In this blog, we discuss two recent developments in privacy case law. The Court of Justice of the European Union clarified when information about doping violations qualifies as "data concerning health" within the meaning of Article 9 GDPR. Additionally, we discuss a series of judgments in which Dutch courts applied the Brillen Rottler ruling for the first time and declared applicants inadmissible due to abuse of GDPR rights.
On 14 July 2026, the Court of Justice delivered its judgment in a case brought by four Austrian athletes against the Nationale Anti-Doping Agentur Austria (NADA) and the Österreichische Anti-Doping Rechtskommission (ÖADR). The central question was whether the online publication of doping sanctions concerns "data concerning health" and thus falls under the strict regime of Article 9 GDPR.
The four athletes had been penalised by the Austrian anti-doping authorities with exclusion from sports competitions due to doping violations. Under Austrian anti-doping law, such sanctions must be published online. NADA publishes a list on its website containing the athlete's name, the sport practised, the violation committed, the sanction imposed, and its start and end dates. The ÖADR publishes similar information in press releases, which also mention the name of the prohibited substance.
The Court reiterates once again that the concept of "data concerning health" must be interpreted broadly. Personal data can be classified as health data when information about someone's health status can be derived "by making logical connections or through deduction".
The Court then makes a nuanced distinction. The mere information that someone has committed a doping violation and has therefore been excluded from competitions does not, in principle, fall under the concept of "data concerning health". From the mere finding of a rule violation, no connection can be made with information about the health of the data subject.
However, this is different when the publication also mentions the name or category of the prohibited substance or method. The Court considers:
"It cannot be ruled out that the mention of the name or category of the prohibited substance or method concerned, when stated in combination with other elements, may at least indirectly reveal information about the, where applicable future, health of the data subject through logical connections or deduction."
The Court mentions as an example the situation where an athlete uses a prohibited substance due to a certain health condition but has not applied for a therapeutic use exemption. The mention of that specific substance may then indirectly reveal that the athlete has a particular condition.
Importantly, the Court emphasises that the concept of "data concerning health" does not only relate to the current health status, but also to health in the past and the future. Information from which it can be inferred that someone may face health risks due to the use of certain substances may also fall under Article 9 GDPR.
The Court confirms that the context in which personal data is published is determinative for classification as health data. The same information can be neutral in one setting and constitute a special category of personal data in another.
This ruling underscores that "logical connections" is a broad criterion. Organisations that publish personal data in the context of violations or sanctions, not only in sports but also in other sectors, would do well to assess whether the published information, in combination with the context, may indirectly reveal something about the health of data subjects.
In April 2026, we discussed the Brillen Rottler ruling, in which the Court of Justice held that even a first access request can be excessive if the applicant intentionally seeks to obtain an advantage by artificially creating the conditions under which that advantage arises. Dutch courts have since applied this ruling in practice. In July 2026, the District Court of Noord-Holland ruled in four cases concerning access requests from the same applicant, directed against Suitable, Scapino, At Home, and Wolters/Fundesign. The District Court of Rotterdam also delivered judgment in a similar case against the municipality of Rotterdam. In all five cases, the applicant was declared inadmissible due to abuse of rights.
The applicant in the Noord-Holland cases had, by his own account, submitted approximately 90 access requests under the GDPR to various webshops over a period of one and a half years. Approximately 20 proceedings were pending at the District Court of Noord-Holland, and similar cases were also ongoing at the District Courts of Rotterdam and Midden-Nederland.
The approach was identical in all cases. The applicant would place an online order or register for a newsletter. Shortly afterwards, an access request under Article 15 GDPR would follow. Within a few weeks, extrajudicial costs of €925 were claimed. A settlement proposal followed under threat of summons. In the summons, a high compensation was then claimed, plus extrajudicial costs and actual litigation costs. However, just before or at the hearing, the request was consistently reduced to access only, without any adequate explanation being provided.
The court furthermore found that the representatives acting on behalf of the applicant (with names such as "E. Donkersloot" and "J. Morsink") never appeared at hearings. The court expressed doubts about the actual existence of these representatives and ruled that the applicant had failed to make their existence plausible.
In the Rotterdam case, an even more extreme pattern was evident. The applicant had submitted 73 separate GDPR requests in four months, on top of 206 previous requests that had already been decided upon. The requests each consisted of multiple sub-requests and were largely directed at the same subjects, often distinguishing themselves only by minor details. According to the court, the requests were aimed at reopening legal assessments from previous criminal and civil proceedings in which the applicant had been convicted.
The District Court of Noord-Holland explicitly applied the assessment framework from the Brillen Rottler ruling. The court considered that the threshold for assuming abuse of rights is high and that restraint is appropriate. Nevertheless, it ruled that sufficiently weighty grounds were present in these cases to conclude that the applicant was abusing his GDPR rights.
As objective indicators of excessiveness, the court mentioned: the voluntary provision of personal data shortly before the access request, the early claiming of costs and compensation, the reduction of claims just before the hearing without adequate explanation, the use of nearly identical summonses in dozens of cases, and the submission of similar requests to many other controllers.
The court inferred the subjective element, the intent to obtain financial advantage, from this pattern. Although in principle each individual case must be assessed for abuse of rights, the court ruled that these cases could not be viewed in isolation from the other similar cases the applicant had initiated. Precisely the pattern in the approach and litigation conduct contributed significantly to the judgment:
"From the foregoing, no other conclusion can be drawn than that [the applicant], using the possibilities of the GDPR, has deliberately constructed a situation that enables him to obtain compensation from the companies concerned."
The court added that it could not escape the impression that the applicant was abusing companies' unfamiliarity with the content and operation of the GDPR and their fear of being ordered to pay high amounts.
The Rotterdam District Court reached the same conclusion, noting in part that the frequency with which the personal data were modified was very low. The data in question were largely statistical in nature, and the large number of access requests did not justify the burden involved.
The judgments contain several procedural points relevant to practice.
In the case against Scapino, the respondent had not expressly invoked abuse of rights. Nevertheless, the court ruled ex officio that abuse was present. This confirms that the court is not dependent on a defence from the controller to sanction abuse of GDPR rights.
In the cases against Suitable and Wolters/Fundesign, the respondents filed counter-requests, in which they requested, among other things, a declaratory judgment that the applicant was abusing rights and compensation. Despite the finding of abuse, the court rejected these counter-requests. The court ruled that the requested declaratory judgments were formulated too vaguely and insufficiently concretely, and that the respondents had not made clear what interest they had in the declaration. As for the claimed compensation, the respondents had not quantified their damages, which meant the court saw no reason to award an amount in equity.
The outcomes regarding litigation costs also varied. Suitable received €7,047.97 in actual litigation costs because it had submitted a cost estimate. At Home received €3,874.00 in actual litigation costs. Wolters/Fundesign, however, received only €2,230.00 based on the standard fee schedule because no cost estimate had been submitted. Scapino received €842.00 because actual litigation costs had not been claimed. This illustrates that an order for actual litigation costs is only granted if the respondent claims them and submits a concrete cost estimate.
For controllers, these judgments mean that refusal of an access request under Article 12(5) GDPR is possible where excessiveness is present. Publicly available information about the applicant's behavioural pattern may be considered in the assessment. Indicators such as the voluntary provision of data, the short time between provision and request, and the early claiming of costs may point to abuse. For a counter-request or claim for compensation, concrete formulation and quantified substantiation are required, and for an order for actual litigation costs, a cost estimate must be submitted.
For data subjects, these judgments make clear that the right of access is not an instrument for obtaining financial advantage. A pattern of requests to multiple controllers can lead to inadmissibility, and the early claiming of costs and the reduction of claims just before the hearing work to the applicant's disadvantage.
A caveat is in order. The evidentiary threshold remains high. In all the cases discussed, an extreme pattern was present: 90 requests in one and a half years in the Noord-Holland cases and 279 requests in the Rotterdam case. It remains to be seen whether a controller confronted with a one-off request from an unknown data subject will be able to provide sufficient evidence to demonstrate excessiveness. The exception in Article 12(5) GDPR therefore still remains to be interpreted restrictively.
This was just one of the recent developments. Interested in more? Read our Data & Privacy case law blog from July below.