Right of Access under Article 15 of the GDPR: When Does a Legitimate Right Become an Abuse of Rights?

  • Author: Arno Schlösser, DP-Dock GmbH
  • Last updated: September 2026
  • Category: Consumer Rights, Data Security

The growing significance of the right of access in day-to-day data protection practice is also reflected in emerging case law. Courts are increasingly dealing with questions regarding the scope of the right of access, time limits and restrictions, and the handling of particularly excessive or repeated requests.

But how far does this right actually extend? And under what circumstances may a company restrict the information it provides or reject a request as excessive?

The CJEU Ruling of 19 March 2026

In March 2026, the CJEU outlined some limitations of this right. In its ruling of 19 March 2026 (C-526/24 – Brillen Rottler), the Court of Justice of the European Union clarified the following:

Even a first-time request for access can, under certain conditions, be classified as “excessive” and thus as an abuse of rights.

This may be the case in particular where it can be proven that the data subject did not submit the request to obtain information about the processing of their personal data or to exercise their data protection rights, but for another, abusive purpose – for example, to deliberately lay the groundwork for a future claim for damages.

However, the controller must provide concrete evidence of the abusive intent, taking into account all circumstances of the individual case. Among other things, the CJEU lists the following factors:

  • how and for what purpose the personal data was originally provided,
  • how much time has elapsed between the collection of the data and the request for access,
  • the conduct of the data subject, and
  • where applicable, indications that requests for access are being made systematically and followed by claims for damages.

What Does This Mean for Companies?

We recommend a clear internal process for handling requests for access:

  1. Record the request: When was the request received, and from whom?
  2. Verify identity: Are there reasonable doubts about the identity of the person making the request?
  3. Review data sources and processing: Which systems and service providers hold the data subject’s personal data?
  4. Monitor the deadline: The statutory deadlines for responding must be met.
  5. Document in cases of suspected abuse: If a company wishes to classify a request as an abuse of rights, the specific circumstances must be documented in a transparent manner.

If you have reason to believe that a request for access constitutes an abuse of rights, DP-Dock will be happy to help you distinguish between a legitimate request and a potentially excessive or abusive one.

Hand holding a magnifying glass over a digital personal profile with a checkmark, surrounded by profile icons in front of a laptop – symbolizing the search for personal information
© krungchingpixs / stock.adobe.com | #2030189805

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy /en/privacy-policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy /en/privacy-policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed