For several years, the General Data Protection Regulation (GDPR) has served as a global gold standard for privacy rights. However, its robust protections have also birthed an unintended industry: the rise of professional “data activists” and claimants who use serial access requests not to protect their privacy, but to manufacture financial claims.

Commonly referred to as “GDPR hopping,” this practice involves individuals systematically targeting companies with Data Subject Access Requests (DSARs) in the hopes of catching a technical or administrative error that can be leveraged into a settlement or court award for “non-material damages.”

The Court of Justice of the European Union (CJEU) has finally addressed this imbalance in the landmark ruling of Case C-526/24 (Brillen Rottler).

What is a DSAR?

A DSAR is a right under the General Data Protection Regulation that allows an individual to ask an organisation whether it is processing their personal data and, if so, to obtain access to that data along with specific information about how it is used. The obligation goes beyond simply handing over a file. A DSAR requires the organisation to locate personal data across its systems, assess what can be disclosed, and present it in a clear and intelligible way. The response must generally be provided within one month, free of charge, and after verifying the requester’s identity. The data controller can only refuse to provide the data if the request is manifestly unfounded or excessive.

What is GDPR Hopping?

The term describes a predatory litigation model where a claimant intentionally creates a relationship with a data controller (e.g. a minor purchase, a newsletter subscription) with the sole purpose of submitting a DSAR. If the company fails to respond perfectly within the 30-day window, the claimant alleges “distress” or “loss of control” over their data and demands compensation under Article 82 of the GDPR.

What happened in the case of Brillen Rottler?

An individual subscribed to the newsletter of a German optician company (Brillen Rottler). About two weeks later, he submitted a DSAR. The company refused to respond. Their argument was not about workload or scope, but about intent: they relied on publicly available information suggesting that this person systematically made DSARs against companies in order to trigger non-compliance and then claim compensation. The individual then claimed damages (around €1,000), arguing that refusal to comply with a DSAR is itself a GDPR infringement.

The dispute ended up before the CJEU because the national court needed clarity on two key issues: whether a DSAR can be refused as “excessive” even if it is the first request, and how far the right to compensation goes.

What did the Court of Justice of the European Union clarify?

The Court essentially drew a line between legitimate use and abuse of rights.

1. Abuse of Rights Can Apply to First-Time Requests
Previously, it was widely assumed that a request could only be deemed “manifestly excessive” if it
was repetitive (i.e., the same person asking the same company multiple times). The CJEU has
now clarified that even a first-time request can be rejected as an abuse of rights if the claimant’s
underlying intent is purely to provoke a violation for financial gain rather than to verify the
lawfulness of data processing.

2. Contextual Pattern Recognition
National courts are now empowered to look beyond the individual request. They may consider a
claimant’s broader behavior, including whether they have a history of serial litigation or “hopping”
between controllers. This allows companies to use a claimant’s public track record as evidence of
abusive intent.

3. The “Self-Inflicted” Damage Defense
One of the most significant aspects of the ruling concerns the causal link between a violation and
the alleged damage. The Court held that if a claimant intentionally places themselves in a position
to have their data processed purely to set a trap, they cannot claim they suffered a “loss of
control.” In legal terms, the “determining cause” of the distress was the claimant’s own conduct, not
the company’s administrative oversight.

Why does this matter for businesses?

Before this case, the market narrative was: you must answer every DSAR unless it’s repetitive. After Brillen Rottler, the position is more nuanced:

Controllers can refuse even a first DSAR, but only in exceptional cases where they can actually evidence abuse.

In other words, this is not a “get out of jail” card for companies. It is a narrow defence against tactical or weaponised DSARs, and the burden of proof sits firmly on the controller.

Most importantly, this ruling marks a shift toward a more balanced and common-sense interpretation of privacy law.

  • It discourages “bounty hunting” by making it harder for serial claimants to secure easy wins in court.
  • Companies can prioritize genuine privacy inquiries from customers who actually care about their data, rather than being overwhelmed by tactical requests.
  • It reaffirms that GDPR enforcement should focus on actual risks to privacy, not on punishing minor procedural errors exploited by professional litigants.

Ultimately, the CJEU has clarified that ‘Data Subject’ is a legal status, not a job title. By ruling that tactical distress doesn’t warrant a payout, the Court is finally distinguishing between those who value their privacy and those who simply value a settlement. It’s a win for any business that prefers dealing with customers over professional litigants!


0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *