Civil Law And Data Protection Authority Civil Penalty Litigation In Europe .

Civil Law and Data Protection Authority Civil Penalty Litigation in Europe

1. Introduction

Data Protection Authority (DPA) civil penalty litigation concerns legal challenges arising from penalties, corrective measures, enforcement orders and related proceedings initiated by European data-protection supervisory authorities against controllers and processors.

The modern framework is principally based on the EU General Data Protection Regulation (GDPR).

A useful distinction should be made at the outset:

Administrative fine → imposed by a supervisory authority under Article 83 GDPR.

Civil compensation → generally sought by an injured individual under Article 82 GDPR.

Judicial review of a DPA decision → the fined organisation challenges the authority's decision before a national court.

Regulatory enforcement → the DPA uses corrective powers under Article 58 GDPR.

Representative/private litigation → individuals or qualified bodies may pursue rights separately from the administrative penalty process.

The CJEU has expressly distinguished the punitive/regulatory function of administrative fines from the compensatory function of Article 82 damages. (EUR-Lex)

2. Meaning of DPA Civil Penalty Litigation

A typical dispute looks like this:

Data processing

↓

DPA investigation

↓

Finding of GDPR infringement

↓

Administrative fine / corrective order

↓

Controller or processor challenges decision

↓

National court review

↓

Possible preliminary reference to CJEU

The dispute may concern:

whether an infringement occurred;

whether the organisation was the controller;

whether it was a processor;

whether the conduct was intentional or negligent;

whether the DPA had jurisdiction;

whether procedural rights were respected;

whether the fine was proportionate;

whether the turnover calculation was correct;

whether the DPA properly exercised discretion.

3. Main Legal Framework

A. GDPR

The central provisions are:

Article 5

Basic principles of processing.

Article 6

Lawfulness of processing.

Articles 12–14

Transparency and information obligations.

Articles 24–25

Controller responsibility and data protection by design/default.

Article 28

Processor obligations.

Article 32

Security of processing.

Article 58

Supervisory-authority powers.

Article 60

Cooperation and consistency mechanism.

Article 65

Dispute resolution by the EDPB.

Article 77

Right to lodge a complaint.

Article 78

Judicial remedy against a supervisory authority.

Article 79

Judicial remedy against a controller or processor.

Article 82

Right to compensation.

Article 83

Administrative fines.

Article 84

Other penalties under Member-State law.

4. Nature of an Administrative Fine

An Article 83 fine is primarily regulatory and punitive, rather than compensation for an individual victim.

The GDPR requires fines to be:

effective;

proportionate;

dissuasive.

The EDPB's current guidance confirms that fines are one of a range of enforcement measures available to DPAs, alongside warnings, reprimands and orders. (European Data Protection Board)

For serious categories of infringement, the GDPR allows fines of up to:

€20 million or 4% of worldwide annual turnover, whichever is higher.

The applicable tier depends upon the infringement involved. (Bailii)

5. Fine vs Civil Compensation

This is a fundamental distinction.

Administrative fine

DPA → organisation

Purpose:

punishment;

deterrence;

regulatory enforcement.

Civil compensation

Individual → controller/processor

Purpose:

compensate actual damage.

The CJEU in Österreichische Post confirmed that a mere GDPR infringement does not automatically create a right to compensation; damage caused by the infringement is required. At the same time, EU law does not permit a national rule imposing an additional minimum seriousness threshold for non-material damage. (EUR-Lex)

Therefore:

Fine ≠ compensation.

A €100 million regulatory fine does not automatically mean that every affected data subject receives part of that amount.

6. Who Can Be Fined?

A DPA may investigate:

Controller

The person or organisation determining the purposes and means of processing.

Processor

The entity processing personal data on behalf of a controller.

Joint controllers

Two or more entities jointly determining purposes and means.

The identification of the correct legal entity is often the first major issue in penalty litigation.

7. Case Law 1 — Deutsche Wohnen SE v Staatsanwaltschaft Berlin

Case C-807/21
CJEU (Grand Chamber), 5 December 2023

This is one of the most important cases on GDPR administrative fines.

Facts

The Berlin data-protection authority imposed fines on Deutsche Wohnen SE concerning the retention and processing of tenants' personal data.

German procedural law raised questions concerning whether a fine could be imposed on a legal person without first attributing the infringement to an identified natural person. (EUR-Lex)

CJEU decision

The CJEU held that EU law does not permit Member States to impose additional substantive conditions under which GDPR administrative fines can be imposed on legal persons.

In particular, national law could not make the fine dependent upon first attributing the infringement to an identified natural person. (EUR-Lex)

Fault

The Court nevertheless confirmed an important limitation:

An Article 83 fine requires a culpable/wrongful infringement, meaning intentional or negligent conduct.

Thus:

GDPR infringement + no wrongful conduct = administrative fine cannot simply be imposed automatically.

Importance

The case establishes:

direct responsibility of legal persons;

importance of culpability;

limits on national procedural/substantive barriers;

autonomous EU standards for GDPR fines.

8. Case Law 2 — Nacionalinis visuomenės sveikatos centras

Case C-683/21
CJEU (Grand Chamber), 5 December 2023

This case concerned a Lithuanian public-health authority and the development of a mobile application during the COVID-19 period.

The application processed personal data concerning persons who had potentially been in contact with infected individuals. (EUR-Lex)

Issues

The CJEU considered:

controller status;

joint controllership;

processor responsibility;

administrative fines;

intentional/negligent conduct.

Decision

The Court held that an administrative fine under Article 83 requires an infringement committed intentionally or negligently.

It also held that a controller can be fined for processing performed by a processor on its behalf, subject to circumstances in which the processor acts for its own purposes or outside the controller's authorised processing framework. (EUR-Lex)

Importance

This case is extremely useful where an organisation argues:

“The processor made the mistake, so we cannot be fined.”

That argument does not automatically succeed.

The relationship between controller and processor must be examined.

9. Case Law 3 — Österreichische Post

Case C-300/21, UI v Österreichische Post AG
CJEU, 4 May 2023

This case is particularly important for the civil-compensation side of DPA enforcement.

Facts

Österreichische Post used an algorithm to predict political affinities of Austrian residents.

The claimant alleged that processing incorrectly associated him with a particular political party and sought compensation for non-material damage. (EUR-Lex)

Decision

The CJEU held:

a GDPR infringement alone is insufficient for Article 82 compensation;

actual damage caused by the infringement must exist;

non-material damage does not have to cross a separate national seriousness threshold. (EUR-Lex)

Importance

The case demonstrates the separation between:

DPA penalty

and

private damages action.

An authority can impose a fine because regulatory conditions are satisfied, while an individual still has to establish the elements of Article 82 for compensation.

10. Case Law 4 — Google Spain

Case C-131/12, Google Spain SL and Google Inc. v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González
CJEU, 13 May 2014

This landmark case concerned the processing of personal data by search engines and the so-called right to be forgotten.

Principle

Search engines can be controllers for processing carried out through indexing and displaying personal information.

Individuals can, under appropriate conditions, request removal of search results concerning them.

Relevance to DPA litigation

The case illustrates the supervisory authority's role in protecting data-subject rights.

It also demonstrates that an organisation may have GDPR/data-protection obligations even where the underlying information was originally published elsewhere.

Civil-law significance

The case links:

privacy;

personality rights;

data protection;

regulatory supervision;

judicial review.

11. Case Law 5 — Wirtschaftsakademie Schleswig-Holstein

Case C-210/16, Wirtschaftsakademie Schleswig-Holstein GmbH v Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
CJEU, 5 June 2018

Facts

Wirtschaftsakademie operated a Facebook fan page.

The German supervisory authority ordered it to deactivate the page because of concerns regarding personal-data processing associated with Facebook's systems.

Issue

Could the fan-page operator be treated as a joint controller even though Facebook technically carried out much of the processing?

Decision

The CJEU adopted a broad understanding of joint controllership.

A party may have controller responsibility even though it does not itself possess every piece of personal data or technically perform every processing operation.

Importance

This principle is highly relevant to DPA penalty litigation.

An organisation cannot necessarily avoid enforcement simply by arguing:

“Another technology company actually processed the data.”

Responsibility can depend upon the organisation's influence over the purposes and means of processing.

12. Case Law 6 — Fashion ID

Case C-40/17, Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV
CJEU, 29 July 2019

Facts

Fashion ID embedded Facebook's “Like” button on its website.

When users visited the website, personal data could be transmitted to Facebook.

Issue

Was Fashion ID a controller even though it did not itself determine all subsequent processing by Facebook?

Decision

The CJEU held that Fashion ID could be a joint controller in relation to the collection and transmission of data to Facebook.

However, controller responsibility did not automatically extend to every subsequent processing operation carried out by Facebook.

Importance

This is highly relevant to penalty litigation because it demonstrates that controller responsibility must be linked to the specific processing operation concerned.

13. Case Law 7 — Schrems II

Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
CJEU, 16 July 2020

Facts

The case concerned transfers of personal data from the European Union to the United States.

Decision

The CJEU invalidated the EU-US Privacy Shield and maintained the validity of Standard Contractual Clauses subject to appropriate safeguards and assessment of the destination country's legal environment.

Importance for DPA penalty litigation

Cross-border transfers can generate substantial regulatory exposure.

A DPA may investigate:

international transfers;

adequacy;

contractual safeguards;

supplementary measures;

access by foreign authorities.

The case demonstrates that technical compliance with contractual mechanisms is not always enough if the destination legal environment prevents adequate protection.

14. Case Law 8 — Data Protection Commission v EDPB

Joined Cases T-70/23, T-84/23 and T-111/23
General Court of the European Union, 29 January 2025

These proceedings arose from the GDPR consistency mechanism involving the Irish DPC and EDPB decisions concerning Facebook, Instagram and WhatsApp.

The DPC challenged parts of EDPB Binding Decisions 3/2022, 4/2022 and 5/2022, particularly directions concerning further investigations and draft decisions. (EUR-Lex)

Importance

This case illustrates the institutional structure of GDPR enforcement:

Lead Supervisory Authority

↓

Concerned Supervisory Authorities

↓

Disagreement

↓

EDPB dispute-resolution mechanism

↓

Binding decision

↓

Judicial review

It is particularly important in cross-border penalty litigation.

15. Case Law 9 — Meta Platforms Ireland v Data Protection Commission

Meta Platforms Ireland Ltd v Data Protection Commission, Irish High Court, 2026

The Irish courts have continued to review major DPC enforcement decisions.

The 2026 litigation includes challenges involving the interpretation and application of GDPR administrative fines, including Article 83 and the relationship between controller/processor obligations and penalty calculation. (Bailii)

Importance

The case demonstrates that major GDPR penalties remain subject to effective judicial review.

A DPA decision is not necessarily the final word.

The fined organisation may challenge:

legal interpretation;

procedural fairness;

evidence;

proportionality;

fine calculation;

statutory authority.

16. Case Law 10 — TikTok Technology Limited v DPC

Irish proceedings concerning TikTok Technology Limited v Data Protection Commission continue to illustrate judicial review of major GDPR enforcement decisions.

The Irish DPC's current judgment register records Supreme Court proceedings decided on 5 May 2026, alongside High Court and Court of Appeal proceedings. (Homepage | Data Protection Commission)

The DPC's published enforcement records show that TikTok received a €530 million administrative fine in April 2025, with the matter listed as pending appeal. (Homepage | Data Protection Commission)

Importance

The litigation illustrates:

judicial scrutiny of DPA decisions;

procedural rights;

proportionality;

interpretation of GDPR obligations;

appeal mechanisms.

17. Case-Law Summary Table

CaseCourtMain issueKey principle
Deutsche Wohnen v Staatsanwaltschaft Berlin, C-807/21CJEUFine against legal personNo requirement to identify a natural person first
Nacionalinis visuomenės sveikatos centras, C-683/21CJEUController/processor and finesFine requires intentional/negligent infringement
Österreichische Post, C-300/21CJEUArticle 82 compensationMere GDPR breach does not automatically establish damages
Google Spain, C-131/12CJEUSearch-engine processingSearch engine can be controller
Wirtschaftsakademie, C-210/16CJEUFacebook fan pageBroad joint-controller concept
Fashion ID, C-40/17CJEUWebsite plug-inController responsibility can be operation-specific
Schrems II, C-311/18CJEUInternational transfersTransfer safeguards must provide effective protection
DPC v EDPB, T-70/23 etc.General CourtCross-border enforcementJudicial review of EDPB consistency decisions
Meta v DPCIrish High CourtGDPR penalty reviewMajor administrative fines remain judicially reviewable
TikTok v DPCIrish courtsLarge GDPR penaltyAppeals can scrutinise regulatory decisions

18. Procedure for Challenging a DPA Penalty

A simplified procedure is:

Stage 1 — Investigation

The DPA collects:

documents;

correspondence;

technical evidence;

audit records;

witness statements;

controller submissions.

Stage 2 — Draft/final decision

The authority determines:

infringement;

corrective measures;

fine;

reasoning.

Stage 3 — Administrative cooperation

In cross-border cases, Articles 60–65 GDPR may become relevant.

Stage 4 — Judicial challenge

The organisation challenges the decision before the competent national court.

Stage 5 — Possible CJEU reference

If interpretation of EU law is uncertain, the national court may refer questions to the CJEU.

19. Grounds of Challenge

A company may challenge a DPA fine on several grounds.

A. No infringement

The organisation argues:

“The GDPR provision was not violated.”

B. Wrong controller

The organisation may argue:

“We were only a processor, not the controller.”

C. Lack of culpability

After Deutsche Wohnen and Nacionalinis, this can be important.

The organisation may argue:

“There was no intentional or negligent conduct.”

D. Insufficient evidence

The authority may have failed to establish:

what happened;

who caused it;

when it occurred;

what data were affected.

E. Procedural violation

Possible issues include:

inadequate opportunity to respond;

insufficient reasoning;

unlawful evidence;

failure to consider submissions;

procedural delay;

failure to respect rights of defence.

F. Disproportionate fine

The organisation may argue that the fine is:

excessive;

insufficiently reasoned;

inconsistent with Article 83;

disproportionate to the infringement.

20. Article 83 Fine Calculation

The DPA must consider relevant factors, including:

nature of infringement;

gravity;

duration;

intentional or negligent character;

mitigation;

preventative measures;

degree of responsibility;

previous infringements;

cooperation;

categories of personal data;

manner in which infringement became known;

compliance with previous measures;

adherence to codes/certification mechanisms;

other aggravating or mitigating factors.

The EDPB's current fines guidance specifically addresses the relationship between administrative fines and other corrective powers. (European Data Protection Board)

21. Proportionality

A major civil-law principle is proportionality.

The authority must balance:

Gravity of infringement

against

Economic impact

and

Deterrence requirement.

A fine should neither become meaningless nor operate as an arbitrary punishment.

The GDPR expressly requires fines to be effective, proportionate and dissuasive. (European Data Protection Board)

22. Turnover of Corporate Groups

The size of a corporate group can matter significantly.

In Deutsche Wohnen, the CJEU confirmed that the concept of an “undertaking” is relevant to calculating the fine, including group turnover, rather than limiting the calculation mechanically to the turnover of a single corporate entity. (EUR-Lex)

This prevents large corporate groups from arguing that a fine should always be calculated solely by reference to a small subsidiary's turnover.

23. Controller and Processor Liability

Consider:

Company A = controller

Company B = processor

Company B makes a GDPR error.

Can A be fined?

Nacionalinis indicates that a controller can, in appropriate circumstances, be fined for processing performed by its processor.

However, if the processor begins processing for its own purposes or materially outside the controller's authorised framework, responsibility may shift toward the processor for that processing. (EUR-Lex)

24. Joint Controllers

Joint controllership is particularly important in:

advertising;

social media;

analytics;

plug-ins;

marketplaces;

mobile applications;

data-sharing arrangements.

Wirtschaftsakademie and Fashion ID show that an organisation can have controller responsibilities even if another company performs the technical processing.

25. Data Breach Penalties

A DPA may impose a fine following:

hacking;

ransomware;

credential theft;

accidental disclosure;

inadequate access controls;

token compromise;

failure to report a breach.

For example, the Irish DPC's December 2024 Meta decisions imposed total administrative fines of €251 million concerning security and breach-related GDPR obligations, including Articles 25 and 33. (Homepage | Data Protection Commission)

The decisions concerned a breach affecting approximately 29 million Facebook accounts globally, including about 3 million in the EU/EEA. (Homepage | Data Protection Commission)

26. DPA Penalty and Individual Damages Can Coexist

Suppose:

DPA fine = €50 million

and

1,000 individuals suffered compensable damage.

The fine does not automatically compensate those individuals.

The individuals may separately pursue Article 82 claims.

Thus:

Regulatory enforcement

and

private civil liability

can operate simultaneously.

The CJEU's treatment in Österreichische Post makes this distinction especially important. (EUR-Lex)

27. Evidence in Penalty Litigation

Important evidence may include:

privacy policies;

data maps;

records of processing activities;

DPIAs;

processor agreements;

security logs;

breach reports;

internal emails;

compliance manuals;

employee instructions;

consent records;

technical architecture;

audit reports;

DPA correspondence;

expert reports.

Technical evidence becomes particularly important in:

cybersecurity cases;

AI processing;

profiling;

automated decision-making;

international transfers.

28. Civil-Law Principles Applicable to DPA Litigation

Although GDPR enforcement is primarily regulatory, civil-law concepts can influence judicial review.

Important principles include:

Good faith

The organisation should deal honestly with regulators and data subjects.

Proportionality

Penalty and corrective measures should correspond to the infringement.

Legal certainty

The organisation should be able to understand the applicable legal requirements.

Due process

The organisation must have an effective opportunity to defend itself.

Reasoned decision-making

The DPA should explain why the infringement and penalty were established.

Causation

Particularly important for separate compensation proceedings.

29. DPA Liability vs Controller Liability

There are actually two different potential disputes.

Dispute A

DPA → controller

Question:

Did the controller violate the GDPR?

Dispute B

Individual → controller

Question:

Did the controller's violation cause compensable damage?

Dispute C

Controller → DPA

Question:

Was the DPA's enforcement decision legally valid?

These should not be confused.

30. Hypothetical Example

Suppose a European social-media company processes 20 million users' data.

The DPA discovers:

unclear privacy information;

unlawful processing basis;

insufficient security;

inadequate retention controls.

The DPA imposes a large fine.

The company challenges it.

The court may examine:

Was the company a controller?

What processing occurred?

Which GDPR provisions applied?

Was the processing unlawful?

Was the company intentionally or negligently responsible?

Did the DPA follow correct procedure?

Were the findings supported by evidence?

Were Article 83 factors considered?

Was the fine proportionate?

Was the DPA required to follow an EDPB binding decision?

If users separately seek compensation, the court handling those claims must additionally examine:

What damage did each claimant actually suffer?

31. Important Difference Between Administrative and Civil Penalties

Strictly speaking, “civil penalty” is not the most precise EU GDPR terminology.

The GDPR primarily uses:

“administrative fines.”

The phrase “civil penalty litigation” can therefore be understood broadly to include litigation concerning the legality, enforcement and judicial review of DPA-imposed administrative penalties.

This distinction is important for exam writing.

32. Current European Enforcement Environment

The scale of enforcement is substantial.

For example, the Irish DPC's published records currently show more than €4.4 billion in fines levied through its inquiries, while also showing that many large fines remain subject to appeal or confirmation. (Homepage | Data Protection Commission)

This illustrates why judicial review is an important part of European GDPR enforcement rather than a purely theoretical possibility.

33. Remedies Available to the Fined Organisation

Depending on national procedural law, the organisation may seek:

annulment of the DPA decision;

reduction of the fine;

remittal for reconsideration;

suspension where available;

correction of factual findings;

judicial declaration;

review of procedural defects.

The exact remedy depends upon the Member State's judicial system.

34. Remedies Available to Data Subjects

A data subject may separately seek:

cessation of unlawful processing;

access;

rectification;

erasure;

restriction;

objection;

judicial remedy;

compensation.

Article 82 compensation requires the elements identified by the CJEU, including damage caused by an infringement. (EUR-Lex)

35. Overall Litigation Framework

A European DPA penalty dispute can be analysed through the following sequence:

1. Identify the processing

↓

2. Identify the controller/processor

↓

3. Identify the GDPR obligation

↓

4. Establish the infringement

↓

5. Establish intentional or negligent conduct

↓

6. Examine DPA jurisdiction

↓

7. Examine procedural fairness

↓

8. Apply Article 83 factors

↓

9. Calculate the fine

↓

10. Test proportionality

↓

11. Conduct judicial review

↓

12. Determine whether annulment/reduction is appropriate

36. Conclusion

Data Protection Authority penalty litigation in Europe is a hybrid field involving administrative law, civil-law principles, EU constitutional principles and data-protection law.

The most important distinction is between administrative punishment and private compensation. Article 83 GDPR allows supervisory authorities to impose effective, proportionate and dissuasive administrative fines, whereas Article 82 provides a separate compensation mechanism for damage caused by GDPR infringements. (European Data Protection Board)

The leading authorities establish several core principles:

Deutsche Wohnen — a legal person can be directly subject to a GDPR fine; Member States cannot add incompatible requirements for attribution to an identified natural person. (EUR-Lex)

Nacionalinis — an Article 83 fine requires intentional or negligent infringement and controller responsibility can extend to processor operations within the controller's authorised framework. (EUR-Lex)

Österreichische Post — a GDPR breach alone does not automatically establish compensable damage. (EUR-Lex)

Wirtschaftsakademie and Fashion ID — controller and joint-controller concepts can extend beyond the entity performing the technical processing.

Schrems II — international data transfers remain subject to substantive protection requirements.

DPC v EDPB — cross-border enforcement involves the GDPR's consistency mechanism and remains subject to judicial review. (EUR-Lex)

Therefore, the central principle is:

A DPA fine is a regulatory sanction, but its imposition is itself subject to substantive, procedural and proportionality requirements, while separate civil compensation requires its own proof of damage and causation.

Exam Keyword Bank

GDPR – DPA – Supervisory Authority – Administrative Fine – Article 58 – Article 60 – Article 65 – Article 78 – Article 82 – Article 83 – Controller – Processor – Joint Controller – Culpability – Intentional Infringement – Negligent Infringement – Proportionality – Effective – Proportionate – Dissuasive – Turnover – Group Undertaking – Judicial Review – Due Process – Rights of Defence – EDPB – Lead Supervisory Authority – Consistency Mechanism – Cross-Border Enforcement – Data Breach – Security – Transparency – Lawful Basis – International Transfer – Civil Compensation – Non-Material Damage – Causation – GDPR Penalty Litigation.

LEAVE A COMMENT