Civil Law And Cross-Border Data Transfer Breach Litigation In Europe .
Civil Law and Cross-Border Data Transfer Breach Litigation in Europe
1. Introduction
Cross-border data transfer breach litigation arises when personal data is transferred from one country to another and the transfer, processing, security measures, or subsequent disclosure allegedly violates data-protection law.
Typical situations include:
an EU company transferring employee data to a non-EU parent company;
a cloud provider storing European customer data outside the EU;
an online platform transferring user data to servers in another country;
a bank sending customer information to an overseas group company;
an employer transferring HR data internationally;
a processor in a third country suffering a cyberattack;
a company using Standard Contractual Clauses (SCCs) for international transfers;
disclosure of transferred data to foreign government authorities;
onward transfer from one third country to another.
The central legal framework is the GDPR, especially Articles 44–49 concerning international transfers and Article 82 concerning compensation.
A major feature of European law is that a lawful transfer is not merely a question of whether paperwork exists. The controller must consider whether the transfer mechanism and the actual protection available in the destination country provide the level of protection required by EU law. This principle is central to Schrems I and Schrems II. (curia)
2. Meaning of Cross-Border Data Transfer
A transfer may be cross-border where personal data moves:
EU/EEA → third country
or through a chain such as:
EU controller → EU processor → US cloud provider → subcontractor in another country
Examples of personal data include:
names;
addresses;
identification numbers;
financial information;
health information;
employment records;
biometric data;
location data;
online identifiers;
customer profiles;
communications.
The fact that the data is transferred electronically does not make the transfer legally insignificant.
3. Parties That May Be Liable
Several parties may potentially be involved.
1. Controller
The organisation deciding why and how personal data is processed.
2. Processor
An entity processing personal data on behalf of the controller.
3. Sub-processor
A processor engaged by another processor.
4. Recipient
The organisation receiving the transferred information.
5. Data importer
The organisation receiving personal data outside the EU/EEA.
6. Group company
A foreign parent, subsidiary or affiliate receiving data.
The identity of the legally responsible party is critical to an Article 82 compensation claim.
4. Main European Legal Framework
A. GDPR Articles 44–49
These provisions regulate transfers of personal data to third countries and international organisations.
Broadly, transfers can rely upon mechanisms such as:
adequacy decisions;
appropriate safeguards;
Standard Contractual Clauses;
Binding Corporate Rules;
certain derogations in limited circumstances.
But a transfer mechanism does not operate in isolation from the actual circumstances of the transfer.
5. Adequacy Decisions
An adequacy decision means the European Commission has determined that a third country or specified framework provides an adequate level of protection.
Where an adequacy decision applies, transfers can generally take place without the controller having to rely upon Article 46 safeguards for that transfer.
However, the adequacy framework remains subject to European legal review.
The history of the EU-US transfer arrangements demonstrates the importance of this issue.
6. Standard Contractual Clauses
SCCs are contractual safeguards used for international transfers.
They allocate obligations between:
exporter;
importer;
controller;
processor;
sometimes third-party beneficiaries.
However, Schrems II established that SCCs do not automatically make every transfer lawful.
The parties must consider whether the law and practices of the destination country undermine the protection required by EU law. (curia)
7. Supplementary Measures
Where SCCs alone do not provide sufficient protection, organisations may need additional safeguards.
Possible measures include:
strong encryption;
pseudonymisation;
technical access restrictions;
strict key management;
minimisation;
contractual restrictions;
organisational safeguards.
The appropriate measures depend on the nature of the transfer and the risks involved.
8. Schrems I — The Foundational Case
Maximillian Schrems v Data Protection Commissioner
Case C-362/14
Court
Court of Justice of the European Union, Grand Chamber.
Background
Max Schrems challenged the transfer of his personal data by Facebook Ireland to the United States.
The dispute concerned the EU-US Safe Harbour framework.
Decision
The CJEU invalidated the European Commission's Safe Harbour adequacy decision.
It also confirmed that national supervisory authorities retain important powers to examine complaints concerning international transfers. (InfoCuria)
Principle
A third country must provide a level of protection essentially equivalent to that guaranteed within the EU legal order.
Civil-law importance
The case established the foundation for subsequent transfer disputes involving:
international cloud services;
multinational corporations;
social media;
outsourcing;
foreign government access;
employee-data transfers.
Classification: Direct and foundational authority.
9. Schrems II — The Most Important Transfer Authority
Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems
Case C-311/18
Court
CJEU, Grand Chamber.
Facts
The case again concerned transfers of personal data from Facebook Ireland to the United States.
The principal transfer mechanisms included:
adequacy decisions;
Standard Contractual Clauses.
Decision
The CJEU invalidated the EU-US Privacy Shield adequacy decision.
At the same time, it upheld the validity in principle of the Commission's Standard Contractual Clauses, subject to effective protection and assessment of the circumstances of the transfer. (curia)
Major principle
The exporter and recipient cannot treat SCCs as a purely formal contractual exercise.
They must consider:
the law of the destination country;
access by public authorities;
available legal remedies;
actual effectiveness of safeguards;
whether additional measures are necessary.
Civil-law significance
A defective international transfer can become the foundation for:
injunction proceedings;
regulatory proceedings;
suspension of transfers;
contractual disputes;
compensation claims.
Classification: Direct and foundational authority.
10. Article 82 GDPR: Civil Compensation
Article 82 creates a right to compensation where a person suffers material or non-material damage as a result of an infringement of the GDPR.
Three elements are particularly important:
1. GDPR infringement
There must be an infringement.
2. Damage
The claimant must establish material or non-material damage.
3. Causal connection
The damage must result from the infringement.
The CJEU has repeatedly treated these as cumulative requirements. (InfoCuria)
11. Case: Österreichische Post
UI v Österreichische Post AG
Case C-300/21
Facts
Österreichische Post processed personal information to determine individuals' political affinities.
The claimant argued that the processing caused distress and reputational harm.
CJEU ruling
The Court held that:
mere infringement of the GDPR does not automatically create a right to compensation;
actual material or non-material damage must exist;
however, non-material damage does not have to reach a particular minimum seriousness threshold. (InfoCuria)
Importance for transfer litigation
A claimant cannot simply argue:
“My data was transferred unlawfully, therefore I automatically receive damages.”
The claimant must establish the legally relevant damage and causal connection.
Classification: Direct Article 82 authority; closely applicable to transfer claims.
12. Case: Natsionalna agentsia za prihodite
VB v Natsionalna agentsia za prihodite
Case C-340/21
Facts
The Bulgarian National Revenue Agency suffered a cyberattack.
Personal data concerning millions of individuals was accessed and published.
Affected persons sought compensation, including for fear that their information might subsequently be misused.
CJEU ruling
The Court examined:
security obligations;
controller responsibility;
Article 32 GDPR;
Article 82 compensation;
non-material damage.
The Court recognized that fear of future misuse can constitute non-material damage where the circumstances establish actual damage rather than merely abstract concern. (InfoCuria)
Cross-border transfer relevance
The case is highly useful where:
EU personal data → foreign processor → security breach.
The claimant can potentially combine:
transfer violation + inadequate security + actual damage
in a civil claim.
Classification: Direct Article 82/security authority; closely applicable to cross-border transfers.
13. Case: Krankenversicherung Nordrhein
ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein
Case C-667/21
Court
CJEU.
Subject
Processing of health-related personal data and compensation under Article 82 GDPR.
Importance
The Court examined:
lawful processing;
special-category data;
Article 82 liability;
non-material damage;
the compensatory character of GDPR damages.
The decision confirms that Article 82 is fundamentally compensatory rather than punitive. (InfoCuria)
Transfer relevance
This is especially important where international transfers involve:
medical records;
insurance data;
employee health information;
genetic information;
other special-category data.
Classification: Direct GDPR damages authority; closely relevant to international transfers.
14. Case: MediaMarktSaturn
VB v MediaMarktSaturn
Case C-687/21
Facts
Personal data was accidentally provided to an unauthorized third party because of an employee error.
CJEU ruling
The Court explained that merely showing an employee accidentally handed information to an unauthorized person is not, by itself, enough to establish that the controller's technical and organisational measures were inappropriate.
The adequacy of the security measures must be assessed.
The Court also confirmed that Article 82 compensation is compensatory, not punitive. (InfoCuria)
Cross-border significance
The case is useful where an international transfer results from:
employee error;
incorrect recipient;
accidental disclosure;
inadequate organisational controls.
Classification: Direct GDPR security/liability authority.
15. Case: Gemeinde Ummendorf
VX and AT v Gemeinde Ummendorf
Case C-456/22
Facts
Personal data was published online without the required legal basis.
The claim concerned non-material damage.
Principle
The CJEU clarified that a mere GDPR infringement does not automatically create compensable damage.
However, actual loss of control over personal data can constitute non-material damage where the claimant demonstrates that such damage was actually suffered. (InfoCuria)
Transfer relevance
This principle can apply when transferred data is:
disclosed;
made accessible;
copied;
published;
exposed to unauthorized recipients.
Classification: Direct Article 82 authority.
16. Case: Scalable Capital
Scalable Capital
Joined Cases C-182/22 and C-189/22
Subject
GDPR compensation and loss of control over personal data.
Principle
The CJEU continued developing the rules concerning:
existence of damage;
non-material damage;
causal connection;
compensation.
Later CJEU case law expressly relies on this authority when explaining that Article 82 requires an infringement, actual damage and a causal link. (Curia)
Cross-border relevance
It is particularly useful in large-scale data incidents involving:
financial data;
customer databases;
international processors;
cloud platforms.
Classification: Direct GDPR damages authority.
17. Case: EDPS v SRB
European Data Protection Supervisor v Single Resolution Board
Case C-413/23 P
Judgment
4 September 2025.
Subject
The case concerned pseudonymised data transferred to Deloitte during proceedings concerning compensation for shareholders and creditors following the resolution of Banco Popular Español.
Principle
The CJEU examined when pseudonymised information remains personal data in the hands of a recipient and clarified the relationship between pseudonymisation and data-protection obligations. (InfoCuria)
Importance
This is particularly relevant to modern cross-border transfers involving:
financial institutions;
consultants;
auditors;
litigation experts;
regulators;
resolution authorities.
It demonstrates that changing identifiers or pseudonymising data does not automatically remove GDPR considerations.
Classification: Direct and recent European data-transfer/pseudonymisation authority.
18. Summary of the Major Cases
| Case | Main principle | Relevance |
|---|---|---|
| Schrems, C-362/14 | Safe Harbour invalid; supervisory control over transfers | Direct |
| Schrems II, C-311/18 | Privacy Shield invalid; SCCs subject to effective protection | Direct |
| Österreichische Post, C-300/21 | Infringement alone does not establish compensation | Direct Article 82 |
| Natsionalna agentsia za prihodite, C-340/21 | Security breach, controller responsibility and non-material damage | Direct/close |
| Krankenversicherung Nordrhein, C-667/21 | Compensation is compensatory; special-category data | Direct GDPR |
| MediaMarktSaturn, C-687/21 | Security measures and employee error | Direct GDPR |
| Gemeinde Ummendorf, C-456/22 | Loss of control and actual non-material damage | Direct GDPR |
| Scalable Capital, C-182/22 & C-189/22 | Damage and causal link under Article 82 | Direct GDPR |
| EDPS v SRB, C-413/23 P | Pseudonymised data and personal-data concept | Direct/recent |
19. Civil Liability for an Unlawful International Transfer
A typical claim can be analyzed through the following structure.
Step 1 — Personal data
Was the information personal data under the GDPR?
Step 2 — Controller/processor
Who determined the purpose and means of processing?
Step 3 — Transfer
Was the data transferred to a third country?
Step 4 — Transfer mechanism
Was the transfer based upon:
adequacy;
SCCs;
Binding Corporate Rules;
another Article 49 derogation?
Step 5 — Destination-country protection
Does the legal environment in the destination country undermine the required level of protection?
Step 6 — Supplementary measures
Were technical and organisational safeguards sufficient?
Step 7 — Breach
Did the controller or processor violate the GDPR?
Step 8 — Damage
Did the individual suffer material or non-material damage?
Step 9 — Causation
Was the damage caused by the GDPR infringement?
Step 10 — Remedy
What compensation, injunction or other relief is available?
20. Material Damage
Material damage may include demonstrable financial loss resulting from the breach.
Examples:
financial fraud;
identity-theft losses;
costs of restoring accounts;
unauthorized transactions;
expenses caused by the breach;
certain consequential financial losses.
The claimant must establish the connection between the unlawful processing/transfer and the loss.
21. Non-Material Damage
Non-material damage can include consequences such as:
anxiety;
fear of misuse;
reputational harm;
loss of control;
distress;
exposure of sensitive information.
But the CJEU has made an important distinction:
A GDPR infringement by itself is not automatically compensable damage.
Actual damage must be established. At the same time, European law does not impose a universal minimum seriousness threshold for non-material damage. (curia)
22. Fear of Future Misuse
This is particularly important in international transfers.
Suppose:
An EU company sends customer data to a foreign processor. The processor suffers a breach. The customer fears that criminals may use the information.
The claimant must establish legally relevant damage rather than relying solely upon a hypothetical possibility.
The CJEU has nevertheless recognized that genuine fear of future misuse can, depending on the facts, constitute non-material damage. (curia)
23. Security Obligations
Article 32 GDPR requires appropriate technical and organisational measures.
Possible measures include:
encryption;
access controls;
authentication;
pseudonymisation;
monitoring;
incident-response systems;
employee training;
data minimisation;
secure deletion.
The assessment is risk-based.
A company is not required to guarantee that a cyberattack can never happen.
24. Liability for Processor Conduct
A controller may engage a processor in another country.
Example:
German company → Irish controller → US cloud processor.
The controller cannot simply assume that the processor's foreign location eliminates its responsibility.
The contractual and GDPR relationship between:
controller;
processor;
sub-processor
must be examined.
25. Onward Transfers
An international transfer may involve several stages.
For example:
France → United States → India → Singapore.
The first transfer may satisfy one legal mechanism, but the subsequent transfer may require separate analysis.
This creates an important civil-litigation question:
At what stage did the GDPR protection become inadequate?
Evidence concerning the entire transfer chain may therefore become important.
26. Group Companies and Intra-Group Transfers
Multinational companies frequently transfer data between:
parent companies;
subsidiaries;
shared-service centres;
HR departments;
central IT systems.
Common examples include:
employee databases;
customer records;
compliance information;
fraud-prevention systems;
central CRM platforms.
Binding Corporate Rules may be relevant for certain intra-group transfers, but corporate ownership alone does not eliminate GDPR obligations.
27. Cloud Computing
Cloud arrangements are a major source of cross-border data-transfer issues.
A European company may not know precisely where data is processed at every stage.
Possible locations include:
EU data centres;
US data centres;
backup facilities;
disaster-recovery systems;
subcontractor facilities.
A civil claim may therefore require examination of:
data-location architecture;
processor contracts;
sub-processing;
encryption;
access rights;
government-access risks.
28. Government Access in the Destination Country
One of the most important issues following Schrems II is whether authorities in the destination country can access transferred information.
The legal analysis may concern:
surveillance legislation;
intelligence powers;
law-enforcement access;
judicial remedies;
proportionality;
independent oversight.
This is why an SCC cannot simply be treated as a piece of paperwork detached from the legal environment of the importing country. (curia)
29. Jurisdiction in Cross-Border Data Litigation
A claimant may potentially bring proceedings in different jurisdictions depending upon:
defendant's establishment;
controller's establishment;
processor's establishment;
place of the claimant;
place where damage occurred;
applicable GDPR jurisdictional rules.
This can create forum and procedural disputes before the substantive merits are even considered.
30. Supervisory Proceedings vs Civil Litigation
Two different legal routes should be distinguished.
Administrative route
A data-protection authority may:
investigate;
order compliance;
restrict processing;
prohibit transfers;
impose administrative fines.
Civil route
An individual may seek:
compensation;
judicial relief;
injunction;
declaration of rights.
These routes can coexist.
A regulatory finding may be highly relevant evidence, but the requirements for a private compensation claim must still be analyzed independently.
31. Compensation Is Not a Penalty
The CJEU has repeatedly emphasized that Article 82 compensation is compensatory rather than punitive.
Therefore, the amount should correspond to the damage actually suffered rather than function as a punishment merely because the infringement was particularly serious. (InfoCuria)
This is an important distinction from administrative fines under Article 83 GDPR.
32. Burden of Proof and Security Measures
Recent CJEU jurisprudence is particularly important concerning the controller's responsibility for security.
In the context of Article 82 claims, the Court has held that the controller bears an important burden concerning whether the security measures implemented were appropriate under Article 32. (Curia)
This can be highly significant in litigation following an international transfer or data breach.
33. Defences Available to Controllers
A controller may argue:
1. Lawful transfer mechanism
The transfer relied on a valid legal mechanism.
2. Adequate safeguards
Appropriate safeguards were implemented.
3. No GDPR infringement
The processing complied with the GDPR.
4. Appropriate security
The controller implemented appropriate technical and organisational measures.
5. No actual damage
The claimant has demonstrated only an infringement, not compensable damage.
6. No causal link
The alleged loss did not result from the transfer.
7. Third-party attack
The breach resulted from an external criminal act.
This defence does not automatically eliminate liability; the controller's own GDPR responsibilities must be assessed.
8. Hypothetical harm
The alleged future misuse is merely speculative.
9. Wrong defendant
Another entity was actually the controller or processor responsible for the relevant operation.
34. Remedies
Potential remedies include:
Compensation
For material or non-material damage.
Injunction
To prevent further unlawful transfers.
Suspension of transfer
Where continued processing is unlawful.
Erasure
Where GDPR requirements are satisfied.
Restriction
Temporary limitation of processing.
Correction
Where inaccurate information has been transferred.
Declaration
Judicial declaration concerning the legality of processing.
Regulatory measures
Separately, a supervisory authority may impose administrative measures.
35. Evidence in Cross-Border Transfer Litigation
Important evidence includes:
| Evidence | Legal significance |
|---|---|
| SCCs | Transfer mechanism |
| Adequacy decision | Legal basis |
| Data-transfer agreement | Contractual obligations |
| Data-flow map | Where information travels |
| Processor agreement | Allocation of responsibility |
| Sub-processor list | Further transfers |
| Encryption records | Security |
| Access logs | Who accessed data |
| Privacy notices | Transparency |
| DPIA | Risk assessment |
| Transfer Impact Assessment | Destination-country analysis |
| Incident report | Nature of breach |
| Government-access records | Destination-country risk |
| Expert evidence | Technical security |
| Financial records | Material damage |
36. Practical Example
Facts
A French company collects European customer information.
It transfers the information to a US-based cloud provider.
The parties use SCCs.
The US processor suffers a cybersecurity incident and customer information becomes accessible to unauthorized persons.
Legal analysis
1. Controller:
French company.
2. Processor:
US cloud provider.
3. Transfer:
EU → third country.
4. Transfer mechanism:
SCCs.
5. Schrems II issue:
Were SCCs accompanied by adequate protection and, where necessary, supplementary measures?
6. Security issue:
Were appropriate technical and organisational measures used?
7. Damage:
Did customers actually suffer material or non-material damage?
8. Causation:
Did the damage result from the GDPR infringement?
9. Remedy:
Potential Article 82 compensation and/or other GDPR remedies.
This illustrates how transfer legality and breach liability are related but distinct questions.
37. Special Issues in Cross-Border Transfer Litigation
Modern cases increasingly involve:
AI training datasets;
international cloud infrastructure;
biometric databases;
genetic data;
financial information;
employee monitoring;
remote-work platforms;
multinational HR systems;
global cybersecurity operations;
international advertising platforms;
ad-tech;
data brokers;
pseudonymised datasets;
automated decision-making.
The 2025 EDPS v SRB judgment is particularly useful for understanding why pseudonymisation does not necessarily take information outside data-protection law. (InfoCuria)
38. Direct vs Closely Applicable Authorities
| Authority | Classification |
|---|---|
| Schrems, C-362/14 | Direct international-transfer case |
| Schrems II, C-311/18 | Direct international-transfer case |
| Natsionalna agentsia za prihodite, C-340/21 | Direct GDPR breach/security authority |
| Österreichische Post, C-300/21 | Direct compensation authority |
| Krankenversicherung Nordrhein, C-667/21 | Direct compensation/special-data authority |
| MediaMarktSaturn, C-687/21 | Direct security/liability authority |
| Gemeinde Ummendorf, C-456/22 | Direct Article 82 authority |
| Scalable Capital, C-182/22 & C-189/22 | Direct Article 82 authority |
| EDPS v SRB, C-413/23 P | Direct/recent personal-data-transfer authority |
39. Exam-Oriented Legal Test
For a problem concerning cross-border data transfer, follow this sequence:
1. Identify the personal data
↓
2. Identify controller and processor
↓
3. Identify the transfer and destination country
↓
4. Identify the Article 44–49 transfer mechanism
↓
5. Examine adequacy/SCC/BCR/derogation
↓
6. Assess destination-country legal risks
↓
7. Examine supplementary safeguards
↓
8. Examine security under Articles 5, 24 and 32
↓
9. Establish GDPR infringement
↓
10. Establish material/non-material damage
↓
11. Establish causal connection
↓
12. Determine Article 82 compensation
↓
13. Consider injunction, restriction or other remedies
↓
14. Determine cross-border jurisdiction and enforcement
40. Quick Revision Table
| Issue | Key rule |
|---|---|
| International transfer | GDPR Articles 44–49 apply |
| Adequacy | Destination must provide required level of protection |
| SCCs | Contractual safeguards, not automatic immunity |
| Schrems I | Safe Harbour invalidated |
| Schrems II | Privacy Shield invalidated; SCCs upheld in principle subject to effective protection |
| Security | Appropriate technical/organisational measures required |
| Article 82 | Compensation for material/non-material damage |
| Mere infringement | Not automatically compensable |
| Non-material damage | No universal minimum seriousness threshold |
| Causation | Must connect infringement and damage |
| Compensation | Compensatory, not punitive |
| Fear of misuse | May constitute damage if genuine/actual rather than purely hypothetical |
| Pseudonymisation | Does not automatically remove GDPR protection |
| Enforcement | Civil compensation and regulatory proceedings are distinct |
Conclusion
Cross-border data transfer breach litigation in Europe is a combination of GDPR substantive law, international-transfer rules and civil liability. The central issue is not simply whether data crossed a national border, but whether the transfer and subsequent processing maintained the level of protection required by EU law.
The two foundational transfer cases are Schrems (C-362/14) and Schrems II (C-311/18). The subsequent Article 82 cases—including Österreichische Post (C-300/21), Natsionalna agentsia za prihodite (C-340/21), Krankenversicherung Nordrhein (C-667/21), MediaMarktSaturn (C-687/21), Gemeinde Ummendorf (C-456/22) and Scalable Capital (C-182/22 and C-189/22)—develop the separate question of when an unlawful processing operation gives rise to compensable damage. (curia)
The basic civil-law formula is:
Unlawful transfer/processing + GDPR breach + actual damage + causal connection = potential civil compensation, subject to the applicable procedural, jurisdictional and remedial rules.

comments