Munich: The Court of Justice of the European Union has handed German national courts a sharper tool for handling speculative GDPR access requests, ruling in Brillen Rottler (C-526/24) that even a first request under Article 15 can be rejected as abusive where the requester has not acted in good faith. The judgment, delivered on 19 March and now reaching its full effect in German litigation, marks the first time the CJEU has accepted that abusive intent can defeat an access claim outright, rather than merely limiting its scope.
The case originated in a referral from a German regional court hearing a damages claim against a Bavarian optician chain. The claimant had signed up for the company’s newsletter, immediately filed an Article 15 request, and then sought non-material damages under Article 82 when the response missed the one-month deadline. The pattern has become known among German practitioners as GDPR hopping, with specialist law firms cycling through dozens of newsletter sign-ups to seed potential damages claims. National courts had been split on whether the abusive nature of such requests could be raised at the access stage at all.
The CJEU’s answer is yes. The Grand Chamber held that the Regulation’s safeguard against manifestly unfounded or excessive requests under Article 12(5) extends to first requests, not only to repeated ones, where the surrounding circumstances show the request is not aimed at exercising any genuine data protection right. The Court emphasised that the controller bears the burden of demonstrating abuse, that the standard is high, and that mere suspicion of damages-seeking does not suffice on its own.
For German privacy practice, the ruling reshapes a fast-growing strand of class-action style litigation. Until now, judges in Cologne and Düsseldorf had granted small non-material damages awards in the €100 to €500 range for response delays, on the theory that the right to access was absolute and any delay constituted infringement. The Brillen Rottler test forces the requester to show some underlying interest in the personal data itself, beyond the mechanical generation of a deadline.
The ruling sits alongside the Court’s Russmedia judgment from December 2025, which expanded platform controllers’ duties around sensitive data, and the February decision allowing direct challenges to European Data Protection Board adequacy findings. Taken together, the three judgments suggest a Court willing to refine the GDPR’s enforcement edges in both directions, narrowing speculative claims while widening genuine platform responsibilities.
National data protection authorities are now reviewing their complaint-handling guidance to reflect Brillen Rottler. The Bavarian DPA, which intervened in the proceedings, said it would publish updated guidance before the autumn on how controllers should document the abuse assessment to withstand later judicial review. The Hamburg authority has signalled it will not change its own enforcement priorities, on the basis that abusive requests have always been a minority of its caseload.
The Commission’s GDPR procedural regulation, agreed in trilogue last year, will when implemented in late 2026 add a further filter for cross-border complaints. Brillen Rottler arrived at the right moment for that text, supplying judicial backing for the proposition that an access right exists to serve the data subject, not as a litigation procurement device.




