The organization must define and document clear criteria for when a data subject’s request may be refused, such as when it is repetitive, manifestly unfounded, or involves disproportionate effort. These criteria ensure consistent and justifiable decisions based on transparent internal guidelines.
Whenever a request is refused, the data subject must be promptly informed of the decision, including the reason for refusal and their right to challenge or appeal it in accordance with applicable data protection laws.