Back to blog

83% of Companies Fail GDPR Data Requests

Based on research by NOYB

schremsaipersonal datadata protectiongdpr

The European Commission is pushing to restrict the GDPR right of access, citing alleged abuse by citizens. The reality is starkly different. A new analysis by NOYB reveals that 83.5% of access requests sent to companies over the past eight years were not properly answered. Only 16.5% received a satisfactory reply, while nearly 30% were ignored entirely. This is not a crisis of citizen entitlement; it is a crisis of corporate compliance.

The proposed Digital Omnibus aims to limit Article 15 GDPR, arguing that individuals misuse their right to know what data companies hold. But the data tells another story. Companies are failing to deliver what the law requires. When you request your data, you are often met with silence or incomplete dumps that make verification impossible. The narrative of abuse is a lobbying construct designed to weaken one of the few tools Europeans have to hold tech giants accountable.

For Swedish CTOs and CISOs, this is a critical warning. If your current data mapping is incomplete, you are already non-compliant. The risk is not just theoretical. More importantly, if you cannot prove you have deleted or corrected data upon request, you cannot prove you are secure. Relying on external LLM APIs where data residency is unclear amplifies this risk. You are outsourcing your compliance to vendors who may not answer your own access requests.

This regulatory chaos reinforces the imperative for local processing. When you store and process data within the EU, you retain control. You can actually answer the access requests. You can audit the data. You are not at the mercy of a vendor’s automated rejection system. Local processing is not just a technical preference; it is a legal necessity in an era where global tech firms are actively trying to erode data subject rights. Secure your data where you can enforce the law.