← All articles

consultant

CJEU C‑526/24 — When a first access request is “abusive” under Art. 12(5)

The CJEU allows, in exceptional cases, refusal of a first access request (Art. 15 GDPR) if the controller proves an abusive intent to manufacture compensable harm. Article 12(5) is interpreted strictly and the burden of proof lies with the controller.

CJEU 19 March 2026 (C‑526/24, Brillen Rottler) — The Court holds that a first access request (Art. 15 GDPR) may be refused where it is made solely to manufacture harm and claim compensation (Art. 82), provided the controller proves abusive intent on a case‑by‑case basis. See judgment C‑526/24 of 19 March 2026 (Infocuria).

The case

Brillen Rottler, a German optician, received an access request from a newsletter subscriber thirteen days after sign‑up. The controller suspected a tactic of multiplying “technical” requests to later allege non‑material damage and seek compensation. In a preliminary ruling, the Court held on 19 March 2026 (C‑526/24) that Art. 12(5) GDPR exceptionally allows refusal of an “excessive” request even at the first exercise, if the controller proves abusive intent (aiming to artificially create conditions for compensation). The Court also clarifies the link with Art. 82 (damage and causation). Official text and press release: judgment C‑526/24 (ECLI:EU:C:2026:216) and Press Release No 38/26 (case file; press release).

Legal reasoning

  • Textual basis. Art. 15 GDPR provides the right of access; Art. 12(5) allows controllers to “refuse to act” on “manifestly unfounded or excessive” requests (burden of proof on the controller); Art. 82(1) grants compensation for material or non‑material damage caused by an infringement. See EUR‑Lex.
  • CJEU interpretation (C‑526/24). The Court finds: (1) “excessive” is not limited to repetition; assessment is qualitative and in concreto (digest); (2) a first access request may be refused if, “despite formal compliance” with Art. 15, it pursues a purpose other than learning about processing and verifying lawfulness, e.g., “artificially” creating conditions for compensation (press release); (3) as an exception, Art. 12(5) must be interpreted strictly: refusal only “exceptionally,” based on objective evidence of abusive intent (digest).
  • Alignment with the EDPB. Guidelines 01/2022 stress facilitation, one‑month response, and refusal only where manifestly unfounded/excessive is duly evidenced (documentation, traceability). Refusals must explain reasons and redress options (EDPB 01/2022).
  • Local convergence (CNPD). Luxembourg’s CNPD explains the right of access, limits and timelines, and provides a practical factsheet (third‑party rights, disproportionate requests, identification). This supports the need for proof and transparency when refusing (access right page; 2024 factsheet).
  • Link with compensation. In line with 2023–2024 case‑law, a GDPR infringement alone is insufficient; the claimant must prove damage and causation (CJEU 2023). This frames the “compensation motive” underpinning abusive intent.

What changes in practice

  • Targeted refusals possible. For Luxembourg controllers, it is now possible — exceptionally — to refuse a first access request where abusive instrumentalisation is proven (compensation‑driven purpose detached from lawfulness control). Reference: CJEU C‑526/24 of 19 March 2026 (text).
  • Internal procedure. Update your data‑subject rights playbook: objective criteria, Art. 12(5) assessment grid, evidence collection, and a “refuse/partial/justify” matrix, with robust traceability. Justify refusals and point to CNPD complaint (Art. 77) and judicial remedy (Art. 79). Rely on the GDPR framework and EDPB 01/2022.
  • Signal to mass requests. In industrialised contentious contexts, the ruling offers a filtering lever without excusing poor responses: EDPB requires processes that facilitate the right and document any restriction (guidelines). Consider support from a certified DPO to secure your responses.
  • CNPD posture in Luxembourg. CNPD expects clear information on reasons, timelines and redress. Where identity is in doubt (Art. 12(6)), request only what is necessary. For local compliance practice, see our GDPR Luxembourg page.

Common pitfalls

  1. Refusing on “gut feeling”. A contentious tone is not enough. Without objective evidence of abusive intent (e.g., templates demanding lump‑sum compensation upfront), refusal is weak (strict reading of 12(5); digest).
  2. Equating “voluminous” with “excessive”. A broad request is not per se excessive. Absent proof of abuse, respond progressively (scope, prioritisation, iterations) as per EDPB 01/2022 (guide).
  3. Missing reasons and redress. A 12(5) refusal must be reasoned and inform of CNPD complaint (Art. 77) and judicial remedy (Art. 79). Opaque refusals risk sanctions (GDPR text).
  4. Neglecting identification. With reasonable doubt (Art. 12(6)), request only the necessary additional information and record your justification (consolidated text).
  5. Confusing damage with the access right. Lack of damage (Art. 82) does not void the access right. Brillen Rottler targets abusive intent, not legitimate litigation‑oriented requests (CJEU 2023).

Official sources

Regulator’s note: EDPB has always strictly framed Art. 12(5) and demanded evidence; CNPD stresses information, timelines and proportionality. C‑526/24 opens a narrow door against manifest abuse without weakening legitimate access rights.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →