The CJEU Set Limits on Abusive GDPR Access Claims

In Brillen Rottler v TC, the CJEU explained when a GDPR access request may be manifestly excessive and how deliberately engineered claims affect compensation.

By THEYDIDNTASK
A right to access personal data is useful only if people can exercise it without unnecessary friction. But a legal right can also be used as part of a deliberately engineered claim. In Brillen Rottler GmbH & Co. KG v TC, the Court of Justice of the European Union addressed where those ideas meet. The Fourth Chamber issued its judgment in Case C-526/24 on March 19, 2026, after a reference from the Local Court of Arnsberg in Germany. The dispute concerned an individual who subscribed to a newsletter, made a GDPR access request thirteen days later, and then sought compensation after the request was refused as abusive. The CJEU’s task was not to decide every underlying fact itself. It interpreted the GDPR rules that the national court must apply. A first request can still be excessive—but not automatically Article 12(5) of the GDPR generally requires communications under data-subject rights to be free. It allows a controller to charge a reasonable fee or refuse to act when a request is manifestly unfounded or excessive, with the controller bearing the burden of demonstrating that character. The judgment explains that the fact a request is a person’s first request does not, by itself, prevent it from being considered manifestly excessive. The assessment can take account of an objectively abusive pattern, including evidence that a person created the relationship only to manufacture a compensation claim. That is a narrow permission, not a shortcut. “First request” does not mean “ordinary request” in every circumstance, but neither does an organization’s suspicion turn a normal request into an excessive one. The controller must demonstrate the abuse with objective evidence. Compensation and deliberately engineered harm The case also concerned Article 82 of the GDPR, which provides compensation for material or non-material damage resulting from an infringement. The Court addressed whether a person who deliberately engineered the circumstances behind a refusal could rely on that refusal to claim compensation. The Court’s reasoning treats causation as central. Where the claimant deliberately creates the conditions for the alleged infringement in order to obtain damages, the causal connection required for compensation can fail. That does not erase the GDPR right of access or permit controllers to disregard requests; it limits a damages claim when the claimant’s own deliberate conduct is what produced the alleged harm. The case therefore separates three questions: whether a request was excessive, whether the controller’s response complied with the GDPR, and whether a particular loss was caused by an infringement. What the judgment does not mean The decision is not a general permission to refuse difficult requests. Article 12(5) places the evidentiary burden on the controller. Organizations still need processes for verifying identity, locating data, responding within the GDPR timetable, and documenting the reason for any refusal. Nor does the judgment make privacy rights conditional on a person proving a commercial motive. The issue was an objectively abusive pattern, not the ordinary fact that someone wants to understand what a company holds about them. Courts and regulators will still have to apply the ruling to particular evidence. A company that labels a request “abusive” without a defensible factual record risks turning a protective exception into a routine barrier. A practical reading for people and controllers Data subjects should keep records of access requests, responses, and the data they are trying to understand. A legitimate access request should not be withdrawn merely because a controller uses the word “excessive.” Controllers should document the data search, the evidence relied on, the proportionality analysis, and the reason a refusal or fee was chosen. They should also avoid treating a compensation demand as proof that the original access request was abusive. The CJEU’s message is a balancing one: the access right must remain real, while legal procedures should not be converted into a manufactured damages machine. The difficult part is proving which situation is actually in front of you.