Anyone who subscribes to a newsletter can, under the General Data Protection Regulation (GDPR), request information about their stored data. But can this right be specifically exercised in order to subsequently claim damages? A case involving the optician Brillen Rottler illustrates where courts draw the line between legitimate requests for data access and abusive “GDPR hopping.”
Subscribed to the newsletter and was charged 1,000 euros
A man living in Vienna signed up for the newsletter of Brillen Rottler, an optical company based in Arnsberg, and provided his personal data in the process. Shortly thereafter, he requested information regarding the processing of his data under Article 15 of the GDPR. The company rejected the request as an abuse of rights. The man then demanded at least 1,000 euros in damages for the refusal to provide the information.
The Arnsberg Local Court referred key questions regarding the interpretation of the GDPR to the European Court of Justice. The ECJ did not rule on the specific dispute, but instead provided the German court with binding guidelines for its legal assessment.
When a GDPR Request for Information May Be Considered “Excessive”
In principle, data subjects have the right to know whether and how a company processes their personal data. However, according to the European Court of Justice, even the first request for information may, in exceptional cases, be considered excessive and thus abusive. This is the case if the request is not intended to monitor data processing but solely to artificially create the basis for a subsequent claim for damages.
The burden of proof lies with the company. It must demonstrate, based on the totality of the circumstances, that there is an intent to abuse the system. In doing so, it may also take into account publicly available information regarding comparable, recurring claims. However, unusual behavior alone is not automatically sufficient.
Why the District Court Did Not Award Damages
The Arnsberg Local Court identified several pieces of circumstantial evidence pointing to a deliberate course of action. These included the voluntary provision of additional data, the short time between subscribing to the newsletter and submitting the request for information, doubts about a genuine interest in the company’s offerings, and publicly known indications of a recurring pattern of behavior.
In the overall assessment, the court held that Brillen Rottler was entitled to refuse to provide the information. Therefore, there was no claim for damages. Furthermore, according to the guidelines of the European Court of Justice, an affected party must prove actual material or non-material damage. If this damage is primarily attributable to the party’s own conduct, compensation is ruled out.
What the Ruling Means for Businesses and Consumers
The right of access under Article 15 of the GDPR remains an important tool for data protection. Companies must therefore not hastily reject requests by citing abuse of rights. They need concrete, documented evidence and must examine each case individually. The defense of abuse of rights remains a strictly limited exception.
Even a refusal to provide information or the provision of incorrect information can still give rise to a claim for damages, provided that actual damages have been incurred. Furthermore, the judgment of the Arnsberg Local Court is not yet final. An appeal against the decision has been announced.
Data protection laws provide protection—but not for every business model
These rulings set an important boundary: The GDPR is intended to give people control over their data, not to make deliberately induced violations of the law financially exploitable. At the same time, a legitimate GDPR request for information remains fully protected. Companies should therefore carefully review such requests and document their decisions in a transparent manner.
Can a company simply refuse to provide access to data?
No. A denial is possible only in justified exceptional cases. The company must demonstrate that the request is excessive or abusive.
Is a quick request for information after registration suspicious?
Not automatically. The short time frame can only be an indication and must be evaluated in conjunction with other circumstances.
Is compensation always awarded when information is withheld?
No. In addition to a GDPR violation, actual damages must be proven. There is no automatic or fixed minimum compensation.
Kostenloser Newsletter
Aktuelle Urteile, Praxistipps und neue Folgen aus Marken-, Urheber-, Medien- und Wettbewerbsrecht. Kompakt per E-Mail.
Double-Opt-in. Abmeldung jederzeit über den Link in jeder E-Mail.


