The ECJ had ruled in Rs. C‑526/24 in the case of Bril­len Rott­ler to assess whe­ther a first-time request for infor­ma­ti­on can be con­side­red „exce­s­si­ve“ within the mea­ning of Art. 12 para. 5 GDPR. This is true, and the requi­re­ments are not even far remo­ved from Swiss law – the inap­pro­pria­ten­ess of the request. Ano­ther que­sti­on again con­cer­ned com­pen­sa­ti­on for damages.

The back­ground to this was a request for infor­ma­ti­on from a per­son living in Austria who had regi­stered for a news­let­ter from Bril­len Rott­ler, an opti­ci­an com­pa­ny in Ger­ma­ny. Almost two weeks later, this per­son sub­mit­ted a request for infor­ma­ti­on, which Bril­len Rott­ler rejec­ted as abu­si­ve. The per­son con­cer­ned sub­se­quent­ly con­tin­ued to demand infor­ma­ti­on and dama­ges of EUR 1,000 – cle­ar­ly a syste­ma­tic approach. In the fol­lo­wing pro­ce­e­dings, the Arns­berg Local Court refer­red eight que­sti­ons to the ECJ for a preli­mi­na­ry ruling.

Inap­pro­pria­te requests for information

The ECJ first con­firms that the Abu­se of a request for infor­ma­ti­on should not be asses­sed sole­ly on the basis of the num­ber of requests The fre­quent repe­ti­ti­on is only men­tio­ned as an exam­p­le in Art. 12 (5) GDPR:

26 In addi­ti­on, the second sen­tence of the first sub­pa­ra­graph of Artic­le 12(5) GDPR sta­tes that requests may be exce­s­si­ve „in par­ti­cu­lar in the case of fre­quent repe­ti­ti­on“. The accu­mu­la­ti­on of requests by a per­son may the­r­e­fo­re be an indi­ca­ti­on that they are exce­s­si­ve […]. Howe­ver, as the Advo­ca­te Gene­ral […] has empha­si­zed, sin­ce fre­quent repe­ti­ti­on is only men­tio­ned as an exam­p­le in this pro­vi­si­on, the clas­si­fi­ca­ti­on of a request for infor­ma­ti­on as „exce­s­si­ve“ does not requi­re that the request in que­sti­on must neces­s­a­ri­ly be rela­ted to the sub­mis­si­on of seve­ral requests by the same data subject.

27 In view of an inter­pre­ta­ti­on of Art. 12 para. 5 GDPR based on the wor­ding, it can the­r­e­fo­re not be ruled out that a first request for infor­ma­ti­on can be regard­ed as „exce­s­si­ve“ within the mea­ning of this provision.

The excep­ti­on is To be inter­pre­ted nar­row­ly:

35 It fol­lows that it is pos­si­ble to con­sider a first request for infor­ma­ti­on to the con­trol­ler under Art. 15 GDPR as „exce­s­si­ve“ within the mea­ning of Art. 12(5) GDPR. Howe­ver, sin­ce the term „exce­s­si­ve requests“, as can be seen from para. 29 of the pre­sent judgment, must be inter­pre­ted nar­row­ly, a con­trol­ler can only invo­ke such an exce­s­si­ve cha­rac­ter in excep­tio­nal cases and the stan­dards for clas­si­fy­ing a first request for infor­ma­ti­on as „exce­s­si­ve“ must be high, as sta­ted by the Advo­ca­te Gene­ral in point 34 of his Opi­ni­on. Fur­ther­mo­re, it should be noted that accor­ding to Art. 12 (5) sub­pa­ra. 2 GDPR, the con­trol­ler must express­ly pro­vi­de pro­of of the exce­s­si­ve nature.

But even if the excep­ti­on is to be inter­pre­ted nar­row­ly: Uni­on law reco­gnizes a Gene­ral pro­hi­bi­ti­on of abu­se of rights:

30 Howe­ver, it fol­lows from the case-law of the Court of Justi­ce on the inter­pre­ta­ti­on of the con­cept of „exce­s­si­ve requests“ in Artic­le 57(4) GDPR, which is appli­ca­ble to the pre­sent case […], that Artic­le 12(5) GDPR expres­ses a gene­ral prin­ci­ple of Uni­on law accor­ding to which indi­vi­du­als may not rely on Uni­on law stan­dards in a frau­du­lent or abu­si­ve man­ner […]. The appli­ca­ti­on of Uni­on law can­not go so far as to pro­tect pro­ce­s­ses that ser­ve an abu­si­ve purpose […].

Abu­se of rights pre­sup­po­ses two ele­ments – that the regu­la­to­ry objec­ti­ve of the right to infor­ma­ti­on would be missed and the per­son con­cer­ned pur­sues an abu­si­ve inten­ti­on:

36 Second­ly, with regard to the cir­cum­stances under which the data subject’s first request for infor­ma­ti­on can be clas­si­fi­ed as „exce­s­si­ve“ within the mea­ning of Art. 12(5) GDPR and thus con­sti­tu­te an abu­se of rights within the mea­ning of the case law cited in reci­tals 23 and 30 abo­ve. 23 and 30 abo­ve, two ele­ments are requi­red to pro­ve abu­si­ve con­duct, name­ly, on the one hand, a set of objec­ti­ve cir­cum­stances show­ing that, despi­te for­mal com­pli­ance with the con­di­ti­ons laid down in the Uni­on legis­la­ti­on, the objec­ti­ve of that legis­la­ti­on has not been achie­ved and, on the other hand, a sub­jec­ti­ve ele­ment con­si­sting of the data subject’s inten­ti­on to obtain an advan­ta­ge resul­ting from the Uni­on legis­la­ti­on by arti­fi­ci­al­ly crea­ting the con­di­ti­ons for obtai­ning it. Such a clas­si­fi­ca­ti­on must also take into account all the facts and cir­cum­stances of the indi­vi­du­al case […].

In par­ti­cu­lar, requests that pur­sue a pur­po­se con­tra­ry to data pro­tec­tion and are made with the inten­ti­on of enrich­ment appear to be an abu­se of rights – the ECJ is plea­sing­ly clo­se to Swiss law here. The Data pro­tec­tion pur­po­se of the right of access is defi­ned by the ECJ as fol­lows, again in accordance with Art. 25 FADP:

45 […] may be regard­ed as „exce­s­si­ve“ within the mea­ning of that Artic­le 12(5) if the con­trol­ler demon­stra­tes, having regard to all the rele­vant cir­cum­stances of the case, that that request […] was not made in order to beco­me awa­re of the pro­ce­s­sing of tho­se data and to veri­fy its lawful­ness so that it can sub­se­quent­ly pro­tect its rights under the GDPR, but with abu­si­ve intent […].

In par­ti­cu­lar, a request for infor­ma­ti­on would the­r­e­fo­re be an abu­se of the law if the per­son respon­si­ble just set a trap shall:

45 […] as to arti­fi­ci­al­ly crea­te the con­di­ti­ons for obtai­ning an advan­ta­ge resul­ting from the GDPR.

The assess­ment of abu­se of rights lies with the sub­stan­ti­ve court. This may also take public infor­ma­ti­on into account, which pro­vi­de infor­ma­ti­on about the moti­ve of the per­son concerned:

45 […] The fact that, accor­ding to publicly available infor­ma­ti­on, the data sub­ject has made seve­ral requests for access to his or her per­so­nal data, for exam­p­le, fol­lo­wed by claims for dama­ges against various con­trol­lers, may be taken into account for the pur­po­se of estab­li­shing such an abu­si­ve intention.

Com­pen­sa­ti­on pos­si­ble in the event of a breach of the right to information

Art. 82 para. 1 GDPR grants a cla­im for dama­ges „for breach of this Regu­la­ti­on“. From this, the ECJ con­clu­des that unlawful data pro­ce­s­sing is not requi­red, but mere­ly a vio­la­ti­on of the GDPR, e.g. the right of access

48 Accor­ding to Art. 82(1) GDPR, a per­son who has suf­fe­r­ed mate­ri­al or non-mate­ri­al dama­ge „as a result of an inf­rin­ge­ment of this Regu­la­ti­on“ is entit­led to com­pen­sa­ti­on from the con­trol­ler. It should be noted that this pro­vi­si­on makes no refe­rence to „pro­ce­s­sing“, so that the cla­im for com­pen­sa­ti­on can­not be limi­t­ed to dama­ge resul­ting from the pro­ce­s­sing of per­so­nal data.

[…]

54 It fol­lows from this that the data sub­ject can also invo­ke the right to com­pen­sa­ti­on pro­vi­ded for in Art. 82 GDPR in the event of a breach of the GDPR, whe­re no data pro­ce­s­sing is implied as such.

55 Accor­din­gly, the ans­wer to the fifth and sixth que­sti­ons is that Artic­le 82(1) GDPR must be inter­pre­ted as gran­ting the data sub­ject a right to com­pen­sa­ti­on for the dama­ge resul­ting from a breach of the right of access under Artic­le 15(1) GDPR.

Inter­rup­ti­on of causality

The ECJ con­firms its case law accor­ding to which the mere loss of con­trol over per­so­nal data or uncer­tain­ty about the pro­ce­s­sing can con­sti­tu­te non-mate­ri­al dama­ge. The­re is no de mini­mis thres­hold. Howe­ver, the data sub­ject must pro­ve that they have actual­ly suf­fe­r­ed dama­ge and that the­re is a cau­sal link bet­ween the breach and the dama­ge. This cau­sal link can be be inter­rupt­ed by the beha­vi­or of the per­son con­cer­ned.

The ECJ rai­ses a second line of defen­se against abu­si­ve requests for infor­ma­ti­on: An inter­rup­ti­on occurs, among other things, if the data sub­ject has crea­ted the loss of con­trol or uncer­tain­ty hims­elf by trans­mit­ting data in order to be able to assert claims after­wards (i.e. an inter­rup­ti­on through gross self-cul­pa­bi­li­ty, so to speak):

65 In order to pro­vi­de the refer­ring court with a useful ans­wer, it must also be poin­ted out that the cau­sal link bet­ween the alle­ged inf­rin­ge­ment and the alle­ged dama­ge may be bro­ken by the con­duct of the per­son con­cer­ned, pro­vi­ded that that con­duct pro­ves to be the decisi­ve cau­se of the dama­ge. A cor­re­spon­ding action can con­sist, among other things, of a decis­i­on by the inju­red per­son, but only if this decis­i­on was not man­da­to­ry for him […].

66 It also fol­lows […] that the exi­stence of a cau­sal link […] is a sine qua non for a cla­im for dama­ges […]. Con­se­quent­ly, the data sub­ject […] can­not be gran­ted com­pen­sa­ti­on for dama­ge alle­gedly suf­fe­r­ed as a result of the loss of con­trol over his per­so­nal data or his uncer­tain­ty as to the exi­stence of pro­ce­s­sing of tho­se data if the cau­sal link is bro­ken as a result of that person’s con­duct becau­se said loss of con­trol or said uncer­tain­ty was brought about by the decis­i­on of the per­son con­cer­ned, to trans­mit this data to the con­trol­ler with the inten­ti­on of arti­fi­ci­al­ly crea­ting the con­di­ti­ons for the appli­ca­ti­on of this provision.