The Court of Justice on the Excessiveness of Access Requests under the GDPR
Sascha Hurst — European Journal of Risk Regulation
Sascha Hurst — European Journal of Risk Regulation
How it connects
References
- CJEU - C-526/24 - Brillen Rottler
- Art. 15
- Art. 82
- Art. 15(1)
- Art. 12(5)
- Art. 82(1)
- Art. 57(4)
- Art. 54
- Art. 8(2)
- Art. 3
- ECLI:NL:GHDHA:2025:2871 Gerechtshof Den Haag , 17-12-2025 / BK-24/954
- BGH - VI ZR 375/2
- OLG Wien - 13R70/25x
- BVwG - W258 2227269-1/39E
- OLG München - 36 U 1054/25 e
- Inzage transactiegegevens. Overwegingen inzake toepassing Maltese uitzondering op inzagerecht.
- Rb. Den Haag - C/09/689833
Related across sources
Full text
C A S E N O T E S The Court of Justice on the Excessiveness of Access Requests under the GDPR Sascha Hurst Department of Law, Stockholm University, Stockholm, Sweden Email: sascha.hurst@juridicum.su.se Abstract This case note comments on the preliminary ruling of the Court of Justice of the EU in Case C-526/24 Brillen Rottler v TC of 19 March 2026, which addresses the abuse of rights under the General Data Protection Regulation (GDPR), specifically in the context of requests for access to personal data under Article 15 GDPR and compensation under Article 82 GDPR. First, the Court held that even a first access request may be regarded as “ excessive ” where the controller demonstrates that it was not made to be aware of the data processing and verify its lawfulness, but with an abusive intention, such as artificially creating the conditions for a compensation claim. Publicly available information showing a pattern of repeated requests and claims to different controllers may be considered in this assessment. Second, the Court confirmed that a right to compensation can arise from an infringement of the right of access. Third, it clarified that non-material damage in those cases encompasses the loss of control over the personal data or the uncertainty about its processing, provided the data subject has actually suffered such damage and has not caused it through their own conduct. This note situates the judgment within the broader framework of case law on the abuse of rights and the recent Digital Omnibus proposal, and it outlines its practical significance for balancing the protection of the data subjects with the need to safeguard controllers against illegitimate claims. Keywords: abuse of rights; excessive requests; General Data Protection Regulation I. Introduction When the law confers rights on individuals, there is the risk that those rights may be exercised in ways that are unjust or pursue aims falling outside their intended purpose. In the context of the General Data Protection Regulation 1 (GDPR), a significant practical scenario concerns abusive access requests by data subjects. Such requests formally seek from the controller confirmation of whether and what personal data are being processed, yet are not driven by a genuine interest in that information, but rather by the intention to provoke a refusal and subsequently bring a claim for compensation. On 19 March 2026, the Court of Justice of the EU (the “ Court ” ) delivered its judgment in Brillen Rottler v TC, 2 a preliminary ruling addressing questions regarding the circumstances under which access requests may constitute an abuse of rights as well as the remedies where a refusal to respond is not justified. The relevant legal framework is shaped by © The Author(s), 2026. Published by Cambridge University Press. This is an Open Access article, distributed under the terms of the Creative Commons Attribution licence (https://creativecommons.org/licenses/by/4.0/), which permits unrestricted re-use, distribution and reproduction, provided the original article is properly cited. 1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, OJ L 119, 4.5.2016, 1 – 88. 2 Case C-526/24 Brillen Rottler GmbH & Co. KG v TC EU:C:2026:216. European Journal of Risk Regulation (2026), 1 – 7 doi:10.1017/err.2026.10117 Downloaded from https://www.cambridge.org/core. IP address: 116.203.68.42, on 17 Jul 2026 at 10:22:25, subject to the Cambridge Core terms of use, available at https://www.cambridge.org/core/terms. https://doi.org/10.1017/err.2026.10117 Article 15(1) GDPR, which establishes the data subject ’ s right of access, and Article 12(5) GDPR, which permits controllers to refuse requests that are manifestly unfounded or excessive, in particular due to their repetitive nature. In addition, Article 82(1) GDPR provides a right to compensation for damage resulting from infringements of the Regulation. Against this background, Brillen Rottler engages with the need to strike a balance between safeguarding the fundamental right to data protection, which expressly includes the right to access, 3 and preventing abusive procedural practices. II. Facts The reference for a preliminary ruling arose in proceedings before the Local Court of Arnsberg, Germany, initiated by Brillen Rottler, a German family-run optician company. The case originated from the actions of TC, a natural person resident in Austria, who subscribed to the company ’ s newsletter by entering his personal data in an online registration form. Only thirteen days later, TC submitted an access request under Article 15 GDPR. Brillen Rottler refused the request on the ground of alleged abuse of rights. TC maintained his request and additionally claimed € 1000 in compensation under Article 82 GDPR. Brillen Rottler subsequently sought a declaration before the referring court that TC was not entitled to such compensation. In support of its refusal, it relied on various online reports, blog posts, and legal newsletters, arguing that these indicated a pattern of conduct whereby TC systematically submits access requests solely to provoke refusals and pursue compensation claims. According to the company, subscribing to newsletters, followed by access requests and claims for compensation, formed TC ’ s modus operandi . TC, by contrast, pursued his claim for compensation by way of a counterclaim, which he based on the non- material damage allegedly suffered as a result of the refusal to grant him access to his personal data. The referring court submitted eight questions to the Court, primarily concerning the interpretation of Articles 12(5) and 82 GDPR. Following the Opinion of Advocate General Szpunar, the Court addressed them in three parts. The first concerned whether, and under what conditions, even a first access request to a controller may be considered “ excessive. ” In particular, the referring court wondered whether a controller may rely on publicly available information about a data subject ’ s conduct when refusing to act on a request. The second and third parts concerned the scope of the right to compensation under Article 82 GDPR. The referring court sought clarification on whether damages may be claimed for an infringement of the right of access as such. Its doubts arose from recital 146 GDPR, which states that compensation is due for damage suffered “ as a result of processing that infringes this Regulation. ” It therefore asked whether an access request itself constitutes “ processing ” of personal data, or whether the right to compensation arises independently of any processing. Finally, the referring court sought clarification on whether an unjustified refusal of access can in itself give rise to non-material damage, notably in the form of loss of control over personal data or the uncertainty resulting from the infringement. III. Judgment To begin with, the Court adopted a qualitative understanding of excessiveness under Article 12(5) GDPR, holding that even a first request for access may be considered excessive. In its reasoning, the Court first referred to the wording of the provision and the 3 Art. 8(2) Charter of Fundamental Rights of the EU ( “ Charter ” ). 2 Sascha Hurst Downloaded from https://www.cambridge.org/core. IP address: 116.203.68.42, on 17 Jul 2026 at 10:22:25, subject to the Cambridge Core terms of use, available at https://www.cambridge.org/core/terms. https://doi.org/10.1017/err.2026.10117 usual meaning in everyday language, in which the term “ excessive ” denotes something that exceeds a desirable or permissible amount and thus goes beyond merely quantitative aspects. 4 Moreover, the reference to the repetitive character of a request in the provision serves only as an example. 5 Considering the wider context, the Court emphasised that the possibility for controllers to refuse manifestly unfounded or excessive requests is exceptional and must be interpreted restrictively. 6 The Court further referred to its decision in Österreichische Datenschutzbehörde , 7 where it interpreted the parallel provision in Article 57(4) GDPR regarding excessive requests to a supervisory authority. There, it understood this provision to be an expression of the general principle that EU law cannot be relied on for abusive or fraudulent ends, which can be transposed to the present case, as Article 12(5) GDPR is worded in similar terms and pursues the same objective. 8 Accordingly, the Court did not find the number of requests, as such, determinative for the controller ’ s option of not acting on a request for access. Finally, the judgment also stresses the consistency of this result with the broader objectives pursued by the GDPR, as the protection of personal data is not absolute but to be considered in relation to its societal function and other fundamental rights. 9 Given the exceptional nature of the provision, the Court held that strict criteria must be met to demonstrate that even a first request is excessive. In line with prior case law, an abusive practice requires an objective and a subjective element. For the objective element, there must be circumstances in which EU rules are formally observed, but their purpose has not been achieved. In this regard, the Court recalled that Article 15 GDPR aims to allow data subjects to be aware of the processing of their personal data and to verify its lawfulness, thereby enabling them to exercise their rights, including claims for compensation. 10 The subjective element requires the controller to demonstrate “ unequivocally ” that the purpose of the request was not to be aware of the processing but to artificially create the conditions for obtaining compensation. 11 The Court emphasised that all circumstances of the case are to be taken into account, including whether the personal data were provided voluntarily, the aim of providing them, the time elapsed before the access request was made, and the data subject ’ s conduct. 12 Public information indicating a systematic use of requests and claims for compensation to various controllers, following a modus operandi like in the present case, can be considered but must be supported by other relevant material. 13 In the second part, the Court addressed the interpretation of Article 82(1) GDPR. Relying on the provision ’ s wording and its systematic position, it ruled that compensation may be claimed for damage resulting from an infringement of the right of access. 14 The Court rejected the argument that unlawful data processing is required for compensation. First, this is because such requirement would exclude refusals to provide access from the scope of the right, as the infringement in these cases is not linked to the processing of personal data as such. 15 Second, in previous case law, infringements of certain other provisions of the GDPR were not seen to constitute unlawful processing, thus excluding the rights to 4 Brillen Rottler , supra note 2, para 25. 5 Ibid, para 26. 6 Ibid, para 29. 7 Case C-416/23 Österreichische Datenschutzbehörde v FR EU:C:2025:3. 8 Brillen Rottler , supra note 2, para 30. 9 Ibid, paras 32 ff. 10 Ibid, para 37, referring to Case C-154/21 RW v Österreichische Post AG EU:C:2023:3. 11 Brillen Rottler , supra note 2, paras 40 f. 12 Ibid, paras 36, 40, 42. 13 Ibid, paras 43, 45. 14 Ibid, para 48. 15 Ibid, paras 50 f. European Journal of Risk Regulation 3 Downloaded from https://www.cambridge.org/core. IP address: 116.203.68.42, on 17 Jul 2026 at 10:22:25, subject to the Cambridge Core terms of use, available at https://www.cambridge.org/core/terms. https://doi.org/10.1017/err.2026.10117 erasure or restriction of processing in these cases. Therefore, the Court argued that such infringements must be remedied by recourse to other measures, including the right to compensation for any damage caused. 16 Third, a teleological interpretation further supports this view, as limiting compensation solely to unlawful processing would significantly weaken the right of access. The third part of the judgment addresses non-material damage resulting from unlawful refusals to provide access. The Court held that the loss of control over personal data or the uncertainty as to whether they have been processed is encompassed by non-material damage as an autonomous concept of EU law. Consistent with previous case law, 17 there is no minimum threshold for such damage; however, mere allegations of fear caused by a loss of control are not sufficient and must be assessed by the national court as well-founded. 18 IV. Comment 1. Abuse of rights under EU law The judgment centres around the prohibition of abuse of EU law. In general terms, the prohibition of abuse of rights operates as a corrective mechanism that limits the strict application of legal rules in situations where the formal conditions of a rule are satisfied but the outcome of its application runs counter the objective of that rule. 19 The prohibition thus addresses the anti-purposive use of a formally satisfied right. While rooted in the private law systems of most Member States, 20 its precise legal nature has long been the subject of discussion. 21 The Court first engaged with the concept in the context of free movement law, beginning with the judgment in van Binsbergen 22 and followed in other free movement cases. 23 Essentially, this earlier case law concerned the possibility of Member States to address the circumvention of national rules through the abusive exercise of EU free movement rights. Subsequent rulings have broadened the scope of the concept. In the key ruling in Emsland-Stärke , the Court developed a test for establishing abuse of rights that is independent of any circumvention of national law, 24 and has since applied this test across a number of areas beyond primary law. Emsland-Stärke itself concerned export refunds, and was later relied upon, for example, in tax law 25 and consumer 16 Ibid, para 52 with reference to Case C-60/22 UZ v Bundesrepublik Deutschland EU:C:2023:373. 17 See Cases C-456/22 VX, AT v Gemeinde Ummendorf EU:C:2023:988, paras 22 f.; C-200/23 Agentsia po vpisvaniyata v OL EU:C:2024:827, para 143. 18 Brillen Rottler , supra note 2, paras 62 f. 19 E.g., A Lenaerts, “ The General Principle of the Prohibition of Abuse of Rights: A Critical Position on Its Role in a Codified European Contract Law ” (2010) 18 European Review of Private Law 1121, 1122; A Kjellgren, “ On the Border of Abuse: The Jurisprudence of the European Court of Justice on Circumvention, Fraud and Other Misuses of Community Law ” (2000) 11 European Business Law Review 179. 20 Lenaerts, supra note 19, 1125 ff. 21 See, e.g., A Arnull, “ What is a General Principle of EU Law? ” in R de La Feria and S Vogenauer (eds), Prohibition of Abuse of Law: A New General Principle of EU Law? (Hart 2011) 7 ff.; S Kamanabrou, “ Abuse of Law in the Context of EU Law ” (2018) 43 European Law Review 534; R de La Feria, “ Prohibition of Abuse of (Community) Law: The Creation of a New General Principle of EC Law through Tax ” (2008) 45 Common Market Law Review 395. 22 Case 33/74 van Binsbergen v Bestuur van de Bedrijsvereniging voor de Metaalnijverheid EU:C:1974:131, paras 12 ff. 23 E.g., Cases 115/78 Knoors v Staatssecretaris van Economische Zaken EU:C:1979:31, para 24; 229/83 Association des Centres distributeurs Édouard Leclerc and Others v SARL “ Au blé vert ” and Others EU:C:1985:1, para 27; 39/86 Lair v Universität Hannover EU:C:1988:322, para 43; C-370/90 The Queen v Immigration Appeal Tribunal and Surinder Singh EU: C:1992:296, para 24. 24 Case C-110/99 Emsland-Stärke GmbH v Hauptzollamt Hamburg-Jonas EU:C:2000:695, paras 52 f. 25 Case C-255/02 Halifax plc and Others v Commissioners of Customs and Excise EU:C:2006:121, para 69; C-196/04 Cadbury Schweppes plc and Others v Commissioners of Inland Revenue EU:C:2006:544, para 64. 4 Sascha Hurst Downloaded from https://www.cambridge.org/core. IP address: 116.203.68.42, on 17 Jul 2026 at 10:22:25, subject to the Cambridge Core terms of use, available at https://www.cambridge.org/core/terms. https://doi.org/10.1017/err.2026.10117 law 26 . The test comprises two cumulative elements, an objective element that requires that the purpose of the EU rule has not been achieved despite formal observance of the conditions, and a subjective element that requires the intention to obtain an advantage by artificially creating the conditions laid down for it. It is current settled case law that the prohibition of abuse of EU law constitutes a general principle of EU law. 27 Not least to note, this principle is also reflected in Article 54 of the Charter. 2. Bringing the two-part abuse test to the GDPR As secondary legislation often serves to specify and give concrete effect to general principles, Brillen Rottler builds on FT and confirms that Article 12(5) GDPR constitutes an expression of the general principle prohibiting abuse of rights, concretised through the notions of “ manifestly unfounded ” or “ excessive ” requests. 28 In the context of access requests, the latter notion is of particular relevance, since those requests are not subject to substantive conditions and therefore cannot be unfounded on their merits. Following a convincing finding that even initial requests may be excessive, which appears well supported particularly by the provision ’ s wording, the core of the Court ’ s reasoning concerns the two-step abuse test drawn from the Emsland-Stärke line of cases. In this regard, the ruling principally aligns well with the prior judicial evolution of this principle. Compared to Österreichische Datenschutzbehörde , where the Court addressed only the requirement of abusive intention as a precondition for excessiveness under Article 57(4) GDPR, 29 Brillen Rottler is more explicit in invoking the established two-part test and clearly distinguishes between the objective and subjective elements. The application of the test in the present case is, however, not straightforward. Particularly intricate is the objective element, requiring a combination of circumstances in which, despite formal observance of the conditions laid down by the EU rules, the purpose of those rules has not been achieved. Determining whether this is satisfied hinges on how the purpose of the rule in question is interpreted. The Court holds that the purpose of Article 15 GDPR is to confer a right of access to essentially verify the lawfulness of the data processing and to be able to exercise the respective rights, including that for compensation. Yet, with this understanding of the purpose, it appears to be objectively fulfilled even where the refusal of access and the subsequent compensation claim have been deliberately provoked. While the Court and the Advocate General also note this tension, 30 it is not made clear how the objective assessment is applied in such cases. The Advocate General found it expedient, where the aim of the rule appears a priori to be achieved, to “ begin ” by analysing the subjective element. 31 After doing so, he did, however, not turn to addressing the application of the objective element specifically, and he linked his proposed answer to the referred question instead to the demonstration of the data subject ’ s abusive intention. The Court, on the other hand, includes both elements as cumulative conditions in its answer, but its only remark on the purpose of Article 15 GDPR formally being fulfilled is that this does not in itself rule out the excessiveness of a request. 32 26 Joined Cases C-38/21, C-47/21, and C-232/21 VK v BMW Bank GmbH and Others EU:C:2023:1014, para 285; C ‑ 33/ 20, C ‑ 155/20 and C ‑ 187/20 UK v Volkswagen Bank GmbH and Others EU:C:2021:736, para 122. 27 See Case C-359/16 Criminal proceedings Ömer Altun and Others EU:C:2018:63, paras 48 f.; C-321/05 Kofoed v Skatteministeriet EU:C:2007:408, para 38. 28 Case C-307/22 FT v DW EU:C:2023:811, para 31. 29 Österreichische Datenschutzbehörde , supra note 7, paras 42 ff. 30 Brillen Rottler , supra note 2, para 38; Opinion of Advocate General Szpunar in Case C-526/24 Brillen Rottler GmbH & Co. KG v TC EU:C:2025:723, para 45. 31 Advocate General Opinion in Brillen Rottler , supra note 30, para 45; see also Opinion of Advocate General Szpunar in Case C-236/23 Matmut v TN and Others EU:C:2024:560, para 67. 32 Brillen Rottler , supra note 2, paras 38 f. European Journal of Risk Regulation 5 Downloaded from https://www.cambridge.org/core. IP address: 116.203.68.42, on 17 Jul 2026 at 10:22:25, subject to the Cambridge Core terms of use, available at https://www.cambridge.org/core/terms. https://doi.org/10.1017/err.2026.10117 Overall, this does not reflect a two-step approach composed of clearly delineated stages, as suggested by the Court. The Court ’ s analysis ultimately builds on Österreichische Datenschutzbehörde and centres on abusive intention, yet the objective circumstances drive the assessment and also carry much of the weight formally attributed to the subjective element. In this respect, the objective and subjective components are more closely intertwined than the formal test might first suggest. The subjective element thus has an objective value, which is significant given the practical difficulties of investigating motives of natural persons. 33 This is also in line with the Court ’ s insistence that the abuse assessment must rest on objective evidence 34 and with the “ objectification ” of intentional elements in other areas of EU law. 35 Furthermore, reliance on an abusive intent as a separate condition sits in tension with FT , where the Court held that data subjects are not obliged to state reasons for their access request and may pursue reasons not related to become aware of the lawfulness of the processing. 36 The Court thus seems to require an abusive intent in a context where the motivation behind exercising the right was not deemed relevant. In this light, Brillen Rottler lacks clarity in the relation between objective and subjective elements. They may better be understood as two perspectives on the same underlying question, namely if the formally legal conduct is artificially creating an outcome against the objective of the invoked rule. 3. Abuse of rights in the Digital Omnibus proposal The rules on abuse of rights are currently under discussion in the context of the proposed Digital Omnibus package, 37 which seeks to simplify and clarify digital rules and specifically addresses the abuse of the right of access under the GDPR. The proposed revision of Article 12(5) GDPR 38 involves two key changes. For one, it adds as an example of manifestly unfounded or excessive requests that a data subject abuses their rights “ for purposes other than the protection of their data ” . This is somewhat circular. While FT and Brillen Rottler treat excessiveness as an expression of abuse of rights, the proposed version frames an abuse as an example of excessiveness. More fundamentally, grounding the assessment only in the data subject ’ s motive for exercising the right cannot, in light of the remarks above, be reconciled with existing case law, and effectively adds a motive condition into the right of access. It is also unclear what qualifies as data protection purposes, given that in practice access requests typically serve an ancillary function in support of legal disputes in other contexts. 39 33 Cf. KE Sørensen, “ Abuse of Rights in Community Law: A Principle of Substance or Merely Rhetoric? ” (2006) 43 Common Market Law Review 423, 454 ff.; M Lang, “ Cadburry Schweppes ’ Line of Case Law from the Member States ’ Perspective ” in R de La Feria and S Vogenauer (eds), supra note 21, 435, 448 ff.; Opinion of Advocate General Geelhoed in Case C-109/01 Secretary of State for the Home Department v Hacene Akrich EU:C:2003:112, para 173; G Butler and KE Sørensen, “ The Prohibition of abuse of EU Law: A Special General Principle ” in K Ziegler, P Neuvonen, and V Moreno- Lax (eds), Research Handbook on General Principles in EU Law (Edward Elgar 2022) p 409; for an opposing view D Weber, “ Abuse of Law in the Context of Indirect Taxation: Why We Need the Subjective Intention Test, When is Combating Abuse an Obligation and Other Comments ” in de La Feria and Vogenauer (eds), supra note 21, 543. 34 See C-373/97 Dionysios Diamantis v Elliniko Dimosio and Others EU:C:2000:150, para 34; C-212/97 Centros Ltd v Erhvervs- og Selskabsstyrelsen EU:C:1999:126, para 25; Lair , supra note 23, para 43. 35 See A Sanchez-Graells, “ Assessing the Public Administration ’ s Intention in EU Economic Law: Chasing Ghosts or Dressing Windows? ” (2016) 18 Cambridge Yearbook of European Legal Studies 93. 36 FT , supra note 28, paras 43, 52. 37 European Commission, Proposal for a Digital Omnibus Regulation, COM (2025) 837 final. 38 Ibid, Art. 3(4). 39 Cf. E Celeste, “ Digital Omnibus: quo vadis? ” ( Dublin City University , 9 December 2025) < https://www.dcu.ie/ blog/2151/digital-omnibus-quo-vadis > ; GG Fuster, “ Caught Between AI and the AI Hype: How the Right to Personal Data Protection was Ambushed ” (2026) Rivista di Diritti Comparati 106, 121 f. 6 Sascha Hurst Downloaded from https://www.cambridge.org/core. IP address: 116.203.68.42, on 17 Jul 2026 at 10:22:25, subject to the Cambridge Core terms of use, available at https://www.cambridge.org/core/terms. https://doi.org/10.1017/err.2026.10117 The amendment thus appears to go beyond the current interpretation, though this does not seem to be the purpose of the revision. 40 The second change would lower the burden of proof for controllers. Whereas Article 12(5) GDPR requires demonstrating the “ excessive character of a request, ” the proposed version would require only “ reasonable grounds to believe ” that the request is excessive. This adjustment is intended to reflect the difficulty that the possibly abusive conduct of a data subject lies primarily outside the controllers ’ sphere of influence. 41 Together with the very broad framing of an abuse, this risks undermining the exceptional character of the provision in practice, 42 which is problematic given the already rather limited level of compliance with the access right. 43 V. Conclusion This judgment does not introduce any far-reaching changes, but its contribution lies in extending earlier guidance on abuse of rights both within and beyond the data protection context. Despite the difficulties that the suggested two-part test gives rise to, the Court still provides additional clarity on the abusiveness of access requests as well as on the application of Article 82(1) GDPR to refusals to provide access. This strengthens the position of controllers in defending against abusive practices by data subjects and illustrates the special character of abuse of rights as a general principle that serves to limit, rather than protect, the exercise of rights. 44 The judgment does not, however, weaken the level of protection of data subjects. Rather, it delineates how the principle applies in the exceptional cases where the conditions of the compensation right under the GDPR are artificially created. The Digital Omnibus proposal, by contrast, risks unsettling this balance by broadening the provision and resting the finding of abuse on the data subject ’ s motivation, a criterion that raises concerns having regard to the case law and practical enforcement. Competing interests. The author has no competing interests to declare. 40 Cf. Digital Omnibus Proposal, supra note 37, 30. Critical also R Mahieu, “ The Ominous Omnibus: Dismantling the Right of Access to Personal Data ” ( Verfassungsblog , 3 December 2025) < https://verfassungsblog.de/digital- omnibus-right-of-access-to-personal-data > ; J Rosse et al., “ DATARights Policy Brief on Data Subject Access Rights in the Proposed Digital Omnibus ” (2026) CEMTI < https://hal.science/hal-05545314v1 > 5 ff.; noyb, “ Digital Omnibus: First Analysis of Select GDPR and ePrivacy Proposals by the Commission ” (version 3, 2026) < https://no yb.eu/en/digital-omnibus-report-v3-analysis-select-gdpr-and-eprivacy-proposals-commission > 29 ff. 41 Digital Omnibus Proposal, supra note 37, recital 35. 42 See also I Erdogan and others, “ White Paper on the Digital Omnibus Proposal and the AI Omnibus Proposal ” (13 March 2026) < https://ssrn.com/abstract = 6409138 > 24 ff. 43 E.g. R Mahieu et al., “ Measuring the Brussels Effect Through Access Requests ” (2011) 11 Journal of Information Policy 301. 44 Cf. Butler and Sørensen, supra note 33, 402, 412 f. Cite this article: S Hurst, “ The Court of Justice on the Excessiveness of Access Requests under the GDPR ” . European Journal of Risk Regulation . https://doi.org/10.1017/err.2026.10117 European Journal of Risk Regulation 7 Downloaded from https://www.cambridge.org/core. IP address: 116.203.68.42, on 17 Jul 2026 at 10:22:25, subject to the Cambridge Core terms of use, available at https://www.cambridge.org/core/terms. https://doi.org/10.1017/err.2026.10117