The FAZ has repor­tedhow the right of access under Art. 15 GDPR can be misu­s­ed to obtain infor­ma­ti­on from third par­ties. On the one hand, com­pa­nies must pre­vent this and iden­ti­fy the appli­cant for this pur­po­se. On the other hand, they must not make the exer­cise of the right of access more dif­fi­cult by impo­sing exce­s­si­ve iden­ti­fi­ca­ti­on requirements.

Appar­ent­ly, the Fede­ra­ti­on of Ger­man Con­su­mer Orga­nizati­ons is alre­a­dy con­duc­ting a case against a com­pa­ny becau­se it deman­ded a copy of an ID card for iden­ti­fi­ca­ti­on pur­po­ses, even though the request was made from a known e‑mail address or a pass­word-pro­tec­ted cus­to­mer account. How the con­tro­ver­si­al Right to copy the que­sti­on of cor­rect iden­ti­fi­ca­ti­on will also occu­py the courts.