Brillen Rottler GmbH & Co. KG – Court Ruling (Germany, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A court ruled on a case involving a newsletter subscriber who requested access to his data but was denied by the company. This decision is crucial for businesses regarding how they handle data access requests.
What happened
Brillen Rottler GmbH refused to provide personal data to a subscriber, claiming the request was an abuse of rights.
Who was affected
A subscriber who requested access to his personal data held by Brillen Rottler GmbH.
What the authority found
The court found that a company can reject data access requests if they are deemed abusive under certain circumstances.
Why this matters
This ruling sets a precedent for how companies can handle access requests, emphasizing the need to assess the legitimacy of such requests carefully.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
An Austrian citizen residing in Vienna (the data subject) subscribed to the newsletter of a family-run optician company (the controller) mainly operating in the German states of North Rhine-Westphalia and Lower Saxony in March 2023. During the registration process, he provided his email address as well as his first and last name and consented to the processing of his personal data. He then made an access request under Article 15 GDPR by fax, using letterhead that included his full home address, email address, and fax number. The controller refused to provide the requested information in April 2023 as it considered the request to constitute abuse of rights. It cited newspaper reports indicating that the defendant had subscribed to numerous newsletters solely for the purpose of asserting claims for damages. The controller brought proceedings concerning the legality of its rejection of the access request. The data subject demanded access to the information required by in Article 15 GDPR and the payment of monetary compensation of €1,000 in a counter-lawsuit. The court referred the case to the CJEU for a preliminary ruling in July 2024. The CJEU rendered its judgment in the case C-526/24 Brillen Rottler on 19 March 2026. It held that even an initial access request could be rejected on the grounds of an abuse of rights. According to the CJEU, the assessment of abusive conduct is based on all circumstances of the individual case. Both objective circumstances and the subjective intent of the data subject need to be taken into account. An abusive intent always exists if the access request is made in order to artificially create a claim for damages. The court held that the lawsuit had originally been well-founded and ruled that the counterclaims were without merit. According to the court, the controller could reject the data subject’s access request as excessive under Article 12(5)(b) GDPR. The data subject also had no right to damages under Article 82 GDPR due to the abs
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (1)
Other cases involving Brillen Rottler GmbH & Co. KG in DE
Details
About this data
Cite as: Cookie Fines. Brillen Rottler GmbH & Co. KG - Germany (2026). Retrieved from cookiefines.eu
Last updated: