Can the right of access be abused? Lessons from case law of the Court of Justice

0

Abuse of rights is frequently invoked by controllers in the context of requests for access by data subjects under Article 15 GDPR. A particularly disputed question in practice is whether a request submitted with the ultimate purpose of gaining an advantage in legal proceedings against the controller can constitute such an abuse. Although there is already a substantial body of decisional practice from national data protection authorities on the matter, drawing a clear boundary remains challenging: at what point does a request for access cross the threshold into an abuse of rights? Which elements should be taken into account? The Court of Justice’s recent judgement in Brillen Rottler of 19 March 2026 addresses this question. In the Brillen Rottler judgement, a natural person submitted a request for access thirteen days after having subscribed to Brillen Rottler’s newsletter. Brillen Rottler rejected the request as abusive. When the data subject subsequently sought compensation under Article 82 GDPR, Brillen Rottler argued that the request formed part of a systematic and abusive pattern aimed at obtaining compensation for an alleged GDPR infringement. Subsequently, the referring court asked the Court of Justice, by way of a preliminary question, whether  a request for access can be rejected as “excessive” on the basis of Article 12(5) GDPR where the data subject appears to be using the GDPR strategically, including to prepare a damages claim.

The Brillen Rottler judgement cannot, however, be read in isolation. It must be read together with previous case law of the Court of Justice on the matter (FT judgement and Österreichische Datenschutzbehörde v FR judgement). This recent judgment offers the perfect opportunity to untangle the framework governing abuse of rights in the context of the right of access, and that is precisely the task this comment undertakes. The practical significance of this question is further demonstrated by recent legislative developments. The Digital Omnibus proposal of November 2025 explicitly incorporates the abuse of rights doctrine into Article 12(5) GDPR, providing that a request for access may be treated as «excessive» where the data subject invokes rights conferred by the GDPR for purposes other than the protection of their personal data.

  1. Abuse of rights has a role to play within data protection law

Abuse of rights as a ground for refusing a request for access finds support in recital 4 GDPR. This recital specifies that the right to the protection of personal data is not absolute, but must be balanced against other fundamental rights, freedoms, and principles recognised by the Charters and enshrined in the Treaties. Both the EU Charter of Fundamental Rights and the European Convention of Human Rights explicitly enshrine the prohibition of the abuse of rights. Moreover, it is a general legal principle that EU law cannot be relied upon for abusive ends.

  1. Any exceptions to the right of access must be interpreted restrictively

It should be kept in mind that any limitations to the right of access must be interpreted restrictively. Within the structure of the GDPR, the right of access constitutes a core provision and serves as the entry point to other rights under the GDPR. With the information and/or a copy of their personal data obtained through such a request, data subjects can, where necessary, exercise their other rights under the GDPR. Therefore, it may be clear that an abuse of rights may only be established in highly specific circumstances.

  1. The mere existence of another purpose unrelated to data protection is insufficient to reject a request for access

In the FT judgement, the Court of Justice addressed the question whether the data subject may receive a copy of his personal data where the request is not related to the purposes of recital 63 GDPR, namely to become aware of the processing and to verify the lawfulness of that processing, but instead pursues a different purpose unrelated to data protection. In this case, the data subject wanted to verify the existence of claims under medical liability law. The Court recalled that neither Article 15 nor Article 12 GDPR requires a data subject to state a reason when exercising the right of access (para 38). Accordingly, recital 63 GDPR cannot be interpreted as requiring a request to be rejected merely because it pursues a purpose other than verifying the lawfulness of the processing (para 51). The mere existence of another purpose is therefore insufficient to reject the request, even where the data subject might use this information in legal proceedings against the controller.

Interestingly, the Court of Justice refers in this judgement to «manifestly unfounded» and «excessive» requests under Article 12(5) GDPR as examples of abuse of rights (para 31). However, the Court also noted that, in the present case, the referring court had expressly stated that the request for access at issue was not abusive (para 32).

Taking into account the above, it is clear that the mere pursuit of another purpose unrelated to data protection is insufficient to reject a request for access. So, at what point does a request for access cross the threshold into an abuse of rights?

  1. The controller should have an abusive intention

We believe that the purpose behind the request for access is not entirely irrelevant, but must instead be assessed through the lens of the doctrine of abuse of rights. In the context of abuse of rights, both an objective and a subjective element must be established.

As regards the objective element, it must be assessed whether, despite formal compliance with the conditions laid down by the relevant rules, the purpose of those rules has not been achieved in light of the objective circumstances of the case. In the context of the right of access, the exercise of that right will often formally correspond with its intended purpose, namely enabling the data subject to become aware of the processing of personal data and to verify the lawfulness of that processing. This was likewise the case in the Brillen Rottler judgement, where the data subject’s personal data were processed for newsletter purposes and a request for access was submitted in relation to that processing (para 38). However, the fact that the objective element is not satisfied, does not necessarily preclude a finding of abuse based on the subjective element (para 39).

The more contested issue concerns indeed the subjective element. In this respect, it must be assessed whether the data subject intends to obtain an advantage from the rules by artificially creating the conditions laid down for obtaining it. In the context of the right of access, the Court of Justice held in the Brillen Rottler judgement that the controller must demonstrate that the data subject exercised the right of access, not for the purpose of becoming aware of the processing of personal data, but rather with the purpose of artificially creating the conditions necessary to claim compensation from the controller (para 40). The assessment must take into account all the circumstances of the case. Relevant factors that were considered in the Brillen Rottler judgement were whether the data subject voluntarily provided personal data despite not being required to do so, the purpose for which those data were provided, the period between the provision of the data and the request for access, and the overall conduct of the data subject (para 42). The Court further clarified that account may also be taken of publicly available information indicating that the individual systematically submits requests for access and compensation claims against various controllers according to a recurring pattern (para 43).

Likewise, in the Österreichische Datenschutzbehörde v FR judgement, which concerned the lodging of multiple complaints by a data subject to a national data protection authority, the Court of Justice considered the existence of an abusive intention to be decisive (para 55). In this case, the Court held that such an abusive intention may be established when the number of requests cannot be explained by the intention to obtain protection of his rights under the GDPR, but instead indicates the pursuit of another objective unrelated to the protection of those rights, such as interfering with the proper functioning of the supervisory authority by taking up its resources (para 56). The assessment must take into account all the circumstances of the case. Relevant factors that were considered in the Österreichische Datenschutzbehörde v FR judgement were the number of complaints lodged against different controllers with whom the data subject had no apparent connection and the content of those complaints (para 57).

  1. Conclusion

Abuse of rights as a ground for refusing a request for access finds support in recital 4 GDPR, as the right to the protection of personal data must be balanced against other fundamental rights, freedoms, and principles. That said, any exceptions to the right of access must be interpreted restrictively. As a result, abuse of rights may only be established in highly specific circumstances. Furthermore, the mere existence of another purpose unrelated to data protection is insufficient to reject a request for access. However, the underlying purpose of the request is not entirely irrelevant. A request for access may be regarded as «excessive» where an abusive intention is demonstrated, in particular where the request is not made to verify the lawfulness of processing, but to artificially create the conditions for obtaining an advantage from the rules. In practice, it may be clear that this requires a careful assessment of all relevant circumstances, since the threshold for establishing such intent is high.

Consider, for example, the scenario where a data subject submits a request for access with the ultimate purpose of using the obtained information in legal proceedings against the controller. Where the data subject has not themselves created the conditions giving rise to the processing, for example, where they did not actively cause their personal data to be processed, and where it can also be shown that they have an interest in verifying the lawfulness of their data, it will be difficult to establish an abusive intention, even if those data may subsequently be relied upon in separate proceedings. This difficulty is reinforced by the fact that, under the GDPR, the burden of demonstrating that a request is «excessive» lies with the controller. A cautious approach is therefore recommended.

It remains to be seen which direction the Court of Justice case law will take on this matter, and how the proposed specification of abuse of rights as an example of an «excessive» request under Article 12(5) GDPR, as envisaged in the Digital Omnibus revisions, will be interpreted if the proposal is adopted.

Share this article!

About Author

Julie Mannekens

Legal researcher, Centre for IT & IP law (KU Leuven)

Leave A Reply