Civil Law And Data Brokerage Misuse Claims In Europe .
Civil Law And Data Brokerage Misuse Claims In Europe
1. Introduction
Data brokerage misuse claims arise when companies collect personal data from multiple sources, combine it into profiles, infer characteristics about individuals, sell or license those profiles to third parties, or otherwise monetise personal information in ways that may exceed the individual's reasonable expectations or violate data-protection law.
The European Data Protection Board's 2026 Data Brokers Market Study describes data brokers as businesses that collect information from multiple public and private sources, process it to develop consumer profiles, monetise that information, and may operate without giving individuals meaningful information or control over how their data is collected or used. (European Data Protection Board)
In Europe, such disputes are primarily governed by:
GDPR (Regulation (EU) 2016/679);
EU Charter of Fundamental Rights;
national civil/privacy laws;
consumer-protection law;
ePrivacy rules where applicable;
competition law in some cases;
Digital Services Act in relevant platform situations;
national procedural and damages rules.
The central civil-law question is:
When does legitimate data collection become unlawful data exploitation, and what remedies does the individual have?
2. Meaning of Data Brokerage
A data broker typically obtains information from several sources and creates or enriches profiles concerning individuals.
Sources can include:
websites;
mobile applications;
loyalty programmes;
public registers;
commercial databases;
advertising networks;
social-media information;
location information;
purchase records;
cookies and tracking technologies;
data obtained from other companies.
The broker may then:
Collect → combine → analyse → infer → profile → sell/license/share
the resulting information.
Example
Company A collects:
person's age;
postal address;
online browsing;
shopping history;
location information.
Company B provides:
credit-related information.
Company C provides:
demographic information.
A broker combines everything and sells:
"High-income consumer, likely to purchase luxury financial products."
The individual may argue that the resulting profile was created or used unlawfully.
3. Why Data Brokerage Creates Civil Liability Issues
Data brokerage creates several possible legal problems.
Main issues
unlawful collection;
lack of transparency;
absence of valid legal basis;
incompatible secondary use;
excessive data collection;
inaccurate information;
unlawful profiling;
unlawful automated decision-making;
disclosure to undisclosed recipients;
sale to third parties;
processing of sensitive data;
unlawful international transfer;
failure to honour access/erasure rights;
inadequate security;
emotional or reputational harm;
financial loss.
4. The GDPR Is the Main Legal Framework
The GDPR provides the central European framework.
Important principles include:
Article 5
Processing must comply with principles including:
lawfulness;
fairness;
transparency;
purpose limitation;
data minimisation;
accuracy;
storage limitation;
integrity and confidentiality;
accountability.
Article 6
Processing needs a lawful basis.
Possible bases include:
consent;
contract;
legal obligation;
vital interests;
public task;
legitimate interests.
Article 9
Special categories of personal data receive stronger protection.
Article 12–15
Individuals receive transparency and access rights.
Article 16
Right to rectification.
Article 17
Right to erasure in applicable circumstances.
Article 18
Right to restriction.
Article 20
Data portability.
Article 21
Right to object.
Article 22
Protection concerning certain solely automated decisions.
Article 82
Right to compensation for material and non-material damage caused by GDPR infringement.
5. First Case — Österreichische Post, C-154/21
CJEU, RW v Österreichische Post AG, C-154/21, 12 January 2023
This is highly relevant to data-brokerage disputes.
Österreichische Post processed personal information and generated information concerning individuals. The claimant wanted to know to whom his personal data had been disclosed.
The CJEU held that, where personal data have been or will be disclosed to recipients, the controller must generally provide the actual identity of those recipients, rather than merely their categories, where those recipients can be identified. (InfoCuria)
Data-broker relevance
Imagine a broker says:
"Your data were shared with marketing partners."
That may be insufficient where the GDPR requires identification of the actual recipients.
Principle
A data subject's access rights can extend to identifying actual data recipients.
This is particularly important where data have passed through a chain of brokers.
6. Second Case — Österreichische Datenschutzbehörde and CRIF, C-487/21
CJEU, C-487/21, 4 May 2023
The case concerned CRIF, a company involved in information services, and the data subject's right of access under Article 15 GDPR.
The CJEU held that the right to obtain a copy of personal data can require the controller to provide a faithful and intelligible reproduction of the personal data being processed, where necessary to enable the individual to exercise GDPR rights effectively. (InfoCuria)
Data-broker relevance
A data broker cannot necessarily respond:
"We hold information about you."
and provide only a vague summary.
The individual may need sufficient information to determine:
what data are held;
whether data are accurate;
where data came from;
how they are being processed;
whether information has been combined incorrectly.
Principle
Access must be sufficiently meaningful to enable the individual to exercise GDPR rights.
7. Third Case — Österreichische Post, C-300/21
CJEU, UI v Österreichische Post AG, C-300/21, 4 May 2023
This is one of the most important cases concerning compensation.
The CJEU held that three conditions are necessary for compensation under Article 82 GDPR:
infringement of the GDPR;
damage suffered by the data subject;
causal link between the infringement and damage.
A mere GDPR infringement, without damage, does not automatically create a right to compensation. The Court also rejected a national rule requiring non-material damage to exceed a particular seriousness threshold before compensation could be awarded. (InfoCuria)
Data-broker example
A broker unlawfully processes someone's data.
The person cannot simply say:
"GDPR was breached, therefore I automatically receive damages."
They must establish the legally relevant damage and causal connection.
Possible damage
anxiety;
loss of control over personal information;
reputational damage;
discrimination;
financial loss.
But the precise existence and amount of damage remain matters for the competent national court.
8. Fourth Case — Meta Platforms, C-252/21
CJEU, Meta Platforms and Others v Bundeskartellamt, C-252/21, 4 July 2023
This case is particularly important for large-scale data aggregation and profiling.
Meta combined data collected:
directly from Facebook;
from other Meta services;
from third-party websites and applications.
The combined data could produce detailed conclusions concerning users' interests and preferences. (InfoCuria)
The CJEU examined the interaction between GDPR compliance and competition law.
It held, among other things, that a competition authority may consider GDPR compliance when assessing abuse of dominance, while respecting the powers of data-protection authorities. (curia)
The Court also examined the requirements for lawful processing, including consent, contractual necessity and legitimate interests. It stated that personalised advertising could not simply be justified as a legitimate interest in the circumstances without the required consent. (curia)
Data-broker relevance
The case is highly relevant to:
cross-platform data combination;
behavioural profiling;
targeted advertising;
secondary use;
consent;
economic exploitation of personal data.
Principle
Combining information from different sources can create a separate GDPR problem; the legality of each underlying collection does not automatically make every subsequent combination lawful.
9. Fifth Case — Schrems II, C-311/18
CJEU, Data Protection Commissioner v Facebook Ireland and Schrems, C-311/18, 16 July 2020
The CJEU invalidated the EU-US Privacy Shield while upholding the validity of standard contractual clauses subject to appropriate safeguards and assessment of the actual level of protection in the receiving country. (curia)
Data-broker relevance
Data brokers frequently operate internationally.
A broker may transfer data:
Europe → US → analytics provider → advertising partner
The fact that a company has contractual relationships with a recipient does not automatically make the transfer lawful.
The controller must consider:
destination-country law;
safeguards;
access by public authorities;
effective remedies;
GDPR transfer requirements.
Principle
International monetisation of personal data must satisfy EU transfer requirements.
10. Sixth Case — Nowak, C-434/16
CJEU, Peter Nowak v Data Protection Commissioner, C-434/16, 20 December 2017
The CJEU interpreted "personal data" broadly.
Information qualifies as personal data where it is related to an identified or identifiable individual, directly or indirectly.
The Court treated information contained in examination scripts and examiner comments as personal data in the circumstances.
Data-broker relevance
Data brokers often argue that certain information is merely:
"commercial data,"
"analytics,"
"scores," or
"profiles."
But the legal question is whether the information relates to an identifiable person.
Principle
Information does not cease to be personal data merely because it has been transformed into an analytical or commercial profile.
11. Seventh Case — OT v Vyriausioji tarnybinės etikos komisija, C-184/20
CJEU, C-184/20, 1 August 2022
The CJEU dealt with the processing and publication of information capable of revealing special-category personal data.
The Court interpreted the protection of sensitive personal data broadly where information can reveal sensitive characteristics indirectly.
Data-broker relevance
This is highly significant for inferred data.
Suppose a broker does not directly collect:
"Person X has condition Y."
Instead, it collects:
searches;
purchases;
website visits;
pharmacy-related information;
location patterns.
It then infers a sensitive characteristic.
The legal analysis cannot necessarily avoid Article 9 simply by saying:
"We never directly collected the sensitive information."
Principle
Inferences can have serious data-protection consequences when they reveal specially protected information.
12. Eighth Case — Google Spain, C-131/12
CJEU, Google Spain SL and Google Inc. v AEPD and Mario Costeja González, C-131/12, 13 May 2014
The CJEU established the famous right to delisting/de-referencing framework.
A person can, under the applicable conditions, request removal of search-engine links from results relating to their name where the continued accessibility of the information is incompatible with EU data-protection law.
Data-broker relevance
Data brokers similarly aggregate information and make it accessible to commercial customers.
The case illustrates a broader European principle:
Individuals retain legal rights concerning the continuing dissemination and accessibility of personal information.
It is therefore relevant to claims involving:
outdated profiles;
inaccurate information;
excessive retention;
reputational harm;
commercial dissemination.
13. Ninth Case — Wirtschaftsakademie, C-210/16
CJEU, Wirtschaftsakademie Schleswig-Holstein, C-210/16, 5 June 2018
The CJEU considered responsibility for processing involving a Facebook fan page.
It recognised circumstances in which an entity that participates in determining the purposes and means of processing can be a joint controller, even where it does not itself possess the underlying personal data.
Data-broker relevance
Data brokerage frequently involves several participants:
Website → platform → broker → analytics company → advertiser
An organisation may attempt to argue:
"We did not technically possess the database."
But legal responsibility can depend on influence over the purposes and means of processing, not simply physical possession of the data.
Principle
Control over processing can be more important than physical possession of the database.
14. Tenth Case — Fashion ID, C-40/17
CJEU, Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW, C-40/17, 29 July 2019
The CJEU examined the use of Facebook's "Like" button on a website.
It held that a website operator can be a joint controller with Facebook for certain collection and transmission operations, even though it did not determine all subsequent processing.
Data-broker relevance
This is highly relevant to data supply chains.
A company cannot necessarily avoid responsibility merely because:
"Another company actually processed the information."
Principle
Different stages of a data-processing chain can create different forms of responsibility.
15. What Counts as Data-Broker Misuse?
A data-broker misuse claim may involve any of the following.
1. Unlawful collection
Data obtained without an appropriate legal basis.
2. Purpose incompatibility
Data collected for one purpose are subsequently used for another incompatible purpose.
3. Excessive collection
The broker collects substantially more information than necessary.
4. Unlawful profiling
Information is combined to create intrusive behavioural profiles.
5. Sensitive inference
Ordinary information is used to infer health, political, religious or other sensitive characteristics.
6. Unlawful disclosure
Data are sold or supplied to recipients without an adequate legal basis.
7. Inaccurate profile
Broker maintains incorrect information.
8. Failure to erase
Broker refuses a legally valid erasure request.
9. Undisclosed recipients
Individual cannot determine who received the information.
10. International transfer
Data are transferred to countries without adequate safeguards.
16. Data Brokerage and Lawful Basis
The most important question is:
Why is the broker legally allowed to process this data?
A broker might rely on:
consent;
legitimate interests;
contractual necessity;
another Article 6 basis.
But the chosen basis must actually fit the processing.
The Meta Platforms judgment is particularly important because the CJEU scrutinised attempts to rely on contractual necessity and legitimate interests for extensive combination and advertising-related processing. (curia)
17. Legitimate Interest
A broker may argue:
"We have a legitimate commercial interest in selling consumer profiles."
That does not automatically end the inquiry.
The controller generally needs to consider:
legitimate interest;
necessity;
balancing against the individual's rights and freedoms.
Where processing is highly intrusive, extensive or unexpected, the balancing exercise becomes particularly important.
18. Consent
Consent must satisfy GDPR requirements.
A data broker should not assume that:
"The individual clicked Accept"
automatically proves valid consent for every subsequent use.
Issues can include:
informed consent;
specific consent;
freely given consent;
withdrawal;
bundled consent;
imbalance;
unclear purposes.
The CJEU's Meta Platforms judgment specifically examined whether consent in a dominant social-network environment was freely given. (curia)
19. Purpose Limitation
Suppose data are collected for:
"delivery of an online purchase."
The company later sells the same information to a data broker for:
"credit-risk profiling."
That second purpose requires separate legal analysis.
The original collection does not automatically legitimise every subsequent commercial use.
20. Data Minimisation
Data brokerage can conflict with the minimisation principle because brokers may seek to collect more information precisely because additional information improves profiling.
Example:
A broker collects:
age;
income;
location;
browsing;
purchase history;
contacts;
app usage;
device information.
The legal question becomes:
Are all of these categories necessary and justified for the claimed purpose?
21. Accuracy of Broker Profiles
Incorrect broker information can have serious consequences.
Example:
Broker database incorrectly states:
"Person has high credit risk."
A lender purchases the information.
Loan is rejected.
Possible claims may concern:
rectification;
erasure;
access;
objection;
automated decision-making;
compensation where the legal conditions are met.
The GDPR's accuracy principle therefore becomes extremely important in data-broker litigation.
22. Profiling
Profiling means using personal data to evaluate or predict characteristics of an individual.
Possible profiles include:
purchasing behaviour;
financial behaviour;
interests;
location patterns;
employment characteristics;
risk;
consumer preferences.
Data brokers can create profiles from apparently harmless pieces of information.
Example
Individually:
"Person visited three websites."
Combined:
"Person probably intends to purchase a mortgage."
The second statement may have significantly greater legal consequences.
23. Automated Decision-Making
Article 22 GDPR becomes important where profiling leads to certain decisions based solely on automated processing.
Examples:
automatic insurance assessment;
credit decisions;
employment screening;
fraud scoring;
housing decisions.
A data broker may not make the final decision itself but may provide the profile used by another company.
This creates difficult questions concerning:
controller status;
transparency;
meaningful information;
logic involved;
human intervention;
contestability.
24. Sensitive Data
Special categories under Article 9 include information concerning matters such as:
health;
biometric data in relevant circumstances;
racial or ethnic origin;
political opinions;
religious or philosophical beliefs;
trade-union membership;
sexual orientation.
A broker may attempt to avoid Article 9 by saying:
"We did not directly collect the sensitive fact."
But C-184/20 demonstrates the importance of examining whether processing reveals or makes available information falling within enhanced protection.
25. Data Broker and Children's Data
Children receive enhanced protection under EU data-protection law.
Data brokers dealing with:
children's browsing;
educational information;
gaming activity;
location;
behavioural profiles;
may therefore face heightened legal concerns.
The combination of children's data and profiling can be particularly sensitive.
26. Right of Access
A person may ask:
"What personal data do you have about me?"
A broker may have to provide meaningful access.
C-487/21 is especially important because the CJEU interpreted the right to obtain a copy broadly enough to enable effective exercise of the data subject's rights. (InfoCuria)
27. Right to Know Recipients
Under C-154/21, where recipients can be identified, the data subject generally has a right to know their actual identities rather than merely generic categories. (InfoCuria)
This is particularly valuable against data brokers.
Example
Instead of:
"We share data with advertising companies."
the claimant may be entitled, in appropriate circumstances, to information identifying the actual recipients.
28. Right to Erasure
An individual may request deletion in circumstances specified by Article 17 GDPR.
Potential grounds include:
data no longer necessary;
withdrawal of consent;
successful objection;
unlawful processing;
legal obligation requiring erasure.
But erasure is not absolute.
Exceptions can include:
freedom of expression;
legal obligations;
public interest;
establishment/exercise/defence of legal claims.
29. Right to Object
Article 21 is especially important for direct marketing.
A data subject can object to processing for direct marketing purposes, including profiling related to such marketing.
A broker continuing such processing after a valid objection may therefore face serious legal consequences.
30. Data Brokerage and Damage
Article 82 GDPR is central to civil compensation.
Following C-300/21, the basic structure is:
GDPR infringement
Damage
Causal link
=
Potential compensation claim
The CJEU has confirmed that a mere infringement without damage is insufficient, while a national minimum seriousness threshold for non-material damage is not permissible in the way rejected in that judgment. (InfoCuria)
31. Material Damage
Material loss may include, depending on the facts and applicable law:
financial loss;
fraudulent transactions;
loss caused by incorrect profiling;
costs incurred to respond to misuse;
other demonstrable economic consequences.
The claimant must establish the legally relevant damage and causation.
32. Non-Material Damage
Possible claims can concern:
anxiety;
distress;
loss of control;
reputational injury;
fear of misuse.
But C-300/21 does not mean every unlawful processing automatically produces compensable non-material damage.
Actual damage and causal connection remain necessary. (InfoCuria)
33. Data Brokerage and Competition Law
Large data brokers can potentially create competition concerns where:
a dominant company controls access to data;
data are combined across services;
rivals cannot compete without equivalent data;
consumers face excessive data extraction;
data processing forms part of an exclusionary strategy.
Meta Platforms, C-252/21 is important because the CJEU recognised that a competition authority can consider GDPR compliance in assessing abuse of dominance, subject to coordination with data-protection authorities. (curia)
34. Data Brokerage and the Digital Services Act
The DSA and GDPR can overlap where online intermediary services process personal data.
The EDPB adopted final Guidelines 3/2025 on the interplay between the DSA and GDPR in September 2026, addressing how the two frameworks should interact where DSA obligations involve personal-data processing. (European Data Protection Board)
Therefore:
Data broker + online platform + targeted advertising
may require analysis under multiple EU digital regimes.
35. International Data Brokerage
A data broker may operate:
EU → US → Singapore → India → EU
Every international transfer raises questions under Chapter V GDPR.
Schrems II demonstrates that contractual safeguards must be assessed alongside the actual legal environment in the destination country. (curia)
36. Joint Controllers
Data brokerage often involves multiple organisations.
For example:
Retailer
↓
Advertising platform
↓
Data broker
↓
Analytics provider
↓
Advertiser
Under Wirtschaftsakademie and Fashion ID, legal responsibility can depend upon participation in determining the purposes and means of relevant processing.
Physical possession of data is therefore not the only question.
37. Controller vs Processor
This distinction is essential.
Controller
Determines purposes and means of processing.
Processor
Processes personal data on behalf of the controller.
A data broker that determines its own commercial purposes may not simply be a passive processor.
The actual contractual and operational relationship must be examined.
38. Data Provenance
One of the most important questions is:
Where did the broker get the data?
Possible sources:
consumer;
public register;
website;
app;
another business;
advertising network;
purchased database.
A broker's obligation to provide information concerning the source of personal data can become important, especially when data were not collected directly from the individual.
39. Data Enrichment
Data brokers frequently perform data enrichment.
Example:
Original database:
Name + address.
Enriched database:
Name + address + income + interests + political preferences + purchasing behaviour + estimated credit risk.
Every additional enrichment operation can raise new questions about:
legal basis;
compatibility;
accuracy;
transparency;
proportionality;
sensitive-data processing.
40. Inferred Data
Inferred data are especially problematic.
Example:
The broker never receives:
"Person is interested in cancer treatment."
But it observes:
repeated medical searches;
pharmacy purchases;
hospital visits;
health-related website activity.
It generates:
"Likely serious medical condition."
The legal analysis must consider the nature and use of the resulting information rather than looking only at the raw source data.
41. Dark Patterns and Data Brokerage
A company may obtain apparently "consented" data through:
confusing interfaces;
preselected choices;
multiple screens;
misleading buttons;
difficult withdrawal;
bundled purposes.
The validity of consent depends upon GDPR requirements, not simply the presence of a checkbox.
42. Data Brokerage and Civil Injunctions
An individual may seek remedies beyond damages.
Depending on national procedural law and the circumstances, possible remedies include:
injunction;
cessation of processing;
deletion;
correction;
restriction;
disclosure;
preservation of evidence.
The GDPR therefore provides a framework that is not limited to monetary compensation.
43. Burden of Proof and Evidence
Data-broker litigation can require evidence concerning:
Technical evidence
databases;
logs;
cookies;
tracking identifiers;
APIs;
data flows.
Commercial evidence
data-sale agreements;
licensing arrangements;
customer lists;
pricing records.
Legal evidence
privacy notices;
consent mechanisms;
legitimate-interest assessments;
data-processing agreements;
records of processing.
Algorithmic evidence
profiling models;
scoring criteria;
automated decision systems.
44. Typical Data-Broker Claim
A claimant might formulate the case as:
"The defendant collected my personal data from multiple sources, combined them without a lawful basis, created an inaccurate profile, disclosed the profile to third parties without adequate transparency, refused my access request and caused me financial and non-material harm."
The legal analysis would proceed:
Personal data?
↓
Processing?
↓
Controller?
↓
Lawful basis?
↓
Purpose limitation?
↓
Transparency?
↓
Accuracy?
↓
Recipients?
↓
Rights violated?
↓
Damage?
↓
Causation?
↓
Remedy?
45. Important Case-Law Table
| Case | Court | Main principle | Data-broker relevance |
|---|---|---|---|
| C-154/21, Österreichische Post | CJEU | Actual recipients may need to be identified | Disclosure chains |
| C-487/21, Österreichische Datenschutzbehörde/CRIF | CJEU | Meaningful copy/access to personal data | Broker databases |
| C-300/21, Österreichische Post | CJEU | GDPR infringement + damage + causation | Compensation |
| C-252/21, Meta Platforms | CJEU | Extensive data combination and GDPR/competition interaction | Profiling and cross-platform data |
| C-311/18, Schrems II | CJEU | International transfer safeguards | Cross-border data brokerage |
| C-434/16, Nowak | CJEU | Broad concept of personal data | Analytical profiles |
| C-184/20 | CJEU | Protection of sensitive/inferred information | Sensitive profiling |
| C-131/12, Google Spain | CJEU | Rights concerning continuing dissemination of personal data | Commercial dissemination |
| C-210/16, Wirtschaftsakademie | CJEU | Joint controllership | Data supply chains |
| C-40/17, Fashion ID | CJEU | Joint responsibility for collection/transmission | Tracking and broker ecosystems |
46. Comparison of the Main Cases
C-154/21
Focus:
Who received my data?
C-487/21
Focus:
What data exactly do you have about me?
C-300/21
Focus:
Did your unlawful processing actually cause me compensable damage?
C-252/21
Focus:
Can extensive cross-platform data combination be justified?
C-311/18
Focus:
Can my data legally be transferred outside the EU?
C-434/16
Focus:
What counts as personal data?
C-184/20
Focus:
Can apparently ordinary data reveal sensitive information?
C-131/12
Focus:
Can continuing dissemination of personal information be challenged?
C-210/16 and C-40/17
Focus:
Who is legally responsible when several organisations participate in processing?
47. Defences Available to Data Brokers
A broker may argue:
1. Lawful basis
Processing was based on Article 6.
2. Consent
The individual gave valid consent.
3. Legitimate interest
The processing was necessary for a legitimate commercial interest and properly balanced.
4. Anonymisation
The information was genuinely anonymised and therefore no longer personal data.
5. No damage
The claimant cannot establish compensable damage.
6. No causation
The alleged loss was caused by something else.
7. Data accuracy
The disputed profile was accurate.
8. Statutory exception
The processing fell within an applicable exception.
Each defence depends heavily on the facts.
48. Claimant's Arguments
A claimant may argue:
no lawful basis;
consent was invalid;
processing was unexpected;
purposes were incompatible;
data were excessive;
profile was inaccurate;
sensitive information was inferred;
recipients were not disclosed;
access request was inadequately answered;
objection was ignored;
international transfer lacked adequate safeguards;
processing caused material or non-material damage.
49. Most Important Distinction
A very important distinction is:
Unlawful processing ≠ automatic compensation.
Under C-300/21, compensation requires:
Infringement + damage + causal link. (InfoCuria)
At the same time:
No serious threshold of damage may be imposed as a blanket condition for non-material damages.
The actual existence of damage still has to be established.
50. Civil Remedies
Depending upon the facts and national procedural law, remedies can include:
1. Compensation
For qualifying material/non-material damage.
2. Erasure
Deletion of unlawfully processed data.
3. Rectification
Correction of inaccurate data.
4. Restriction
Temporary limitation of processing.
5. Objection
Particularly important for direct marketing.
6. Access
Information concerning processing and copies of personal data.
7. Disclosure
Identification of recipients where required.
8. Injunction
Court order stopping unlawful processing.
51. Practical Example
Facts
A data broker collects:
online purchases;
location information;
browsing history;
public records.
It combines them and creates a profile:
"Likely financially distressed, interested in medical treatment and politically conservative."
The profile is sold to an insurance company.
The individual discovers the profile and requests information.
The broker only responds:
"We process data for commercial purposes."
Possible claims
Issue 1: Was the original collection lawful?
Issue 2: Was combination lawful?
Issue 3: Did the profile involve sensitive inferred information?
Issue 4: Was there adequate transparency?
Issue 5: Who received the profile?
Issue 6: Was the access response adequate?
Issue 7: Was the profile accurate?
Issue 8: Did the processing cause damage?
Issue 9: Is there a causal link?
The principles from C-154/21, C-487/21, C-300/21, C-184/20 and C-252/21 become particularly relevant.
52. Data Broker Liability Chain
A useful examination diagram is:
Data Source
↓
Collector
↓
Data Broker
↓
Data Enrichment
↓
Profiling
↓
Data Sale/Sharing
↓
Customer
↓
Automated/Commercial Decision
↓
Harm
At each stage the court can ask:
Who determined the purpose and means?
What legal basis existed?
Was the use compatible with the original purpose?
Was the individual informed?
53. European Approach to Data Brokerage
The emerging European approach is based on several interconnected principles:
Transparency
Individuals should understand how their information is used.
Control
Individuals have rights over their personal data.
Accountability
Controllers must be able to demonstrate compliance.
Purpose limitation
Data should not be freely repurposed.
Data minimisation
Collection should be limited to what is necessary.
Accuracy
Commercial profiles should not contain unjustified inaccuracies.
Security
Data must be appropriately protected.
Compensation
Actual qualifying damage caused by unlawful processing can give rise to compensation.
The EDPB's 2026 Data Brokers Market Study confirms that data-broker business models can involve extensive collection, profiling and monetisation while providing individuals limited information or control, making GDPR principles particularly significant in this sector. (European Data Protection Board)
54. Future Development
Data-broker litigation is likely to increasingly concern:
AI-generated consumer profiles;
inferred sensitive data;
data enrichment;
location-data markets;
purchase-data markets;
connected-device information;
facial recognition databases;
biometric data;
data clean rooms;
advertising ecosystems;
cross-platform profiling;
automated insurance scoring;
automated employment screening;
international data transfers.
The combination of AI + data brokerage is particularly significant because AI can transform apparently harmless datasets into detailed predictions about individuals.
55. Overall Conclusion
Data brokerage misuse claims in Europe are principally governed by the GDPR's framework of lawful processing, transparency, purpose limitation, data minimisation, accuracy, individual rights and compensation.
The European case law provides a strong set of principles:
C-154/21 strengthens the right to know actual recipients of personal data. (InfoCuria)
C-487/21 strengthens meaningful access to personal data held by information companies. (InfoCuria)
C-300/21 establishes the infringement–damage–causation structure for Article 82 compensation. (InfoCuria)
C-252/21 demonstrates the importance of scrutinising extensive data aggregation, profiling and consent. (InfoCuria)
C-311/18 controls the legal environment for international data transfers. (curia)
C-434/16 supports a broad understanding of personal data.
C-184/20 is important where ordinary information can reveal sensitive characteristics.
C-131/12 establishes important principles concerning continued dissemination of personal information.
C-210/16 and C-40/17 show how responsibility can extend across multi-party data ecosystems.
The central civil-law principle is therefore:
A company cannot treat personal information as an unrestricted commercial commodity merely because it was technically able to collect, combine or purchase it. The legality of data brokerage depends upon the nature of the data, purpose of processing, legal basis, transparency, recipients, profiling, individual rights, applicable safeguards, damage and causation.
Ultra-Basic Keywords
Data Broker – Data Brokerage – Personal Data – GDPR – Data Misuse – Unlawful Processing – Data Sale – Data Sharing – Data Enrichment – Data Profiling – Consumer Profile – Behavioural Profile – Sensitive Data – Inferred Data – Consent – Legitimate Interest – Purpose Limitation – Data Minimisation – Accuracy – Transparency – Access Right – Recipient – Erasure – Rectification – Objection – Automated Decision – Article 22 – Compensation – Material Damage – Non-Material Damage – Causation – Joint Controller – Processor – International Transfer – Schrems II – Meta Platforms – Österreichische Post – CRIF – Nowak – Google Spain – Wirtschaftsakademie – Fashion ID – Data Protection – Civil Liability – Injunction – Restitution – Damages – AI Profiling – Advertising Data – Cross-Platform Data – Data Enrichment.

comments