Brillen Rottler: High Bar for DSAR Abuse and Compensation
Navigating the Labyrinth of Data Rights and Compensation
In the ever-evolving landscape of digital privacy, the General Data Protection Regulation (GDPR) stands as a formidable charter of individual rights. Central to its framework are the right of access, enshrined in Article 15, and the right to compensation, detailed in Article 82. The Data Subject Access Request (DSAR) has become a powerful tool for individuals to hold organisations accountable for how their personal data is handled. However, this empowerment has also given rise to a contentious issue: the potential for these rights to be weaponised for financial gain, a practice some have dubbed ‘GDPR ambulance chasing’. This complex intersection of legitimate rights and potential misuse was brought into sharp focus in a recent opinion from Advocate General Maciej Szpunar, which offers crucial guidance for businesses navigating these treacherous waters.
The opinion, delivered on 12 September 2025 in Case C-526/24, colloquially known as the Brillen Rottler case, delves into the delicate balance between a data subject’s fundamental right to access their information and a data controller’s right to defend against abusive or excessive requests. More than just a procedural clarification, the Advocate General’s analysis provides a profound legal evaluation of liability and compensation under Article 82 of the GDPR, promising to shape how courts across the European Union interpret claims for damages. For organisations, this opinion is not merely an academic exercise; it is a vital piece of the puzzle in understanding when they can legitimately refuse a DSAR and what constitutes a legitimate claim that a professional can assess for compensation, potentially stemming the tide of serial, profit-motivated requests.
The Case in Question: A German Optician and a Prolific Claimant
The factual matrix of the Brillen Rottler case is deceptively simple, yet it encapsulates the core of the problem. An Austrian individual, identified as TC, subscribed to the online newsletter of Brillen Rottler, a family-operated chain of opticians based in Germany. A mere thirteen days after subscribing, TC submitted a comprehensive DSAR under Article 15, demanding to know what data the company held on him. Brillen Rottler, however, took the unusual step of refusing the request. Their justification was not based on a technical inability to comply but on the character and alleged motives of the requester.
The company contended that TC was not making a genuine inquiry to exercise his data protection rights. Instead, they argued, he was a serial claimant, systematically and deliberately provoking GDPR infringements with the sole objective of claiming compensation. To support this assertion, Brillen Rottler pointed to a body of publicly available information, including various online reports and blog posts from legal professionals, which identified TC as an individual who had initiated numerous similar actions against other companies. They argued that TC’s request was an abuse of rights, designed from the outset to create a cause of action for a financial claim.
TC, in turn, brought the matter before the District Court of Arnsberg in Germany, seeking €1,000 in compensation for the refusal. He argued that his right of access was fundamental and could be exercised unconditionally, without his motives being called into question. The German court found itself at a crossroads. It acknowledged that limiting a fundamental right, particularly for an initial request, should only be permissible in truly exceptional circumstances. The court was not convinced that TC’s subsequent intention to seek compensation was, in itself, sufficient grounds to label his request an abuse. Furthermore, the court expressed concern that allowing controllers to rely on public reports about a data subject’s litigation history could lead to controllers abusing this exception to deny legitimate requests. Faced with these profound questions of EU law, the Arnsberg court referred the matter to the Court of Justice of the European Union (CJEU) for a preliminary ruling, setting the stage for the Advocate General’s influential opinion.
The Advocate General’s Nuanced Opinion
Advocate General Szpunar’s opinion navigates this complex issue with careful precision, seeking to uphold the fundamental nature of the right of access while acknowledging that this right is not absolute. He agreed with the referring German court that an initial DSAR could, in principle, be considered an abuse of rights, but only under a very strict and high threshold of proof.
Decoding ‘Abuse of Rights’ and the ‘Excessive’ Request
The AG’s analysis centred on Article 12(5) of the GDPR, which permits a controller to refuse to act on requests that are ‘manifestly unfounded or excessive’. While repeated, voluminous requests are the classic example of ‘excessive’, the AG explored whether a single, initial request could ever meet this definition. He concluded that it could, but the burden of proof lies squarely and heavily on the data controller.
Drawing on previous CJEU jurisprudence, the AG reiterated that while a data subject never needs to provide a reason for their DSAR, their underlying intention is not entirely precluded from judicial scrutiny. He proposed a crucial test: a controller must be able to objectively demonstrate an abusive intention on the part of the data subject. Crucially, this intention must be judged in light of all relevant circumstances of the specific case. The AG provided a stark example of what could constitute such an abusive intention: a situation where an individual has consented to the processing of their personal data for the specific, premeditated purpose of provoking an infringement to then be able to submit a DSAR and subsequently claim compensation. This moves beyond a mere suspicion of motive into a demonstrable strategy to entrap a controller.
However, the AG was equally clear about what does *not* meet this high bar. He explicitly stated that a controller cannot simply rely on publicly available information indicating that a data subject has made similar requests or claimed compensation against other controllers in a large number of cases. This, in itself, is insufficient to classify a new request to a different controller as ‘excessive’ or abusive. Each request must be assessed on its own merits. This distinction is vital; it protects the rights of individuals who may have legitimate reasons to query multiple organisations (for instance, data privacy advocates or individuals systematically cleaning up their digital footprint) from being unfairly blacklisted. Any refusal must be justified, proportionate, and meticulously documented by the controller.
The Broad Reach of Article 82 Compensation
The second major pillar of the AG’s opinion concerned the scope of compensation for non-material damage under Article 82 of the GDPR. Brillen Rottler’s defence implied that compensation should only be available for damage caused by unlawful *data processing* activities, such as a data breach or unauthorised use of data. The AG firmly rejected this narrow interpretation.
He argued that such a restrictive reading would undermine the GDPR’s core objective of strengthening and clarifying the rights of data subjects. If the EU legislature had intended to limit compensation solely to processing-related infringements, it would have used more precise and restrictive language in the text of Article 82. Instead, the AG proposed a more expansive view. He posited that Article 82(2), which specifically mentions liability for damage caused by ‘processing’, should be read as a supplement to the broader principle established in Article 82(1), which refers to damage resulting from an ‘infringement of this Regulation’.
Therefore, the AG concluded that a right to compensation can arise from *any* infringement of the GDPR, provided that the claimant can demonstrate they have suffered damage as a result. This means that procedural failures, such as an unjustified refusal to respond to a DSAR, can themselves form the basis of a valid compensation claim, even if no unlawful data processing has occurred. This clarifies that the harm is not just in the misuse of data, but also in the frustration of a data subject’s fundamental rights.
In doing so, the AG also reaffirmed the principles established in the landmark *Österreichische Post* case. He stressed that three conditions must be met for a successful claim under Article 82: (i) there must be an infringement of the GDPR; (ii) the individual must have suffered material or non-material damage; and (iii) there must be a direct causal link between the infringement and the damage. The burden of proving this causal link rests with the claimant. Importantly, the opinion also restates that there is no *de minimis* threshold; even a minor level of damage or distress can be compensable, though the infringement alone is not sufficient to automatically trigger compensation.
Practical Implications for Data Controllers
While the final judgment from the CJEU is yet to be delivered, Advocate General opinions are highly persuasive and often followed by the Court. If the CJEU adopts this reasoning, it will represent a significant, albeit double-edged, development for businesses. On one hand, it provides a welcome confirmation that the right of access is not a blank cheque for vexatious claimants. On the other, it broadens the scope of infringements that can lead to compensation claims.
Organisations must therefore refine their DSAR handling procedures with these nuances in mind. The key takeaway is that refusing a DSAR on grounds of abuse is a high-risk strategy that should only be contemplated in the most exceptional and well-documented cases. Businesses seeking to rely on the ‘excessive’ nature of a request must be prepared to present objective, compelling evidence of the data subject’s abusive intent, going far beyond pointing to their litigation history. This might include evidence of a coordinated campaign or direct communications revealing an ulterior motive.
Furthermore, the opinion serves as a stark reminder that procedural compliance is paramount. An unjustified or poorly documented refusal to respond to a DSAR is not a neutral act; it is an infringement of the GDPR in its own right. This infringement can directly cause non-material damage (such as frustration, anxiety, and a sense of loss of control) and thus form the basis of a successful compensation claim. Therefore, the internal process for assessing and responding to DSARs must be robust, timely, and transparent. Any decision to refuse a request must be carefully reasoned, legally sound, and recorded in detail, demonstrating a proportionate consideration of the data subject’s fundamental rights against the evidence of abuse.
The Path Ahead: Awaiting the CJEU’s Final Word
The Advocate General’s opinion in the Brillen Rottler case provides a sophisticated framework for analysing the tension at the heart of the GDPR’s access rights. It champions the protection of fundamental rights while simultaneously acknowledging that these rights can be exploited. It seeks to prevent the system from being clogged by bad-faith actors while ensuring that legitimate claimants are not unfairly dismissed. For businesses, the message is clear: the bar for proving abuse is exceptionally high, and procedural rigour is non-negotiable. The forthcoming CJEU judgment is now one of the most anticipated decisions in data protection law. It will provide the definitive ruling that could either arm businesses with a clearer defence against serial claimants or further underscore the immense power vested in the hands of the data subject, shaping the contours of data privacy litigation for years to come.
Free Claim Assessment
Find out if you have a valid claim — free, no obligation.
Start Free Assessment