administrative costs, or refuse to act on the request. This is a discretion, not an obligation, and each option must be justified.
Burden of Proof
Article 12(5) GDPR places the burden of demonstrating that a request is manifestly unfounded or excessive on the controller. A refusal or fee cannot be applied by default; it must be substantiated on a case-by-case basis for the specific request.
Procedural Safeguards on Refusal
Where a controller refuses to act, it must generally inform the data subject without undue delay of the reasons, and of the possibility to lodge a complaint with a supervisory authority and to seek a judicial remedy. Refusal does not remove these accompanying transparency obligations.
National and UK Variation
The core provision derives from Article 12(5) of the EU GDPR, with a materially equivalent provision in the UK GDPR. Member state implementing law and regulator guidance can shape how the threshold is interpreted in practice, so the position may vary across jurisdictions.

Common questions

Answers to the questions practitioners most commonly ask about Manifestly Unfounded or Excessive Request.

Does a 'manifestly unfounded or excessive' request simply mean the controller can refuse any request it finds inconvenient or burdensome?
No. The threshold is deliberately high and does not turn on mere inconvenience or the administrative burden of responding. Under Article 12(5) GDPR, a controller may either charge a reasonable fee or refuse to act only where a request is manifestly unfounded or manifestly excessive, and the word 'manifestly' signals a demanding standard. A large volume of work, or the fact that a request is difficult to fulfil, does not by itself make it excessive. The controller bears the burden of demonstrating the manifestly unfounded or excessive character of the request, and regulators generally expect this to be assessed case by case rather than applied as a routine gatekeeping tool. Guidance from supervisory authorities and the European Data Protection Board can inform this assessment, and readers should verify the current position against official sources.
Is a request automatically 'excessive' just because the same individual has made requests before or asks repeatedly?
Not automatically. Repetition can be a relevant factor, and Article 12(5) expressly refers to the repetitive character of a request as an example that may support a finding of excess. However, repetition alone is not decisive. A person may have legitimate reasons to make a further request, for example because their data has changed, because new processing has occurred, or because a reasonable interval has passed. The controller should assess each repeated request on its facts rather than assuming that any follow-up is excessive. What counts as a reasonable interval between requests can depend on the nature of the data and the processing, and interpretations may vary between supervisory authorities, so the reader should check current guidance.
Who has to prove that a request is manifestly unfounded or excessive, and how should that be documented?
The controller carries the burden of demonstrating that a request meets the threshold under Article 12(5). In practice this generally means recording the specific reasons for the conclusion, the facts relied upon, and the assessment carried out, so that the decision can be justified to the individual and, if challenged, to a supervisory authority. Documenting this reasoning also supports the accountability principle. The level of detail that will satisfy a regulator can vary, so organisations typically maintain a consistent internal record for each decision rather than relying on a general policy statement.
When a request qualifies as manifestly unfounded or excessive, what options does a controller have?
Article 12(5) generally provides two alternatives: the controller may charge a reasonable fee taking account of the administrative costs of providing the information or taking the action requested, or it may refuse to act on the request. These are alternatives, not a single mandatory outcome, and the choice should be proportionate to the circumstances. Where the controller refuses, it typically must still inform the individual of the reasons and of their rights, including the right to lodge a complaint with a supervisory authority and to seek a judicial remedy. The precise procedural expectations can vary under national implementing law, so verify against the applicable text.
How should a controller respond when a request is very broad rather than clearly unfounded?
A broad request is not the same as an excessive one, and breadth alone does not meet the threshold. Where the scope is genuinely unclear or wide-ranging, a common practical step is to ask the individual to clarify or specify the information or processing activities to which the request relates, particularly where the controller processes a large quantity of data about that person. Any such clarification should be sought without unduly delaying the response and without using it as a tactic to frustrate the request. If clarification is not provided, the controller generally still needs to make a reasonable effort to respond to the request as made.
Does invoking this provision affect the timescale for responding to a data subject request?
Assessing whether a request is manifestly unfounded or excessive should generally form part of the controller's handling of the request within the applicable response period rather than being treated as a way to pause the clock. Under Article 12(3), controllers are typically required to respond without undue delay and within the standard period, which may be extended in defined circumstances taking into account the complexity and number of requests. Where the controller decides to charge a fee or refuse, it should communicate that decision and the reasons within the applicable timeframe. Because extension rules and their conditions are set out in the Regulation and may be affected by national law, the reader should verify the current requirements.

Common misconceptions

A request can be refused simply because it is burdensome or time-consuming to fulfil.
Difficulty or cost alone does not generally render a request manifestly unfounded or excessive. The threshold is high, and the controller must demonstrate the specific character of the request rather than relying on internal inconvenience.
A second or repeated request is automatically excessive and can be turned down.
While Article 12(5) GDPR references repetitive requests as an indicator of excessiveness, there is no fixed number that triggers this. Excessiveness is assessed case by case, taking account of factors such as the time elapsed and whether circumstances have changed.
If a request is manifestly unfounded or excessive, the controller can simply ignore it.
Even where the controller declines to act, it generally must inform the data subject of the reasons and of their right to complain to a supervisory authority and to a judicial remedy. Charging a fee or refusing does not remove these transparency and procedural obligations.

Best practices

Assess each request individually and document the specific factual reasons why it is considered manifestly unfounded or excessive, since the controller carries the burden of proof under Article 12(5) GDPR.
Treat refusal and fees as exceptions applied to a high threshold, not as a default response to requests that are merely inconvenient or resource-intensive.
When declining to act, inform the data subject without undue delay of the reasons and of their right to lodge a complaint with a supervisory authority and to seek a judicial remedy.
Where a fee is charged, ensure it is reasonable and tied to actual administrative costs, and retain the calculation basis in case it is later challenged.
Consult the applicable supervisory authority guidance and, where relevant, distinguish the EU GDPR position from UK GDPR and national implementing law, as interpretation can vary.
Maintain an auditable internal procedure and record of decisions so that any refusal or fee can be justified consistently and reviewed if the data subject or a regulator challenges it.