Authored By: Giftson J.S.
Government Law College, Theni ( affiliated to Tamil Nadu Dr. Amnedkar Law University)
CASE CITATION AND BASIC INFORMATION
Case Name: Brillen Rottler GmbH & Co. KG v TC
Citation: Case C‑526/24, EU:C:2026:000 (provisional text)
Court: Court of Justice of the European Union (hereinafter “the CJEU” or “the Court”), Fourth Chamber (on a reference for a preliminary ruling under Article 267 of the Treaty on the Functioning of the European Union (hereinafter “the TFEU”) from the Amtsgericht Arnsberg (Local Court, Arnsberg, Germany), decision of 31 July 2024)
Date of Decision: 19 March 2026
Judges/Bench Composition:
I. Jarukaitis, President of the Chamber
K. Lenaerts, President of the Court, acting as Judge of the Fourth Chamber
M. Condinanzi, Judge
N. Jääskinen, Judge
R. Frendo, Judge-Rapporteur
M. Szpunar, Advocate General
INTRODUCTION:
This preliminary reference concerns the boundaries of two of the most frequently litigated provisions of the General Data Protection Regulation (hereinafter “the GDPR”): firstly, the controller’s limited right to refuse a data-subject access request as “manifestly unfounded or excessive” under Article 12(5), and the data subject’s right to compensation for non-material damage under Article 82(1). This particular case is significant because it addresses, for the first time at the level of a first request for access, whether the absence of a prior pattern of repeated requests precludes a finding of abuse, and because it clarifies that Article 82(1) is not confined to damage flowing from “processing” in the narrow, technical sense of Article 4(2) GDPR. The judgment therefore sits at the intersection of two competing policy concerns that pervade European Union (hereinafter “the EU”) data-protection law: safeguarding the practical effectiveness of data-subject rights, and preventing those same rights from being weaponised for purely pecuniary ends.
FACTS OF THE CASE
TC[2], a natural person resident in Austria, subscribed in March 2023 to the newsletter of Brillen Rottler GmbH & Co. KG, a small family-run optician established in Arnsberg, Germany, by submitting his personal data through the registration form on the company’s website and consenting to processing. Thirteen days later, TC submitted a request for access to his personal data under Article 15 GDPR.
Brillen Rottler refused the request within the one-month statutory period, characterising it as abusive within the meaning of the second sentence of the first subparagraph of Article 12(5) GDPR, and called on TC to withdraw it. TC maintained the request and added a claim for EUR 1,000 in compensation under Article 82 GDPR. Brillen Rottler then brought a negative declaratory action before the Amtsgericht Arnsberg, seeking a declaration that TC was not entitled to compensation.
Brillen Rottler relied on publicly available reports, blog posts, and legal newsletters suggesting that TC systematically subscribes to newsletters, requests access, and subsequently claims compensation which is a recurring modus operandi allegedly repeated across multiple controllers. TC denied any abusive intent and counterclaimed for the EUR 1,000 in non-material damages, arguing that the refusal itself infringed his right of access.
LEGAL ISSUES
- Whether a data subject’s first request for access under Article 15 GDPR, made without any earlier such request, can ever be classified as “excessive” within the meaning of Article 12(5) GDPR?
- If so, what circumstances, including publicly available information about the data subject’s litigation pattern with other controllers, may be relied upon by a controller to establish that excessive character?
- Whether a request for access, and or the controller’s response to it, constitutes “processing” within the meaning of Article 4(2) GDPR?
- Whether Article 82(1) GDPR confers a right to compensation only for damage resulting from “processing,” or also for damage flowing from infringement of the right of access under Article 15(1) as such?
- Whether mere loss of control over, or uncertainty about, one’s personal data, following an infringement of Article 15(1), amounts to compensable damage that is not material within the meaning of Article 82(1), and whether it requires any further, more tangible detriment?
ARGUMENTS PRESENTED
Brillen Rottler’s (Controller’s) Arguments
Brillen Rottler submitted that TC’s conduct followed a discernible and repeated three step pattern: [i] subscribing to a newsletter, [ii] immediately requesting access, and then [iii] claiming compensation once access was refused or delayed. It argued that this pattern, evidenced by publicly available commentary describing TC’s practices toward other controllers, demonstrated an abusive intention to manufacture a cause of action rather than a genuine wish to verify the lawfulness of processing, and therefore justified refusal under Article 12(5)(b) GDPR, even though the request was, formally, TC’s first request addressed to that particular controller.
TC’s (Data Subject’s) Arguments
TC contended that his request was a legitimate and formally compliant exercise of the right of access guaranteed by Article 15 GDPR, made shortly after providing his data, and that Brillen Rottler was attempting an unlawful restriction of a fundamental data protection right by inferring abuse from conduct concerning unrelated controllers. He further argued that the unjustified refusal itself caused him damage that was not material in nature, in the form of loss of control over, and uncertainty as to, the processing of his data, for which he was entitled to compensation under Article 82(1) GDPR regardless of whether any “processing” as such had occurred.
COURT’S REASONING AND ANALYSIS
Reasoning on Article 12(5): Excessiveness of a First Request
The Court began from the ordinary meaning of “excessive,” holding that it denotes a qualitative as much as a quantitative excess, and therefore does not, on its wording alone, exclude a first request from ever being excessive.[3] While the “repetitive character” language in Article 12(5) shows that a pattern of requests is a paradigm example of excess, the Court emphasised that this is only illustrative, not an exhaustive precondition.[4]
Situating the provision within Chapter III of the GDPR, the Court characterised Article 12(5) as a narrowly construed exception to the data controller’s general duty to facilitate data subject rights, itself an expression of the general principle of EU law that rights conferred by Union law cannot be invoked for abusive or fraudulent ends.[5]
Applying the classic two limbed test for abuse of rights, an objective element (formal compliance with the rule, while its purpose is defeated) and a subjective element (intention to secure an advantage by artificially engineering the conditions for it),[6] the Court held that the number of prior requests is not, by itself, determinative.[7] A controller may therefore refuse even a first request where it demonstrates, from the totality of the circumstances, an abusive intention. However, because Article 12(5) is a restrictively construed derogation and the burden of proof lies on the controller, such a finding must remain exceptional.[8] Publicly available material evidencing a data subject’s broader pattern toward other controllers may be taken into account, but only as corroborative evidence alongside other indicators, and cannot alone discharge the controller’s burden.[9]
Reasoning on the “Processing” Question
The referring court had also asked whether a request for access under Article 15(1), and/or the controller’s response to it, constitutes “processing” within the meaning of Article 4(2) GDPR.[10] The Court declined to give answer to this question, having resolved the compensation questions (discussed below) on an independent basis that did not require characterising the request or response as “processing.” The fourth question was thus rendered moot.[11]
Reasoning on Article 82(1): Scope of Compensable Damage
The Court engaged in a textual, contextual, and teleological analysis of Article 82(1). Textually, the provision refers to damage suffered “as a result of an infringement of this Regulation,” with no express tether to “processing.”[12] Contextually, Article 82 sits within Chapter VIII, which operationalises judicial remedies for all rights under the Regulation, including the rights to information and access under Articles 12 and 15; reading recital 146’s narrower “as a result of processing” language as limiting Article 82(1) would strip that remedy of effectiveness precisely where no processing as such occurs, as in a refusal to act on a request.[13]Teleologically, Article 82(1) reinforces the rights strengthened by the Regulation, and confining it to processing based harm would weaken the right of access.[14]
The Court drew support from Bundesrepublik Deutschland (Court electronic mailbox), C‑60/22, where infringements of Articles 26 and 30 GDPR, likewise not constituting unlawful processing, were nonetheless held remediable through Article 82.[15]
On the nature of compensable damage that is not material in character, the Court reaffirmed the three cumulative conditions established in Österreichische Post, C‑300/21: infringement, damage actually suffered, and a causal link, with no de minimis threshold permitted under national law.[16] It confirmed, following Agentsia po vpisvaniyata, C‑200/23, that mere loss of control over personal data ipso facto, without any concrete misuse, can constitute such damage, and extended this logic to uncertainty as to whether one’s data have been processed following an Article 15(1) infringement.[17] Critically, the Court added a caveat on causation: where the data subject’s own conduct, for instance deliberately supplying data with a view to artificially generating a claim, is the determining cause of the alleged loss of control or uncertainty, the causal chain between the infringement and the damage is broken, and no compensation is due.[18]
JUDGMENT AND RATIO DECIDENDI
The Court ruled, first, that a first request for access may be classified as “excessive” under Article 12(5) GDPR where the controller demonstrates, from all the relevant circumstances, that the request was made not to verify the lawfulness of processing but with an abusive intention to artificially create the conditions for an advantage under the Regulation. Publicly available evidence of a broader pattern of requests followed by compensation claims against other controllers may support, but cannot alone establish, such a finding.[19]
Second, Article 82(1) GDPR confers a right to compensation for damage resulting from infringement of the right of access under Article 15(1), independently of whether the infringement involved “processing” as such.[20]
Third, damage that is not material in character under Article 82(1) encompasses loss of control over personal data or uncertainty as to whether it has been processed, provided the data subject demonstrates actual damage, however minimal, and that the infringement, rather than the data subject’s own conduct, was the determining cause of that damage.[21]
The ratio decidendi is thus twofold: first, excessiveness under Article 12(5) is an intention-based test for abuse of rights, not conditioned on repetition; and second, Article 82(1) liability extends to infringements of rights beyond processing in the strict sense, subject always to genuine, causally linked, and not self inflicted harm.[22]
CRITICAL ANALYSIS
Significance of the Decision
This judgment closes two gaps in the law. The first gap follows from Österreichische Datenschutzbehörde (Excessive requests), C‑416/23, which had already held that even a first complaint to a supervisory authority can be excessive under Article 57(4).[23] This case extends that same logic to Article 12(5), applying it directly to controllers rather than supervisory authorities. Without this extension, a data subject could simply target a new controller each time and always claim a “first” request, avoiding any finding of abuse. The second gap concerns Article 82(1). By confirming that compensation is not limited to harm arising from “processing,” the Court ensures that refusals of access, rectification, or erasure remain remediable in damages, even where no processing as such takes place.[24]
Implications and Impact
For controllers, particularly small businesses without compliance teams, this ruling provides a real but narrow defence against so‑called “GDPR trolling.” However, the burden remains demanding: a controller must prove the data subject’s actual intent to abuse the right, not merely point to statistics or a pattern of behaviour.[25]For data subjects, the ruling strengthens the practical value of the right of access, since compensation is no longer confined to processing based harm. This fits the Court’s consistent trend, seen since Österreichische Post, of reading “damage” broadly under the GDPR.[26] The Court’s causation rule is a useful addition: it stops claimants from creating their own harm, for instance by supplying data purely to generate a compensation claim, and then seeking damages for that self created harm. This brings GDPR compensation law in line with general EU principles that deny recovery for self inflicted loss.[27]
Critical Evaluation
The Court’s reasoning is sound and fits well with earlier rulings, but it leaves real uncertainty for future cases. The judgment does not say what evidence is enough to prove abusive intent on a first request. Instead, it offers a broad, multi factor test that national courts must apply on a case by case basis. This risks inconsistent outcomes across Member States, which runs against the GDPR’s own goal of uniform application, as stated in recitals 10 and 11.[28]The Court also treats publicly available information, such as blog posts or press reports, as merely supporting evidence, without saying how much weight it should carry. This is likely to trigger further disputes over whether such sources are reliable enough to use in court. Finally, the Court chose not to answer whether a request for access, or a response to it, counts as “processing” under Article 4(2). This left an important question unresolved, one that could matter well beyond this specific dispute.[29]
CONCLUSION
The Brillen Rottler case confirms that abuse of the right of access under the GDPR turns on the data subject’s intent, not repetition. A controller may refuse even a first request only where it proves the request was made to manufacture a claim, not to verify processing. Compensation under Article 82(1) similarly extends beyond processing harm to any breach of Regulation rights, including access itself, though self-inflicted harm remains non-recoverable. The decision balances a meaningful right of access against its misuse for damages claims, leaving open how much weight courts should give past conduct and what counts as “processing” under Article 4(2).
Reference(S):
Cases
Case C‑526/24 Brillen Rottler GmbH & Co. KG v TC EU:C:2026:000 (provisional text)
Case C‑416/23 Österreichische Datenschutzbehörde (Excessive requests) EU:C:2025:3
Case C‑300/21 Österreichische Post (Non-material damage in connection with the processing of personal data) EU:C:2023:370
Case C‑200/23 Agentsia po vpisvaniyata EU:C:2024:827
Case C‑60/22 Bundesrepublik Deutschland (Court electronic mailbox) EU:C:2023:373
Case C‑307/22 FT (Copies of medical records) EU:C:2023:811
Case C‑154/21 Österreichische Post (Information regarding the recipients of personal data) EU:C:2023:3
Case C‑456/22 Gemeinde Ummendorf EU:C:2023:988
Case C‑590/22 PS (Incorrect address) EU:C:2024:536
Case C‑655/23 Quirin Privatbank EU:C:2025:655
Case C‑236/23 Matmut EU:C:2024:761
Joined Cases C‑38/21, C‑47/21 and C‑232/21 BMW Bank and Others EU:C:2023:1014
Case C‑667/21 Krankenversicherung Nordrhein EU:C:2023:1022
Case C‑679/23 P WS and Others v Frontex (Joint return operation) EU:C:2025:976
Case 292/82 Merck EU:C:1983:335
Legislation
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [2016] OJ L119/1
Treaty on the Functioning of the European Union (consolidated version) [2012] OJ C326/47
Charter of Fundamental Rights of the European Union [2012] OJ C326/391
[1] Brillen Rottler GmbH & Co. KG v TC, Case C‑526/24, EU:C:2026:000.
[2] “TC” is the anonymised identifier assigned by the Court to protect the individual litigant’s identity, consistent with standard CJEU practice in cases involving natural persons.
[3] Case C‑526/24 Brillen Rottler GmbH & Co. KG v TC EU:C:2026:000, para 25, citing Case C‑416/23 Österreichische Datenschutzbehörde (Excessive requests) EU:C:2025:3, para 43.
[4] Case C‑526/24 (n 2) para 26.
[5] Case C‑526/24 (n 2) paras 28–30, citing Case C‑416/23 (n 2) para 49; Case C‑236/23 Matmut EU:C:2024:761, para 52.
[6] Case C‑526/24 (n 2) para 36, citing Joined Cases C‑38/21, C‑47/21 and C‑232/21 BMW Bank and Others EU:C:2023:1014, paras 285–286.
[7] Case C‑526/24 (n 2) para 31, citing Case C‑416/23 (n 2) para 50.
[8] Case C‑526/24 (n 2) para 35.
[9] Case C‑526/24 (n 2) para 43.
[10] Case C‑526/24 Brillen Rottler GmbH & Co. KG v TC EU:C:2026:000 (n 2), para 18.
[11] Case C‑526/24 (n 2) para 56
[12] Case C‑526/24 (n 2) para 48.
[13] Case C‑526/24 (n 2) paras 49–51, citing recital 146 GDPR.
[14] Case C‑526/24 (n 2) para 53.
[15] Case C‑526/24 (n 2) para 52, citing Case C‑60/22 Bundesrepublik Deutschland (Court electronic mailbox) EU:C:2023:373, paras 66–67
[16] Case C‑526/24 (n 2) para 59, citing Case C‑300/21 Österreichische Post (Non-material damage in connection with the processing of personal data) EU:C:2023:370, paras 31–33; Case C‑655/23 Quirin Privatbank EU:C:2025:655, para 56; Case C‑456/22 Gemeinde Ummendorf EU:C:2023:988, paras 22–23.
[17] Case C‑526/24 (n 2) paras 61, 64, citing Case C‑200/23 Agentsia po vpisvaniyata EU:C:2024:827, paras 141, 145.
[18] Case C‑526/24 (n 2) paras 65–66, citing (by analogy) Case C‑679/23 P WS and Others v Frontex (Joint return operation) EU:C:2025:976, paras 151–152.
[19] Case C‑526/24 Brillen Rottler GmbH & Co. KG v TC EU:C:2026:000 (n 2), para 45 and operative part, point 1.
[20]Case C‑526/24 (n 2) para 55 and operative part, point 2.
[21] Case C‑526/24 (n 2) para 67 and operative part, point 3.
[22] Case C‑526/24 (n 2) paras 45, 54–55, 67 (author’s synthesis of the operative part).
[23] Case C‑416/23 Österreichische Datenschutzbehörde (Excessive requests) EU:C:2025:3, paras 49–57; Case C‑526/24 Brillen Rottler GmbH & Co. KG v TC EU:C:2026:000 (n 2), paras 30–31.
[24] Case C‑526/24 (n 2) paras 48–53.
[25] Case C‑526/24 (n 2) paras 35, 40–41
[26] Case C‑300/21 Österreichische Post (Non-material damage in connection with the processing of personal data) EU:C:2023:370, paras 31–33; Case C‑526/24 (n 2) para 61.
[27] Case C‑526/24 (n 2) paras 65–66
[28] Case C‑526/24 (n 2) paras 40–43 (author’s critical assessment); recitals 10–11 GDPR.
[29] Case C‑526/24 (n 2) para 56 (author’s critical assessment).

