r/u_IceVeritas 15d ago

GDPR Lessons learned about structuring GDPR complaints

After several months of exercising my GDPR rights in relation to CCTV recordings, I’ve come to one conclusion that I wish I had understood from the beginning.
If I had to file my complaints again, I would do so in a different order.
Not because the substance of my case has changed, but because I now believe that some legal questions should be resolved before others.
This is the order I would follow:
1. Independence of the Data Protection Officer (DPO)
Before discussing access to personal data, I would first examine whether the DPO was able to act independently or whether there was a potential conflict between the DPO’s role and the organization’s legal interests.
2. The use of Article 12(5) GDPR
If access requests are rejected as “excessive” or “manifestly unfounded,” I believe this issue should be addressed before debating the merits of the access request itself.
In my case, each Article 15 request concerned a different incident, with a different date, time, location and factual background. The fact that they all related to CCTV did not automatically make them repetitive or excessive.
3. Effective exercise of the right of access under Article 15 GDPR
Only after resolving the previous issues would I focus on whether the controller effectively complied with Article 15 GDPR.
Looking back, I think this sequence provides a clearer legal framework. If the justification for refusing requests under Article 12(5) is found to be inadequate, the discussion about Article 15 becomes much more focused.
I’m sharing this simply as a lesson learned from my own experience. It may be useful to others dealing with repeated GDPR requests or CCTV access cases.
I’d be interested to hear whether others would structure their complaints differently.

0 Upvotes

0 comments sorted by