Skip to main content
Category: Data Subject Rights

Response Without Charge

Simply put

The evidence provided does not contain a coherent, reliable definition for the phrase "Response Without Charge" as a data privacy or GDPR term. The available sources relate to unrelated topics such as crossword clues for "without charge" (meaning free of cost), dictionary entries for "answer a charge," a fire and rescue "response charge," and informal commentary on non-responses. No authoritative definition can be constructed from this material.

Formal definition

Insufficient and non-authoritative evidence to define this term. The supplied sources do not establish "Response Without Charge" as a recognized concept in data protection, GDPR, or privacy compliance. In particular, none of the sources address data subject rights requests under the GDPR (for example, the general rule under Article 12 that a controller must, in most cases, act on requests free of charge, subject to exceptions for manifestly unfounded or excessive requests). Because that framework is not present in the evidence, no definition is asserted here. A precise entry should be drafted only against the relevant official regulatory text and guidance, which the reader should verify directly.

Why it matters

The phrase "Response Without Charge" cannot be reliably defined as a data privacy or GDPR term on the basis of the available evidence. The sources gathered relate to unrelated subjects: a crossword clue for "without charge" meaning free of cost, a dictionary usage of "answer a charge," a fire and rescue service "response charge" for treatment rendered, and informal commentary about non-responses. None of this material establishes the phrase as a recognized concept in data protection or compliance practice.

This matters because a glossary entry that presented these fragments as a coherent privacy definition would risk misleading the lawyers, data protection officers, and compliance leads who rely on precise terminology. Introducing an invented definition could cause a reader to build a compliance position on a term that does not, on this evidence, exist in the regulatory vocabulary. Where the evidence does not support a defensible entry, the responsible course is to withhold a definition rather than manufacture one.

Readers who encountered this phrase in the context of data subject rights should note that the GDPR does address whether controllers may charge for responding to requests, but that framework is not present in the evidence supplied here and cannot be attributed to this term. Any such analysis should be drafted directly against the current official regulatory text and guidance and verified accordingly.

Who it's relevant to

Data Protection Officers and Compliance Leads
Practitioners who encounter this phrase should treat it with caution, as the available evidence does not support a data privacy definition. Do not adopt or cite "Response Without Charge" as an established compliance term without first confirming its meaning against current official regulatory text and guidance.
Privacy Lawyers and Advisors
Where a client or document uses this phrase, clarify the intended meaning directly rather than assuming a GDPR framework applies. If the intended reference concerns whether data subject rights requests may be handled free of charge, that is a distinct topic that must be assessed against the relevant Regulation text, which this evidence does not address.
Editorial and Glossary Reviewers
This term is flagged as unsupported by reliable evidence. It should not be published as a settled definition. Consider retaining it as a placeholder pending sourced regulatory material, or removing it to avoid conflating unrelated meanings drawn from non-authoritative sources.

Inside Response Without Charge

Fee-free response principle
The general rule under Article 12(5) GDPR that information provided and actions taken in response to data subject requests (such as access, rectification, erasure, or portability) are, in most cases, provided without charge to the data subject.
Scope of covered rights
The no-charge principle typically applies to the exercise of data subject rights under Articles 15 to 22 GDPR, including the right of access, rectification, erasure, restriction, portability, and objection, subject to assessment of the specific request.
Manifestly unfounded or excessive exception
Article 12(5) permits a controller, where a request is manifestly unfounded or excessive (in particular because of its repetitive character), either to charge a reasonable fee taking account of administrative costs, or to refuse to act. The controller bears the burden of demonstrating the manifestly unfounded or excessive character of the request.
Reasonable fee alternative
Where the exception applies, any fee charged should reflect the administrative costs of providing the information, communication, or taking the action requested. What constitutes reasonable is context dependent and may be subject to regulator guidance.
Controller obligation
The obligation to respond without charge falls on the controller, who determines the purposes and means of processing, rather than on a processor acting solely on the controller's documented instructions.

Common questions

Answers to the questions practitioners most commonly ask about Response Without Charge.

Does responding without charge mean a controller can never charge a data subject anything for handling a request?
No. The general position under the GDPR is that controllers act on requests free of charge, but this is not absolute. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, a controller may either charge a reasonable fee taking account of administrative costs or refuse to act. The default is no charge, but the exception exists and should be assessed on a case-by-case basis rather than treated as unavailable.
Is the no-charge principle limited only to access requests, or does it apply more broadly?
It is not limited to access requests. The no-charge default generally applies across the exercise of data subject rights and to the information a controller provides, subject to the same exception for manifestly unfounded or excessive requests. Readers should check the specific provisions governing the right being exercised, as the precise wording and any conditions can differ, and national implementing law may affect the position.
What documentation should a controller keep when it decides to charge a fee or refuse a request?
Generally, a controller bears the burden of demonstrating that a request is manifestly unfounded or excessive. It is prudent to record the reasoning for that assessment, the factors considered (such as repetition), how any fee reflects administrative costs, and the date and outcome. This supports accountability and helps if the decision is later challenged or reviewed by a supervisory authority. Retain such records in line with your broader documentation practices.
How should a controller calculate a reasonable fee if it decides charging is justified?
Where charging is permitted, any fee should be based on the administrative costs of providing the information or taking the action requested, rather than set at a level intended to deter requests. Because what counts as reasonable is context-dependent and can attract regulator scrutiny, controllers typically document the cost basis. Note that supervisory authority guidance on fee calculation may exist and can evolve, so verify against current guidance.
How can front-line staff and intake systems be set up to apply the no-charge default correctly?
In most cases it helps to configure request-handling workflows so that no fee is applied by default, with any decision to charge or refuse routed to a designated reviewer who assesses whether the manifestly unfounded or excessive threshold is met. Training intake staff to recognise that charging is the exception, not the norm, reduces the risk of improperly deterring valid requests. Align these processes with your data subject rights procedures.
What are the risks of wrongly charging a fee or refusing a request on cost grounds?
Improperly charging or refusing can be treated as a failure to facilitate the exercise of data subject rights and may expose the controller to complaints and supervisory action. Because the controller generally must demonstrate that the exception applied, an unsupported charge is difficult to defend. The specific consequences are context and enforcement dependent and can vary between regulators, so treat cautious application of the no-charge default as the safer approach.

Common misconceptions

A controller may routinely charge an administrative fee for handling any access request.
As a general rule under Article 12(5) GDPR, responses to data subject requests are provided without charge. A fee may only be considered where a request is manifestly unfounded or excessive, and the controller must be able to justify that characterisation.
Once a request is labelled repetitive, the controller can automatically charge a fee or refuse.
Repetitive character is one factor that may indicate a request is excessive, but this requires case-by-case assessment. The controller carries the burden of demonstrating that the request is manifestly unfounded or excessive, and refusal or charging is not automatic.
The no-charge principle means a controller must fulfil every request in full regardless of circumstances.
The principle concerns the absence of a fee, not an unqualified obligation to comply. Requests remain subject to applicable exemptions, limitations, and assessment, and in defined cases a controller may charge a reasonable fee or decline to act.

Best practices

Treat the fee-free response as the default position and document any decision to depart from it by charging or refusing.
Where relying on the manifestly unfounded or excessive exception, record the specific reasoning and evidence, since the burden of proof rests with the controller.
If charging a fee, base it on demonstrable administrative costs and retain a clear calculation to withstand scrutiny.
Assess each request on its own facts rather than applying blanket policies to categories such as repeat requesters.
Consult current supervisory authority guidance, as interpretation of reasonable fee and excessive requests can evolve and may vary between regulators.
Where processing is carried out through a processor, ensure the controller retains responsibility for responding and that supporting arrangements are reflected in the relevant contractual terms.