Skip to content

GDPR access request as a business model: when is it an abuse of rights?

16 July 2026Juriaan de Vries

GDPR access requests and abuse of rights

The District Court of North Holland declared a claimant who systematically filed GDPR access requests against online retailers inadmissible: he was not after his privacy, but after money. An access request pursued for a purely financial purpose amounts to an abuse of rights (Section 3:13 DCC read together with Article 12(5) GDPR). An online retailer that answers such a request promptly and substantively is in a strong position.

A systematic access request ends in inadmissibility

Anyone who places an order with an online retailer leaves personal data behind. Under Article 15 GDPR they may request access to that data. In two decisions of the District Court of North Holland of 13 July 2026 (ECLI:NL:RBNHO:2026:8285 and ECLI:NL:RBNHO:2026:8436) that right was deployed as a debt-collection instrument, and it failed.

A consumer had ordered from an online retailer and filed an access request on 18 July 2025. A little over a month later a formal demand followed: comply within fourteen days, plus 925 euros in extrajudicial costs. Another month later came a non-negotiable settlement proposal of 1,250 euros, under threat of court proceedings. The retailer responded substantively to the request and asked the claimant to verify his identity. That verification never came. Proceedings were brought nonetheless, with the claimant reducing his claim at the hearing to access alone, reinforced by a penalty payment of 250 euros per day up to 35,000 euros.

The court did not reach a substantive assessment. This case did not stand alone: the same claimant had brought around twenty such cases before the court between mid-2025 and April 2026, and admitted at the hearing to having filed some ninety access requests in eighteen months. Comparable cases are pending before the District Courts of Rotterdam and Central Netherlands as well. From that pattern the court inferred that the claimant was not after his data, but after financial gain.

Abuse of rights: a high threshold, but the pattern counts

The core provision is Section 3:13 DCC: a person who abuses a power cannot invoke it. Restraint is called for in procedural matters. For the right of access, Article 12(5) GDPR provides its own test: the controller may refuse to act on manifestly unfounded or excessive requests, in particular where they are repetitive. The EDPB Guidelines cite as an example of an excessive request the situation in which someone offers to withdraw the request in exchange for a benefit.

The framework gained a sharper edge through the judgment of the Court of Justice of the EU of 19 March 2026 (C-526/24, Brillen Rottler/TC). Abuse requires, on the one hand, a set of objective circumstances and, on the other, a subjective element: the intention to obtain a benefit conferred by EU law by artificially creating the conditions for it. Account may be taken of publicly accessible information showing that a person systematically files access requests and damages claims following a comparable pattern. It was precisely that pattern, early notice of costs, pressure to settle, a claim reduced just before the hearing, and representatives whose very existence could not be shown to be plausible, that led the court to find the threshold met.

The procedural consequence is strict. A person who abuses their rights is declared inadmissible, as the Administrative Jurisdiction Division of the Council of State had earlier held. In the most fully reasoned case the court went further and ordered the claimant to pay the actual legal costs of over ten thousand euros, instead of the usual fixed statutory scale.

What can online retailers do about an improper GDPR request?

Always respond promptly and substantively to an access request. It was precisely the retailers that took the request seriously and asked for identity verification (possibly under Article 12(6) GDPR) that stood strong once it emerged that the claimant did not engage. Document the correspondence, and watch for the signals: a demand for costs shortly after the request, a settlement proposal under threat of proceedings, or a claim that keeps changing.

If the request turns out to be part of a pattern, a reliance on Article 12(5) GDPR (manifestly unfounded or excessive) and on abuse of rights (Section 3:13 DCC) is the most far-reaching defence, it makes a substantive assessment unnecessary. A party who can show that proceedings were brought on a false or improper basis can moreover claim the actual legal costs. More on this type of dispute at commercial litigation.

Frequently asked questions

May a company refuse a GDPR access request?

In principle no: the right of access under Article 15 GDPR applies, and the request need not be justified. Article 12(5) GDPR makes an exception for manifestly unfounded or excessive requests, in particular where they are repetitive. The burden of showing that a request is excessive rests on the controller.

When is an access request excessive or an abuse of rights?

When the request does not serve to check one's own data, but another purpose, for instance financial gain. According to the Court of Justice (C-526/24), besides objective circumstances a subjective element is required: the intention to obtain a benefit by artificially creating the conditions. A systematic pattern of requests and settlement pressure counts.

Who bears the legal costs if abuse is established?

The claimant is declared inadmissible and ordered to pay the legal costs. Where a defendant appears in person, that is limited to a fixed amount. But in the event of demonstrable abuse of process, the court may award the actual, full lawyer's fees, over ten thousand euros in the heaviest case.

Cited case law

Court of Justice of the European Union
- CJEU 19 March 2026, C-526/24 (Brillen Rottler/TC)

Council of State
- ECLI:NL:RVS:2022:2403: abuse of rights leads to inadmissibility

District Courts
- ECLI:NL:RBNHO:2026:8285: District Court of North Holland, 13 July 2026 (assessment framework)
- ECLI:NL:RBNHO:2026:8436: District Court of North Holland, 13 July 2026
- ECLI:NL:RBROT:2025:13631: District Court of Rotterdam, 21 November 2025
- ECLI:NL:RBROT:2024:299: District Court of Rotterdam, 19 January 2024 (abuse of process)
- ECLI:NL:RBMNE:2022:2320: District Court of Central Netherlands, 25 May 2022

See also