On 19 March 2026 the Court of Justice of the European Union decided Case C-526/24, Brillen Rottler, and the headline is real: a data subject’s very first access request can be refused as excessive under Article 12(5) GDPR, provided the controller can demonstrate it was made with abusive intent. The less quotable part of the judgment is the one that matters for daily practice: the burden of proving abuse sits with the controller, the bar is high, and nothing in the ruling changes what you owe the overwhelming majority of requests, which is a full, on-time, properly redacted response.
The Facts, Because They Are the Point
An Austrian resident subscribed to the newsletter of Brillen Rottler, a family-run German opticians, through the sign-up form on its website. Thirteen days later he submitted an Article 15 access request. The company refused, pointing to publicly available reports and legal newsletters describing a systematic pattern: subscribe to a newsletter, submit an access request, then claim compensation when the controller stumbles. He maintained the request was legitimate and claimed at least 1,000 euros in non-material damages under Article 82. The Local Court in Arnsberg referred the questions to the CJEU. This is the scenario sometimes called GDPR hopping, and it is the scenario the ruling addresses: a request engineered to create the conditions for a damages claim, not to find out what a controller holds.
What the Court Held
Three propositions. First, the reference to repeated requests in Article 12(5) is illustrative, not a boundary, so a first request can already be excessive where abuse is shown. Second, what has to be shown is abusive intent: that the request was made not to exercise the rights of transparency and control the GDPR protects, but to manufacture a compensation claim. Publicly available evidence of a pattern of serial requests and claims against other controllers can form part of that assessment, though not the sole basis. Third, on the damages side, compensation under Article 82 is available for a breach of the access right itself, so refusing wrongly is not free. A controller that refuses must still do so within the statutory deadlines and give its reasons.
The Guardrail the Ruling Sits Inside
Brillen Rottler did not arrive from nowhere. In earlier case law on manifestly unfounded and excessive requests, the Court had already made clear that volume alone does not establish abuse: a person making many requests or complaints is not, by that fact, acting abusively, and what is required is evidence of the abusive intention itself. Read together, the message to controllers is symmetrical. You are not defenceless against manufactured requests, and you are not licensed to treat inconvenient ones as abusive. The distance between those two positions is evidence, documented before you refuse.
Does It Apply in the UK?
Not directly. CJEU judgments delivered after Brexit do not bind UK courts, though they can be considered. UK GDPR has its own manifestly unfounded or excessive language, and the ICO’s long-standing position is that a controller relying on it needs a strong justification it is prepared to demonstrate to the individual and to the ICO. The direction of travel is similar, and UK organisations facing a genuine compensation-farming pattern will find the reasoning useful, but a UK refusal stands on UK GDPR and ICO guidance, not on this judgment. From 19 June 2026 a refused requester also has a statutory route to challenge you first: the section 164A complaints procedure means your refusal reasoning will be re-read, on the record, by you, before the ICO ever sees it.
Why You Usually Still Redact
Here is the practical arithmetic the legal alerts skip. Abusive requests are a tail. The request in front of you today almost certainly comes from an employee, a customer, or a tenant with a genuine interest, and for that request the ruling changes nothing: you search proportionately, you review everything the search returns, you protect third parties, and you deliver on time. Building a refusal case costs senior time, invites a complaint, and fails unless the evidence of intent is real, which means the economic answer to nearly every request is a clean response produced efficiently, not a speculative refusal. The organisations that handle this well treat Brillen Rottler as an insurance policy for the rare pattern case and treat a disciplined search plus fast, reviewable redaction as the answer to everything else.
How SafeRedact Fits
Files never leave your browser: documents are processed client-side, only extracted text is sent for AI detection, and no documents are stored on servers. Detection text is never used for training and is deleted within 30 days. DSAR mode lets you name the data subject whose information should be preserved while other individuals’ personal information is flagged for redaction across every file in the case. Every detection is reviewed by a human before anything is exported, and the output includes a processing summary and audit trail your privacy officer can stand behind if the ICO asks how the response was produced.
A Data Processing Agreement is available, and enterprise cases are priced per case, with the price set with you and shown before you download. See the enterprise overview or the enterprise FAQ for how cases run end to end.
Answer the Real Requests Fast
AI-assisted detection, human review, and an audit trail for the responses you actually have to send. Files never leave your browser.
Start Your EvaluationRelated Guides
Microsoft, Microsoft 365, SharePoint, Exchange Online, OneDrive, Teams, and Purview are trademarks of Microsoft Corporation. SafeRedact is not affiliated with or endorsed by Microsoft. This page is informational, not legal advice; the legislation, court rulings, ICO guidance, and your counsel govern.