The ECJ had ruled in Rs. C‑526/24 in the case of Brillen Rottler to assess whether a first-time request for information can be considered „excessive“ within the meaning of Art. 12 para. 5 GDPR. This is true, and the requirements are not even far removed from Swiss law – the inappropriateness of the request. Another question again concerned compensation for damages.
The background to this was a request for information from a person living in Austria who had registered for a newsletter from Brillen Rottler, an optician company in Germany. Almost two weeks later, this person submitted a request for information, which Brillen Rottler rejected as abusive. The person concerned subsequently continued to demand information and damages of EUR 1,000 – clearly a systematic approach. In the following proceedings, the Arnsberg Local Court referred eight questions to the ECJ for a preliminary ruling.
Inappropriate requests for information
The ECJ first confirms that the Abuse of a request for information should not be assessed solely on the basis of the number of requests The frequent repetition is only mentioned as an example in Art. 12 (5) GDPR:
26 In addition, the second sentence of the first subparagraph of Article 12(5) GDPR states that requests may be excessive „in particular in the case of frequent repetition“. The accumulation of requests by a person may therefore be an indication that they are excessive […]. However, as the Advocate General […] has emphasized, since frequent repetition is only mentioned as an example in this provision, the classification of a request for information as „excessive“ does not require that the request in question must necessarily be related to the submission of several requests by the same data subject.
27 In view of an interpretation of Art. 12 para. 5 GDPR based on the wording, it can therefore not be ruled out that a first request for information can be regarded as „excessive“ within the meaning of this provision.
The exception is To be interpreted narrowly:
35 It follows that it is possible to consider a first request for information to the controller under Art. 15 GDPR as „excessive“ within the meaning of Art. 12(5) GDPR. However, since the term „excessive requests“, as can be seen from para. 29 of the present judgment, must be interpreted narrowly, a controller can only invoke such an excessive character in exceptional cases and the standards for classifying a first request for information as „excessive“ must be high, as stated by the Advocate General in point 34 of his Opinion. Furthermore, it should be noted that according to Art. 12 (5) subpara. 2 GDPR, the controller must expressly provide proof of the excessive nature.
But even if the exception is to be interpreted narrowly: Union law recognizes a General prohibition of abuse of rights:
30 However, it follows from the case-law of the Court of Justice on the interpretation of the concept of „excessive requests“ in Article 57(4) GDPR, which is applicable to the present case […], that Article 12(5) GDPR expresses a general principle of Union law according to which individuals may not rely on Union law standards in a fraudulent or abusive manner […]. The application of Union law cannot go so far as to protect processes that serve an abusive purpose […].
Abuse of rights presupposes two elements – that the regulatory objective of the right to information would be missed and the person concerned pursues an abusive intention:
36 Secondly, with regard to the circumstances under which the data subject’s first request for information can be classified as „excessive“ within the meaning of Art. 12(5) GDPR and thus constitute an abuse of rights within the meaning of the case law cited in recitals 23 and 30 above. 23 and 30 above, two elements are required to prove abusive conduct, namely, on the one hand, a set of objective circumstances showing that, despite formal compliance with the conditions laid down in the Union legislation, the objective of that legislation has not been achieved and, on the other hand, a subjective element consisting of the data subject’s intention to obtain an advantage resulting from the Union legislation by artificially creating the conditions for obtaining it. Such a classification must also take into account all the facts and circumstances of the individual case […].
In particular, requests that pursue a purpose contrary to data protection and are made with the intention of enrichment appear to be an abuse of rights – the ECJ is pleasingly close to Swiss law here. The Data protection purpose of the right of access is defined by the ECJ as follows, again in accordance with Art. 25 FADP:
45 […] may be regarded as „excessive“ within the meaning of that Article 12(5) if the controller demonstrates, having regard to all the relevant circumstances of the case, that that request […] was not made in order to become aware of the processing of those data and to verify its lawfulness so that it can subsequently protect its rights under the GDPR, but with abusive intent […].
In particular, a request for information would therefore be an abuse of the law if the person responsible just set a trap shall:
45 […] as to artificially create the conditions for obtaining an advantage resulting from the GDPR.
The assessment of abuse of rights lies with the substantive court. This may also take public information into account, which provide information about the motive of the person concerned:
45 […] The fact that, according to publicly available information, the data subject has made several requests for access to his or her personal data, for example, followed by claims for damages against various controllers, may be taken into account for the purpose of establishing such an abusive intention.
Compensation possible in the event of a breach of the right to information
Art. 82 para. 1 GDPR grants a claim for damages „for breach of this Regulation“. From this, the ECJ concludes that unlawful data processing is not required, but merely a violation of the GDPR, e.g. the right of access
48 According to Art. 82(1) GDPR, a person who has suffered material or non-material damage „as a result of an infringement of this Regulation“ is entitled to compensation from the controller. It should be noted that this provision makes no reference to „processing“, so that the claim for compensation cannot be limited to damage resulting from the processing of personal data.
[…]54 It follows from this that the data subject can also invoke the right to compensation provided for in Art. 82 GDPR in the event of a breach of the GDPR, where no data processing is implied as such.
55 Accordingly, the answer to the fifth and sixth questions is that Article 82(1) GDPR must be interpreted as granting the data subject a right to compensation for the damage resulting from a breach of the right of access under Article 15(1) GDPR.
Interruption of causality
The ECJ confirms its case law according to which the mere loss of control over personal data or uncertainty about the processing can constitute non-material damage. There is no de minimis threshold. However, the data subject must prove that they have actually suffered damage and that there is a causal link between the breach and the damage. This causal link can be be interrupted by the behavior of the person concerned.
The ECJ raises a second line of defense against abusive requests for information: An interruption occurs, among other things, if the data subject has created the loss of control or uncertainty himself by transmitting data in order to be able to assert claims afterwards (i.e. an interruption through gross self-culpability, so to speak):
65 In order to provide the referring court with a useful answer, it must also be pointed out that the causal link between the alleged infringement and the alleged damage may be broken by the conduct of the person concerned, provided that that conduct proves to be the decisive cause of the damage. A corresponding action can consist, among other things, of a decision by the injured person, but only if this decision was not mandatory for him […].
66 It also follows […] that the existence of a causal link […] is a sine qua non for a claim for damages […]. Consequently, the data subject […] cannot be granted compensation for damage allegedly suffered as a result of the loss of control over his personal data or his uncertainty as to the existence of processing of those data if the causal link is broken as a result of that person’s conduct because said loss of control or said uncertainty was brought about by the decision of the person concerned, to transmit this data to the controller with the intention of artificially creating the conditions for the application of this provision.