Increasingly, companies are being confronted with individuals who use the General Data Protection Regulation (GDPR) solely to claim lucrative damages. The Court of Justice of the European Union, in a ruling dated March 19, 2026 (C-526/24) clarifies that a company may refuse a request for access to personal data on the grounds of an abuse of rights, even if it is the very first such request. This is permissible if the company can prove that the requester is making the request solely to create financial gain, and not to inform itself about the processing of its data.
The facts and legal context
In this case, an individual signed up for the newsletter of a German optical company, Eyewear Rottler, in March 2023. With this subscription, he voluntarily provided some personal data and consented to its processing. Barely 13 days later, he sent the company a request for access to his personal data under Article 15 of the GDPR.
The optician refused to grant this request, arguing that the man was guilty of misuse within the meaning of Article 12(5) of the GDPR. On this, the individual went to court and claimed damages of 1,000 euros for a violation of his data protection rights. In his defense, the optician argued that publicly accessible forums and blogs showed that this individual was systematically, and abusively, requesting newsletters in order to immediately thereafter demand access and damages from all kinds of companies.
The Court's decision
The ECJ had to rule on the limits of the GDPR, and specifically on whether a first request can already qualify as an “excessive request”.
The Court's ruling is clear:
- An initial request may be excessive: Although the GDPR refers to requests being excessive “in particular because of their repetitive character” , the Court emphasizes that this is only an example. Consequently, even an initial request for inspection may be considered “excessive” and thus abusive.
- Intention for financial gain: Abuse occurs when the data subject does not use the right of access to verify the lawfulness of the data processing, but artificially creates the situation for the sole purpose of enforcing a benefit or compensation.
- Public sources as evidence: The controller may use publicly available information - showing that the applicant has a pattern of filing claims with multiple companies - to prove intentional misuse.
Finally, the Court stated that the unlawful refusal of a request for access can itself constitute immaterial damage (due to loss of control). However, if the plaintiff's conduct (knowingly provoking the breach) is the overriding cause of that injury, the right to compensation under Article 82 GDPR is forfeited.
Legal analysis and interpretation
This ruling firmly anchors the application of the general Union law principle on abuse of rights within the private enforcement of the GDPR
Attorney General Szpunar, in his conclusion already noted that the right to protection of personal data is not an absolute right, but must be tested against proportionality. The GDPR aims to protect the fundamental rights of natural persons, but this objective is perversely ulcerated when individuals use the regulation as a ‘business model.
Legally-technically, the Court expressly places the burden of proof on the data controller (in accordance with Art. 12(5) GDPR). To successfully invoke abuse, one must meet a rigorous two-step test:
- An objective element: The circumstances indicate that the actual purpose of the legislation (transparency and control ) is not being achieved in practice.
- A subjective element: The applicant had the effective intention of obtaining an undue advantage by invoking the rules.
The qualification of damages (Art. 82 GDPR) is also interesting. Whereas traditionally it was assumed that there must be unlawful processing, the Court states that mere frustration of the right of access can constitute a ground for compensation. However, the causality chain is broken when the applicant deliberately triggers the damage himself.
What this specifically means
For companies, SMEs and Data Protection Officers (DPOs), this ruling represents an essential relief in the fight against so-called ‘privacy trolls. The legal system now offers a solid handle to defend against orchestrated campaigns that are purely out for a quick financial settlement.
Points of interest for practice:
- No general rejection: A request should never be rejected lightly. Rejection always requires a thorough case-by-case assessment.
- File building is crucial: Because the burden of proof is on your company, you must objectively substantiate the abuse. Document the timing of the notification versus the request and (where possible) gather public information about the requester's actions.
- Review procedures: Check if your internal privacy protocols include guidelines for detecting excessive or fraudulent requests.
Frequently asked questions (FAQ)
Can a company refuse my initial request for access to personal data?
Yes, a company can also refuse an initial access request if it can prove that you are abusing your right. This is the case, for example, if you make the request solely to artificially create the conditions for claiming damages.
May a company use online forums to prove that I am abusing the GDPR?
Yes. The Court of Justice has ruled that publicly available information showing that a person makes systematic claims for damages from various companies in a large number of instances may be used as evidence to prove the abusive nature of an application.
Am I always entitled to compensation if a company refuses my access request?
No. To be entitled to compensation, you must have actually suffered demonstrable damage and there must be a causal connection. If your own conduct (for example, deliberately provoking the error) is the overriding cause of your loss of control over the data, you are not entitled to compensation.
Conclusion
European case law is clear: data protection is a fundamental right, but it must not become a business model through abuse of the law. This recent ruling gives entrepreneurs in Belgium the necessary legal certainty to ward off fraudulent or orchestrated requests, provided this abuse can be accurately proven.



