Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.
Extension announced after the first month had already run
high likelihoodThis is a complex request, so we are extending the deadline by two months under Art. 12(3).
What answers it
Art. 12(3) permits the extension only where the controller informs you of it, with the reasons, *within one month of receipt* of the request. An extension announced in week six is not an extension; it is an admission that the first deadline was missed. Point at the date of your request and the date of their notice.
GDPR Art. 12(3) — one month to respond, extendable by two — Art. 12(3)
A summary or a screenshot instead of a copy
high likelihoodHere is a summary of the categories of data we hold about you.
What answers it
Art. 15(3) requires a copy of the personal data undergoing processing. In Case C-487/21 the Court held that this means a faithful and intelligible reproduction, and that where it is indispensable to make the data intelligible, extracts or whole documents must be provided. A table of "categories" is Art. 15(1)(b) information, not the Art. 15(3) copy, and supplying one does not discharge the other.
Case C-487/21 Österreichische Datenschutzbehörde and CRIF (CJEU, 4 May 2023) — paras 32–45
Refusing erasure by pointing at a retention obligation
high likelihoodWe are legally required to retain your data, so we cannot delete it.
What answers it
Art. 17(3)(b) does disapply erasure where processing is necessary for compliance with a legal obligation — but only for that data, for that period, for that purpose. Ask which specific obligation, under which law, covers which fields, and for how long. Data outside that scope (marketing profiles, analytics, enrichment data bought from brokers) must still be erased, and the retained data must be restricted under Art. 18 rather than kept in active use.
Endless identity verification
high likelihoodWe cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.
What answers it
A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.
"We hold no personal data about you"
high likelihoodA search of our systems returned no personal data relating to you.
What answers it
Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.
"You have suffered no damage"
high likelihoodEven if we were late, you have not shown any loss, so no compensation is payable.
What answers it
This is the correct legal test and it is often a good defence — meet it with specifics rather than indignation. Case C-340/21 holds that a well-founded fear of misuse of data can itself be non-material damage; Case C-456/22 holds there is no de minimis threshold. Describe the concrete consequence: the time lost, the anxiety and why it was reasonable, the decision you could not challenge without the data, the marketing you could not stop.
Case C-300/21 UI v Österreichische Post AG (CJEU, 4 May 2023) — paras 32–42, 50
A fee for the first copy
medium likelihoodWe charge an administrative fee of EUR X to process subject access requests.
What answers it
Art. 12(5) makes action on an Art. 15 request free of charge. Art. 15(3) permits a reasonable fee only for further copies after the first. A standing fee for the first copy is unlawful, and the burden of showing that a request is manifestly unfounded or excessive sits on the controller.
GDPR Art. 12(5) — free unless manifestly unfounded or excessive — Art. 12(5)
"We are only a processor, ask our client"
medium likelihoodWe process this data on behalf of another company. Please direct your request to them.
What answers it
That may be correct, and if so the controller must tell you who the controller is — Art. 12(2) requires the processor to facilitate the exercise of your rights, and a processor that receives a request is contractually obliged under Art. 28(3)(e) to assist. Ask for the controller's identity and contact details in writing. A processor that cannot name its own controller is telling you something useful.
Blanket confidentiality or trade-secret refusal
medium likelihoodThe information you have requested is commercially confidential / contains our trade secrets / is proprietary.
What answers it
Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.
Refusal because the data mentions someone else
medium likelihoodWe cannot disclose these records because they contain the personal data of other individuals.
What answers it
The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.
"Your request is manifestly excessive"
medium likelihoodYour request is manifestly unfounded or excessive, so we are refusing it / charging a fee.
What answers it
The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.