Ruling
Brillen Rottler: even a first access request can be abusive if made solely to claim compensation
- Date
- Status
- final
- Body
- Hof van Justitie van de EU (Vierde kamer), Brillen Rottler GmbH & Co. KG tegen TC
- Reference
- C-526/24, ECLI:EU:C:2026:216
What it is about
Question: may a controller refuse a first access request as excessive where the requester evidently makes it only to claim compensation afterwards, and does the requester have a right to compensation when access is refused? Ruling: a first request can be excessive and thus abusive where the controller shows it was made not to know and verify the processing but to artificially create a claim; a publicly known pattern of many requests followed by claims may be taken into account. Breach of the right of access does give a right to compensation for damage actually suffered, even without any processing and including loss of control or uncertainty, but not where the data subject's own conduct is the determining cause.
What this means in practice
You may not refuse an access request lightly, but you now have a concrete defence against claim farmers, provided you substantiate the abuse with facts. Record in your access procedure how you assess and document indications of abuse, and keep handling ordinary requests within one month. Remain careful: an unjustified refusal remains an infringement that can lead to compensation.
The GDPR articles concerned
Source: EUR-Lex, arrest C-526/24checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
Case law
- Dun & Bradstreet: right to an intelligible explanation of an automated decision, trade secrets are no absolute ground for refusal
2025-02-27 · final, Hof van Justitie van de EU (Eerste kamer), CK tegen Magistrat der Stadt Wien, met Dun & Bradstreet Austria GmbH als andere partij
- Österreichische Post: no compensation without damage, but no seriousness threshold for non-material damage
2023-05-04 · final, Hof van Justitie van de EU (Derde kamer), UI tegen Österreichische Post AG
- Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
2025-09-24 · final, Raad van State, Afdeling bestuursrechtspraak
- Council of State upholds 6,000 euro DPA fine for recruitment firm
2024-05-29 · final, Raad van State, Afdeling bestuursrechtspraak
- SCHUFA: a credit score on which third parties draw strongly is automated decision-making
2023-12-07 · final, Hof van Justitie van de EU (Eerste kamer), OQ tegen Land Hessen, met SCHUFA Holding AG als interveniënt
- Legal Newsdesk Sweden: paid online publication of criminal convictions is in principle not journalism, national exemptions may not switch off the GDPR
2026-07-09 · final, Hof van Justitie van de EU (Vijfde kamer), ND tegen Legal Newsdesk Sweden AB (voorheen Garrapatica AB)
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
Guidelines
- Guidelines on transparency under Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines
- Netflix fined 4.75 million euros for failing to properly inform customers
2024-11-26 · under appeal, Autoriteit Persoonsgegevens
- 10 million euro fine for Uber over unclear retention and transfer information, objection rejected
2023-12-11 · under appeal, Autoriteit Persoonsgegevens
- 6,000 euro fine for Ambitious People Group for ignoring erasure requests
2020-07-30 · final, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
2024-05-16 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: refusing requests that abuse the right of access (Article 12(5) GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie