A controller refuses a subject access request in full by citing a police-investigation exception, without checking whether Member State law actually authorises that restriction or whether a narrower response is possible. What is the sound GDPR approach?
Select an answer to reveal the explanation.
Short Explanation
Think of rights restrictions like a lock on a filing cabinet that only the statute can turn. You cannot invent a police exception out of thin air or slam the door on the whole request without reading the law. Check the legal basis for the restriction and narrow it to what is actually needed.
Full Explanation
GDPR allows Member States to restrict certain data-subject rights under Article 23 when necessary and proportionate for objectives such as the prevention, investigation, detection or prosecution of criminal offences. Controllers must verify that a lawful restriction applies and tailor the response accordingly. A wholesale refusal without legal analysis or necessity assessment does not meet that standard.