From the Right of Access to a Claim for Compensation
The broad effect of a narrow Swedish GDPR judgment
An eight-page judgment of the Förvaltningsrätten i Umeå appears, at first sight, to concern a narrow dispute: a data subject asked a Swedish municipality for full access under the GDPR. In response to the request at issue, the municipality did not provide the requested copies of the data or the log and access information. Instead, it took the position that the personal data had already been disclosed in full on an earlier occasion. The earlier disclosure through party access to the file had, however, been selective and incomplete.
The administrative court set aside the two central grounds of refusal and remitted the matter to the Social Welfare Committee for a new examination.
The narrowness of the dispute is precisely what makes the judgment useful. The court separates two common attempts to limit the right of access. Information previously disclosed under another legal regime does not exhaust the autonomous right under Article 15 GDPR. And access information does not cease to relate to the data subject merely because the authority classifies it as technical security information.
The broader effect emerges when the judgment is read together with the case law on which the court itself relies. Brillen Rottler, C-526/24, sits on both sides of the threshold: the Court of Justice explains when an access request may be rejected because of an abusive purpose. In the same judgment, it expressly holds that Article 82(1) GDPR covers compensation for damage resulting from an infringement of the right of access under Article 15(1). The Court also places loss of control over personal data and uncertainty as to whether and how the data have been processed within the concept of non-material damage.
The Swedish judgment does not itself award compensation. What it does is practically prior to that question: it anchors the unlawfulness of two limitations on the right of access in the very CJEU case law from which a clear causal chain to Article 82 can then be constructed.
1. Case overview
The mini-corpus consists of two documents. The first is the judgment of the Förvaltningsrätten i Umeå concerning the Social Welfare Committee of Svalövs kommun and its partial refusal of a GDPR access request. The second is a compensation claim formulated after the judgment under Article 82 GDPR, connecting the judicial findings with an ongoing logic of loss of control and damage.
The judgment is not a precedent of Sweden's highest administrative court. Its wider importance lies elsewhere: it applies authoritative EU case law to an ordinary municipal dispute and makes the sequence of legal questions unusually compact and visible.
2. Central question
How can an unlawful limitation of the GDPR right of access be translated into a legally anchored causal chain leading to a compensation claim under Article 82 GDPR?
The answer lies in combining legal propositions already present in the judgment and the CJEU case law it applies:
access → control of processing → knowledge of access, time and purpose → verification of accuracy and lawfulness → exercise of further data-subject rights → loss of that control through unlawful restriction → non-material damage → Article 82.
3. Method
The judgment is the primary source for the administrative proceedings, the parties' positions and the court's findings. The subsequent compensation claim is read as the second core document. It shows how the judicial finding was translated into a concrete Article 82 chain of causation.
The study keeps the levels distinct: the court decides on the lawfulness of the refusal of access. The second document takes that finding and places it into a damage and causation argument under Article 82.
4. Case statistics
| Metric | Finding |
|---|---|
| Core documents | 2 |
| Judicial decisions in the mini-corpus | 1 |
| Length of the judgment | 8 pages |
| Central municipal grounds of refusal | 2 |
| Refusal grounds set aside and remitted | 2 |
| CJEU judgments relied on by the court for the central issues | 3 |
| CJEU judgments expressly cited in the compensation claim | 6 |
| Separate press or right-of-reply communication | 0 |
The case is not notable because of communication volume. Its importance lies in the density of the legal connection between access, control and damage.
5. The background
Before the GDPR request, there had been a disclosure through party access to the file. That disclosure was selective and incomplete. Documents referred to elsewhere in the communication were missing.
When the later full Article 15 request was made, the municipality did not provide the requested new copies of the data or processing traces. Instead, it relied on the position that the personal data had already been made fully available earlier.
That produced the first fundamental question: Can an autonomous GDPR right of access effectively disappear because an authority asserts that the same information was previously disclosed under another legal regime?
6. What the municipality did
The data subject requested a full access extract under Articles 12 to 15 GDPR. The request covered all personal data processed about him by the municipality, irrespective of storage format or system, together with the information required by Article 15.
The Social Welfare Committee did not provide the requested copies of the data or the log and access information in response to that request. As to the copies, it relied on Article 12(5) GDPR. Its core reasoning was that the data subject had already received the personal data shortly beforehand through other channels and was therefore already able to verify their accuracy and lawfulness. A renewed demand was characterised as manifestly unfounded or excessive.
The municipality rejected the request for log and access information on a second ground. Such information, it argued, was not personal data about the data subject but a technical security measure used by the controller.
Two distinct legal questions therefore emerged: When may an authority treat an access request as manifestly unfounded or excessive? And do access traces fall within the information protected by Article 15?
7. What the claimant argued
The claimant separated the GDPR right of access from the earlier party access. The previous disclosure had been selective and incomplete; more fundamentally, Article 15 was an autonomous right of control. Disclosure under another legal regime does not answer whether the controller has fully complied with Article 15.
On the second issue, he challenged the technical classification of the logs. Access, registration, changes and metadata matter precisely because they can show how personal data have been processed. The informational value lies not only in the content of a file, but also in when data were read, used or changed and for what purpose.
He also relied on Article 12(3) GDPR, under which the controller must provide information on action taken on a request without undue delay and in principle within one month.
8. What the court made of it
8.1. Article 12(5): the authority bears the burden of the refusal threshold
On the first ground of refusal, the Förvaltningsrätten relied on Brillen Rottler, C-526/24, and additionally on Österreichische Datenschutzbehörde, C-416/23.
From that case law it derived a clear threshold: a controller seeking to refuse an access request under Article 12(5) as manifestly unfounded or excessive must establish the abusive purpose relied on.
In the proceedings before it, the court found nothing to indicate that this was anything other than the data subject's first request under Articles 12 and 15 GDPR. The fact that information had previously been disclosed under other legislation was not sufficient.
The central proposition can therefore be stated simply:
Previous disclosure of information does not replace proof of the conditions for refusal under Article 12(5).
8.2. Article 15: access traces belong inside the sphere of control
On the second ground, the court relied on Pankki S, C-579/21. The Court of Justice had held there that information concerning consultations of personal data, in particular the dates and purposes of those consultations, falls within the right of access.
The Förvaltningsrätten therefore concluded that log and access information is covered by Article 15(1). The Social Welfare Committee could not refuse the request merely by classifying the information as technical security data.
The court formulated the positive information duty in concrete terms: information must be provided on the date or time of access or reading and on the purpose of the processing. The technical reason why the information exists does not remove its function of making processing controllable by the data subject.
9. The one-month rule links Article 15 to a whole block of rights
Article 12(3) GDPR appears in the judgment as a general legal starting point. It requires action without undue delay and in principle within one month. Its scope is expressly broader than Article 15: it concerns measures under Articles 15 to 22 GDPR.
The Regulation therefore creates a common procedural framework for a chain of data-subject rights: access under Article 15, rectification under Article 16, erasure under Article 17, restriction under Article 18, notification duties under Article 19, data portability under Article 20, objection under Article 21 and rights relating to automated decision-making under Article 22.
For this case, Articles 15, 16, 18 and 19 are particularly closely connected. A person who cannot reliably identify what personal data are being processed, where they came from, when they were accessed and for what purpose loses part of the factual basis for testing their accuracy and for seeking effective rectification or restriction.
The connection is therefore not merely temporal. It is functional.
10. One judgment, two CJEU tracks
10.1. Brillen Rottler: refusal threshold and bridge to Article 82
The Förvaltningsrätten first uses Brillen Rottler to limit the possibility of refusal. Article 12(5) does not allow a controller to reject a request merely because it regards the request as unnecessary or already satisfied. The conditions of the exception must be established.
The municipality failed at that threshold in the Swedish case.
For the damage dimension, the decisive point is that Brillen Rottler does not stop there. The Court of Justice expressly answers whether Article 82(1) covers damage caused by an infringement of the right of access under Article 15(1). Its answer is yes.
The judgment goes further on the concept of damage. The Court places loss of control over personal data and uncertainty about whether personal data have been processed within the concept of non-material damage.
The same CJEU judgment that the Förvaltningsrätten uses to reject the municipality's Article 12(5) reasoning therefore provides the direct legal bridge to a compensation claim.
10.2. Pankki S: what control means in practice
Pankki S makes the content of that control concrete. The right of access is not confined to static file content. Information about consultations of personal data may be necessary precisely in order to verify whether processing has been lawful.
The date and purpose of a consultation are therefore not merely system details. They answer questions central to control: When were my data used? For what purpose?
The Förvaltningsrätten applies that proposition to the municipal logs and access data. This gives the later damage chain a concrete object. The information withheld concerns when data were accessed or read and the purpose for which the processing took place.
Loss of control is therefore not left as an abstraction. It is attached to identifiable information about processing.
11. The second core document: from judicial finding to damage chain
The compensation claim formulated after the judgment takes these elements and arranges them into a causal chain:
unlawful limitation of access → limited knowledge of processing and access → loss of control → impaired verification of accuracy, origin and use → impaired rectification and restriction → continued presence of disputed data → continuing non-material burden → compensation claim under Article 82.
What is striking is the legal anchoring of each link.
The first link comes from the Swedish judgment: the municipality could neither rely on the reasoning it used under Article 12(5) nor exclude log and access information wholesale from Article 15.
The second and third links are joined by Pankki S and Brillen Rottler. Pankki S treats access information as part of control. Brillen Rottler places the loss of that control and uncertainty about processing within the concept of non-material damage under Article 82.
The next links are built into the system of data-subject rights itself. Article 15 enables control; Article 16 opens the route to rectification of inaccurate data; Article 18 allows restriction of processing while disputed accuracy is checked; Article 19 carries the effect onwards to recipients to whom the data were disclosed.
Brillen Rottler reinforces that structure. The Court of Justice expressly explains that Article 82 cannot be reduced to damage caused by a processing operation in the narrow sense. The refusal of Chapter III rights can itself cause compensable damage. In that reasoning the Court specifically refers to access, rectification, erasure, restriction and portability.
The chain access – control – rectification – restriction – downstream effect therefore reflects the architecture of the GDPR as described by the Court of Justice.
12. The causal chain in one line
The practical effect of the judgment can be compressed into a single sequence:
Article 15 request → unlawful refusal → no access to control-relevant access information → loss of control and continuing uncertainty → impaired verification and correction of personal data → non-material harm → Article 82 compensation claim.
The Swedish judgment and Brillen Rottler meet at the decisive point: the Förvaltningsrätten establishes the unlawfulness of the restriction of the right of access; the Court of Justice expressly places damage from an infringement of that right within Article 82 and treats loss of control and uncertainty as forms of non-material damage.
13. The disputes side by side
| Issue | Position of the Social Welfare Committee | Claimant's objection | Förvaltningsrätten's conclusion | Article 82 significance |
|---|---|---|---|---|
| Earlier disclosure | Everything had already been made available; another copy was manifestly unfounded or excessive | Earlier party access was selective and incomplete; Article 15 is autonomous | Earlier disclosure under other law is insufficient for Article 12(5); abusive purpose was not established | Unlawful limitation of Article 15 provides the starting point for the damage chain |
| Logs and access data | Technical security information, not personal data about the data subject | Access traces are linked to the processing of an identifiable person | Date/time of access or reading and processing purpose fall within the protected information sphere | The loss of control concerns concrete information about processing operations |
| Function of access | The asserted earlier disclosure already enabled control | Full control requires the autonomous Article 15 right | The court applies Article 15 independently of earlier disclosure routes | Brillen Rottler connects infringement of the control right with Article 82 |
| Rights chain | Focus on previously known file content | Access should make further rights effective | Article 12(3) covers action under Articles 15–22; Article 15 is applied as a control right | Access, control, rectification, restriction and downstream effect form a coherent claim logic |
14. Communication and knowledge chain
The mini-corpus contains no separate press or right-of-reply exchange. The decisive knowledge chain is already visible in the dispute reconstructed in the judgment.
The Social Welfare Committee knew that there was a complete request expressly based on Articles 12 and 15 GDPR. It decided not to provide the requested copies of the data or the log and access information on that basis, and relied on the assertion that the relevant personal data had already been made available.
The claimant opposed that reasoning with the autonomous nature of Article 15 and the incompleteness of the earlier party access. The conflict over the logs was equally clear: technical security information according to the municipality, control-relevant processing traces according to the claimant.
The court resolved both conflicts by reference to the EU-law function of the right of access as a right of control.
15. Institutional mechanism
The two municipal grounds of refusal appear different. One looks backwards: everything had already been disclosed. The other looks at technical function: logs were security data.
Structurally, however, both do the same thing. They move the boundary of the right of access away from the purpose of Article 15 and towards an administrative prior judgment about what information the data subject still needs and what information should count as relating to him.
The Förvaltningsrätten corrects both shifts through the same principle: the controlling function of the data-subject right is decisive.
Under Article 12(5), this means that the controller cannot curtail the right merely by declaring the information need already satisfied.
For logs, it means that the controller cannot exclude control-relevant information merely because it is generated technically or stored for security purposes.
16. Legal dimension of the compensation claim
16.1. Article 15: access as a right of control
Article 15 does more than expose static file content. It exists to make processing visible and reviewable. Pankki S makes this concrete for access events: the time and purpose of a consultation are among the information that enables that control.
16.2. Articles 16, 18 and 19: control becomes corrective effect
Where control reveals inaccurate or disputed data, Article 16 provides rectification. Article 18(1)(a) links a dispute about accuracy with temporary restriction of processing while accuracy is verified. Article 19 carries rectification, erasure or restriction onwards to recipients to whom the data were disclosed.
The practical chain is therefore: see, verify, contest, rectify or restrict, correct downstream effects.
16.3. Article 82: the rights chain acquires a damage dimension
Brillen Rottler removes the possible break between Chapter III and Article 82. The Court of Justice expressly holds that damage resulting from an infringement of the Article 15 right of access is covered by Article 82(1). Compensation is not confined to damage arising directly from a processing operation in the narrow sense.
The broader CJEU case law fits alongside that holding: Ă–sterreichische Post rejects a general seriousness threshold for non-material damage; Natsionalna agentsia za prihodite recognises fear of possible future misuse as capable of constituting non-material damage; Scalable Capital stresses full and effective compensation for the damage actually suffered; Quirin Privatbank places negative feelings such as fear or anger within non-material damage where they arise from loss of control, possible misuse or reputational harm.
For this case, however, the most direct connection remains Brillen Rottler itself:
infringement of Article 15 → damage under Article 82; loss of control and uncertainty about processing → non-material damage.
17. The broad effect of the narrow judgment
The UmeĂĄ judgment does not create a new EU-law right to compensation. It does something more practically useful: in a very small case, it shows where existing CJEU lines of authority meet.
An authority cannot neutralise an Article 15 request by asserting that the data subject has already received everything through another route. It must satisfy the conditions of Article 12(5).
It cannot exclude access information merely because that information is created in a technical security or logging system. What matters is its function in enabling control of processing.
And that control is the very concept that Brillen Rottler carries directly into the damage dimension.
The subsequent compensation claim makes that connection visible:
unlawful restriction → loss of control → impaired exercise of the rights in Articles 15, 16, 18 and 19 → continuing non-material harm → Article 82.
The practical significance of the judgment therefore reaches beyond the immediate question whether one municipality had to provide one particular access extract. It shows why access has a hinge function within the GDPR: restricting access does not merely restrict information. It restricts the ability to control processing and to exercise the rights that follow from that control.
18. Scope of the judicial finding
The Förvaltningsrätten decides the lawfulness of the two grounds on which the access request was refused. The compensation claim later formulated under Article 82 was not the subject of that judgment.
That is precisely what makes the two documents analytically fit together: the first supplies the judicial finding on the unlawful restriction of access; the second places that finding into the damage and causation structure opened by the Court of Justice under Article 82.
19. Conclusion
The eight-page judgment from UmeĂĄ is an unusually compact example of how an apparently narrow access dispute becomes a much broader GDPR issue.
The municipality treated the information need as already satisfied and treated access traces as technical information outside the data-subject right. The court rejected both routes. Earlier disclosure under another legal basis is insufficient to trigger Article 12(5), and access information about time and purpose belongs within the control sphere of Article 15.
The decisive next step comes from the very case law used by the court. Brillen Rottler expressly connects infringement of the right of access with Article 82 and places loss of control and uncertainty about processing within the concept of non-material damage. Pankki S shows what information makes that control practical.
The judgment therefore anchors a clear causal chain:
right of access → unlawful restriction → missing control over processing and access → impaired verification and correction → continuing loss of control and non-material harm → compensation claim under Article 82.
That is the broad effect of this narrow judgment.
20. Sources
20.1. Core documents
- Förvaltningsrätten i Umeå: anonymised eight-page judgment concerning the partial refusal of a GDPR access request by the Social Welfare Committee of Svalövs kommun.
- Subsequent compensation claim under Article 82 GDPR: Swedish original text, analysed in the mini-corpus as the documented construction of the compensation claim.
20.2. EU law
- Regulation (EU) 2016/679 – General Data Protection Regulation, in particular Articles 12, 15, 16, 18, 19 and 82.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
20.3. Court of Justice of the European Union
- Brillen Rottler, C-526/24, EU:C:2026:216 – Article 12(5); Article 15(1); abusive access requests; Article 82; damage resulting from infringement of the right of access; loss of control and uncertainty about processing.
- Pankki S, C-579/21, EU:C:2023:501 – Article 15; information concerning consultations of personal data; dates and purposes of access.
- Österreichische Datenschutzbehörde, C-416/23, EU:C:2025:3 – excessive requests and proof of abusive purpose.
- Österreichische Post, C-300/21, EU:C:2023:370 – conditions of Article 82; no general seriousness threshold for non-material damage.
- Natsionalna agentsia za prihodite, C-340/21, EU:C:2023:986 – fear of possible future misuse of personal data as non-material damage.
- Scalable Capital, Joined Cases C-182/22 and C-189/22, EU:C:2024:531 – full and effective compensation for non-material damage actually suffered.
- Quirin Privatbank, C-655/23, EU:C:2025:655 – loss of control and resulting negative feelings within the concept of non-material damage.
21. Original judgment – complete page images
The judgment is reproduced here unchanged in the original Swedish.







