Civil Law And Data Loss Platform Liability In Europe
Civil Law and Data Loss Platform Liability in Europe
1. Introduction
Data loss platform liability concerns civil and data-protection claims arising when an online platform, digital service, marketplace, cloud service, social-media platform, fintech application, health platform or other digital intermediary loses, exposes, destroys, corrupts or unlawfully discloses personal or commercially important data.
Typical situations include:
hacking of a platform;
accidental disclosure of customer information;
loss of databases;
ransomware;
deletion or corruption of stored data;
employee disclosure;
insecure APIs;
cloud-storage failures;
loss of account information;
third-party processor failures;
inadequate access controls;
unauthorised copying;
loss of personal data during migration.
The central legal question is:
When does a platform's loss or exposure of data create civil liability and a right to compensation?
In Europe, the principal framework is the GDPR, supplemented by national civil law, contract law, consumer law, cybersecurity legislation and, depending on the platform, sector-specific rules.
2. Meaning of Data Loss
"Data loss" should be understood broadly.
It can involve:
A. Destruction
Data is permanently deleted or destroyed.
B. Loss of availability
The data technically exists but the customer cannot access it.
Example:
A cloud platform suffers ransomware and customers cannot access their business files.
C. Unauthorised disclosure
Data is disclosed to someone who was not authorised to receive it.
D. Unauthorised access
A hacker enters the platform's systems.
E. Data corruption
Information is changed or damaged.
F. Data theft
Personal or confidential information is copied or extracted.
G. Accidental transmission
An employee sends information to the wrong recipient.
3. Platform Liability Can Have Several Legal Foundations
A single incident may create several possible causes of action.
1. GDPR liability
Where personal data is involved.
2. Contractual liability
Where the platform breached its agreement with the customer.
3. Tort/delict liability
Where an independent duty under national civil law was breached.
4. Consumer protection
Where the customer is a consumer.
5. Cybersecurity regulation
For regulated platforms and digital service providers.
6. Intellectual-property/confidentiality liability
Where commercially confidential information is lost.
Therefore:
Data loss does not automatically equal one particular legal claim.
The correct legal regime depends on the type of data, parties, contract, platform and harm.
4. GDPR Framework
Where personal data is involved, important GDPR provisions include:
Article 5 — data-processing principles;
Article 6 — lawful processing;
Articles 12–14 — transparency;
Article 24 — controller responsibility;
Article 25 — data protection by design and default;
Article 28 — processors;
Article 32 — security of processing;
Articles 33–34 — breach notification;
Article 35 — data-protection impact assessment;
Article 82 — compensation;
Article 83 — administrative fines.
Article 32 is particularly important because controllers and processors must implement technical and organisational measures appropriate to the risks.
5. Data Loss Is Not Automatically GDPR Compensation
This is one of the most important principles.
Under Article 82, three elements generally have to be established:
1. GDPR infringement
There must be a violation of the GDPR.
2. Damage
The claimant suffered material or non-material damage.
3. Causation
The infringement caused that damage.
The CJEU repeatedly describes these three conditions as cumulative. (InfoCuria)
Therefore:
Data breach ≠ automatic damages.
6. Material Damage
Material damage means an economically measurable loss.
Examples:
money stolen following a data breach;
financial fraud;
identity-related financial loss;
business interruption;
restoration costs;
data-recovery costs;
replacement costs;
lost commercial opportunities;
additional cybersecurity expenses.
However, the claimant must demonstrate the connection between the platform's conduct and the financial loss.
7. Non-Material Damage
Non-material damage can involve:
anxiety;
fear of misuse;
loss of control over personal data;
distress;
reputational harm;
privacy interference.
The CJEU has held that non-material damage does not need to satisfy a minimum seriousness threshold merely to qualify for Article 82 compensation. But actual damage must still be established; infringement alone is insufficient. (curia)
8. Data Loss vs Data Breach
These concepts should be distinguished.
Data loss
The data may be:
deleted;
inaccessible;
corrupted;
destroyed.
Data breach
The GDPR definition of a personal-data breach covers a breach of security leading to:
destruction;
loss;
alteration;
unauthorised disclosure; or
unauthorised access
to personal data.
Therefore, data loss can itself constitute a personal-data breach when the affected information is personal data.
9. Platform as Controller
A platform may be a data controller when it determines the purposes and means of processing personal data.
Example:
An online marketplace decides what customer information it collects, why it collects it and how it uses it.
The controller has primary responsibility for compliance with GDPR obligations.
10. Platform as Processor
Sometimes the platform acts as a processor.
Example:
A cloud provider stores personal data on behalf of a bank, but the bank determines the purposes of processing.
The processor still has important GDPR obligations, particularly regarding:
security;
contractual compliance;
assistance to the controller;
breach notification to the controller;
appropriate technical and organisational measures.
11. Controller-Processor Liability
A complicated data-loss incident can involve:
Customer → Platform → Cloud provider → Cybersecurity contractor
The claimant must determine:
Who controlled the data?
Who processed it?
Who caused the security failure?
Who had responsibility for the relevant technical measure?
Was there a contractual allocation of responsibility?
Did the processor notify the controller?
Did the controller respond appropriately?
Article 82 can potentially impose liability on controllers and processors, subject to the GDPR's liability rules.
12. Security Standard
Article 32 requires security measures appropriate to the risk.
Relevant measures may include:
encryption;
pseudonymisation;
access controls;
authentication;
network segmentation;
backup systems;
incident-response procedures;
vulnerability management;
employee training;
monitoring;
disaster recovery.
The question is not simply:
"Was the platform hacked?"
The more important question is:
Were the technical and organisational measures appropriate to the risks at the relevant time?
13. Hacker Attack Is Not Automatically a Defence
A platform may argue:
"The hacker caused the loss, not us."
That argument is not automatically successful.
The CJEU's Natsionalna agentsia za prihodite judgment makes clear that a successful hacking attack does not by itself establish that the controller's security measures were inadequate, but the controller must be able to demonstrate the appropriateness of the measures in the circumstances. (curia)
Thus:
Hacking → investigate security → assess adequacy → determine infringement → assess damage and causation.
14. Case Law
Case 1 — Natsionalna agentsia za prihodite (NAP)
CJEU, Case C-340/21
Judgment: 14 December 2023
This is one of the most important European cases on cyberattack-related data loss.
The Bulgarian National Revenue Agency suffered a cyberattack resulting in unauthorised access to and dissemination of personal data.
The litigation concerned:
adequacy of security measures;
hacking;
burden of proof;
Article 32;
Article 82;
fear of future misuse.
The CJEU held that the mere fact that a hacking attack succeeded does not automatically prove that the security measures were inappropriate.
At the same time, fear concerning possible future misuse of personal data can constitute non-material damage where the relevant conditions are satisfied. (curia)
Principle
A controller cannot be held liable simply because a hacker succeeded, but neither can a controller avoid scrutiny merely by pointing to the hacker.
Importance
This case is directly relevant to:
platform hacking;
ransomware;
cybersecurity;
data theft;
Article 32;
Article 82;
non-material damage.
15. Case 2 — MediaMarktSaturn
CJEU, Case C-687/21
Judgment: 25 January 2024
Employees accidentally provided a document containing personal data to an unauthorised third party.
The Court considered Articles 24, 32 and 82 GDPR.
The CJEU held that the accidental disclosure, by itself, did not automatically establish that the technical and organisational measures were inappropriate. The assessment must be concrete and consider the circumstances. (InfoCuria)
The Court also confirmed that Article 82 compensation is compensatory rather than punitive. (InfoCuria)
Principle
Employee error does not automatically prove inadequate security.
Importance
Very useful for:
employee mistakes;
wrong-email incidents;
accidental disclosure;
internal platform controls;
Article 32 security;
Article 82 damages.
16. Case 3 — Österreichische Post
CJEU, Case C-300/21
Judgment: 4 May 2023
Österreichische Post used an algorithm to analyse information and determine political affinities of individuals.
The case concerned compensation for alleged non-material damage.
The CJEU held:
Mere infringement of the GDPR does not automatically create a right to compensation.
The claimant must establish:
infringement;
damage;
causal connection.
At the same time, EU law does not permit compensation for non-material damage to be made conditional upon crossing an additional minimum seriousness threshold. (curia)
Importance for platform data loss
It provides the basic damages framework for almost every GDPR data-loss claim.
17. Case 4 — Gemeinde Ummendorf
CJEU, Case C-456/22
Judgment: 14 December 2023
The case concerned unlawful online publication of personal data.
The CJEU considered whether loss of control over personal information could constitute non-material damage.
The Court recognised that even a relatively short loss of control may constitute compensable non-material damage if the individual actually suffered such damage. (Curia)
Principle
Loss of control over personal data can be legally significant even without proven financial loss.
Importance
This is highly relevant to:
public platform disclosure;
website publication;
database exposure;
online dissemination;
unauthorised access.
18. Case 5 — Scalable Capital
CJEU, Joined Cases C-182/22 and C-189/22
Judgment: 20 June 2024
The litigation arose from a personal-data security incident affecting customers of a financial platform.
The Court examined:
loss of control;
fear of misuse;
Article 82;
compensation;
causal connection.
The CJEU reaffirmed that GDPR compensation requires infringement, damage and causation, but a claimant does not need to prove that the damage reached some additional minimum level of seriousness. (Curia)
Principle
A claimant can potentially recover for non-material damage arising from loss of control, including where the harm is relatively limited, provided actual damage is demonstrated.
Importance
This is particularly useful for:
financial platforms;
fintech;
customer databases;
account information;
cybersecurity incidents.
19. Case 6 — PS (Incorrect Address)
CJEU, Case C-590/22
Judgment: 20 June 2024
The case concerned personal data being transmitted to an incorrect address.
The CJEU again emphasised that:
infringement alone is insufficient;
damage must actually be suffered;
causation must be established.
The Court also rejected the idea that every data theft must result in actual identity theft before non-material damage can be compensated. (InfoCuria)
Principle
Actual identity theft is not a mandatory prerequisite for Article 82 compensation.
Importance
This is particularly useful for:
wrong-recipient incidents;
platform communication errors;
accidental disclosure;
customer-data transmission.
20. Case 7 — Krankenversicherung Nordrhein
CJEU, Case C-667/21
Judgment: 21 December 2023
This case concerned GDPR compensation and processing involving sensitive personal information.
The Court reaffirmed the compensatory nature of Article 82 and the requirement for:
infringement;
damage;
causation.
Principle
Article 82 compensation is designed to compensate the damage actually suffered, rather than punish the controller.
Importance
It is useful where platform data loss involves:
health information;
special-category data;
confidential customer information.
21. Case 8 — juris
CJEU, Case C-741/21
Judgment: 11 April 2024
The CJEU again considered Article 82 compensation.
The Court reaffirmed that:
infringement + damage + causal link
are cumulative requirements.
The judgment is important because it reinforces the distinction between a GDPR violation and compensable harm. (Curia)
Importance
It provides useful support for the general Article 82 framework in platform liability litigation.
22. Direct and Analogous Authorities
| Case | Relevance to Data Loss Platform Liability |
|---|---|
| NAP, C-340/21 | Direct — hacking/data breach/security |
| MediaMarktSaturn, C-687/21 | Direct — accidental disclosure/security |
| Scalable Capital, C-182/22 & C-189/22 | Direct/very strong — platform data incident and compensation |
| Österreichische Post, C-300/21 | Direct for Article 82 damages |
| Gemeinde Ummendorf, C-456/22 | Strong — loss of control/online disclosure |
| PS (Incorrect Address), C-590/22 | Strong — accidental disclosure |
| Krankenversicherung Nordrhein, C-667/21 | Strong — sensitive data/compensation |
| juris, C-741/21 | Strong — Article 82 liability framework |
These cases are preferable to using unrelated general contract cases because the CJEU has now developed a substantial body of Article 82 jurisprudence.
23. Data Loss and Contractual Liability
GDPR liability is not necessarily the only claim.
Suppose:
A business pays a cloud platform €50,000 annually to store its customer database.
The platform's contract promises:
backups;
99.9% availability;
encryption;
disaster recovery;
security monitoring.
The platform fails to maintain backups and the database is permanently lost.
The customer may potentially have:
Contractual claim
Breach of:
backup obligation;
security obligation;
availability obligation;
disaster-recovery obligation.
GDPR claim
If the database contains personal data.
Tort/delict claim
Depending upon national law.
Therefore:
One incident can generate multiple legal causes of action.
24. Data Loss and Commercial Information
Not all data is personal data.
A platform may lose:
trade secrets;
source code;
financial models;
customer lists;
business strategies;
research data;
confidential contracts.
These matters may fall primarily under:
contract law;
trade-secret law;
confidentiality obligations;
intellectual-property law;
tort/delict.
GDPR compensation cannot be used merely because commercially valuable information was lost if it does not constitute personal data.
25. Availability Failure
A platform may not disclose data at all but may nevertheless become liable because customers cannot access their data.
Example:
Cloud platform is unavailable for 72 hours.
A business loses €100,000 in sales.
The central questions become:
What did the contract promise?
Was availability guaranteed?
Was there an SLA?
Was the outage foreseeable?
Was it caused by force majeure?
Did the customer mitigate the loss?
Is lost profit recoverable?
Is there a contractual liability cap?
This is primarily a contractual damages analysis unless personal-data obligations are also implicated.
26. Ransomware
Ransomware creates several possible legal issues.
Scenario
A platform is attacked.
Attackers:
encrypt customer files;
steal personal information;
demand payment;
prevent access.
Potential claims include:
GDPR;
contractual liability;
cybersecurity obligations;
confidentiality;
negligence/delict;
business interruption;
regulatory liability.
The platform's key defence may be:
"The attack was an external criminal act."
But NAP demonstrates that the existence of an external hacker does not eliminate the need to assess whether security measures were appropriate. (curia)
27. Data Loss and Third-Party Processors
A platform may outsource:
cloud storage;
email;
analytics;
customer support;
payment processing;
cybersecurity;
database management.
Example:
Platform → Cloud Provider → Subprocessor
A security failure at the subprocessor does not automatically end the platform's responsibility.
The contractual and GDPR roles of each entity must be identified.
28. Causation
Causation is often the hardest part of the claim.
Example
Platform suffers data breach.
Customer later loses €20,000 due to identity fraud.
The claimant must establish a sufficiently direct causal connection.
The court may ask:
Was the fraud actually caused by this particular breach?
If the same information was already publicly available from several other sources, causation may become difficult.
29. Fear of Future Misuse
This is an important modern issue.
Suppose:
Platform data is stolen, but no identity fraud has yet occurred.
Can the claimant recover for fear that the data may be misused?
Potentially yes, but the claimant must establish actual non-material damage.
The CJEU has recognised that fear concerning possible future misuse can constitute non-material damage in appropriate circumstances. NAP is particularly important on this point. (curia)
But:
mere theoretical fear + no actual damage
does not automatically establish an Article 82 claim.
30. Data Loss Involving Sensitive Data
Risk is especially serious where the platform loses:
health information;
biometric data;
genetic information;
political information;
religious information;
sexual-orientation information;
financial information.
Such processing can trigger Article 9 and heightened risk considerations.
The amount of compensation is not automatically determined by the sensitivity of the data alone, but the nature and consequences of the damage remain relevant to the assessment.
31. Evidence
A claimant should preserve:
breach notifications;
platform emails;
incident reports;
access logs;
screenshots;
account records;
contracts;
service-level agreements;
cybersecurity reports;
evidence of financial losses;
evidence of fraud;
communications with the platform;
data-access responses;
evidence of anxiety or reputational harm where relevant.
The platform may need to demonstrate:
security measures;
risk assessments;
incident-response procedures;
access controls;
employee training;
encryption;
audit records;
processor arrangements.
32. Data Breach Notification
Under GDPR Articles 33 and 34, certain personal-data breaches trigger notification obligations.
Generally:
Supervisory authority
Where required, notification must be made without undue delay and, where feasible, within 72 hours after the controller becomes aware of the breach.
Data subjects
Where the breach is likely to result in a high risk to individuals, affected persons may also need to be informed without undue delay.
However:
Failure to notify and compensation for damage are separate questions.
A notification violation does not automatically establish Article 82 damages.
The claimant still needs the required damage and causal connection.
33. Contractual Limitation Clauses
Platforms frequently include:
liability caps;
exclusions for indirect loss;
exclusions for lost profits;
force-majeure provisions;
service credits;
disaster-recovery limitations.
Their enforceability depends upon:
applicable national law;
whether the customer is a consumer;
mandatory GDPR rights;
gross negligence or intentional misconduct;
unfair-contract-term rules.
A contract cannot simply eliminate mandatory statutory rights.
34. Consumer Platform Liability
Consumer platforms may include:
social-media services;
shopping platforms;
cloud-storage services;
digital-content services;
fintech applications;
health applications.
Consumer protection may restrict:
unfair liability clauses;
excessive exclusions;
unclear security obligations;
unilateral modification of terms.
The GDPR operates alongside, rather than simply replacing, consumer protection.
35. Platform's Possible Defences
A platform may argue:
1. No GDPR infringement
The processing/security measures were lawful and appropriate.
2. Appropriate security
The platform implemented reasonable technical and organisational measures.
3. External criminal attack
The loss resulted from an unforeseeable third-party attack.
4. No damage
The claimant suffered no legally recognised harm.
5. No causation
The alleged loss was caused by another event.
6. Mitigation failure
The claimant failed to take reasonable steps to reduce the loss.
7. Contractual limitation
A valid liability cap applies.
8. Force majeure
The incident falls within an applicable contractual or legal excuse.
36. Claimant's Arguments
A claimant may argue:
The platform knew the risk.
Security controls were inadequate.
Known vulnerabilities were not corrected.
Backups were inadequate.
Access controls were defective.
Employees were insufficiently trained.
The platform failed to monitor systems.
The platform failed to notify affected persons.
The platform violated contractual security commitments.
The loss caused actual financial or non-material damage.
The claimant should distinguish evidence of inadequate security from the mere fact that an incident occurred.
NAP and MediaMarktSaturn are particularly important on this distinction. (curia)
37. Remedies
Possible remedies include:
GDPR remedies
compensation;
erasure;
rectification;
restriction;
objection;
judicial remedy;
supervisory authority measures.
Contractual remedies
damages;
specific performance;
repair/restoration;
replacement;
service credits;
termination;
restitution.
Civil remedies
Depending upon national law:
injunction;
declaration;
compensation;
restitution;
damages for consequential loss.
38. Example
A European cloud platform stores the customer database of an online retailer.
The platform suffers a ransomware attack.
Consequences
customer data stolen;
database unavailable for 48 hours;
retailer loses €30,000;
€10,000 spent on forensic investigation;
customers suffer fear concerning misuse.
Potential analysis:
GDPR
Personal data was compromised.
Article 32
Were security measures appropriate?
Article 82
Did customers suffer actual material or non-material damage?
Contract
Did the cloud provider breach its security/SLA obligations?
Causation
Did the outage cause the €30,000 loss?
Damages
Potentially:
€30,000 business loss + €10,000 reasonable recovery cost + proven GDPR-related damage,
subject to the governing law, contract and evidence.
39. Core Legal Formula
For examination purposes, use:
D-S-B-C-D-R
D — Data
What data was lost?
S — Security
Were appropriate technical and organisational measures implemented?
B — Breach
Was there a GDPR or contractual breach?
C — Causation
Did the breach cause the loss?
D — Damage
What material or non-material damage occurred?
R — Remedy
What compensation or other remedy is available?
40. Quick Revision Table
| Issue | Main Legal Question |
|---|---|
| Data destruction | Was data unlawfully lost or made unavailable? |
| Hacking | Were security measures appropriate? |
| Accidental disclosure | Were organisational controls adequate? |
| Ransomware | What security and contractual duties existed? |
| Personal data | Does GDPR apply? |
| Article 82 | Was actual damage suffered? |
| Causation | Did the platform's breach cause the damage? |
| Loss of control | Can it constitute non-material damage? |
| Fear of misuse | Was actual non-material damage established? |
| Business loss | Can the contractual claimant prove financial loss? |
| Processor failure | Which entity had responsibility? |
| Breach notification | Were Articles 33/34 complied with? |
| Liability cap | Is the contractual limitation enforceable? |
| Compensation | Must be compensatory, not punitive |
41. Key Case-Law Summary
| Case | Main Rule |
|---|---|
| NAP, C-340/21 | Successful hacking does not automatically prove inadequate security; fear of misuse can constitute non-material damage in appropriate circumstances. |
| MediaMarktSaturn, C-687/21 | Employee's accidental disclosure does not automatically establish inadequate security; Article 82 compensation is compensatory. |
| Österreichische Post, C-300/21 | GDPR infringement alone is insufficient; infringement, damage and causation are required. |
| Gemeinde Ummendorf, C-456/22 | Loss of control over personal data can constitute non-material damage if actually suffered. |
| Scalable Capital, C-182/22 & C-189/22 | Data-security incident; no additional minimum seriousness threshold, but actual damage and causation remain necessary. |
| PS (Incorrect Address), C-590/22 | Accidental transmission does not automatically create compensation; identity theft is not required for every compensable data-theft claim. |
| Krankenversicherung Nordrhein, C-667/21 | Article 82 is compensatory; relevant to sensitive personal-data processing. |
| juris, C-741/21 | Reinforces the cumulative requirements of infringement, damage and causation. |
42. Conclusion
Data loss platform liability in Europe is not based merely on the fact that a platform suffered a cyberattack or lost information. The legal analysis requires identification of the platform's role, the nature of the data, the applicable security and contractual duties, the circumstances of the loss, and the actual damage suffered.
The strongest modern authorities are NAP (C-340/21) for hacking and security, MediaMarktSaturn (C-687/21) for accidental disclosure, and Scalable Capital (C-182/22 and C-189/22) for platform-related data incidents and compensation. The CJEU's Article 82 jurisprudence consistently requires the claimant to establish (1) infringement, (2) damage and (3) causation. (InfoCuria)
The central principle can therefore be stated as:
Data Loss + Legal Duty + Security/Contractual Breach + Causation + Recognised Damage = Potential Platform Liability
Importantly, regulatory liability, GDPR compensation and contractual damages are distinct. A platform may face regulatory consequences for a compliance failure while an individual claimant may still have to prove actual compensable damage before obtaining civil compensation.

comments