Skip to content
Case Law · District Court Rotterdam ·ROT 25/8349, 25/8350, 25/6295, 25/6296 and 25/6297 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Rotterdam court upholds municipality's refusal of excessive GDPR requests

A data subject submitted 73 separate GDPR requests to the Municipal Executive of Rotterdam, the controller, between November 2024 and February 2025.

Original title: Rb. Rotterdam - ROT 25/8349, 25/8350, 25/6295, 25/6296 and 25/6297

Judgment·ECLI:NL:RBROT:2026:9885

Holding

The Court partially upheld the appeals but maintained the legal effects of the controller's decisions. Regarding Articles 15, 16, 17 and 19 GDPR, the Court held that requests may be refused under Article 12(5) GDPR where, considering all circumstances, they are manifestly excessive. Although the controller's initial reasoning was insufficient, its supplementary submissions demonstrated that the data subject had submitted numerous repetitive and largely overlapping requests within a short period concerning mostly static personal data. The Court therefore considered the requests intentionally abusive and held that the controller was entitled to refuse them. Regarding Article 14 GDPR, the Court held that a request for information under this provision does not result in an administrative decision under Article 34 UAVG (Uitvoeringswet Algemene Verordening Gegevensbescherming, the Dutch Data Protection Act). Therefore, the controller's response could not be challenged through an administrative objection. The data subject could instead seek enforcement before the DPA or the civil courts. The Court consequently annulled the contested decisions for insufficient reasoning but maintained their legal effects, while dismissing the appeals concerning Article 14 GDPR.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

Most requests contained several sub-requests and relied on Articles 5, 6, 10, 14, 15, 16, 17 and 19 GDPR. The controller refused the requests under Articles 15, 16, 17 and 19 GDPR on the basis of Article 12(5) GDPR, considering them excessive. It found that the requests had been submitted systematically within short periods, often concerned the same subject matter and could have been consolidated. The controller also considered that processing the requests imposed an unnecessary administrative burden. Requests under Articles 5, 6, 10 and 14 GDPR were treated as requests for information rather than applications giving rise to an administrative decision. It therefore declared the data subject's objections concerning those requests inadmissible. By contrast, the objections concerning the requests under Articles 15 to 19 GDPR were examined on the merits and declared unfounded. The data subject challenged these decisions before the Court. During the proceedings, the data subject withdrew several requests and maintained three access requests under Article 15 GDPR, as well as requests under Articles 14, 16, 17 and 19 GDPR.

Full text 23 paragraphs

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

ECLI:NL:BROT:2026:9885 Share pronunciation Agency Court of Rotterdam Date of ruling July 24, 2026 Date of publication August 11, 2026 Case number ROT 25/8349, 25/8350, 25/6295, 25/6296, and 25/6297 Jurisdictions Administrative law Special features First instance – single judge Content indication Miscellaneous. GDPR. Appeal filed with the legal effects remaining in force. The court finds that the College, with the additional justification provided, has sufficiently demonstrated that the requests submitted by the plaintiff are excessive. With that additional justification, the College was able to refuse to comply with these requests pursuant to Articles 15, 16, 17, and 19 of the GDPR. Because the plaintiff’s requests under Article 14 of the GDPR must be regarded as requests for information, the Board’s response to them does not constitute a decision within the meaning of the General Administrative Law Act (Awb) against which an objection may be filed. The Board has therefore correctly declared these objections inadmissible. Find locations Rechtspraak.nl Enriched verdict Ruling ROTTERDAM COURT Administrative law Case numbers: ROT 25/8349, 25/8350, 25/6295, 25/6296, and 25/6297 Decision of the Single Chamber of July 24, 2026, in the Joined Cases between [name of plaintiff], of [place], plaintiff and the College of Mayor and Aldermen of Rotterdam, the College (authorized representatives: Mr. N. Elsheikh and Mr. E.F. Vaal). Summary

applies Art. 14
¶1

This ruling concerns the rejection of the claimant’s requests under the General Data Protection Regulation (GDPR) on the grounds that those requests were manifestly excessive. The claimant disagrees with the rejection. To this end, he raises a number of grounds for appeal.

¶1.1

The court concludes in this ruling that, although the plaintiff’s appeal is well-founded, the legal effects of the contested decisions can be upheld. The Board has correctly held that, in light of all the relevant circumstances of this particular case, the claimant’s requests are manifestly excessive. The court then explains how it reached this judgment and what consequences this judgment entails. Progress of the Proceedings Cases 25/6296 and 25/6297, 25/8349, 25/8350

¶2.1

The claimant has made several requests pursuant to the GDPR. The Board has rejected these requests—insofar as they constitute an application within the meaning of Article 1:3 of the General Administrative Law Act (Awb)—by means of the initial decisions dated January 21, 2025 (Case 25/6296), January 21, 2025 (25/6297), March 27, 2025 (25/8349), and May 9, 2025 (25/8350).

applies Art. 1
¶2.2

With the contested decisions of February 20, 2025 (25/6295, 25/6296, and 25/6297) and September 15, 2025 (25/8349 and 25/8350), the Board upheld the initial decisions. The objections, to the extent that they relate to requests containing elements that are covered by Articles 15 through 22 of the GDPR, have been declared unfounded, and the objections regarding the other requests have been declared inadmissible. Case 25/6295

¶2.3

In its initial decision of February 20, 2025, the Board rejected the plaintiff’s request for a penalty payment due to the failure to issue timely decisions in response to the plaintiff’s request of November 6, 2024, pursuant to Article 14 of the GDPR.

applies Art. 14
¶2.4

In the contested decision of July 22, 2025, the Board declared the plaintiff’s objection unfounded and upheld the initial decision, providing enhanced reasoning. Cases 25/6295, 25/6296, 25/6297, 25/8349, and 25/8350

¶2.5

The plaintiff filed a separate appeal in each case. The board has filed its answers.

¶2.6

The plaintiff has submitted a further response. In this document, dated June 7, 2025 (2026, as the court understands it), the plaintiff has withdrawn a large portion of his claims and reformulated another portion of his claims. 1.7 The court heard the appeals simultaneously on June 22, 2026. Those present included the plaintiff and the college’s representatives, along with [Person A]. After the hearing, the court consolidated the appeals. Summary of the contested decisions

¶3.1

The cases concern a total of 73 separate requests under the GDPR that the plaintiff submitted to the Board between November 1, 2024, and February 23, 2025. (Almost) each of these requests is subdivided into multiple sub-requests. The claimant based his (sub)requests on Articles 5, 6, 10, 14, 15, 16, 17, and 19 of the GDPR.

¶3.2

In its initial decisions, the Board provided overviews of all of the claimant’s GDPR requests addressed in those decisions, setting forth the dates and legal grounds for the requests. The Board also refers to earlier decisions in which it ruled on 206 separate GDPR requests from the claimant. The Board rejected the requests based on articles 15, 16, 17, and 19 of the GDPR. First and foremost, the Board takes the position that the requests for information under Article 14 of the GDPR and the requests under Articles 15–19 of the GDPR are excessive. On this basis, the Board may, pursuant to article 12, paragraph 5, of the GDPR, refuse to comply with the requests. The College believes that the requests were submitted systematically and as part of a campaign, and that they could easily have been bundled together. Submitting multiple requests without reasonable intervals is disproportionate. Furthermore, according to the Board, the submission of the requests is not objectively necessary for the protection of the data subject’s rights under the GDPR. With regard to the requests for access under Article 15 of the GDPR, the defendant takes the view that some of these requests do not qualify as requests for access within the meaning of the aforementioned article. With regard to another part of the requests, the Board does not possess any further personal data and/or the documents mentioned by the plaintiff. In addition, some of the requests pertain to cases on which this court has already ruled. The College has rejected the requests for rectification and/or erasure pursuant to Articles 16 and 17 of the GDPR because the requests refer to data that the municipality does not possess or whose rectification and erasure is not within its authority; the right to rectification is not intended to correct or remove any personal data that is not inaccurate or incomplete, or because the data in question is not inaccurate or incomplete According to the College, the requests under Articles 5, 6, 10, and 14 of the GDPR are to be regarded as requests for information and treated as such. The College states that it has previously provided the plaintiff with full information and has no additional information.

¶3.3

In the contested decisions, the College declared the plaintiff’s objections to the requests under Articles 15–19 to be unfounded and, to the extent that they were directed against the requests based on the other articles, declared them inadmissible. The Board has determined that the claims seeking information under Article 14 of the GDPR and the requests under Articles 15–19 of the GDPR are excessive. The requests cannot be separated from the GDPR requests that the plaintiff submitted between November 1, 2024, and January 29, 2025, nor from the KPMG investigation and the final report prepared in response to it. The Board also takes the view that the manner in which the plaintiff submits his requests places an unnecessary burden on the Board. This concerns the way in which the plaintiff formulates his requests, the structure of these requests, and the relatively short period within which the numerous requests have been submitted. The requests often relate to the same (sub)topic and are frequently distinguished only by a single detail. Almost every request contains a number of sub-requests. Furthermore, the Board considers that the plaintiff is legally savvy, is familiar with the municipality’s work processes, and knows how to slow them down. Based on these considerations, the Board concludes that the plaintiff’s requests cannot reasonably serve any purpose other than to reopen the legal assessments of the facts that previously led to the plaintiff’s civil and criminal convictions. With regard to declaring the objection directed against the plaintiffs’ requests inadmissible on the basis of Articles 5, 6, 10, and 14 of the GDPR, the Board takes the position that these are merely requests for information and that they have been addressed. The municipality’s response to these requests for information does not constitute a decision within the meaning of article 1:3 of the General Administrative Law Act (Awb). Review by the Court

¶4

The court notes first and foremost that, in his submission of June 7, 2026, the plaintiff withdrew all his requests (for evidence) based on Articles 5, 6, and 10 of the GDPR. This also applies to his requests for access under Article 15 of the GDPR regarding the processing of his personal data during the period from January 1, 2012, to October 1, 2019. It was established at the hearing that, as a result, the plaintiff maintains three requests for access, namely the requests dated February 11, 13, and 16, 2025. The plaintiff also maintains the requests under Articles 14, 16, 17, and 19 of the GDPR, whether or not they have been reformulated. In this ruling, the court addresses only the validity of the plaintiff’s requests. It will assess whether the contested decisions, insofar as they relate to those requests, can be upheld. It does so on the basis of the grounds for appeal filed by the plaintiff. Are the requests excessive?

¶5

The court will first address the question of whether the board was entitled to refuse the requests regarding Articles 15, 16, 17, and 19 of the GDPR on the grounds of Article 12, paragraph 5, of the GDPR because they constitute excessive requests. In this regard, the plaintiff argues that the Board is wrong to take the position that the requests are excessive. He claims to have submitted all his requests separately, in a detailed and documented manner, with the aim of verifying the accuracy of his processed personal data and the lawfulness of the data processing, as well as enabling the municipality to assess his requests in the context of their respective dataprocessing. It is up to the municipal executive to demonstrate that the plaintiff submitted his GDPR requests with malicious intent. According to the plaintiff, the municipal executive has failed to do so. The municipal executive focuses solely on the number of requests, but must also consider the context of the requests and the objectives of the GDPR.

¶5.1

Under the GDPR, a data subject such as the plaintiff has the right to access the personal data collected about him and, where applicable, to have that data rectified or erased. He must be able to exercise this right easily and at reasonable intervals so that he can become aware of the processing and verify its lawfulness.1 A data subject also has the right, where applicable, to have his personal data rectified or erased.2 However, these data subject rights are not unlimited. If a data subject’s requests are manifestly excessive, particularly due to their repetitive nature, the controller may refuse to comply with the request.3 It is up to the controller—in this case, the board—to demonstrate the manifestly excessive nature of the requests. The term “excessive” must be interpreted restrictively. In doing so, consideration must be given not only to the number of requests submitted but also to all specific circumstances of the case. The presence of bad faith is not a requirement, and the controller is therefore not required to demonstrate it. However, based on all relevant circumstances of the specific case, it must be established that there is intentional abuse by the data subject, whereby intent can be established when this person submits the request without it being objectively necessary to protect the rights he derives from the GDPR.4

¶5.2

In the court’s judgement, the board has not demonstrated intentional abuse based on the reasoning provided in the contested decisions; consequently, there has been a violation of Articles 3:2 and 7:12 of the General Administrative Law Act (Awb). The contested decisions therefore cannot stand. However, the court reaches the judgement that the Board, through the additional reasoning provided in the statement of defense dated June 11, 2026—which refers to the statement of defense dated July 7, 2025, as submitted in the objection— has nevertheless sufficiently demonstrated that the requests submitted by the plaintiff are excessive. With that additional justification, the Municipal Executive was entitled to refuse to comply with these requests pursuant to Articles 15, 16, 17, and 19 of the GDPR. For that reason, the court will rule that the legal effects of the annulled contested decisions remain in force.

¶5.3

It is undisputed that the plaintiff submitted a large number of GDPR requests within a period of several months and that the individual requests often consist of various sub-requests. The panel correctly states that the claimant’s GDPR requests cannot be viewed in isolation from the investigation conducted by KPMG and other (ongoing) proceedings initiated by the claimant before administrative, criminal, civil, and disciplinary courts, as well as proceedings involving and against (officials of) the Municipality of Rotterdam, Divosa, (auditors of) KPMG, the ombudsman, and his own trustee. A request for access to his personal data previously submitted by the plaintiff to the Board during the period from January 1, 2012, to October 1, 2019, was concluded by the Board with decisions dated January 3, 2020, June 30, 2020, and April 19, 2022. At the time these requests were submitted, this matter was pending before the Administrative Law Division of the Council of State.5 A large portion of the requests for access underlying the contested decisions relate to the same personal data. The College correctly observes that the frequency with which this personal data is updated is (very) low. Following the aforementioned decisions, the claimant’s personal data that the College has processed has not changed, except that processing takes place in the context of the proceedings initiated by the claimant (including the present GDPR requests themselves) and to comply with statutory retention periods. The Board correctly states that the claimant’s requests therefore pertain to a (largely) static set of personal data. The Board’s processing of the claimant’s personal data does not, in any event, justify the large number of requests for access pursuant to Article 15 of the GDPR. In addition, the college has been able to conclude that the manner in which the plaintiff has submitted his requests is unnecessarily burdensome for the college. For example, within a short period of time—sometimes submitting several requests per day—the plaintiff has not only submitted a large number of requests but has often submitted requests on the same topics and/or regarding the same (procedural) documents; furthermore, there are several separate requests that often differ from one another only in minor details. Verifying whether and, if so, how these requests differ is (unnecessarily) time-consuming. In its response of July 7, 2025, the college provided some examples of this. A total of eight separate requests dated January 12, 2025, indicate that the same annexes were sent with each request. In each of the requests, the plaintiff refers to document [document number]. The plaintiffs’ sub-requests then refer to invoices from CID Management dated December 9, 2010, and April 20, 2011; Factor 3BV dated April 13, April 15, 18, and 19, 2011, and Werkland B.V.’s invoices dated November 19, 2009 (twice). The partial requests are, for the rest, identical across all eight requests. The court agrees with the panel that there is no indication that the plaintiff could not have filed these requests as a single bundle and that splitting the requests was necessary to protect his rights under the GDPR.

¶5.4

All in all, there has been deliberate abuse on the part of the plaintiff. The fact that the plaintiff, in his letter dated June 7, 2026, withdrew a large portion of his requests does not alter this conclusion. The court assesses whether the board correctly concluded that the requests were excessive at the time of the contested decisions (i.e., on February 20, 2025, and July 22, 2025). That is the case. This also means that the revised requests are not addressed. The requests based on Article 14 of the GDPR.

applies Art. 14
¶6

With regard to the requests under Article 14 of the GDPR, the court will assess whether the written resolution of these requests is intended to produce legal effects and thus constitutes a decision within the meaning of Article 1:3 of the General Administrative Law Act (Awb). In this regard, the plaintiff argues that the board misinterprets the provisions of the GDPR and the General Administrative Law Act (Awb). The duty to provide information under Article 14 of the GDPR is aimed at producing legal effects. The reason Article 14 of the GDPR is not mentioned in Article 34 of the UAVG is that the legislature apparently (and, according to the plaintiff, therefore incorrectly) assumed that controllers would comply with the duty to provide information incumbent upon them and that a citizen would not need to request it. On the basis of article 1:3, paragraph 1, of the General Administrative Law Act (Awb), a “decision” is defined as: a written decision by an administrative body constituting a legal act under public law. On the basis of article 1:3, paragraph 1, of the General Administrative Law Act (Awb), an “application” means a request from an interested party to make a decision. Pursuant to Article 34 of the GDPR Implementing Act (UAVG), a written decision on a request referred to in Articles 15 through 22 of the GDPR must be issued within the time limits specified in Article 12(3) of the GDPR and, to the extent that it has been issued by a governing body, is considered a decision within the meaning of the Awb. 6.2 The court finds that it follows from Article 34 of the UAVG that a response to a request under Articles 15–22 of the GDPR constitutes a decision within the meaning of the Awb. The legislature did not choose to classify a response to requests under Article 14 of the GDPR as a decision or to treat it as such for the purposes of legal protection. The plaintiffs’ requests under Article 14 of the GDPR are requests for information. This also follows from the relevant articles of the GDPR. The data subject rights, as well as the obligations of a controller, are directly determined by the GDPR. Chapter III of the GDPR addresses the data subject rights. These are Articles 12 through 23 of the GDPR. Articles 15 through 22 of the GDPR grant data subjects a number of rights, such as the right of access and the right to rectification. Data subjects may exercise these data subject rights by submitting requests to the controller. A response to such a request constitutes, to the extent that the controller is an administrative body, a decision within the meaning of the General Administrative Law Act (Awb). This is not the case with a response to a request under Article 14 of the GDPR, even though this article is also included in Chapter III of the GDPR. Article 14 of the GDPR concerns the provision of information to the data subject. A response by an administrative body granting or denying a request for information does not constitute a legal act under public law because such a request does not involve a change in the rights and obligations of the applicant (or anyone else). Whether or not information is provided is a factual act. From the judgments of the District Court of Oost-Brabant, Amsterdam, and the Court of Appeal in The Hague, the court does not infer that an administrative court, upon appeal, can be required to ensure compliance with Article 14 of the GDPR by applying Article 34 of the GDPR analogously. Nor does this follow from the judgments of the Court of Justice of the European Union dated July 11, 2025, October 4, 2024, and November 28, 2024. This does not mean that the plaintiff cannot challenge the board’s response to the requests for information or the lack of a response. If necessary, the plaintiff may contact the Dutch Data Protection Authority or the civil court if he believes that the board is improperly fulfilling its obligations under Article 14 of the GDPR. 6.3 Because the plaintiff’s requests under Article 14 of the GDPR must be regarded as requests for information, the Board’s response to them (as set forth in the primary decisions mentioned above in sections 2.1 and 2.3 of this judgment) is not a decision within the meaning of the General Administrative Law Act (Awb) against which an objection may be filed. The Board therefore correctly declared these objections inadmissible. The appeal against this decision is unfounded.

¶7

Because the other grounds for appeal raised by the plaintiff relate to a substantive assessment of the various GDPR requests, the court will not address these grounds. The appeal against the periodic penalty payment decision (25/6295).

¶8

It follows from the above considerations in paragraph 6 of this judgment that the plaintiff’s appeal against the rejection of his application for a periodic penalty payment is also unfounded. The application for a periodic penalty payment was based on the failure to decide on a request in a timely manner pursuant to Article 14 of the GDPR. As noted above, this is a request for information. The Board was therefore not obligated to issue a decision on this request, and thus the Board correctly rejected the periodic penalty payment. Incidentally, the Board responded to the plaintiff’s request for information on January 23, 2025. Conclusion and Consequences

applies Art. 14
¶9

The claimant’s appeals in Cases 25/8349, 25/8350, 25/6296, and 25/6297 are well-founded, to the extent that they challenge the rejection of the requests pursuant to Articles 15–22 of the GDPR. The College provided a sufficient justification for the defense filed on June 11, 2026—which referred to the defense in the objection filed on July 7, 2025—only to the extent that the requests were manifestly excessive. The contested decisions of February 20, 2025, and September 15, 2025, violate Articles 3:2 and 7:12 of the Awb. The court will set aside these decisions but, pursuant to Article 8:72, paragraph 3, introductory sentence and point (a) of the Awb, will uphold their legal effects, because the College has remedied the defects on appeal. This means that the Board does not (yet) have to address the plaintiff’s requests on their merits. The appeals against the declaration that the objections to the applications were inadmissible pursuant to Article 14 of the GDPR are unfounded.

applies Art. 8Art. 14
¶10

Because the appeals in Cases 25/8349, 25/8350, 25/6296, and 25/6297 are well-founded, the Board must reimburse the plaintiff for the filing fee. Due to the consistency among the plaintiff’s various cases, only in Case 25/8349 (and not in Case 25/8350) and only in Case 25/6295 (and not in Cases 25/6296 and 25/6297) was an amount of (2 × €194 =) €388 in court fees paid. There are no further litigation costs eligible for reimbursement. Decision The court; - - declares the appeals, to the extent they are directed against the declaration that the objection is inadmissible, to be unfounded; - - declares the appeals, to the extent they are directed against the rejection of the requests under Articles 15–22 of the GDPR; - - annuls the contested decisions of February 20, 2025, and July 22, 2025, to the extent they relate to the rejection of the requests under Articles 15–22 of the GDPR; - - orders that the legal effects of the annulled portions of these decisions remain in force; - - orders the Board to reimburse the plaintiff for the registrar’s fees paid by the plaintiff, totaling €388. This statement was made by Mr. J.J.R. Lautenbach, judge, in the presence of Mr. L. Meijer, Registrar. Pronounced in open court on July 24, 2026.

How it connects

13 of 23 paragraphs apply legislation or carry a topic — see them in the full text ↓
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 May 13, 2026 Right of Access Criminal Data Personal Data
Opinion 01/2025 EDPB- EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR De EDPB en EDPS steunen het doel om de administratieve lasten voor SMCs en MKB te verminderen, mits dit de bescherming van fundamentele rechten niet verlaagt. Ze benadrukken de… Opinion Jul 9, 2025 Accountability Criminal Data Processing