Manifestly Unfounded or Excessive Request
This describes a request made by an individual to exercise their data protection rights (such as a subject access request) that is clearly baseless or unreasonable in nature or scope. Where a request meets this threshold, an organisation may, subject to assessment, be able to charge a reasonable fee or refuse to act on it. The bar is generally high, and an organisation should assess each request individually rather than applying the label routinely.
A characterisation applied to a data subject rights request that permits a controller, in certain circumstances, to charge a reasonable fee or to refuse to act on the request. According to ICO guidance, a request may be 'manifestly unfounded' where the individual clearly has no intention to exercise the right in question, or where the request is malicious in intent; a request may be 'manifestly excessive' following an assessment of whether it is clearly or obviously unreasonable, taking account of relevant circumstances. The word 'manifestly' signals that the unfounded or excessive character must be obvious or clear, and the assessment is made on a case-by-case basis rather than as a blanket policy. The controller generally bears the burden of demonstrating that a request meets this threshold. This entry reflects UK GDPR guidance from the ICO and comparable framing referenced by the Irish Data Protection Commission; practitioners should verify the applicable provisions and thresholds against the current official text of the relevant regime, as national implementing law and regulator guidance may vary, and specific article references should be confirmed against the current Regulation text.
Why it matters
The right of access and other data subject rights are cornerstones of data protection, and the default position is that organisations must respond to valid requests without charge and within the applicable statutory timeframe. The 'manifestly unfounded or excessive' provision is one of the few recognised routes by which a controller may depart from that default, either by charging a reasonable fee or by declining to act. Because it functions as an exception to a fundamental right, the threshold is generally high, and misapplying the label carries real compliance risk, including complaints to the supervisory authority and potential enforcement action.
The practical significance lies in the discipline it demands. According to ICO guidance, a request may be manifestly unfounded where the individual clearly has no intention to exercise the right in question or where the request is malicious in intent, and a request may be manifestly excessive following an assessment of whether it is clearly or obviously unreasonable in the circumstances. The word 'manifestly' signals that the unfounded or excessive character must be obvious. Organisations that treat the provision as a routine filter, or that apply it as a blanket policy to burdensome requests, risk unlawfully refusing legitimate requests.
The controller generally bears the burden of demonstrating that a request meets the threshold, so contemporaneous reasoning and record-keeping matter. Practitioners should also be aware that this framing reflects UK GDPR guidance from the ICO, with comparable framing referenced by the Irish Data Protection Commission; national implementing law and regulator guidance may vary, and specific provisions and thresholds should be verified against the current official text of the applicable regime.
Who it's relevant to
Inside Manifestly Unfounded or Excessive Request
Common questions
Answers to the questions practitioners most commonly ask about Manifestly Unfounded or Excessive Request.