Skip to content
Case Law · GDPRhub ·526/24 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

CJEU - C-526/24 - Brillen Rottler

On 16 March 2023, the data subject (a private individual living in Vienna) subscribed to the ‘newsletter’ on the website of the controller (a family run optician company established in North Rhine-Westphalia) by entering his personal data in the registration form, confirming his consent to data processing by ticking a box and submitting the form. On 29 March 2023, the data subject sent by fax an information request pursuant to Article 15 GDPR. The controller acknowledged receipt of the request and stated that it would respond to it within the one-month period. However, by letter of 26 April 2023, the controller refused to provide the information since it classified the information request as an abuse of right for the purposes of the second sentence of Article 12(5)(b) GDPR. The controller sought a declaration from the referring court that the data subject is not entitled to compensation in the amount of €1000. The court decided to refer the following questions set out in point I. to the CJEU for a preliminary ruling pursuant to Article 267 TFEU: Is the second sentence of Article 12(5) GDPR to be interpreted as meaning there cannot be an excessive information request from the data subject when the first request is made to the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that the controller can refuse an information request from the data subject if the data subject intends to use the information request to provoke claims for damages against the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that grounds for refusing to provide information can be provided by publicly available information about the data subject which suggests that the data subject is asserting claims for damages against the controller in a large number of cases of infringement of the law relating to the protection of personal data? Is Article 4(2) GDPR to be interpreted as meaning that an information request from a data subject to the controller pursuant to Article 15(1) GDPR and/or a response to that request constitutes processing within the meaning of Article 4(2) GDPR? In view of the first sentence of recital 146 GDPR, is Article 82(1) GDPR to be interpreted as meaning that only damage which the data subject suffers or has suffered as a result of processing is eligible for compensation? Does this mean that for there to be a claim for damages under Article 82(1) GDPR – assuming causal damage to the data subject exists – there must necessarily have been processing of the data subject’s personal data? If the answer to Question 5 is in the affirmative: Does this mean that the data subject – assuming causal damage exists – has no claim for compensation under Article 82(1) GDPR solely on the basis of an infringement of his or her right to information under Article 15(1) GDPR? Is Article 82(1) GDPR to be interpreted as meaning that the controller’s objection relating to an abuse of right in relation to an information request from the data subject cannot, in view of EU law, consist in the fact that the data subject brought about processing of his or her personal data solely or inter alia in order to assert claims for damages? If the answers to Questions 5 and 6 are in the negative: Does the mere loss of control and/or uncertainty about the processing of the data subject’s personal data associated with an infringement of Article 15(1) GDPR constitute non-material damage to the data subject within the meaning of Article 82(1) GDPR or does it also require a further (objective or subjective) restriction and/or (significant) damage to the data subject? Advocate General Opinion — In addressing the first, second, third, and seventh questions referred by the national court: — The excessive character of an initial access request Advocate General emphasized that while an initial access request can, in theory, be considered "excessive," this must be limited to exceptional circumstances since the right of access is fundamental and linked to other GDPR rights. The circumstances that allow a request to be characterized as ‘excessive’ The Advocate General analyzed when a data access request under Article 15 GDPR could be considered excessive under Article 12(5) GDPR . He concluded that such a request may only be treated as excessive if the controller can demonstrate an abusive intention. However, merely having a pattern of making similar claims in many cases does not, on its own, prove abuse, and strict criteria must be applied to ensure that the fundamental right of access is not unduly restricted. In addressing the the fourth, fifth and sixth questions referred by the national court : — The event giving rise to the damage within the meaning of Article 82 of the GDPR The Advocate General analyzed whether only data processing that violates the GDPR can give rise to compensation under Article 82 GDPR. He concluded that not just unlawful processing, but any infringement of the GDPR can be a basis for compensation, provided that damage and a causal link are proven. The concept of ‘processing’ for the purposes of the right to compensation The Advocate General explains that although sending an access request is not "processing" under the GDPR, a controller’s act of responding to such personal data , which can fall under the scope of the GDPR. However, the actual damage arises not from this technical processing, but from the unjustified refusal to fulfill the access request. To ensure the effectiveness of Article 15 GDPR and the right to compensation under Article 82, the concept of “processing that caused the damage” should be interpreted broadly. The existence of non-material damage The Advocate General clarifies that a violation of Article 15 GDPR alone does not automatically entitle a data subject to compensation; the individual must prove actual non-material harm resulting from the infringement. The Court has recognized that even temporary loss of control over personal data may qualify as non-material damage, without requiring a minimum severity threshold. Conclusion — In the Advocate General’s view, an initial access request under Article 15 GDPR can only be considered “excessive” where the data controller can clearly demonstrate, based on all relevant circumstances, that the data subject acted with abusive intent, specifically, where the individual consented to the processing of their personal data solely to submit an access request and subsequently claim compensation. Importantly, the mere fact that a data subject has frequently exercised their right to compensation in similar cases does not, in itself, justify classifying the request as excessive. Moreover, under Article 82(1) GDPR, a data subject is entitled to compensation for damage resulting from a violation of the Regulation, even if that damage was not directly caused by the processing of personal data. Holding — Is a first access request excessive in accordance with Article 12(5) GDPR, and under what circumstances is it possible to establish such an excessive nature? (Questions 1, 2, 3 and 7) — The court first noted that the GDPR guarantees the right to access in Article 15(1) GDPR. However, Article 12(5) GDPR allows the controller to charge a reasonable fee or refuse the request if it is “manifestly unfounded or excessive”. Given the fact that the GDPR does not define these terms, the concept must be understood through its wording and objectives pursued . The court stated that Article 12(5) GDPR does not rule out the possibility that a first request may be considered excessive. This is because the repetitive character referred to in this article is an example, meaning “excessive” is not necessarily limited to the number of requests. However, this must be interpreted strictly; therefore, the controller may only rely on this in exceptional cases, and the controller bears the burden of demonstrating the excessive nature of the request. In terms of circumstances, the court noted that proof of an abusive practice must meet objective and subjective requirements. The court noted that the data subject’s access request met the formal requirements, as the data subject exercised the right to access to be aware of the processing and verify its lawfulness in accordance with the aim of Article 15 GDPR. The subjective element, on the other hand, concerns the intention of the data subject; in this case the controller must unequivocally demonstrate that the data subject has made the request for a purpose other than being aware of the processing and verifying its lawfulness (such as artificially creating conditions to obtain compensation). The court stated that it is necessary to take into consideration all the circumstances of the case, including the fact that the data subject provided the data voluntarily, or the time elapsed between providing the data and requesting access. The court noted that the controller may use publicly available information, provided that it is supported by other material. The court concluded that it was for the referring court to determine whether the controller demonstrated that the data subject made the access request with abusive intentions. Does Article 82(1) confer the right to compensation for damages resulting from an infringement of the right to access? (questions 5 and 6) — The court first noted that under Article 82(1) GDPR data subjects that have suffered (non)material damages as a result of an infringement of the GDPR are entitled to compensation. Since the Article does not refer to “processing”, the right to compensation is not limited to damage resulting from the processing of personal data. In this case, an infringement is liable for damages from the refusal to act, rather than from the actual processing of personal data as such. The court also noted that the right of access would be significantly weakened if Article 82(1) GDPR was limited solely to unlawful acts involving data processing. In light of the answer to these questions, the court saw no need to answer question 4. Does non-material damage for data subjects include loss of control or uncertainty over how their data is processed? (question 8) — The court noted that the GDPR does not define “(non)material damages” or “compensation for damages suffered”. Therefore, they must be considered autonomous concepts of EU law, and interpreted in a uniform manner . The court referred to previous case law, and highlighted the fact that “non material damage” cannot be limited by the degree of seriousness. However, an infringement on its own does not give data subjects the right to compensation, as it is one of the three conditions that must be met cumulatively. Therefore, the data subject must also establish that the infringement caused them harm, and that there is a causal link between the damage and the infringement. This applies to loss of control, as well as data subjects’ fears regarding the misuse of their data. Finally, the court stated that the causal link may be broken by the behaviour of the data subject; this means a data subject may not receive compensation for damages when the loss of control or fears over misuse of data were caused by the data subject submitting this data to the controller with the aim of artificially creating conditions to obtain compensation).

GDPRhub

How it connects

16 of 16 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 16 paragraphs

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

Facts — On 16 March 2023, the data subject (a private individual living in Vienna) subscribed to the ‘newsletter’ on the website of the controller (a family run optician company established in North Rhine-Westphalia) by entering his personal data in the registration form, confirming his consent to data processing by ticking a box and submitting the form. On 29 March 2023, the data subject sent by fax an information request pursuant to Article 15 GDPR. The controller acknowledged receipt of the request and stated that it would respond to it within the one-month period. However, by letter of 26 April 2023, the controller refused to provide the information since it classified the information request as an abuse of right for the purposes of the second sentence of Article 12(5)(b) GDPR. The controller sought a declaration from the referring court that the data subject is not entitled to compensation in the amount of €1000.

§

The court decided to refer the following questions set out in point I. to the CJEU for a preliminary ruling pursuant to Article 267 TFEU: Is the second sentence of Article 12(5) GDPR to be interpreted as meaning there cannot be an excessive information request from the data subject when the first request is made to the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that the controller can refuse an information request from the data subject if the data subject intends to use the information request to provoke claims for damages against the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that grounds for refusing to provide information can be provided by publicly available information about the data subject which suggests that the data subject is asserting claims for damages against the controller in a large number of cases of infringement of the law relating to the protection of personal data?

§

Is Article 4(2) GDPR to be interpreted as meaning that an information request from a data subject to the controller pursuant to Article 15(1) GDPR and/or a response to that request constitutes processing within the meaning of Article 4(2) GDPR? In view of the first sentence of recital 146 GDPR, is Article 82(1) GDPR to be interpreted as meaning that only damage which the data subject suffers or has suffered as a result of processing is eligible for compensation? Does this mean that for there to be a claim for damages under Article 82(1) GDPR – assuming causal damage to the data subject exists – there must necessarily have been processing of the data subject’s personal data? If the answer to Question 5 is in the affirmative: Does this mean that the data subject – assuming causal damage exists – has no claim for compensation under Article 82(1) GDPR solely on the basis of an infringement of his or her right to information under Article 15(1) GDPR?

§

Is Article 82(1) GDPR to be interpreted as meaning that the controller’s objection relating to an abuse of right in relation to an information request from the data subject cannot, in view of EU law, consist in the fact that the data subject brought about processing of his or her personal data solely or inter alia in order to assert claims for damages? If the answers to Questions 5 and 6 are in the negative: Does the mere loss of control and/or uncertainty about the processing of the data subject’s personal data associated with an infringement of Article 15(1) GDPR constitute non-material damage to the data subject within the meaning of Article 82(1) GDPR or does it also require a further (objective or subjective) restriction and/or (significant) damage to the data subject? Advocate General Opinion — In addressing the first, second, third, and seventh questions referred by the national court: — The excessive character of an initial access request Advocate General emphasized that while an initial access request can, in theory, be considered "excessive," this must be limited to exceptional circumstances since the right of access is fundamental and linked to other GDPR rights.

§

The circumstances that allow a request to be characterized as ‘excessive’ The Advocate General analyzed when a data access request under Article 15 GDPR could be considered excessive under Article 12(5) GDPR . He concluded that such a request may only be treated as excessive if the controller can demonstrate an abusive intention. However, merely having a pattern of making similar claims in many cases does not, on its own, prove abuse, and strict criteria must be applied to ensure that the fundamental right of access is not unduly restricted. In addressing the the fourth, fifth and sixth questions referred by the national court : — The event giving rise to the damage within the meaning of Article 82 of the GDPR The Advocate General analyzed whether only data processing that violates the GDPR can give rise to compensation under Article 82 GDPR. He concluded that not just unlawful processing, but any infringement of the GDPR can be a basis for compensation, provided that damage and a causal link are proven.

§

The concept of ‘processing’ for the purposes of the right to compensation The Advocate General explains that although sending an access request is not "processing" under the GDPR, a controller’s act of responding to such personal data , which can fall under the scope of the GDPR. However, the actual damage arises not from this technical processing, but from the unjustified refusal to fulfill the access request. To ensure the effectiveness of Article 15 GDPR and the right to compensation under Article 82, the concept of “processing that caused the damage” should be interpreted broadly. The existence of non-material damage The Advocate General clarifies that a violation of Article 15 GDPR alone does not automatically entitle a data subject to compensation; the individual must prove actual non-material harm resulting from the infringement. The Court has recognized that even temporary loss of control over personal data may qualify as non-material damage, without requiring a minimum severity threshold.

§

Conclusion — In the Advocate General’s view, an initial access request under Article 15 GDPR can only be considered “excessive” where the data controller can clearly demonstrate, based on all relevant circumstances, that the data subject acted with abusive intent, specifically, where the individual consented to the processing of their personal data solely to submit an access request and subsequently claim compensation. Importantly, the mere fact that a data subject has frequently exercised their right to compensation in similar cases does not, in itself, justify classifying the request as excessive. Moreover, under Article 82(1) GDPR, a data subject is entitled to compensation for damage resulting from a violation of the Regulation, even if that damage was not directly caused by the processing of personal data. Holding — Is a first access request excessive in accordance with Article 12(5) GDPR, and under what circumstances is it possible to establish such an excessive nature?

§

(Questions 1, 2, 3 and 7) — The court first noted that the GDPR guarantees the right to access in Article 15(1) GDPR. However, Article 12(5) GDPR allows the controller to charge a reasonable fee or refuse the request if it is “manifestly unfounded or excessive”. Given the fact that the GDPR does not define these terms, the concept must be understood through its wording and objectives pursued . The court stated that Article 12(5) GDPR does not rule out the possibility that a first request may be considered excessive. This is because the repetitive character referred to in this article is an example, meaning “excessive” is not necessarily limited to the number of requests. However, this must be interpreted strictly; therefore, the controller may only rely on this in exceptional cases, and the controller bears the burden of demonstrating the excessive nature of the request. In terms of circumstances, the court noted that proof of an abusive practice must meet objective and subjective requirements.

§

The court noted that the data subject’s access request met the formal requirements, as the data subject exercised the right to access to be aware of the processing and verify its lawfulness in accordance with the aim of Article 15 GDPR. The subjective element, on the other hand, concerns the intention of the data subject; in this case the controller must unequivocally demonstrate that the data subject has made the request for a purpose other than being aware of the processing and verifying its lawfulness (such as artificially creating conditions to obtain compensation). The court stated that it is necessary to take into consideration all the circumstances of the case, including the fact that the data subject provided the data voluntarily, or the time elapsed between providing the data and requesting access. The court noted that the controller may use publicly available information, provided that it is supported by other material.

§

The court concluded that it was for the referring court to determine whether the controller demonstrated that the data subject made the access request with abusive intentions. Does Article 82(1) confer the right to compensation for damages resulting from an infringement of the right to access? (questions 5 and 6) — The court first noted that under Article 82(1) GDPR data subjects that have suffered (non)material damages as a result of an infringement of the GDPR are entitled to compensation. Since the Article does not refer to “processing”, the right to compensation is not limited to damage resulting from the processing of personal data. In this case, an infringement is liable for damages from the refusal to act, rather than from the actual processing of personal data as such. The court also noted that the right of access would be significantly weakened if Article 82(1) GDPR was limited solely to unlawful acts involving data processing.

§

In light of the answer to these questions, the court saw no need to answer question 4. Does non-material damage for data subjects include loss of control or uncertainty over how their data is processed? (question 8) — The court noted that the GDPR does not define “(non)material damages” or “compensation for damages suffered”. Therefore, they must be considered autonomous concepts of EU law, and interpreted in a uniform manner . The court referred to previous case law, and highlighted the fact that “non material damage” cannot be limited by the degree of seriousness. However, an infringement on its own does not give data subjects the right to compensation, as it is one of the three conditions that must be met cumulatively. Therefore, the data subject must also establish that the infringement caused them harm, and that there is a causal link between the damage and the infringement. This applies to loss of control, as well as data subjects’ fears regarding the misuse of their data.

§

Finally, the court stated that the causal link may be broken by the behaviour of the data subject; this means a data subject may not receive compensation for damages when the loss of control or fears over misuse of data were caused by the data subject submitting this data to the controller with the aim of artificially creating conditions to obtain compensation). Holding — Is a first access request excessive in accordance with Article 12(5) GDPR, and under what circumstances is it possible to establish such an excessive nature? (Questions 1, 2, 3 and 7) — The court first noted that the GDPR guarantees the right to access in Article 15(1) GDPR. However, Article 12(5) GDPR allows the controller to charge a reasonable fee or refuse the request if it is “manifestly unfounded or excessive”. Given the fact that the GDPR does not define these terms, the concept must be understood through its wording and objectives pursued .

§

The court stated that Article 12(5) GDPR does not rule out the possibility that a first request may be considered excessive. This is because the repetitive character referred to in this article is an example, meaning “excessive” is not necessarily limited to the number of requests. However, this must be interpreted strictly; therefore, the controller may only rely on this in exceptional cases, and the controller bears the burden of demonstrating the excessive nature of the request. In terms of circumstances, the court noted that proof of an abusive practice must meet objective and subjective requirements. The court noted that the data subject’s access request met the formal requirements, as the data subject exercised the right to access to be aware of the processing and verify its lawfulness in accordance with the aim of Article 15 GDPR. The subjective element, on the other hand, concerns the intention of the data subject; in this case the controller must unequivocally demonstrate that the data subject has made the request for a purpose other than being aware of the processing and verifying its lawfulness (such as artificially creating conditions to obtain compensation).

§

The court stated that it is necessary to take into consideration all the circumstances of the case, including the fact that the data subject provided the data voluntarily, or the time elapsed between providing the data and requesting access. The court noted that the controller may use publicly available information, provided that it is supported by other material. The court concluded that it was for the referring court to determine whether the controller demonstrated that the data subject made the access request with abusive intentions. Does Article 82(1) confer the right to compensation for damages resulting from an infringement of the right to access? (questions 5 and 6) — The court first noted that under Article 82(1) GDPR data subjects that have suffered (non)material damages as a result of an infringement of the GDPR are entitled to compensation. Since the Article does not refer to “processing”, the right to compensation is not limited to damage resulting from the processing of personal data.

§

In this case, an infringement is liable for damages from the refusal to act, rather than from the actual processing of personal data as such. The court also noted that the right of access would be significantly weakened if Article 82(1) GDPR was limited solely to unlawful acts involving data processing. In light of the answer to these questions, the court saw no need to answer question 4. Does non-material damage for data subjects include loss of control or uncertainty over how their data is processed? (question 8) — The court noted that the GDPR does not define “(non)material damages” or “compensation for damages suffered”. Therefore, they must be considered autonomous concepts of EU law, and interpreted in a uniform manner . The court referred to previous case law, and highlighted the fact that “non material damage” cannot be limited by the degree of seriousness. However, an infringement on its own does not give data subjects the right to compensation, as it is one of the three conditions that must be met cumulatively.

§

Therefore, the data subject must also establish that the infringement caused them harm, and that there is a causal link between the damage and the infringement. This applies to loss of control, as well as data subjects’ fears regarding the misuse of their data. Finally, the court stated that the causal link may be broken by the behaviour of the data subject; this means a data subject may not receive compensation for damages when the loss of control or fears over misuse of data were caused by the data subject submitting this data to the controller with the aim of artificially creating conditions to obtain compensation). Comment — The case AG Arnsberg - 42 C 434/23 was decided by the referring court on 1 July 2026.