{"id":51724,"date":"2026-03-26T11:00:49","date_gmt":"2026-03-26T10:00:49","guid":{"rendered":"https:\/\/www.eh.at\/?p=51724"},"modified":"2026-03-26T11:31:15","modified_gmt":"2026-03-26T10:31:15","slug":"access-abuse-damages-cjeu-draws-the-line","status":"publish","type":"post","link":"https:\/\/www.eh.at\/en\/access-abuse-damages-cjeu-draws-the-line\/","title":{"rendered":"Access, Abuse, Damages: CJEU Draws the Line"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"51724\" class=\"elementor elementor-51724 elementor-51713\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-735d0f1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"735d0f1\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1c35001\" data-id=\"1c35001\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-35d92e6 elementor-widget elementor-widget-text-editor\" data-id=\"35d92e6\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>26.03.2026<em><br \/><a href=\"https:\/\/www.eh.at\/team\/gernot-fritz\/\">Gernot Fritz<\/a>,\u00a0<a href=\"https:\/\/www.eh.at\/team\/tanja-pfleger\/\">Tanja Pfleger<\/a><\/em><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1483b1f elementor-widget elementor-widget-text-editor\" data-id=\"1483b1f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>In its judgment of 19 March 2026 in case <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:62024CJ0526\" target=\"_blank\" rel=\"noopener\">C-526\/24<\/a> (<em>Brillen Rottler<\/em>), the CJEU addressed key practical questions on the interplay between the right of access, the concept of abuse, and damages under the GDPR. The Court clarified, on the one hand, that controllers may, in exceptional circumstances, rely on the excessive or abusive nature of even a first access request. On the other hand, it made equally clear that a breach of the right of access under Article 15 GDPR can, in itself, give rise to a claim for damages under Article 82 GDPR. In doing so, the Court sharpens the boundaries between legitimate exercise of rights and abuse, without undermining the right of access as a core data subject right.<\/p><p>The case arose from a scenario that is increasingly familiar from a business perspective: a data subject subscribed to a newsletter, shortly thereafter submitted an access request under Article 15 GDPR, and subsequently claimed non-material damages. The company refused to respond, arguing that the request was abusive and intended to provoke damages claims. The referring German court therefore sought clarification, in particular, on whether even a first access request can be \u201cexcessive\u201d and whether a mere infringement of the right of access can give rise to damages.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7f22853 elementor-widget elementor-widget-heading\" data-id=\"7f22853\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">A first access request can exceptionally be excessive<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0d1eb6c elementor-widget elementor-widget-text-editor\" data-id=\"0d1eb6c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Notably, the CJEU does not exclude a first request under Article 15 GDPR from the scope of Article 12(5) GDPR. According to the Court, even an initial access request may be considered \u201cexcessive\u201d where the controller demonstrates, in light of all relevant circumstances, that the request was not made to become aware of the processing or to verify its lawfulness, but rather for abusive purposes \u2013 for example, to artificially create the conditions for obtaining a benefit under the GDPR, in particular a damages claim.<\/p><p>At the same time, the Court emphasises that this remains an exception. The threshold is high, the concept must be interpreted narrowly, and the burden of proof lies with the controller.<\/p><p>For practice, this is a key clarification. This judgment does not mean that companies can routinely invoke abuse in response to inconvenient or \u201csuspicious\u201d requests. Rather, the CJEU requires clear evidence that the right of access is being misused for purposes other than those intended by the GDPR. Publicly available information suggesting that an individual has pursued similar patterns of requests followed by damages claims may serve as an indication \u2013 but it will not be sufficient on its own. The decisive factor remains the overall assessment of the specific case.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1827c88 elementor-widget elementor-widget-heading\" data-id=\"1827c88\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The CJEU safeguards the right of access \u2013 despite the abuse exception<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f3d6cd8 elementor-widget elementor-widget-text-editor\" data-id=\"f3d6cd8\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>From a doctrinal perspective, the decision fits well into the CJEU\u2019s existing case law. The Court once again underlines that the right of access is a central mechanism of the GDPR, enabling data subjects to gain transparency and verify the lawfulness of processing. Precisely for that reason, the abuse exception must not be interpreted too broadly.<\/p><p>For companies, this is a useful clarification, but not a general relief. Any reliance on Article 12(5) GDPR requires a solid factual basis, and courts can be expected to apply this exception cautiously. Mere discomfort with the applicant\u2019s motives will not suffice. Nor will it generally be enough that a request is submitted shortly after data collection or accompanied by legal claims. What matters is whether abusive intent can be established on both an objective and subjective level.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5728aef elementor-widget elementor-widget-heading\" data-id=\"5728aef\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Damages also for mere infringement of the right of access<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-432095b elementor-widget elementor-widget-text-editor\" data-id=\"432095b\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>Even more significant for day-to-day advisory work is the second core finding: according to the CJEU, Article 82(1) GDPR does not require that the claimed damage stems directly from a separate act of data processing. A breach of a data subject right \u2013 in this case, the right of access under Article 15(1) GDPR \u2013 may itself give rise to compensable damage.<\/p><p>In other words, unlawfully refusing to provide access may, in itself, trigger liability under Article 82 GDPR.<\/p><p>This approach is consistent. Limiting Article 82 GDPR to damages resulting from \u201cprocessing operations\u201d in a narrow sense would deprive core data subject rights of their practical effectiveness. The Court explicitly avoids this outcome, emphasising that Chapter III GDPR strengthens data subject rights and that Article 82 must also cover their infringement as an effective remedy.<\/p><p>For practice, this means that incorrect or refused responses to access requests are not merely a regulatory issue, but may have direct civil liability consequences. Companies should therefore treat access request handling not as an administrative side issue, but as a core compliance function with liability implications.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a501739 elementor-widget elementor-widget-heading\" data-id=\"a501739\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Loss of control and uncertainty may constitute non-material damage \u2013 but not automatically<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9f87448 elementor-widget elementor-widget-text-editor\" data-id=\"9f87448\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The CJEU confirms its established approach to non-material damage. A loss of control over personal data or uncertainty as to whether such data are being processed may, in principle, constitute non-material damage within the meaning of Article 82 GDPR.<\/p><p>At the same time, the Court reiterates that a GDPR infringement does not automatically give rise to a damages claim. The data subject must demonstrate actual damage and a causal link between the infringement and that damage. A mere assumption is not sufficient.<\/p><p>The Court thus maintains a balanced position. On the one hand, it rejects any de minimis threshold and recognises loss of control as a potentially compensable harm. On the other hand, it continues to require a real and demonstrable damage and a concrete causal link. This is particularly relevant in the context of strategically submitted access requests: where the data subject has effectively engineered the situation leading to the alleged damage, causation may be lacking.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7dca22f elementor-widget elementor-widget-heading\" data-id=\"7dca22f\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What does this mean for companies?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7f4ef0b elementor-widget elementor-widget-text-editor\" data-id=\"7f4ef0b\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>The judgment does not revolutionise existing practice, but it recalibrates it in important respects. Companies gain a potentially useful \u2013 but narrowly confined \u2013 argument against clearly abusive access requests. At the same time, the practical importance of well-structured access request processes increases further, as the CJEU reinforces the liability implications of infringements of Article 15 GDPR.<\/p><p>From an operational perspective, there is much to be said for reviewing and refining internal processes for handling data subject requests. This includes consistent documentation, clear decision-making criteria for potential abuse scenarios, robust escalation paths, and careful reasoning where reliance on Article 12(5) GDPR is considered. Rejecting access requests prematurely will increasingly expose companies to damages claims.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3357a39 elementor-widget elementor-widget-heading\" data-id=\"3357a39\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Conclusion<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-84a299a elementor-widget elementor-widget-text-editor\" data-id=\"84a299a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>With its judgment in <em>Brillen Rottler<\/em>, the CJEU establishes a balanced yet demanding framework. The right of access remains a strong data subject right and cannot be dismissed merely because a request appears strategic or confrontational. In exceptional cases, however, even a first request may be abusive and thus excessive. At the same time, the Court makes it clear that infringements of the right of access must be taken seriously from a liability perspective.<\/p><p>The practical takeaway is clear: the abuse defence should be used with great caution \u2013 while access request processes require the highest level of care.<\/p><p>\u00a0<\/p><p><em>Because the real risk often lies in the process, not the request. We are happy to support you in assessing the impact of this decision on your organisation and with data subject access requests.<\/em><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>26.03.2026Gernot Fritz,\u00a0Tanja Pfleger In its judgment of 19 March 2026 in case C-526\/24 (Brillen Rottler), the CJEU addressed key practical questions on the interplay between the right of access, the concept of abuse, and damages under the GDPR. The Court clarified, on the one hand, that controllers may, in exceptional circumstances, rely on the excessive [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"rank_math_lock_modified_date":false,"inline_featured_image":false,"footnotes":""},"categories":[235],"tags":[385,906],"group":[],"area":[],"location":[],"systype":[],"class_list":["post-51724","post","type-post","status-publish","format-standard","hentry","category-legal-update-en","tag-cjeu","tag-right-of-access"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/posts\/51724"}],"collection":[{"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/comments?post=51724"}],"version-history":[{"count":5,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/posts\/51724\/revisions"}],"predecessor-version":[{"id":51729,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/posts\/51724\/revisions\/51729"}],"wp:attachment":[{"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/media?parent=51724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/categories?post=51724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/tags?post=51724"},{"taxonomy":"group","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/group?post=51724"},{"taxonomy":"area","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/area?post=51724"},{"taxonomy":"location","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/location?post=51724"},{"taxonomy":"systype","embeddable":true,"href":"https:\/\/www.eh.at\/en\/wp-json\/wp\/v2\/systype?post=51724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}