Right of Access under Article 15 of the GDPR: When Does a Legitimate Right Become an Abuse of Rights?
- Author: Arno Schlösser, DP-Dock GmbH
- Last updated: September 2026
- Category: Consumer Rights, Data Security
The growing significance of the right of access in day-to-day data protection practice is also reflected in emerging case law. Courts are increasingly dealing with questions regarding the scope of the right of access, time limits and restrictions, and the handling of particularly excessive or repeated requests.
But how far does this right actually extend? And under what circumstances may a company restrict the information it provides or reject a request as excessive?
The CJEU Ruling of 19 March 2026
In March 2026, the CJEU outlined some limitations of this right. In its ruling of 19 March 2026 (C-526/24 – Brillen Rottler), the Court of Justice of the European Union clarified the following:
Even a first-time request for access can, under certain conditions, be classified as “excessive” and thus as an abuse of rights.
This may be the case in particular where it can be proven that the data subject did not submit the request to obtain information about the processing of their personal data or to exercise their data protection rights, but for another, abusive purpose – for example, to deliberately lay the groundwork for a future claim for damages.
However, the controller must provide concrete evidence of the abusive intent, taking into account all circumstances of the individual case. Among other things, the CJEU lists the following factors:
- how and for what purpose the personal data was originally provided,
- how much time has elapsed between the collection of the data and the request for access,
- the conduct of the data subject, and
- where applicable, indications that requests for access are being made systematically and followed by claims for damages.
What Does This Mean for Companies?
We recommend a clear internal process for handling requests for access:
- Record the request: When was the request received, and from whom?
- Verify identity: Are there reasonable doubts about the identity of the person making the request?
- Review data sources and processing: Which systems and service providers hold the data subject’s personal data?
- Monitor the deadline: The statutory deadlines for responding must be met.
- Document in cases of suspected abuse: If a company wishes to classify a request as an abuse of rights, the specific circumstances must be documented in a transparent manner.
If you have reason to believe that a request for access constitutes an abuse of rights, DP-Dock will be happy to help you distinguish between a legitimate request and a potentially excessive or abusive one.