Dusseldorf: A short judgment out of Luxembourg has done more to rebalance the GDPR access regime than three years of guidance documents managed between them. In Case C-526/24, known in data protection circles as Brillen Rottler, the Court of Justice held that even a first request for access under Article 15 of the GDPR may be deemed abusive if it is made without good faith. The ruling was handed down by the Fourth Chamber on 19 March and is now filtering into national supervisory authority practice across the bloc.
The facts are simple and faintly mundane. A natural person living in Austria signed up to the newsletter of an Arnsberg optician, Brillen Rottler, in March 2023, gave his data and consented to processing. Thirteen days later he submitted an Article 15 access request. The company refused the request as abusive within the meaning of the second sentence of the first subparagraph of Article 12(5), pointing to reports and lawyers newsletters that documented a systematic pattern of access requests followed by Article 82 compensation claims against unconnected controllers.
Until now, the dominant reading at national level was that a controller had to handle the first request and could only deny later iterations as excessive. The Court has now closed that gap. A first request may already be regarded as excessive and therefore abusive where the controller can show that, despite formal compliance with the access conditions, the request was made not to learn how data is processed but to manufacture the preconditions for an Article 82 damages claim. The fact that the data subject is publicly known to have submitted a large volume of access requests with follow-on compensation claims to various controllers can be taken into account in establishing that abusive intention.
The burden of proof sits firmly on the controller. The Court was clear that the controller has to demonstrate the abusive intent rather than the data subject having to disprove it, and the threshold sits well above mere inconvenience. The decision reads in light of Recital 4 of the GDPR, which frames the right to data protection as one fundamental right among several and not an absolute claim. That balancing language is unusual in the Court’s GDPR case law and is being read as a deliberate signal that proportionality has more room to operate than earlier rulings suggested.
On compensation, the second strand of the judgment runs the other way. Article 82(1) confers a right to compensation for damage resulting from a breach of the right of access under Article 15(1), even where that breach does not involve an act of data processing in the strict sense. The damage still has to be actual and demonstrable, which limits the value of automated mass claims, but the cause of action is settled. The two strands together leave a sharper but narrower channel for genuine access claims and close the synthetic channel that some claimant firms had built into a business model.
For controllers, the practical workstream lands in three places. Logging and documentation around access requests now needs to capture the contextual signals that may indicate abusive intent, including request volume across the market, public reporting on the requester, and the proximity between data collection and request. Refusal letters need to set out those signals with evidentiary discipline, because supervisory authorities and lower courts will test the controller’s reasoning. And national codes of practice that were drafted before the ruling will need a redraft cycle that EDPB members began discussing within days of the judgment landing.




