Auditors ✓ Lawyers ✓ Tax advisors ✓ and business consultants ✓ : Four perspectives. One solution. Worldwide. Learn …
Auditing and audit-related advice for companies ✓ Experienced auditors ✓ Excellent advice ✓ Tailor-made solutions » …
Our clients entrust us with their most important legal matters. Learn more about our legal services!
Tax laws are complex and dynamic. We face the challenge of tax law together with you - find out more.
Business consulting for companies ✓ Experienced consultants ✓ Excellent advice ✓ Tailor-made solutions » more
Baker Tilly Advises IX Group on Partnership with HTGS
Share Sale: German Federal Fiscal Court Sets Narrower Limits on the Deduction of Transaction Costs
Reform Package “Recovery and Employment”: What Employers Need to Know
Baker Tilly continues to expand its Real Estate Valuation Services
Baker Tilly advises Capmont on add-on acquisitions in the electrical segment
Validity of a dismissal despite incorrect collective redundancy notification
Baker Tilly strengthens legal services in Dortmund through partnership with pwk & Partner
Ensuring Strategic Stability in Accounting
ICT risks when using AI: New BaFin guidance
One year of DORA: What's next for financial companies
Survey: Two thirds of German automotive suppliers anticipate a market shakeout
Cross-industry expertise for individual solutions ✓ Our interdisciplinary teams combine expertise & market …
Baker Tilly advises CERTANIA on the Acquisition of InnoDiab
New SGEI Decision: Key Changes at a Glance
SGEI Decision: New Funding Opportunities for Affordable Housing
Risk management ✓ Compliance and controls ✓ Increase and ensure security & conformity ✓ more»
Baker Tilly offers a wide range of individual and innovative consulting services. Find out more!
The right of access under Article 15 GDPR has become a common tool for both employees and job applicants. The European Court of Justice (ECJ) has now ruled that, under certain circumstances, even an initial access request may be classified as abusive.
The right of access under Article 15 GDPR has become a standard instrument both in employment relationships and in recruitment processes. In its judgment of March 19, 2026 (C-526/24), the European Court of Justice (ECJ) clarified that an access request may, in individual cases, be classified as “excessive” within the meaning of Article 12(5) GDPR if it is submitted abusively, even where it is a first-time request. At the same time, however, the Court emphasized that access requests must continue to be taken seriously and that the abuse objection applies only in limited circumstances.
The case concerned an individual who submitted an access request under Article 15 GDPR to a company only 13 days after signing up for its newsletter. The company rejected the request on the grounds that it constituted an abuse of rights. The individual subsequently sought compensation under Article 82 GDPR.
In its defense, the company argued, among other things, that the individual systematically submitted access requests to various companies in order to deliberately generate compensation claims for alleged GDPR violations. Following a referral from the local court, the ECJ clarified that an access request may be classified as excessive where it is made exclusively for abusive purposes. However, the data controller must demonstrate the existence of such abuse on the basis of objective circumstances.
For employers, the decision does not represent a fundamental departure from existing data protection principles. The right to access personal data under Article 15 GDPR remains the general rule. Access requests from employees and applicants must continue to be handled properly and in accordance with GDPR requirements.
The ECJ nevertheless made clear that the abuse objection is not automatically excluded simply because the request is being made for the first time. What matters is an assessment of the specific circumstances of each individual case. Employers must be able to provide concrete and reliable evidence showing that the request was submitted solely for the purpose of creating the basis for a compensation claim under Article 82 GDPR.
The decision strengthens employers' position only in a narrowly limited category of clearly abusive access requests. The threshold for lawfully rejecting a request remains high because the burden of presentation and proof lies with the controller.
An access request may only be refused if it is manifestly unfounded or excessive. The mere strategic use of the right of access before or during employment-related disputes is not sufficient on its own. Unjustified refusals continue to carry significant liability risks.
Against this background, employers should continue to ensure the careful, structured, and timely handling of access requests. A blanket or premature rejection based on a presumed abuse of rights is not advisable.
Where there are concrete indications that a request serves exclusively abusive purposes, a legal assessment should be carried out before rejecting it. Employers should also document all relevant facts comprehensively. Only in this way can the risks of an unjustified refusal and potential claims under Article 82 GDPR be minimized.
Access requests submitted by employees and applicants generally continue to require a response. Rejecting a request on the basis of abuse of rights remains the exception and requires specific, objectively verifiable indications.
While the ECJ has opened the door to raising an abuse objection even against a first-time access request in individual cases, it simultaneously emphasized the exceptional nature of such situations. In practice, it therefore remains essential to examine access requests carefully while exercising caution before refusing them, in order to avoid unnecessary liability risks.
Dr. Theofanis Tacou, LL.M.
Partner
Attorney-at-Law (Rechtsanwalt), Specialist Lawyer in Labor Law, Dikigoros
Talk to us. Simply without obligation
Get in touch
View all news