Civil Law And Data Protection Authority Civil Penalty Litigation In Europe .
Civil Law and Data Protection Authority Civil Penalty Litigation in Europe
1. Introduction
Data Protection Authority (DPA) civil penalty litigation concerns legal challenges arising from penalties, corrective measures, enforcement orders and related proceedings initiated by European data-protection supervisory authorities against controllers and processors.
The modern framework is principally based on the EU General Data Protection Regulation (GDPR).
A useful distinction should be made at the outset:
Administrative fine → imposed by a supervisory authority under Article 83 GDPR.
Civil compensation → generally sought by an injured individual under Article 82 GDPR.
Judicial review of a DPA decision → the fined organisation challenges the authority's decision before a national court.
Regulatory enforcement → the DPA uses corrective powers under Article 58 GDPR.
Representative/private litigation → individuals or qualified bodies may pursue rights separately from the administrative penalty process.
The CJEU has expressly distinguished the punitive/regulatory function of administrative fines from the compensatory function of Article 82 damages. (EUR-Lex)
2. Meaning of DPA Civil Penalty Litigation
A typical dispute looks like this:
Data processing
↓
DPA investigation
↓
Finding of GDPR infringement
↓
Administrative fine / corrective order
↓
Controller or processor challenges decision
↓
National court review
↓
Possible preliminary reference to CJEU
The dispute may concern:
whether an infringement occurred;
whether the organisation was the controller;
whether it was a processor;
whether the conduct was intentional or negligent;
whether the DPA had jurisdiction;
whether procedural rights were respected;
whether the fine was proportionate;
whether the turnover calculation was correct;
whether the DPA properly exercised discretion.
3. Main Legal Framework
A. GDPR
The central provisions are:
Article 5
Basic principles of processing.
Article 6
Lawfulness of processing.
Articles 12–14
Transparency and information obligations.
Articles 24–25
Controller responsibility and data protection by design/default.
Article 28
Processor obligations.
Article 32
Security of processing.
Article 58
Supervisory-authority powers.
Article 60
Cooperation and consistency mechanism.
Article 65
Dispute resolution by the EDPB.
Article 77
Right to lodge a complaint.
Article 78
Judicial remedy against a supervisory authority.
Article 79
Judicial remedy against a controller or processor.
Article 82
Right to compensation.
Article 83
Administrative fines.
Article 84
Other penalties under Member-State law.
4. Nature of an Administrative Fine
An Article 83 fine is primarily regulatory and punitive, rather than compensation for an individual victim.
The GDPR requires fines to be:
effective;
proportionate;
dissuasive.
The EDPB's current guidance confirms that fines are one of a range of enforcement measures available to DPAs, alongside warnings, reprimands and orders. (European Data Protection Board)
For serious categories of infringement, the GDPR allows fines of up to:
€20 million or 4% of worldwide annual turnover, whichever is higher.
The applicable tier depends upon the infringement involved. (Bailii)
5. Fine vs Civil Compensation
This is a fundamental distinction.
Administrative fine
DPA → organisation
Purpose:
punishment;
deterrence;
regulatory enforcement.
Civil compensation
Individual → controller/processor
Purpose:
compensate actual damage.
The CJEU in Österreichische Post confirmed that a mere GDPR infringement does not automatically create a right to compensation; damage caused by the infringement is required. At the same time, EU law does not permit a national rule imposing an additional minimum seriousness threshold for non-material damage. (EUR-Lex)
Therefore:
Fine ≠ compensation.
A €100 million regulatory fine does not automatically mean that every affected data subject receives part of that amount.
6. Who Can Be Fined?
A DPA may investigate:
Controller
The person or organisation determining the purposes and means of processing.
Processor
The entity processing personal data on behalf of a controller.
Joint controllers
Two or more entities jointly determining purposes and means.
The identification of the correct legal entity is often the first major issue in penalty litigation.
7. Case Law 1 — Deutsche Wohnen SE v Staatsanwaltschaft Berlin
Case C-807/21
CJEU (Grand Chamber), 5 December 2023
This is one of the most important cases on GDPR administrative fines.
Facts
The Berlin data-protection authority imposed fines on Deutsche Wohnen SE concerning the retention and processing of tenants' personal data.
German procedural law raised questions concerning whether a fine could be imposed on a legal person without first attributing the infringement to an identified natural person. (EUR-Lex)
CJEU decision
The CJEU held that EU law does not permit Member States to impose additional substantive conditions under which GDPR administrative fines can be imposed on legal persons.
In particular, national law could not make the fine dependent upon first attributing the infringement to an identified natural person. (EUR-Lex)
Fault
The Court nevertheless confirmed an important limitation:
An Article 83 fine requires a culpable/wrongful infringement, meaning intentional or negligent conduct.
Thus:
GDPR infringement + no wrongful conduct = administrative fine cannot simply be imposed automatically.
Importance
The case establishes:
direct responsibility of legal persons;
importance of culpability;
limits on national procedural/substantive barriers;
autonomous EU standards for GDPR fines.
8. Case Law 2 — Nacionalinis visuomenės sveikatos centras
Case C-683/21
CJEU (Grand Chamber), 5 December 2023
This case concerned a Lithuanian public-health authority and the development of a mobile application during the COVID-19 period.
The application processed personal data concerning persons who had potentially been in contact with infected individuals. (EUR-Lex)
Issues
The CJEU considered:
controller status;
joint controllership;
processor responsibility;
administrative fines;
intentional/negligent conduct.
Decision
The Court held that an administrative fine under Article 83 requires an infringement committed intentionally or negligently.
It also held that a controller can be fined for processing performed by a processor on its behalf, subject to circumstances in which the processor acts for its own purposes or outside the controller's authorised processing framework. (EUR-Lex)
Importance
This case is extremely useful where an organisation argues:
“The processor made the mistake, so we cannot be fined.”
That argument does not automatically succeed.
The relationship between controller and processor must be examined.
9. Case Law 3 — Österreichische Post
Case C-300/21, UI v Österreichische Post AG
CJEU, 4 May 2023
This case is particularly important for the civil-compensation side of DPA enforcement.
Facts
Österreichische Post used an algorithm to predict political affinities of Austrian residents.
The claimant alleged that processing incorrectly associated him with a particular political party and sought compensation for non-material damage. (EUR-Lex)
Decision
The CJEU held:
a GDPR infringement alone is insufficient for Article 82 compensation;
actual damage caused by the infringement must exist;
non-material damage does not have to cross a separate national seriousness threshold. (EUR-Lex)
Importance
The case demonstrates the separation between:
DPA penalty
and
private damages action.
An authority can impose a fine because regulatory conditions are satisfied, while an individual still has to establish the elements of Article 82 for compensation.
10. Case Law 4 — Google Spain
Case C-131/12, Google Spain SL and Google Inc. v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González
CJEU, 13 May 2014
This landmark case concerned the processing of personal data by search engines and the so-called right to be forgotten.
Principle
Search engines can be controllers for processing carried out through indexing and displaying personal information.
Individuals can, under appropriate conditions, request removal of search results concerning them.
Relevance to DPA litigation
The case illustrates the supervisory authority's role in protecting data-subject rights.
It also demonstrates that an organisation may have GDPR/data-protection obligations even where the underlying information was originally published elsewhere.
Civil-law significance
The case links:
privacy;
personality rights;
data protection;
regulatory supervision;
judicial review.
11. Case Law 5 — Wirtschaftsakademie Schleswig-Holstein
Case C-210/16, Wirtschaftsakademie Schleswig-Holstein GmbH v Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
CJEU, 5 June 2018
Facts
Wirtschaftsakademie operated a Facebook fan page.
The German supervisory authority ordered it to deactivate the page because of concerns regarding personal-data processing associated with Facebook's systems.
Issue
Could the fan-page operator be treated as a joint controller even though Facebook technically carried out much of the processing?
Decision
The CJEU adopted a broad understanding of joint controllership.
A party may have controller responsibility even though it does not itself possess every piece of personal data or technically perform every processing operation.
Importance
This principle is highly relevant to DPA penalty litigation.
An organisation cannot necessarily avoid enforcement simply by arguing:
“Another technology company actually processed the data.”
Responsibility can depend upon the organisation's influence over the purposes and means of processing.
12. Case Law 6 — Fashion ID
Case C-40/17, Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV
CJEU, 29 July 2019
Facts
Fashion ID embedded Facebook's “Like” button on its website.
When users visited the website, personal data could be transmitted to Facebook.
Issue
Was Fashion ID a controller even though it did not itself determine all subsequent processing by Facebook?
Decision
The CJEU held that Fashion ID could be a joint controller in relation to the collection and transmission of data to Facebook.
However, controller responsibility did not automatically extend to every subsequent processing operation carried out by Facebook.
Importance
This is highly relevant to penalty litigation because it demonstrates that controller responsibility must be linked to the specific processing operation concerned.
13. Case Law 7 — Schrems II
Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
CJEU, 16 July 2020
Facts
The case concerned transfers of personal data from the European Union to the United States.
Decision
The CJEU invalidated the EU-US Privacy Shield and maintained the validity of Standard Contractual Clauses subject to appropriate safeguards and assessment of the destination country's legal environment.
Importance for DPA penalty litigation
Cross-border transfers can generate substantial regulatory exposure.
A DPA may investigate:
international transfers;
adequacy;
contractual safeguards;
supplementary measures;
access by foreign authorities.
The case demonstrates that technical compliance with contractual mechanisms is not always enough if the destination legal environment prevents adequate protection.
14. Case Law 8 — Data Protection Commission v EDPB
Joined Cases T-70/23, T-84/23 and T-111/23
General Court of the European Union, 29 January 2025
These proceedings arose from the GDPR consistency mechanism involving the Irish DPC and EDPB decisions concerning Facebook, Instagram and WhatsApp.
The DPC challenged parts of EDPB Binding Decisions 3/2022, 4/2022 and 5/2022, particularly directions concerning further investigations and draft decisions. (EUR-Lex)
Importance
This case illustrates the institutional structure of GDPR enforcement:
Lead Supervisory Authority
↓
Concerned Supervisory Authorities
↓
Disagreement
↓
EDPB dispute-resolution mechanism
↓
Binding decision
↓
Judicial review
It is particularly important in cross-border penalty litigation.
15. Case Law 9 — Meta Platforms Ireland v Data Protection Commission
Meta Platforms Ireland Ltd v Data Protection Commission, Irish High Court, 2026
The Irish courts have continued to review major DPC enforcement decisions.
The 2026 litigation includes challenges involving the interpretation and application of GDPR administrative fines, including Article 83 and the relationship between controller/processor obligations and penalty calculation. (Bailii)
Importance
The case demonstrates that major GDPR penalties remain subject to effective judicial review.
A DPA decision is not necessarily the final word.
The fined organisation may challenge:
legal interpretation;
procedural fairness;
evidence;
proportionality;
fine calculation;
statutory authority.
16. Case Law 10 — TikTok Technology Limited v DPC
Irish proceedings concerning TikTok Technology Limited v Data Protection Commission continue to illustrate judicial review of major GDPR enforcement decisions.
The Irish DPC's current judgment register records Supreme Court proceedings decided on 5 May 2026, alongside High Court and Court of Appeal proceedings. (Homepage | Data Protection Commission)
The DPC's published enforcement records show that TikTok received a €530 million administrative fine in April 2025, with the matter listed as pending appeal. (Homepage | Data Protection Commission)
Importance
The litigation illustrates:
judicial scrutiny of DPA decisions;
procedural rights;
proportionality;
interpretation of GDPR obligations;
appeal mechanisms.
17. Case-Law Summary Table
| Case | Court | Main issue | Key principle |
|---|---|---|---|
| Deutsche Wohnen v Staatsanwaltschaft Berlin, C-807/21 | CJEU | Fine against legal person | No requirement to identify a natural person first |
| Nacionalinis visuomenės sveikatos centras, C-683/21 | CJEU | Controller/processor and fines | Fine requires intentional/negligent infringement |
| Österreichische Post, C-300/21 | CJEU | Article 82 compensation | Mere GDPR breach does not automatically establish damages |
| Google Spain, C-131/12 | CJEU | Search-engine processing | Search engine can be controller |
| Wirtschaftsakademie, C-210/16 | CJEU | Facebook fan page | Broad joint-controller concept |
| Fashion ID, C-40/17 | CJEU | Website plug-in | Controller responsibility can be operation-specific |
| Schrems II, C-311/18 | CJEU | International transfers | Transfer safeguards must provide effective protection |
| DPC v EDPB, T-70/23 etc. | General Court | Cross-border enforcement | Judicial review of EDPB consistency decisions |
| Meta v DPC | Irish High Court | GDPR penalty review | Major administrative fines remain judicially reviewable |
| TikTok v DPC | Irish courts | Large GDPR penalty | Appeals can scrutinise regulatory decisions |
18. Procedure for Challenging a DPA Penalty
A simplified procedure is:
Stage 1 — Investigation
The DPA collects:
documents;
correspondence;
technical evidence;
audit records;
witness statements;
controller submissions.
Stage 2 — Draft/final decision
The authority determines:
infringement;
corrective measures;
fine;
reasoning.
Stage 3 — Administrative cooperation
In cross-border cases, Articles 60–65 GDPR may become relevant.
Stage 4 — Judicial challenge
The organisation challenges the decision before the competent national court.
Stage 5 — Possible CJEU reference
If interpretation of EU law is uncertain, the national court may refer questions to the CJEU.
19. Grounds of Challenge
A company may challenge a DPA fine on several grounds.
A. No infringement
The organisation argues:
“The GDPR provision was not violated.”
B. Wrong controller
The organisation may argue:
“We were only a processor, not the controller.”
C. Lack of culpability
After Deutsche Wohnen and Nacionalinis, this can be important.
The organisation may argue:
“There was no intentional or negligent conduct.”
D. Insufficient evidence
The authority may have failed to establish:
what happened;
who caused it;
when it occurred;
what data were affected.
E. Procedural violation
Possible issues include:
inadequate opportunity to respond;
insufficient reasoning;
unlawful evidence;
failure to consider submissions;
procedural delay;
failure to respect rights of defence.
F. Disproportionate fine
The organisation may argue that the fine is:
excessive;
insufficiently reasoned;
inconsistent with Article 83;
disproportionate to the infringement.
20. Article 83 Fine Calculation
The DPA must consider relevant factors, including:
nature of infringement;
gravity;
duration;
intentional or negligent character;
mitigation;
preventative measures;
degree of responsibility;
previous infringements;
cooperation;
categories of personal data;
manner in which infringement became known;
compliance with previous measures;
adherence to codes/certification mechanisms;
other aggravating or mitigating factors.
The EDPB's current fines guidance specifically addresses the relationship between administrative fines and other corrective powers. (European Data Protection Board)
21. Proportionality
A major civil-law principle is proportionality.
The authority must balance:
Gravity of infringement
against
Economic impact
and
Deterrence requirement.
A fine should neither become meaningless nor operate as an arbitrary punishment.
The GDPR expressly requires fines to be effective, proportionate and dissuasive. (European Data Protection Board)
22. Turnover of Corporate Groups
The size of a corporate group can matter significantly.
In Deutsche Wohnen, the CJEU confirmed that the concept of an “undertaking” is relevant to calculating the fine, including group turnover, rather than limiting the calculation mechanically to the turnover of a single corporate entity. (EUR-Lex)
This prevents large corporate groups from arguing that a fine should always be calculated solely by reference to a small subsidiary's turnover.
23. Controller and Processor Liability
Consider:
Company A = controller
Company B = processor
Company B makes a GDPR error.
Can A be fined?
Nacionalinis indicates that a controller can, in appropriate circumstances, be fined for processing performed by its processor.
However, if the processor begins processing for its own purposes or materially outside the controller's authorised framework, responsibility may shift toward the processor for that processing. (EUR-Lex)
24. Joint Controllers
Joint controllership is particularly important in:
advertising;
social media;
analytics;
plug-ins;
marketplaces;
mobile applications;
data-sharing arrangements.
Wirtschaftsakademie and Fashion ID show that an organisation can have controller responsibilities even if another company performs the technical processing.
25. Data Breach Penalties
A DPA may impose a fine following:
hacking;
ransomware;
credential theft;
accidental disclosure;
inadequate access controls;
token compromise;
failure to report a breach.
For example, the Irish DPC's December 2024 Meta decisions imposed total administrative fines of €251 million concerning security and breach-related GDPR obligations, including Articles 25 and 33. (Homepage | Data Protection Commission)
The decisions concerned a breach affecting approximately 29 million Facebook accounts globally, including about 3 million in the EU/EEA. (Homepage | Data Protection Commission)
26. DPA Penalty and Individual Damages Can Coexist
Suppose:
DPA fine = €50 million
and
1,000 individuals suffered compensable damage.
The fine does not automatically compensate those individuals.
The individuals may separately pursue Article 82 claims.
Thus:
Regulatory enforcement
and
private civil liability
can operate simultaneously.
The CJEU's treatment in Österreichische Post makes this distinction especially important. (EUR-Lex)
27. Evidence in Penalty Litigation
Important evidence may include:
privacy policies;
data maps;
records of processing activities;
DPIAs;
processor agreements;
security logs;
breach reports;
internal emails;
compliance manuals;
employee instructions;
consent records;
technical architecture;
audit reports;
DPA correspondence;
expert reports.
Technical evidence becomes particularly important in:
cybersecurity cases;
AI processing;
profiling;
automated decision-making;
international transfers.
28. Civil-Law Principles Applicable to DPA Litigation
Although GDPR enforcement is primarily regulatory, civil-law concepts can influence judicial review.
Important principles include:
Good faith
The organisation should deal honestly with regulators and data subjects.
Proportionality
Penalty and corrective measures should correspond to the infringement.
Legal certainty
The organisation should be able to understand the applicable legal requirements.
Due process
The organisation must have an effective opportunity to defend itself.
Reasoned decision-making
The DPA should explain why the infringement and penalty were established.
Causation
Particularly important for separate compensation proceedings.
29. DPA Liability vs Controller Liability
There are actually two different potential disputes.
Dispute A
DPA → controller
Question:
Did the controller violate the GDPR?
Dispute B
Individual → controller
Question:
Did the controller's violation cause compensable damage?
Dispute C
Controller → DPA
Question:
Was the DPA's enforcement decision legally valid?
These should not be confused.
30. Hypothetical Example
Suppose a European social-media company processes 20 million users' data.
The DPA discovers:
unclear privacy information;
unlawful processing basis;
insufficient security;
inadequate retention controls.
The DPA imposes a large fine.
The company challenges it.
The court may examine:
Was the company a controller?
What processing occurred?
Which GDPR provisions applied?
Was the processing unlawful?
Was the company intentionally or negligently responsible?
Did the DPA follow correct procedure?
Were the findings supported by evidence?
Were Article 83 factors considered?
Was the fine proportionate?
Was the DPA required to follow an EDPB binding decision?
If users separately seek compensation, the court handling those claims must additionally examine:
What damage did each claimant actually suffer?
31. Important Difference Between Administrative and Civil Penalties
Strictly speaking, “civil penalty” is not the most precise EU GDPR terminology.
The GDPR primarily uses:
“administrative fines.”
The phrase “civil penalty litigation” can therefore be understood broadly to include litigation concerning the legality, enforcement and judicial review of DPA-imposed administrative penalties.
This distinction is important for exam writing.
32. Current European Enforcement Environment
The scale of enforcement is substantial.
For example, the Irish DPC's published records currently show more than €4.4 billion in fines levied through its inquiries, while also showing that many large fines remain subject to appeal or confirmation. (Homepage | Data Protection Commission)
This illustrates why judicial review is an important part of European GDPR enforcement rather than a purely theoretical possibility.
33. Remedies Available to the Fined Organisation
Depending on national procedural law, the organisation may seek:
annulment of the DPA decision;
reduction of the fine;
remittal for reconsideration;
suspension where available;
correction of factual findings;
judicial declaration;
review of procedural defects.
The exact remedy depends upon the Member State's judicial system.
34. Remedies Available to Data Subjects
A data subject may separately seek:
cessation of unlawful processing;
access;
rectification;
erasure;
restriction;
objection;
judicial remedy;
compensation.
Article 82 compensation requires the elements identified by the CJEU, including damage caused by an infringement. (EUR-Lex)
35. Overall Litigation Framework
A European DPA penalty dispute can be analysed through the following sequence:
1. Identify the processing
↓
2. Identify the controller/processor
↓
3. Identify the GDPR obligation
↓
4. Establish the infringement
↓
5. Establish intentional or negligent conduct
↓
6. Examine DPA jurisdiction
↓
7. Examine procedural fairness
↓
8. Apply Article 83 factors
↓
9. Calculate the fine
↓
10. Test proportionality
↓
11. Conduct judicial review
↓
12. Determine whether annulment/reduction is appropriate
36. Conclusion
Data Protection Authority penalty litigation in Europe is a hybrid field involving administrative law, civil-law principles, EU constitutional principles and data-protection law.
The most important distinction is between administrative punishment and private compensation. Article 83 GDPR allows supervisory authorities to impose effective, proportionate and dissuasive administrative fines, whereas Article 82 provides a separate compensation mechanism for damage caused by GDPR infringements. (European Data Protection Board)
The leading authorities establish several core principles:
Deutsche Wohnen — a legal person can be directly subject to a GDPR fine; Member States cannot add incompatible requirements for attribution to an identified natural person. (EUR-Lex)
Nacionalinis — an Article 83 fine requires intentional or negligent infringement and controller responsibility can extend to processor operations within the controller's authorised framework. (EUR-Lex)
Österreichische Post — a GDPR breach alone does not automatically establish compensable damage. (EUR-Lex)
Wirtschaftsakademie and Fashion ID — controller and joint-controller concepts can extend beyond the entity performing the technical processing.
Schrems II — international data transfers remain subject to substantive protection requirements.
DPC v EDPB — cross-border enforcement involves the GDPR's consistency mechanism and remains subject to judicial review. (EUR-Lex)
Therefore, the central principle is:
A DPA fine is a regulatory sanction, but its imposition is itself subject to substantive, procedural and proportionality requirements, while separate civil compensation requires its own proof of damage and causation.
Exam Keyword Bank
GDPR – DPA – Supervisory Authority – Administrative Fine – Article 58 – Article 60 – Article 65 – Article 78 – Article 82 – Article 83 – Controller – Processor – Joint Controller – Culpability – Intentional Infringement – Negligent Infringement – Proportionality – Effective – Proportionate – Dissuasive – Turnover – Group Undertaking – Judicial Review – Due Process – Rights of Defence – EDPB – Lead Supervisory Authority – Consistency Mechanism – Cross-Border Enforcement – Data Breach – Security – Transparency – Lawful Basis – International Transfer – Civil Compensation – Non-Material Damage – Causation – GDPR Penalty Litigation.

comments