Civil Law And Data Loss Platform Liability In Europe

Civil Law and Data Loss Platform Liability in Europe

1. Introduction

Data loss platform liability concerns civil and data-protection claims arising when an online platform, digital service, marketplace, cloud service, social-media platform, fintech application, health platform or other digital intermediary loses, exposes, destroys, corrupts or unlawfully discloses personal or commercially important data.

Typical situations include:

hacking of a platform;

accidental disclosure of customer information;

loss of databases;

ransomware;

deletion or corruption of stored data;

employee disclosure;

insecure APIs;

cloud-storage failures;

loss of account information;

third-party processor failures;

inadequate access controls;

unauthorised copying;

loss of personal data during migration.

The central legal question is:

When does a platform's loss or exposure of data create civil liability and a right to compensation?

In Europe, the principal framework is the GDPR, supplemented by national civil law, contract law, consumer law, cybersecurity legislation and, depending on the platform, sector-specific rules.

2. Meaning of Data Loss

"Data loss" should be understood broadly.

It can involve:

A. Destruction

Data is permanently deleted or destroyed.

B. Loss of availability

The data technically exists but the customer cannot access it.

Example:

A cloud platform suffers ransomware and customers cannot access their business files.

C. Unauthorised disclosure

Data is disclosed to someone who was not authorised to receive it.

D. Unauthorised access

A hacker enters the platform's systems.

E. Data corruption

Information is changed or damaged.

F. Data theft

Personal or confidential information is copied or extracted.

G. Accidental transmission

An employee sends information to the wrong recipient.

3. Platform Liability Can Have Several Legal Foundations

A single incident may create several possible causes of action.

1. GDPR liability

Where personal data is involved.

2. Contractual liability

Where the platform breached its agreement with the customer.

3. Tort/delict liability

Where an independent duty under national civil law was breached.

4. Consumer protection

Where the customer is a consumer.

5. Cybersecurity regulation

For regulated platforms and digital service providers.

6. Intellectual-property/confidentiality liability

Where commercially confidential information is lost.

Therefore:

Data loss does not automatically equal one particular legal claim.

The correct legal regime depends on the type of data, parties, contract, platform and harm.

4. GDPR Framework

Where personal data is involved, important GDPR provisions include:

Article 5 — data-processing principles;

Article 6 — lawful processing;

Articles 12–14 — transparency;

Article 24 — controller responsibility;

Article 25 — data protection by design and default;

Article 28 — processors;

Article 32 — security of processing;

Articles 33–34 — breach notification;

Article 35 — data-protection impact assessment;

Article 82 — compensation;

Article 83 — administrative fines.

Article 32 is particularly important because controllers and processors must implement technical and organisational measures appropriate to the risks.

5. Data Loss Is Not Automatically GDPR Compensation

This is one of the most important principles.

Under Article 82, three elements generally have to be established:

1. GDPR infringement

There must be a violation of the GDPR.

2. Damage

The claimant suffered material or non-material damage.

3. Causation

The infringement caused that damage.

The CJEU repeatedly describes these three conditions as cumulative. (InfoCuria)

Therefore:

Data breach ≠ automatic damages.

6. Material Damage

Material damage means an economically measurable loss.

Examples:

money stolen following a data breach;

financial fraud;

identity-related financial loss;

business interruption;

restoration costs;

data-recovery costs;

replacement costs;

lost commercial opportunities;

additional cybersecurity expenses.

However, the claimant must demonstrate the connection between the platform's conduct and the financial loss.

7. Non-Material Damage

Non-material damage can involve:

anxiety;

fear of misuse;

loss of control over personal data;

distress;

reputational harm;

privacy interference.

The CJEU has held that non-material damage does not need to satisfy a minimum seriousness threshold merely to qualify for Article 82 compensation. But actual damage must still be established; infringement alone is insufficient. (curia)

8. Data Loss vs Data Breach

These concepts should be distinguished.

Data loss

The data may be:

deleted;

inaccessible;

corrupted;

destroyed.

Data breach

The GDPR definition of a personal-data breach covers a breach of security leading to:

destruction;

loss;

alteration;

unauthorised disclosure; or

unauthorised access

to personal data.

Therefore, data loss can itself constitute a personal-data breach when the affected information is personal data.

9. Platform as Controller

A platform may be a data controller when it determines the purposes and means of processing personal data.

Example:

An online marketplace decides what customer information it collects, why it collects it and how it uses it.

The controller has primary responsibility for compliance with GDPR obligations.

10. Platform as Processor

Sometimes the platform acts as a processor.

Example:

A cloud provider stores personal data on behalf of a bank, but the bank determines the purposes of processing.

The processor still has important GDPR obligations, particularly regarding:

security;

contractual compliance;

assistance to the controller;

breach notification to the controller;

appropriate technical and organisational measures.

11. Controller-Processor Liability

A complicated data-loss incident can involve:

Customer → Platform → Cloud provider → Cybersecurity contractor

The claimant must determine:

Who controlled the data?

Who processed it?

Who caused the security failure?

Who had responsibility for the relevant technical measure?

Was there a contractual allocation of responsibility?

Did the processor notify the controller?

Did the controller respond appropriately?

Article 82 can potentially impose liability on controllers and processors, subject to the GDPR's liability rules.

12. Security Standard

Article 32 requires security measures appropriate to the risk.

Relevant measures may include:

encryption;

pseudonymisation;

access controls;

authentication;

network segmentation;

backup systems;

incident-response procedures;

vulnerability management;

employee training;

monitoring;

disaster recovery.

The question is not simply:

"Was the platform hacked?"

The more important question is:

Were the technical and organisational measures appropriate to the risks at the relevant time?

13. Hacker Attack Is Not Automatically a Defence

A platform may argue:

"The hacker caused the loss, not us."

That argument is not automatically successful.

The CJEU's Natsionalna agentsia za prihodite judgment makes clear that a successful hacking attack does not by itself establish that the controller's security measures were inadequate, but the controller must be able to demonstrate the appropriateness of the measures in the circumstances. (curia)

Thus:

Hacking → investigate security → assess adequacy → determine infringement → assess damage and causation.

14. Case Law

Case 1 — Natsionalna agentsia za prihodite (NAP)

CJEU, Case C-340/21
Judgment: 14 December 2023

This is one of the most important European cases on cyberattack-related data loss.

The Bulgarian National Revenue Agency suffered a cyberattack resulting in unauthorised access to and dissemination of personal data.

The litigation concerned:

adequacy of security measures;

hacking;

burden of proof;

Article 32;

Article 82;

fear of future misuse.

The CJEU held that the mere fact that a hacking attack succeeded does not automatically prove that the security measures were inappropriate.

At the same time, fear concerning possible future misuse of personal data can constitute non-material damage where the relevant conditions are satisfied. (curia)

Principle

A controller cannot be held liable simply because a hacker succeeded, but neither can a controller avoid scrutiny merely by pointing to the hacker.

Importance

This case is directly relevant to:

platform hacking;

ransomware;

cybersecurity;

data theft;

Article 32;

Article 82;

non-material damage.

15. Case 2 — MediaMarktSaturn

CJEU, Case C-687/21
Judgment: 25 January 2024

Employees accidentally provided a document containing personal data to an unauthorised third party.

The Court considered Articles 24, 32 and 82 GDPR.

The CJEU held that the accidental disclosure, by itself, did not automatically establish that the technical and organisational measures were inappropriate. The assessment must be concrete and consider the circumstances. (InfoCuria)

The Court also confirmed that Article 82 compensation is compensatory rather than punitive. (InfoCuria)

Principle

Employee error does not automatically prove inadequate security.

Importance

Very useful for:

employee mistakes;

wrong-email incidents;

accidental disclosure;

internal platform controls;

Article 32 security;

Article 82 damages.

16. Case 3 — Österreichische Post

CJEU, Case C-300/21
Judgment: 4 May 2023

Österreichische Post used an algorithm to analyse information and determine political affinities of individuals.

The case concerned compensation for alleged non-material damage.

The CJEU held:

Mere infringement of the GDPR does not automatically create a right to compensation.

The claimant must establish:

infringement;

damage;

causal connection.

At the same time, EU law does not permit compensation for non-material damage to be made conditional upon crossing an additional minimum seriousness threshold. (curia)

Importance for platform data loss

It provides the basic damages framework for almost every GDPR data-loss claim.

17. Case 4 — Gemeinde Ummendorf

CJEU, Case C-456/22
Judgment: 14 December 2023

The case concerned unlawful online publication of personal data.

The CJEU considered whether loss of control over personal information could constitute non-material damage.

The Court recognised that even a relatively short loss of control may constitute compensable non-material damage if the individual actually suffered such damage. (Curia)

Principle

Loss of control over personal data can be legally significant even without proven financial loss.

Importance

This is highly relevant to:

public platform disclosure;

website publication;

database exposure;

online dissemination;

unauthorised access.

18. Case 5 — Scalable Capital

CJEU, Joined Cases C-182/22 and C-189/22
Judgment: 20 June 2024

The litigation arose from a personal-data security incident affecting customers of a financial platform.

The Court examined:

loss of control;

fear of misuse;

Article 82;

compensation;

causal connection.

The CJEU reaffirmed that GDPR compensation requires infringement, damage and causation, but a claimant does not need to prove that the damage reached some additional minimum level of seriousness. (Curia)

Principle

A claimant can potentially recover for non-material damage arising from loss of control, including where the harm is relatively limited, provided actual damage is demonstrated.

Importance

This is particularly useful for:

financial platforms;

fintech;

customer databases;

account information;

cybersecurity incidents.

19. Case 6 — PS (Incorrect Address)

CJEU, Case C-590/22
Judgment: 20 June 2024

The case concerned personal data being transmitted to an incorrect address.

The CJEU again emphasised that:

infringement alone is insufficient;

damage must actually be suffered;

causation must be established.

The Court also rejected the idea that every data theft must result in actual identity theft before non-material damage can be compensated. (InfoCuria)

Principle

Actual identity theft is not a mandatory prerequisite for Article 82 compensation.

Importance

This is particularly useful for:

wrong-recipient incidents;

platform communication errors;

accidental disclosure;

customer-data transmission.

20. Case 7 — Krankenversicherung Nordrhein

CJEU, Case C-667/21
Judgment: 21 December 2023

This case concerned GDPR compensation and processing involving sensitive personal information.

The Court reaffirmed the compensatory nature of Article 82 and the requirement for:

infringement;

damage;

causation.

Principle

Article 82 compensation is designed to compensate the damage actually suffered, rather than punish the controller.

Importance

It is useful where platform data loss involves:

health information;

special-category data;

confidential customer information.

21. Case 8 — juris

CJEU, Case C-741/21
Judgment: 11 April 2024

The CJEU again considered Article 82 compensation.

The Court reaffirmed that:

infringement + damage + causal link

are cumulative requirements.

The judgment is important because it reinforces the distinction between a GDPR violation and compensable harm. (Curia)

Importance

It provides useful support for the general Article 82 framework in platform liability litigation.

22. Direct and Analogous Authorities

CaseRelevance to Data Loss Platform Liability
NAP, C-340/21Direct — hacking/data breach/security
MediaMarktSaturn, C-687/21Direct — accidental disclosure/security
Scalable Capital, C-182/22 & C-189/22Direct/very strong — platform data incident and compensation
Österreichische Post, C-300/21Direct for Article 82 damages
Gemeinde Ummendorf, C-456/22Strong — loss of control/online disclosure
PS (Incorrect Address), C-590/22Strong — accidental disclosure
Krankenversicherung Nordrhein, C-667/21Strong — sensitive data/compensation
juris, C-741/21Strong — Article 82 liability framework

These cases are preferable to using unrelated general contract cases because the CJEU has now developed a substantial body of Article 82 jurisprudence.

23. Data Loss and Contractual Liability

GDPR liability is not necessarily the only claim.

Suppose:

A business pays a cloud platform €50,000 annually to store its customer database.

The platform's contract promises:

backups;

99.9% availability;

encryption;

disaster recovery;

security monitoring.

The platform fails to maintain backups and the database is permanently lost.

The customer may potentially have:

Contractual claim

Breach of:

backup obligation;

security obligation;

availability obligation;

disaster-recovery obligation.

GDPR claim

If the database contains personal data.

Tort/delict claim

Depending upon national law.

Therefore:

One incident can generate multiple legal causes of action.

24. Data Loss and Commercial Information

Not all data is personal data.

A platform may lose:

trade secrets;

source code;

financial models;

customer lists;

business strategies;

research data;

confidential contracts.

These matters may fall primarily under:

contract law;

trade-secret law;

confidentiality obligations;

intellectual-property law;

tort/delict.

GDPR compensation cannot be used merely because commercially valuable information was lost if it does not constitute personal data.

25. Availability Failure

A platform may not disclose data at all but may nevertheless become liable because customers cannot access their data.

Example:

Cloud platform is unavailable for 72 hours.

A business loses €100,000 in sales.

The central questions become:

What did the contract promise?

Was availability guaranteed?

Was there an SLA?

Was the outage foreseeable?

Was it caused by force majeure?

Did the customer mitigate the loss?

Is lost profit recoverable?

Is there a contractual liability cap?

This is primarily a contractual damages analysis unless personal-data obligations are also implicated.

26. Ransomware

Ransomware creates several possible legal issues.

Scenario

A platform is attacked.

Attackers:

encrypt customer files;

steal personal information;

demand payment;

prevent access.

Potential claims include:

GDPR;

contractual liability;

cybersecurity obligations;

confidentiality;

negligence/delict;

business interruption;

regulatory liability.

The platform's key defence may be:

"The attack was an external criminal act."

But NAP demonstrates that the existence of an external hacker does not eliminate the need to assess whether security measures were appropriate. (curia)

27. Data Loss and Third-Party Processors

A platform may outsource:

cloud storage;

email;

analytics;

customer support;

payment processing;

cybersecurity;

database management.

Example:

Platform → Cloud Provider → Subprocessor

A security failure at the subprocessor does not automatically end the platform's responsibility.

The contractual and GDPR roles of each entity must be identified.

28. Causation

Causation is often the hardest part of the claim.

Example

Platform suffers data breach.

Customer later loses €20,000 due to identity fraud.

The claimant must establish a sufficiently direct causal connection.

The court may ask:

Was the fraud actually caused by this particular breach?

If the same information was already publicly available from several other sources, causation may become difficult.

29. Fear of Future Misuse

This is an important modern issue.

Suppose:

Platform data is stolen, but no identity fraud has yet occurred.

Can the claimant recover for fear that the data may be misused?

Potentially yes, but the claimant must establish actual non-material damage.

The CJEU has recognised that fear concerning possible future misuse can constitute non-material damage in appropriate circumstances. NAP is particularly important on this point. (curia)

But:

mere theoretical fear + no actual damage

does not automatically establish an Article 82 claim.

30. Data Loss Involving Sensitive Data

Risk is especially serious where the platform loses:

health information;

biometric data;

genetic information;

political information;

religious information;

sexual-orientation information;

financial information.

Such processing can trigger Article 9 and heightened risk considerations.

The amount of compensation is not automatically determined by the sensitivity of the data alone, but the nature and consequences of the damage remain relevant to the assessment.

31. Evidence

A claimant should preserve:

breach notifications;

platform emails;

incident reports;

access logs;

screenshots;

account records;

contracts;

service-level agreements;

cybersecurity reports;

evidence of financial losses;

evidence of fraud;

communications with the platform;

data-access responses;

evidence of anxiety or reputational harm where relevant.

The platform may need to demonstrate:

security measures;

risk assessments;

incident-response procedures;

access controls;

employee training;

encryption;

audit records;

processor arrangements.

32. Data Breach Notification

Under GDPR Articles 33 and 34, certain personal-data breaches trigger notification obligations.

Generally:

Supervisory authority

Where required, notification must be made without undue delay and, where feasible, within 72 hours after the controller becomes aware of the breach.

Data subjects

Where the breach is likely to result in a high risk to individuals, affected persons may also need to be informed without undue delay.

However:

Failure to notify and compensation for damage are separate questions.

A notification violation does not automatically establish Article 82 damages.

The claimant still needs the required damage and causal connection.

33. Contractual Limitation Clauses

Platforms frequently include:

liability caps;

exclusions for indirect loss;

exclusions for lost profits;

force-majeure provisions;

service credits;

disaster-recovery limitations.

Their enforceability depends upon:

applicable national law;

whether the customer is a consumer;

mandatory GDPR rights;

gross negligence or intentional misconduct;

unfair-contract-term rules.

A contract cannot simply eliminate mandatory statutory rights.

34. Consumer Platform Liability

Consumer platforms may include:

social-media services;

shopping platforms;

cloud-storage services;

digital-content services;

fintech applications;

health applications.

Consumer protection may restrict:

unfair liability clauses;

excessive exclusions;

unclear security obligations;

unilateral modification of terms.

The GDPR operates alongside, rather than simply replacing, consumer protection.

35. Platform's Possible Defences

A platform may argue:

1. No GDPR infringement

The processing/security measures were lawful and appropriate.

2. Appropriate security

The platform implemented reasonable technical and organisational measures.

3. External criminal attack

The loss resulted from an unforeseeable third-party attack.

4. No damage

The claimant suffered no legally recognised harm.

5. No causation

The alleged loss was caused by another event.

6. Mitigation failure

The claimant failed to take reasonable steps to reduce the loss.

7. Contractual limitation

A valid liability cap applies.

8. Force majeure

The incident falls within an applicable contractual or legal excuse.

36. Claimant's Arguments

A claimant may argue:

The platform knew the risk.

Security controls were inadequate.

Known vulnerabilities were not corrected.

Backups were inadequate.

Access controls were defective.

Employees were insufficiently trained.

The platform failed to monitor systems.

The platform failed to notify affected persons.

The platform violated contractual security commitments.

The loss caused actual financial or non-material damage.

The claimant should distinguish evidence of inadequate security from the mere fact that an incident occurred.

NAP and MediaMarktSaturn are particularly important on this distinction. (curia)

37. Remedies

Possible remedies include:

GDPR remedies

compensation;

erasure;

rectification;

restriction;

objection;

judicial remedy;

supervisory authority measures.

Contractual remedies

damages;

specific performance;

repair/restoration;

replacement;

service credits;

termination;

restitution.

Civil remedies

Depending upon national law:

injunction;

declaration;

compensation;

restitution;

damages for consequential loss.

38. Example

A European cloud platform stores the customer database of an online retailer.

The platform suffers a ransomware attack.

Consequences

customer data stolen;

database unavailable for 48 hours;

retailer loses €30,000;

€10,000 spent on forensic investigation;

customers suffer fear concerning misuse.

Potential analysis:

GDPR

Personal data was compromised.

Article 32

Were security measures appropriate?

Article 82

Did customers suffer actual material or non-material damage?

Contract

Did the cloud provider breach its security/SLA obligations?

Causation

Did the outage cause the €30,000 loss?

Damages

Potentially:

€30,000 business loss + €10,000 reasonable recovery cost + proven GDPR-related damage,

subject to the governing law, contract and evidence.

39. Core Legal Formula

For examination purposes, use:

D-S-B-C-D-R

D — Data
What data was lost?

S — Security
Were appropriate technical and organisational measures implemented?

B — Breach
Was there a GDPR or contractual breach?

C — Causation
Did the breach cause the loss?

D — Damage
What material or non-material damage occurred?

R — Remedy
What compensation or other remedy is available?

40. Quick Revision Table

IssueMain Legal Question
Data destructionWas data unlawfully lost or made unavailable?
HackingWere security measures appropriate?
Accidental disclosureWere organisational controls adequate?
RansomwareWhat security and contractual duties existed?
Personal dataDoes GDPR apply?
Article 82Was actual damage suffered?
CausationDid the platform's breach cause the damage?
Loss of controlCan it constitute non-material damage?
Fear of misuseWas actual non-material damage established?
Business lossCan the contractual claimant prove financial loss?
Processor failureWhich entity had responsibility?
Breach notificationWere Articles 33/34 complied with?
Liability capIs the contractual limitation enforceable?
CompensationMust be compensatory, not punitive

41. Key Case-Law Summary

CaseMain Rule
NAP, C-340/21Successful hacking does not automatically prove inadequate security; fear of misuse can constitute non-material damage in appropriate circumstances.
MediaMarktSaturn, C-687/21Employee's accidental disclosure does not automatically establish inadequate security; Article 82 compensation is compensatory.
Österreichische Post, C-300/21GDPR infringement alone is insufficient; infringement, damage and causation are required.
Gemeinde Ummendorf, C-456/22Loss of control over personal data can constitute non-material damage if actually suffered.
Scalable Capital, C-182/22 & C-189/22Data-security incident; no additional minimum seriousness threshold, but actual damage and causation remain necessary.
PS (Incorrect Address), C-590/22Accidental transmission does not automatically create compensation; identity theft is not required for every compensable data-theft claim.
Krankenversicherung Nordrhein, C-667/21Article 82 is compensatory; relevant to sensitive personal-data processing.
juris, C-741/21Reinforces the cumulative requirements of infringement, damage and causation.

42. Conclusion

Data loss platform liability in Europe is not based merely on the fact that a platform suffered a cyberattack or lost information. The legal analysis requires identification of the platform's role, the nature of the data, the applicable security and contractual duties, the circumstances of the loss, and the actual damage suffered.

The strongest modern authorities are NAP (C-340/21) for hacking and security, MediaMarktSaturn (C-687/21) for accidental disclosure, and Scalable Capital (C-182/22 and C-189/22) for platform-related data incidents and compensation. The CJEU's Article 82 jurisprudence consistently requires the claimant to establish (1) infringement, (2) damage and (3) causation. (InfoCuria)

The central principle can therefore be stated as:

Data Loss + Legal Duty + Security/Contractual Breach + Causation + Recognised Damage = Potential Platform Liability

Importantly, regulatory liability, GDPR compensation and contractual damages are distinct. A platform may face regulatory consequences for a compliance failure while an individual claimant may still have to prove actual compensable damage before obtaining civil compensation.

LEAVE A COMMENT