Civil Law And Data Brokerage Misuse Claims In Europe .

Civil Law And Data Brokerage Misuse Claims In Europe

1. Introduction

Data brokerage misuse claims arise when companies collect personal data from multiple sources, combine it into profiles, infer characteristics about individuals, sell or license those profiles to third parties, or otherwise monetise personal information in ways that may exceed the individual's reasonable expectations or violate data-protection law.

The European Data Protection Board's 2026 Data Brokers Market Study describes data brokers as businesses that collect information from multiple public and private sources, process it to develop consumer profiles, monetise that information, and may operate without giving individuals meaningful information or control over how their data is collected or used. (European Data Protection Board)

In Europe, such disputes are primarily governed by:

GDPR (Regulation (EU) 2016/679);

EU Charter of Fundamental Rights;

national civil/privacy laws;

consumer-protection law;

ePrivacy rules where applicable;

competition law in some cases;

Digital Services Act in relevant platform situations;

national procedural and damages rules.

The central civil-law question is:

When does legitimate data collection become unlawful data exploitation, and what remedies does the individual have?

2. Meaning of Data Brokerage

A data broker typically obtains information from several sources and creates or enriches profiles concerning individuals.

Sources can include:

websites;

mobile applications;

loyalty programmes;

public registers;

commercial databases;

advertising networks;

social-media information;

location information;

purchase records;

cookies and tracking technologies;

data obtained from other companies.

The broker may then:

Collect → combine → analyse → infer → profile → sell/license/share

the resulting information.

Example

Company A collects:

person's age;

postal address;

online browsing;

shopping history;

location information.

Company B provides:

credit-related information.

Company C provides:

demographic information.

A broker combines everything and sells:

"High-income consumer, likely to purchase luxury financial products."

The individual may argue that the resulting profile was created or used unlawfully.

3. Why Data Brokerage Creates Civil Liability Issues

Data brokerage creates several possible legal problems.

Main issues

unlawful collection;

lack of transparency;

absence of valid legal basis;

incompatible secondary use;

excessive data collection;

inaccurate information;

unlawful profiling;

unlawful automated decision-making;

disclosure to undisclosed recipients;

sale to third parties;

processing of sensitive data;

unlawful international transfer;

failure to honour access/erasure rights;

inadequate security;

emotional or reputational harm;

financial loss.

4. The GDPR Is the Main Legal Framework

The GDPR provides the central European framework.

Important principles include:

Article 5

Processing must comply with principles including:

lawfulness;

fairness;

transparency;

purpose limitation;

data minimisation;

accuracy;

storage limitation;

integrity and confidentiality;

accountability.

Article 6

Processing needs a lawful basis.

Possible bases include:

consent;

contract;

legal obligation;

vital interests;

public task;

legitimate interests.

Article 9

Special categories of personal data receive stronger protection.

Article 12–15

Individuals receive transparency and access rights.

Article 16

Right to rectification.

Article 17

Right to erasure in applicable circumstances.

Article 18

Right to restriction.

Article 20

Data portability.

Article 21

Right to object.

Article 22

Protection concerning certain solely automated decisions.

Article 82

Right to compensation for material and non-material damage caused by GDPR infringement.

5. First Case — Österreichische Post, C-154/21

CJEU, RW v Österreichische Post AG, C-154/21, 12 January 2023

This is highly relevant to data-brokerage disputes.

Österreichische Post processed personal information and generated information concerning individuals. The claimant wanted to know to whom his personal data had been disclosed.

The CJEU held that, where personal data have been or will be disclosed to recipients, the controller must generally provide the actual identity of those recipients, rather than merely their categories, where those recipients can be identified. (InfoCuria)

Data-broker relevance

Imagine a broker says:

"Your data were shared with marketing partners."

That may be insufficient where the GDPR requires identification of the actual recipients.

Principle

A data subject's access rights can extend to identifying actual data recipients.

This is particularly important where data have passed through a chain of brokers.

6. Second Case — Österreichische Datenschutzbehörde and CRIF, C-487/21

CJEU, C-487/21, 4 May 2023

The case concerned CRIF, a company involved in information services, and the data subject's right of access under Article 15 GDPR.

The CJEU held that the right to obtain a copy of personal data can require the controller to provide a faithful and intelligible reproduction of the personal data being processed, where necessary to enable the individual to exercise GDPR rights effectively. (InfoCuria)

Data-broker relevance

A data broker cannot necessarily respond:

"We hold information about you."

and provide only a vague summary.

The individual may need sufficient information to determine:

what data are held;

whether data are accurate;

where data came from;

how they are being processed;

whether information has been combined incorrectly.

Principle

Access must be sufficiently meaningful to enable the individual to exercise GDPR rights.

7. Third Case — Österreichische Post, C-300/21

CJEU, UI v Österreichische Post AG, C-300/21, 4 May 2023

This is one of the most important cases concerning compensation.

The CJEU held that three conditions are necessary for compensation under Article 82 GDPR:

infringement of the GDPR;

damage suffered by the data subject;

causal link between the infringement and damage.

A mere GDPR infringement, without damage, does not automatically create a right to compensation. The Court also rejected a national rule requiring non-material damage to exceed a particular seriousness threshold before compensation could be awarded. (InfoCuria)

Data-broker example

A broker unlawfully processes someone's data.

The person cannot simply say:

"GDPR was breached, therefore I automatically receive damages."

They must establish the legally relevant damage and causal connection.

Possible damage

anxiety;

loss of control over personal information;

reputational damage;

discrimination;

financial loss.

But the precise existence and amount of damage remain matters for the competent national court.

8. Fourth Case — Meta Platforms, C-252/21

CJEU, Meta Platforms and Others v Bundeskartellamt, C-252/21, 4 July 2023

This case is particularly important for large-scale data aggregation and profiling.

Meta combined data collected:

directly from Facebook;

from other Meta services;

from third-party websites and applications.

The combined data could produce detailed conclusions concerning users' interests and preferences. (InfoCuria)

The CJEU examined the interaction between GDPR compliance and competition law.

It held, among other things, that a competition authority may consider GDPR compliance when assessing abuse of dominance, while respecting the powers of data-protection authorities. (curia)

The Court also examined the requirements for lawful processing, including consent, contractual necessity and legitimate interests. It stated that personalised advertising could not simply be justified as a legitimate interest in the circumstances without the required consent. (curia)

Data-broker relevance

The case is highly relevant to:

cross-platform data combination;

behavioural profiling;

targeted advertising;

secondary use;

consent;

economic exploitation of personal data.

Principle

Combining information from different sources can create a separate GDPR problem; the legality of each underlying collection does not automatically make every subsequent combination lawful.

9. Fifth Case — Schrems II, C-311/18

CJEU, Data Protection Commissioner v Facebook Ireland and Schrems, C-311/18, 16 July 2020

The CJEU invalidated the EU-US Privacy Shield while upholding the validity of standard contractual clauses subject to appropriate safeguards and assessment of the actual level of protection in the receiving country. (curia)

Data-broker relevance

Data brokers frequently operate internationally.

A broker may transfer data:

Europe → US → analytics provider → advertising partner

The fact that a company has contractual relationships with a recipient does not automatically make the transfer lawful.

The controller must consider:

destination-country law;

safeguards;

access by public authorities;

effective remedies;

GDPR transfer requirements.

Principle

International monetisation of personal data must satisfy EU transfer requirements.

10. Sixth Case — Nowak, C-434/16

CJEU, Peter Nowak v Data Protection Commissioner, C-434/16, 20 December 2017

The CJEU interpreted "personal data" broadly.

Information qualifies as personal data where it is related to an identified or identifiable individual, directly or indirectly.

The Court treated information contained in examination scripts and examiner comments as personal data in the circumstances.

Data-broker relevance

Data brokers often argue that certain information is merely:

"commercial data,"
"analytics,"
"scores," or
"profiles."

But the legal question is whether the information relates to an identifiable person.

Principle

Information does not cease to be personal data merely because it has been transformed into an analytical or commercial profile.

11. Seventh Case — OT v Vyriausioji tarnybinės etikos komisija, C-184/20

CJEU, C-184/20, 1 August 2022

The CJEU dealt with the processing and publication of information capable of revealing special-category personal data.

The Court interpreted the protection of sensitive personal data broadly where information can reveal sensitive characteristics indirectly.

Data-broker relevance

This is highly significant for inferred data.

Suppose a broker does not directly collect:

"Person X has condition Y."

Instead, it collects:

searches;

purchases;

website visits;

pharmacy-related information;

location patterns.

It then infers a sensitive characteristic.

The legal analysis cannot necessarily avoid Article 9 simply by saying:

"We never directly collected the sensitive information."

Principle

Inferences can have serious data-protection consequences when they reveal specially protected information.

12. Eighth Case — Google Spain, C-131/12

CJEU, Google Spain SL and Google Inc. v AEPD and Mario Costeja González, C-131/12, 13 May 2014

The CJEU established the famous right to delisting/de-referencing framework.

A person can, under the applicable conditions, request removal of search-engine links from results relating to their name where the continued accessibility of the information is incompatible with EU data-protection law.

Data-broker relevance

Data brokers similarly aggregate information and make it accessible to commercial customers.

The case illustrates a broader European principle:

Individuals retain legal rights concerning the continuing dissemination and accessibility of personal information.

It is therefore relevant to claims involving:

outdated profiles;

inaccurate information;

excessive retention;

reputational harm;

commercial dissemination.

13. Ninth Case — Wirtschaftsakademie, C-210/16

CJEU, Wirtschaftsakademie Schleswig-Holstein, C-210/16, 5 June 2018

The CJEU considered responsibility for processing involving a Facebook fan page.

It recognised circumstances in which an entity that participates in determining the purposes and means of processing can be a joint controller, even where it does not itself possess the underlying personal data.

Data-broker relevance

Data brokerage frequently involves several participants:

Website → platform → broker → analytics company → advertiser

An organisation may attempt to argue:

"We did not technically possess the database."

But legal responsibility can depend on influence over the purposes and means of processing, not simply physical possession of the data.

Principle

Control over processing can be more important than physical possession of the database.

14. Tenth Case — Fashion ID, C-40/17

CJEU, Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW, C-40/17, 29 July 2019

The CJEU examined the use of Facebook's "Like" button on a website.

It held that a website operator can be a joint controller with Facebook for certain collection and transmission operations, even though it did not determine all subsequent processing.

Data-broker relevance

This is highly relevant to data supply chains.

A company cannot necessarily avoid responsibility merely because:

"Another company actually processed the information."

Principle

Different stages of a data-processing chain can create different forms of responsibility.

15. What Counts as Data-Broker Misuse?

A data-broker misuse claim may involve any of the following.

1. Unlawful collection

Data obtained without an appropriate legal basis.

2. Purpose incompatibility

Data collected for one purpose are subsequently used for another incompatible purpose.

3. Excessive collection

The broker collects substantially more information than necessary.

4. Unlawful profiling

Information is combined to create intrusive behavioural profiles.

5. Sensitive inference

Ordinary information is used to infer health, political, religious or other sensitive characteristics.

6. Unlawful disclosure

Data are sold or supplied to recipients without an adequate legal basis.

7. Inaccurate profile

Broker maintains incorrect information.

8. Failure to erase

Broker refuses a legally valid erasure request.

9. Undisclosed recipients

Individual cannot determine who received the information.

10. International transfer

Data are transferred to countries without adequate safeguards.

16. Data Brokerage and Lawful Basis

The most important question is:

Why is the broker legally allowed to process this data?

A broker might rely on:

consent;

legitimate interests;

contractual necessity;

another Article 6 basis.

But the chosen basis must actually fit the processing.

The Meta Platforms judgment is particularly important because the CJEU scrutinised attempts to rely on contractual necessity and legitimate interests for extensive combination and advertising-related processing. (curia)

17. Legitimate Interest

A broker may argue:

"We have a legitimate commercial interest in selling consumer profiles."

That does not automatically end the inquiry.

The controller generally needs to consider:

legitimate interest;

necessity;

balancing against the individual's rights and freedoms.

Where processing is highly intrusive, extensive or unexpected, the balancing exercise becomes particularly important.

18. Consent

Consent must satisfy GDPR requirements.

A data broker should not assume that:

"The individual clicked Accept"

automatically proves valid consent for every subsequent use.

Issues can include:

informed consent;

specific consent;

freely given consent;

withdrawal;

bundled consent;

imbalance;

unclear purposes.

The CJEU's Meta Platforms judgment specifically examined whether consent in a dominant social-network environment was freely given. (curia)

19. Purpose Limitation

Suppose data are collected for:

"delivery of an online purchase."

The company later sells the same information to a data broker for:

"credit-risk profiling."

That second purpose requires separate legal analysis.

The original collection does not automatically legitimise every subsequent commercial use.

20. Data Minimisation

Data brokerage can conflict with the minimisation principle because brokers may seek to collect more information precisely because additional information improves profiling.

Example:

A broker collects:

age;

income;

location;

browsing;

purchase history;

contacts;

app usage;

device information.

The legal question becomes:

Are all of these categories necessary and justified for the claimed purpose?

21. Accuracy of Broker Profiles

Incorrect broker information can have serious consequences.

Example:

Broker database incorrectly states:

"Person has high credit risk."

A lender purchases the information.

Loan is rejected.

Possible claims may concern:

rectification;

erasure;

access;

objection;

automated decision-making;

compensation where the legal conditions are met.

The GDPR's accuracy principle therefore becomes extremely important in data-broker litigation.

22. Profiling

Profiling means using personal data to evaluate or predict characteristics of an individual.

Possible profiles include:

purchasing behaviour;

financial behaviour;

interests;

location patterns;

employment characteristics;

risk;

consumer preferences.

Data brokers can create profiles from apparently harmless pieces of information.

Example

Individually:

"Person visited three websites."

Combined:

"Person probably intends to purchase a mortgage."

The second statement may have significantly greater legal consequences.

23. Automated Decision-Making

Article 22 GDPR becomes important where profiling leads to certain decisions based solely on automated processing.

Examples:

automatic insurance assessment;

credit decisions;

employment screening;

fraud scoring;

housing decisions.

A data broker may not make the final decision itself but may provide the profile used by another company.

This creates difficult questions concerning:

controller status;

transparency;

meaningful information;

logic involved;

human intervention;

contestability.

24. Sensitive Data

Special categories under Article 9 include information concerning matters such as:

health;

biometric data in relevant circumstances;

racial or ethnic origin;

political opinions;

religious or philosophical beliefs;

trade-union membership;

sexual orientation.

A broker may attempt to avoid Article 9 by saying:

"We did not directly collect the sensitive fact."

But C-184/20 demonstrates the importance of examining whether processing reveals or makes available information falling within enhanced protection.

25. Data Broker and Children's Data

Children receive enhanced protection under EU data-protection law.

Data brokers dealing with:

children's browsing;

educational information;

gaming activity;

location;

behavioural profiles;

may therefore face heightened legal concerns.

The combination of children's data and profiling can be particularly sensitive.

26. Right of Access

A person may ask:

"What personal data do you have about me?"

A broker may have to provide meaningful access.

C-487/21 is especially important because the CJEU interpreted the right to obtain a copy broadly enough to enable effective exercise of the data subject's rights. (InfoCuria)

27. Right to Know Recipients

Under C-154/21, where recipients can be identified, the data subject generally has a right to know their actual identities rather than merely generic categories. (InfoCuria)

This is particularly valuable against data brokers.

Example

Instead of:

"We share data with advertising companies."

the claimant may be entitled, in appropriate circumstances, to information identifying the actual recipients.

28. Right to Erasure

An individual may request deletion in circumstances specified by Article 17 GDPR.

Potential grounds include:

data no longer necessary;

withdrawal of consent;

successful objection;

unlawful processing;

legal obligation requiring erasure.

But erasure is not absolute.

Exceptions can include:

freedom of expression;

legal obligations;

public interest;

establishment/exercise/defence of legal claims.

29. Right to Object

Article 21 is especially important for direct marketing.

A data subject can object to processing for direct marketing purposes, including profiling related to such marketing.

A broker continuing such processing after a valid objection may therefore face serious legal consequences.

30. Data Brokerage and Damage

Article 82 GDPR is central to civil compensation.

Following C-300/21, the basic structure is:

GDPR infringement

  •  

Damage

  •  

Causal link

=

Potential compensation claim

The CJEU has confirmed that a mere infringement without damage is insufficient, while a national minimum seriousness threshold for non-material damage is not permissible in the way rejected in that judgment. (InfoCuria)

31. Material Damage

Material loss may include, depending on the facts and applicable law:

financial loss;

fraudulent transactions;

loss caused by incorrect profiling;

costs incurred to respond to misuse;

other demonstrable economic consequences.

The claimant must establish the legally relevant damage and causation.

32. Non-Material Damage

Possible claims can concern:

anxiety;

distress;

loss of control;

reputational injury;

fear of misuse.

But C-300/21 does not mean every unlawful processing automatically produces compensable non-material damage.

Actual damage and causal connection remain necessary. (InfoCuria)

33. Data Brokerage and Competition Law

Large data brokers can potentially create competition concerns where:

a dominant company controls access to data;

data are combined across services;

rivals cannot compete without equivalent data;

consumers face excessive data extraction;

data processing forms part of an exclusionary strategy.

Meta Platforms, C-252/21 is important because the CJEU recognised that a competition authority can consider GDPR compliance in assessing abuse of dominance, subject to coordination with data-protection authorities. (curia)

34. Data Brokerage and the Digital Services Act

The DSA and GDPR can overlap where online intermediary services process personal data.

The EDPB adopted final Guidelines 3/2025 on the interplay between the DSA and GDPR in September 2026, addressing how the two frameworks should interact where DSA obligations involve personal-data processing. (European Data Protection Board)

Therefore:

Data broker + online platform + targeted advertising

may require analysis under multiple EU digital regimes.

35. International Data Brokerage

A data broker may operate:

EU → US → Singapore → India → EU

Every international transfer raises questions under Chapter V GDPR.

Schrems II demonstrates that contractual safeguards must be assessed alongside the actual legal environment in the destination country. (curia)

36. Joint Controllers

Data brokerage often involves multiple organisations.

For example:

Retailer

↓

Advertising platform

↓

Data broker

↓

Analytics provider

↓

Advertiser

Under Wirtschaftsakademie and Fashion ID, legal responsibility can depend upon participation in determining the purposes and means of relevant processing.

Physical possession of data is therefore not the only question.

37. Controller vs Processor

This distinction is essential.

Controller

Determines purposes and means of processing.

Processor

Processes personal data on behalf of the controller.

A data broker that determines its own commercial purposes may not simply be a passive processor.

The actual contractual and operational relationship must be examined.

38. Data Provenance

One of the most important questions is:

Where did the broker get the data?

Possible sources:

consumer;

public register;

website;

app;

another business;

advertising network;

purchased database.

A broker's obligation to provide information concerning the source of personal data can become important, especially when data were not collected directly from the individual.

39. Data Enrichment

Data brokers frequently perform data enrichment.

Example:

Original database:

Name + address.

Enriched database:

Name + address + income + interests + political preferences + purchasing behaviour + estimated credit risk.

Every additional enrichment operation can raise new questions about:

legal basis;

compatibility;

accuracy;

transparency;

proportionality;

sensitive-data processing.

40. Inferred Data

Inferred data are especially problematic.

Example:

The broker never receives:

"Person is interested in cancer treatment."

But it observes:

repeated medical searches;

pharmacy purchases;

hospital visits;

health-related website activity.

It generates:

"Likely serious medical condition."

The legal analysis must consider the nature and use of the resulting information rather than looking only at the raw source data.

41. Dark Patterns and Data Brokerage

A company may obtain apparently "consented" data through:

confusing interfaces;

preselected choices;

multiple screens;

misleading buttons;

difficult withdrawal;

bundled purposes.

The validity of consent depends upon GDPR requirements, not simply the presence of a checkbox.

42. Data Brokerage and Civil Injunctions

An individual may seek remedies beyond damages.

Depending on national procedural law and the circumstances, possible remedies include:

injunction;

cessation of processing;

deletion;

correction;

restriction;

disclosure;

preservation of evidence.

The GDPR therefore provides a framework that is not limited to monetary compensation.

43. Burden of Proof and Evidence

Data-broker litigation can require evidence concerning:

Technical evidence

databases;

logs;

cookies;

tracking identifiers;

APIs;

data flows.

Commercial evidence

data-sale agreements;

licensing arrangements;

customer lists;

pricing records.

Legal evidence

privacy notices;

consent mechanisms;

legitimate-interest assessments;

data-processing agreements;

records of processing.

Algorithmic evidence

profiling models;

scoring criteria;

automated decision systems.

44. Typical Data-Broker Claim

A claimant might formulate the case as:

"The defendant collected my personal data from multiple sources, combined them without a lawful basis, created an inaccurate profile, disclosed the profile to third parties without adequate transparency, refused my access request and caused me financial and non-material harm."

The legal analysis would proceed:

Personal data?

↓

Processing?

↓

Controller?

↓

Lawful basis?

↓

Purpose limitation?

↓

Transparency?

↓

Accuracy?

↓

Recipients?

↓

Rights violated?

↓

Damage?

↓

Causation?

↓

Remedy?

45. Important Case-Law Table

CaseCourtMain principleData-broker relevance
C-154/21, Österreichische PostCJEUActual recipients may need to be identifiedDisclosure chains
C-487/21, Österreichische Datenschutzbehörde/CRIFCJEUMeaningful copy/access to personal dataBroker databases
C-300/21, Österreichische PostCJEUGDPR infringement + damage + causationCompensation
C-252/21, Meta PlatformsCJEUExtensive data combination and GDPR/competition interactionProfiling and cross-platform data
C-311/18, Schrems IICJEUInternational transfer safeguardsCross-border data brokerage
C-434/16, NowakCJEUBroad concept of personal dataAnalytical profiles
C-184/20CJEUProtection of sensitive/inferred informationSensitive profiling
C-131/12, Google SpainCJEURights concerning continuing dissemination of personal dataCommercial dissemination
C-210/16, WirtschaftsakademieCJEUJoint controllershipData supply chains
C-40/17, Fashion IDCJEUJoint responsibility for collection/transmissionTracking and broker ecosystems

46. Comparison of the Main Cases

C-154/21

Focus:

Who received my data?

C-487/21

Focus:

What data exactly do you have about me?

C-300/21

Focus:

Did your unlawful processing actually cause me compensable damage?

C-252/21

Focus:

Can extensive cross-platform data combination be justified?

C-311/18

Focus:

Can my data legally be transferred outside the EU?

C-434/16

Focus:

What counts as personal data?

C-184/20

Focus:

Can apparently ordinary data reveal sensitive information?

C-131/12

Focus:

Can continuing dissemination of personal information be challenged?

C-210/16 and C-40/17

Focus:

Who is legally responsible when several organisations participate in processing?

47. Defences Available to Data Brokers

A broker may argue:

1. Lawful basis

Processing was based on Article 6.

2. Consent

The individual gave valid consent.

3. Legitimate interest

The processing was necessary for a legitimate commercial interest and properly balanced.

4. Anonymisation

The information was genuinely anonymised and therefore no longer personal data.

5. No damage

The claimant cannot establish compensable damage.

6. No causation

The alleged loss was caused by something else.

7. Data accuracy

The disputed profile was accurate.

8. Statutory exception

The processing fell within an applicable exception.

Each defence depends heavily on the facts.

48. Claimant's Arguments

A claimant may argue:

no lawful basis;

consent was invalid;

processing was unexpected;

purposes were incompatible;

data were excessive;

profile was inaccurate;

sensitive information was inferred;

recipients were not disclosed;

access request was inadequately answered;

objection was ignored;

international transfer lacked adequate safeguards;

processing caused material or non-material damage.

49. Most Important Distinction

A very important distinction is:

Unlawful processing ≠ automatic compensation.

Under C-300/21, compensation requires:

Infringement + damage + causal link. (InfoCuria)

At the same time:

No serious threshold of damage may be imposed as a blanket condition for non-material damages.

The actual existence of damage still has to be established.

50. Civil Remedies

Depending upon the facts and national procedural law, remedies can include:

1. Compensation

For qualifying material/non-material damage.

2. Erasure

Deletion of unlawfully processed data.

3. Rectification

Correction of inaccurate data.

4. Restriction

Temporary limitation of processing.

5. Objection

Particularly important for direct marketing.

6. Access

Information concerning processing and copies of personal data.

7. Disclosure

Identification of recipients where required.

8. Injunction

Court order stopping unlawful processing.

51. Practical Example

Facts

A data broker collects:

online purchases;

location information;

browsing history;

public records.

It combines them and creates a profile:

"Likely financially distressed, interested in medical treatment and politically conservative."

The profile is sold to an insurance company.

The individual discovers the profile and requests information.

The broker only responds:

"We process data for commercial purposes."

Possible claims

Issue 1: Was the original collection lawful?

Issue 2: Was combination lawful?

Issue 3: Did the profile involve sensitive inferred information?

Issue 4: Was there adequate transparency?

Issue 5: Who received the profile?

Issue 6: Was the access response adequate?

Issue 7: Was the profile accurate?

Issue 8: Did the processing cause damage?

Issue 9: Is there a causal link?

The principles from C-154/21, C-487/21, C-300/21, C-184/20 and C-252/21 become particularly relevant.

52. Data Broker Liability Chain

A useful examination diagram is:

Data Source

↓

Collector

↓

Data Broker

↓

Data Enrichment

↓

Profiling

↓

Data Sale/Sharing

↓

Customer

↓

Automated/Commercial Decision

↓

Harm

At each stage the court can ask:

Who determined the purpose and means?

What legal basis existed?

Was the use compatible with the original purpose?

Was the individual informed?

53. European Approach to Data Brokerage

The emerging European approach is based on several interconnected principles:

Transparency

Individuals should understand how their information is used.

Control

Individuals have rights over their personal data.

Accountability

Controllers must be able to demonstrate compliance.

Purpose limitation

Data should not be freely repurposed.

Data minimisation

Collection should be limited to what is necessary.

Accuracy

Commercial profiles should not contain unjustified inaccuracies.

Security

Data must be appropriately protected.

Compensation

Actual qualifying damage caused by unlawful processing can give rise to compensation.

The EDPB's 2026 Data Brokers Market Study confirms that data-broker business models can involve extensive collection, profiling and monetisation while providing individuals limited information or control, making GDPR principles particularly significant in this sector. (European Data Protection Board)

54. Future Development

Data-broker litigation is likely to increasingly concern:

AI-generated consumer profiles;

inferred sensitive data;

data enrichment;

location-data markets;

purchase-data markets;

connected-device information;

facial recognition databases;

biometric data;

data clean rooms;

advertising ecosystems;

cross-platform profiling;

automated insurance scoring;

automated employment screening;

international data transfers.

The combination of AI + data brokerage is particularly significant because AI can transform apparently harmless datasets into detailed predictions about individuals.

55. Overall Conclusion

Data brokerage misuse claims in Europe are principally governed by the GDPR's framework of lawful processing, transparency, purpose limitation, data minimisation, accuracy, individual rights and compensation.

The European case law provides a strong set of principles:

C-154/21 strengthens the right to know actual recipients of personal data. (InfoCuria)

C-487/21 strengthens meaningful access to personal data held by information companies. (InfoCuria)

C-300/21 establishes the infringement–damage–causation structure for Article 82 compensation. (InfoCuria)

C-252/21 demonstrates the importance of scrutinising extensive data aggregation, profiling and consent. (InfoCuria)

C-311/18 controls the legal environment for international data transfers. (curia)

C-434/16 supports a broad understanding of personal data.

C-184/20 is important where ordinary information can reveal sensitive characteristics.

C-131/12 establishes important principles concerning continued dissemination of personal information.

C-210/16 and C-40/17 show how responsibility can extend across multi-party data ecosystems.

The central civil-law principle is therefore:

A company cannot treat personal information as an unrestricted commercial commodity merely because it was technically able to collect, combine or purchase it. The legality of data brokerage depends upon the nature of the data, purpose of processing, legal basis, transparency, recipients, profiling, individual rights, applicable safeguards, damage and causation.

Ultra-Basic Keywords

Data Broker – Data Brokerage – Personal Data – GDPR – Data Misuse – Unlawful Processing – Data Sale – Data Sharing – Data Enrichment – Data Profiling – Consumer Profile – Behavioural Profile – Sensitive Data – Inferred Data – Consent – Legitimate Interest – Purpose Limitation – Data Minimisation – Accuracy – Transparency – Access Right – Recipient – Erasure – Rectification – Objection – Automated Decision – Article 22 – Compensation – Material Damage – Non-Material Damage – Causation – Joint Controller – Processor – International Transfer – Schrems II – Meta Platforms – Österreichische Post – CRIF – Nowak – Google Spain – Wirtschaftsakademie – Fashion ID – Data Protection – Civil Liability – Injunction – Restitution – Damages – AI Profiling – Advertising Data – Cross-Platform Data – Data Enrichment.

LEAVE A COMMENT