The Court of Justice of the European Union (CJEU) has, in its recent judgement in Brillen Rottler (Case C-526/24), delivered on 19th March 2026, confirmed that the right of access under Article 15 GDPR is not absolute and may, in certain circumstances, be denied where its exercise amounts to an abuse of rights.
The judgment is significant because it confirms that, although the right of access under Article 15 GDPR is an important mechanism through which individuals may understand and verify the lawfulness of the processing of their personal data, it is not immune from the general principle that EU law cannot be relied upon for abusive or fraudulent purposes.
The case arose from a request submitted by an Austrian individual who subscribed to the newsletter of Brillen Rottler, a German optical retailer, and consented to the processing of his personal data. Shortly after, the individual submitted a request for access under Article 15 GDPR, seeking, seeking confirmation as to whether his personal data were being processed and if so, access to that data and related information prescribed by the GDPR.
Brillen Rottler refused to act on the request, taking the view that it was abusive within the meaning of Article 12(5) GDPR. The company relied on various reports, blog articles and lawyers’ newsletters which, according to it, indicated that the individual had engaged in a pattern of conduct whereby he subscribed to newsletters, submitted access requests, and subsequently pursued compensation claims against companies. The individual disputed that position and maintained that his request was a legitimate exercise of his Article 15 rights.
After maintaining his access request, the individual also claimed compensation under Article 82 GDPR in the amount of at least €1,000 for non-material damage allegedly suffered as a result of Brillen Rottler’s refusal to grant access. Brillen Rottler, in turn, brought proceedings before the Local Court of Arnsberg, Germany, seeking a declaration that the individual was not entitled to compensation.
The referring court asked the CJEU, among other matters, whether a first access request may be considered “excessive” for the purposes of Article 12(5) GDPR, whether publicly available information about the data subject’s conduct may be taken into account, and whether an infringement of the right of access may give rise to compensation under Article 82 GDPR.
The CJEU held that even a first request for access may, in certain circumstances, be regarded as excessive and therefore constitute an abuse of rights. The Court clarified that this may arise where a controller is able to demonstrate that, although the request formally satisfies the requirements of Article 15 GDPR, it was not made with the genuine purpose of understanding the processing of personal data or verifying its lawfulness. Rather, the request must be shown to have been made for an abusive purpose, such as artificially creating the conditions necessary to pursue a claim for compensation under Article 82 GDPR.
The CJEU further noted that the existence of an abusive intention may be assessed in light of the surrounding circumstances. In particular, publicly available information indicating that a data subject has previously submitted numerous access requests to different controllers, followed by compensation claims, may be relevant in determining whether the request was made for an improper purpose. The CJEU also confirmed that a data subject may be entitled to compensation under Article 82 GDPR where an infringement of the Regulation, including a breach of the right of access, has caused material or non-material damage. However, compensation is not automatic: the data subject must demonstrate that damage has in fact been suffered and that there is a causal link between the infringement and the damage claimed. The CJEU further clarified that compensation cannot be awarded where the damage results primarily from the data subject’s own conduct.
This judgement confirms that while the right of access under the GDPR remains a fundamental tool enabling individuals to understand and control the processing of their personal data, it cannot be exercised for abusive reasons, such as purposely creating the basis for compensation claims. The CJEU’s decision also clarifies that controllers may refuse a data subject access request, including a first request, where they can demonstrate that the request is made in bad faith and does not pursue the genuine objectives underlying Article 15 GDPR.