Civil Law And Data Protection Claims In Europe .

Civil Law and Data Protection Claims in Europe

1. Introduction

Data protection claims in Europe are civil or judicial claims brought by individuals or organisations where personal data has been collected, processed, disclosed, retained, transferred, profiled or otherwise handled in violation of applicable data-protection law.

The principal framework is the EU General Data Protection Regulation (GDPR), supplemented by:

national civil and procedural law;

EU Charter rights;

consumer-protection law;

employment law;

electronic-communications rules;

cybersecurity legislation;

sector-specific regulation.

The GDPR gives individuals several substantive rights, including access, rectification, erasure, restriction, objection and, in appropriate circumstances, compensation. Article 15 expressly provides a right to obtain access to personal data and information concerning its processing, while Article 17 provides the right to erasure subject to specified exceptions. (EUR-Lex)

The central civil-law principle is:

A GDPR infringement does not automatically mean that damages are payable. The claimant generally has to establish the infringement, legally recognised damage and a causal connection between them.

The CJEU has repeatedly confirmed these cumulative requirements. (InfoCuria)

2. What Is a Data Protection Claim?

A data protection claim may arise when a controller or processor:

collects personal data unlawfully;

uses data for an incompatible purpose;

processes data without an appropriate legal basis;

fails to provide required information;

refuses a valid access request;

retains data excessively;

refuses to rectify inaccurate data;

unlawfully discloses information;

transfers data unlawfully;

conducts unlawful profiling;

makes an unlawful automated decision;

fails to maintain appropriate security;

suffers a personal-data breach causing damage.

3. Personal Data

Personal data is information relating to an identified or identifiable natural person.

Examples include:

name;

address;

email;

telephone number;

identification number;

IP address;

location data;

financial information;

health information;

employment information;

biometric information;

online identifiers;

behavioural profiles.

The definition is intentionally broad.

4. Controller and Processor

A. Controller

The controller determines the purposes and means of processing.

Example:

A bank decides what customer information it collects and why.

The bank is generally the controller.

B. Processor

A processor processes personal data on behalf of the controller.

Example:

A cloud company stores the bank's customer database under the bank's instructions.

The distinction is important because different obligations and liability rules can apply.

5. Main GDPR Principles

Article 5 GDPR establishes fundamental principles including:

1. Lawfulness, fairness and transparency

Processing must have a legal basis and be transparent.

2. Purpose limitation

Data collected for one purpose should not ordinarily be used for incompatible purposes.

3. Data minimisation

Only data necessary for the purpose should be processed.

4. Accuracy

Incorrect information should be corrected.

5. Storage limitation

Data should not be retained indefinitely without justification.

6. Integrity and confidentiality

Appropriate security must be maintained.

7. Accountability

The controller must be able to demonstrate compliance.

6. Legal Bases for Processing

Article 6 provides several possible legal bases:

consent;

contract;

legal obligation;

vital interests;

public task;

legitimate interests.

A company cannot simply say:

"We have the data, therefore we may use it."

It must identify an applicable legal basis.

7. Consent

Valid consent generally requires that the individual understands what he or she is agreeing to and can exercise genuine choice.

Questions in litigation include:

Was consent actually obtained?

Was it freely given?

Was it specific?

Was it informed?

Was the purpose clear?

Could consent be withdrawn?

Was consent bundled with unrelated conditions?

Consent is particularly important in:

advertising;

cookies;

profiling;

health applications;

biometric processing;

direct marketing.

8. Legitimate Interests

Businesses may sometimes rely on legitimate interests.

The basic analysis is:

Legitimate interest → Necessity → Balancing → Individual rights

The controller must consider the impact of processing on the individual.

This becomes especially important in:

direct marketing;

fraud prevention;

credit assessment;

employee monitoring;

analytics;

data-broker activities.

9. Special Categories of Data

Article 9 provides enhanced protection for information concerning matters such as:

health;

racial or ethnic origin;

political opinions;

religion;

trade-union membership;

genetic data;

biometric data for identification;

sex life or sexual orientation.

Processing such information is generally prohibited unless a specific Article 9 exception applies.

10. Right of Access

Article 15 is one of the most important litigation tools.

An individual can generally request information about:

whether data is being processed;

the data itself;

purposes;

categories;

recipients;

retention;

sources;

relevant information concerning processing.

The GDPR expressly provides a right to obtain a copy of personal data being processed. (EUR-Lex)

This can help a claimant discover:

What data does the company have about me, where did it come from, and who received it?

11. Right to Rectification

Article 16 provides a right to correct inaccurate personal data.

Example

A credit database states:

"Customer has defaulted on a €50,000 loan."

The person never had such a loan.

The individual can seek rectification.

12. Right to Erasure

Article 17 is commonly called the right to be forgotten.

Erasure may be available where, for example:

data is no longer necessary;

consent has been withdrawn and no other legal basis exists;

the individual successfully objects;

processing was unlawful;

erasure is legally required.

However, Article 17 contains important exceptions, including freedom of expression, legal obligations and certain public-interest purposes. (EUR-Lex)

13. Right to Object

Article 21 allows individuals, in specified circumstances, to object to processing.

This is particularly significant for:

direct marketing;

profiling;

legitimate-interest processing.

The controller may sometimes continue processing where overriding legitimate grounds exist, depending upon the particular legal basis and circumstances.

14. Automated Decision-Making and Profiling

Article 22 is important where decisions are made solely through automated processing and have legal or similarly significant effects.

Examples:

automatic credit rejection;

automated insurance decisions;

employment screening;

fraud-risk classification.

The CJEU's SCHUFA scoring judgment, Case C-634/21, is particularly important because it concerned automated generation of a probability score concerning an individual's ability to meet financial obligations.

The case demonstrates that an apparently preliminary or "advisory" algorithmic score can fall within Article 22 where another party gives the score decisive importance in making a decision about the individual.

15. Data Breach Claims

A data breach can involve:

hacking;

ransomware;

accidental disclosure;

lost devices;

employee error;

unauthorised access;

database leakage;

incorrect transmission.

Article 32 requires appropriate technical and organisational security measures.

Article 33 concerns notification to the supervisory authority in specified circumstances, while Article 34 concerns communication to affected individuals where a breach is likely to result in a high risk.

16. Compensation Under Article 82

Article 82 is the main GDPR compensation provision.

A claimant generally needs to establish:

1. Infringement

A GDPR obligation was violated.

2. Damage

The individual suffered:

material damage; or

non-material damage.

3. Causation

The damage resulted from the infringement.

The CJEU has expressly described these requirements as cumulative. (InfoCuria)

17. Material Damage

Material damage may include:

financial loss;

fraud losses;

additional expenses;

lost income;

costs of restoring identity;

business losses;

loss caused by an unlawful automated decision.

The claimant must establish the causal connection.

18. Non-Material Damage

Non-material damage may include:

distress;

fear of misuse;

loss of control over personal information;

reputational consequences;

privacy interference.

The CJEU has held that national law cannot impose an additional minimum seriousness threshold as a condition for compensating non-material damage.

However:

The claimant still has to demonstrate actual non-material damage; infringement alone is insufficient. (curia)

19. Case Law

Case 1 — Österreichische Post

CJEU, Case C-300/21
Judgment: 4 May 2023

Österreichische Post used an algorithm to determine political affinities of individuals.

The claimant had not consented to that processing and argued that the creation of a political profile caused distress and loss of confidence.

The CJEU held that:

GDPR infringement alone does not establish a right to compensation;

damage must actually be suffered;

a causal link is required;

non-material damage does not need to exceed a particular seriousness threshold. (InfoCuria)

Principle

Infringement ≠ automatic compensation.

Importance

This is one of the most important cases for:

privacy claims;

profiling;

political data;

non-material damage;

Article 82.

20. Case 2 — Natsionalna agentsia za prihodite

CJEU, Case C-340/21
Judgment: 14 December 2023

The Bulgarian National Revenue Agency suffered a cyberattack in which personal data was accessed.

Individuals brought compensation claims.

The CJEU considered:

Article 32 security;

controller responsibility;

cyberattacks;

burden of proof;

fear of potential misuse;

Article 82 compensation. (InfoCuria)

Principle

A successful cyberattack does not automatically establish that security measures were inadequate.

The appropriateness of the security measures must be assessed in the circumstances.

The Court also recognised that fear of potential misuse may constitute non-material damage where the legal requirements are satisfied.

Importance

This case is central to:

cybersecurity claims;

data breaches;

controller liability;

non-material damage.

21. Case 3 — MediaMarktSaturn

CJEU, Case C-687/21
Judgment: 25 January 2024

Personal data was accidentally disclosed to an unauthorised third party because of employee conduct.

The CJEU examined Articles 24 and 32 GDPR.

It confirmed that an accidental disclosure does not automatically establish inadequate security. The appropriateness of technical and organisational measures must be assessed concretely.

The Court also confirmed that Article 82 compensation is compensatory rather than punitive. (InfoCuria)

Principle

Employee error + data disclosure does not automatically equal GDPR damages.

Importance

Useful for:

internal data breaches;

employee mistakes;

organisational security;

Article 32;

Article 82.

22. Case 4 — Gemeinde Ummendorf

CJEU, Case C-456/22
Judgment: 14 December 2023

The case concerned unlawful publication of personal information.

The CJEU considered whether loss of control over personal data could constitute non-material damage.

It confirmed that non-material damage can be compensable without an additional seriousness threshold, but actual damage must still be established. The general Article 82 framework requires infringement, damage and causation. (InfoCuria)

Principle

Loss of control over personal data can constitute legally relevant damage.

Importance

Particularly relevant to:

online publication;

website disclosure;

public databases;

privacy claims.

23. Case 5 — Scalable Capital

CJEU, Joined Cases C-182/22 and C-189/22
Judgment: 20 June 2024

The cases arose from a personal-data security incident involving a financial platform.

The CJEU examined:

Article 82;

material and non-material damage;

loss of control;

causal connection;

compensation.

The Court reaffirmed that Article 82 is based upon compensation for actual damage and not punishment. (EUR-Lex)

Principle

A claimant does not need to establish some additional minimum level of seriousness, but must demonstrate actual damage resulting from the GDPR infringement.

Importance

Useful for:

financial platforms;

cybersecurity;

customer databases;

loss of control;

non-material damage.

24. Case 6 — Krankenversicherung Nordrhein

CJEU, Case C-667/21
Judgment: 21 December 2023

The case concerned GDPR compensation and the processing of personal information involving sensitive data.

The CJEU examined the conditions for Article 82 liability and the compensatory nature of GDPR damages.

Principle

Article 82 compensation is designed to compensate the actual damage suffered, rather than punish the controller.

Importance

The case is particularly relevant to:

health information;

sensitive personal data;

confidentiality;

compensation claims.

The CJEU's later Article 82 jurisprudence continues to cite this case as part of the cumulative infringement-damage-causation framework. (InfoCuria)

25. Case 7 — PS (Incorrect Address)

CJEU, Case C-590/22
Judgment: 20 June 2024

The case concerned personal data being transmitted to an incorrect address.

The Court considered Article 82 and the relationship between:

unlawful disclosure;

damage;

causation;

compensation.

Principle

A claimant does not necessarily need to prove actual identity theft before obtaining compensation for non-material damage.

But the claimant must still establish actual damage caused by the GDPR infringement.

Importance

It is useful for:

wrong-recipient cases;

email disclosure;

administrative mistakes;

accidental transmission.

26. Case 8 — Nowak v Data Protection Commissioner

CJEU, Case C-434/16
Judgment: 20 December 2017

The case concerned access to examination-related information.

The CJEU interpreted "personal data" broadly.

Information can constitute personal data even when it involves an assessment or evaluation relating to an identifiable person.

Principle

Personal data are not limited to simple factual information.

Importance

The decision is relevant to:

employment assessments;

credit scores;

performance evaluations;

algorithmic profiles;

risk assessments.

27. Case 9 — Google Spain

CJEU, Case C-131/12
Judgment: 13 May 2014

The case concerned personal information appearing in search-engine results.

The CJEU recognised circumstances in which an individual could seek removal of search results containing personal information.

Principle

An intermediary that determines how personal information is processed can have independent data-protection responsibilities.

Importance

It established a foundational approach to:

erasure;

online privacy;

intermediary responsibility;

balancing privacy against information rights.

28. Case 10 — Breyer

CJEU, Case C-582/14
Judgment: 19 October 2016

The case concerned dynamic IP addresses.

The CJEU held that a dynamic IP address can constitute personal data where the controller has legal means enabling identification using additional information held by another party.

Principle

Information does not need to contain a person's name to constitute personal data.

Importance

This is highly relevant to:

websites;

platforms;

online advertising;

cybersecurity;

cookies;

IP addresses;

digital tracking.

29. Case Law Table

CaseMain IssueImportance
Österreichische Post, C-300/21Non-material damageInfringement alone is insufficient
NAP, C-340/21Cyberattack/securitySecurity and fear of misuse
MediaMarktSaturn, C-687/21Employee disclosureConcrete security assessment
Gemeinde Ummendorf, C-456/22Online disclosureLoss of control/non-material damage
Scalable Capital, C-182/22 & C-189/22Financial-platform breachArticle 82 compensation
Krankenversicherung Nordrhein, C-667/21Sensitive dataCompensatory damages
PS, C-590/22Incorrect transmissionDamage and causation
Nowak, C-434/16Personal-data definitionEvaluative information
Google Spain, C-131/12Search resultsErasure and intermediary responsibility
Breyer, C-582/14IP addressBroad personal-data concept

30. Data Protection and Civil Law

GDPR claims can interact with traditional civil-law principles.

A. Contract

Example:

A customer contracts with a platform to store personal data.

A security failure may constitute:

breach of contract;

breach of confidentiality;

failure to provide promised security.

B. Tort/Delict

National law may provide an independent claim for:

privacy infringement;

negligence;

unlawful disclosure;

reputational injury.

C. Consumer Law

Unfair contractual clauses attempting to exclude mandatory data-protection rights may be challenged.

D. Employment Law

Employee monitoring, biometric systems and workplace surveillance can create GDPR and employment-law disputes.

31. Data Protection and Privacy

Data protection and privacy overlap but are not identical.

Privacy

Broadly concerns:

intrusion into private life and personal autonomy.

Data protection

Concerns:

how personal data is collected, processed, stored, disclosed and otherwise handled.

A single incident can violate both.

32. Cross-Border Data Protection Claims

Modern businesses may have:

Customer in France

→ platform in Germany

→ cloud provider in Ireland

→ analytics provider in the Netherlands

→ data transfer outside the EEA.

This creates questions about:

jurisdiction;

applicable law;

controller/processor roles;

international transfers;

supervisory authority;

enforcement;

damages.

The GDPR provides a framework for cooperation between supervisory authorities, while private judicial claims are additionally affected by EU and national procedural rules.

33. Data Protection and International Transfers

International transfers can involve:

adequacy decisions;

Standard Contractual Clauses;

appropriate safeguards;

transfer impact assessments;

supplementary measures.

The leading Schrems II judgment, Case C-311/18, is particularly important because the CJEU examined transfers of personal data to third countries and the need for effective protection.

This is particularly relevant for:

cloud platforms;

multinational companies;

social-media services;

global data brokers;

AI providers.

34. Data Protection and Profiling

Profiling may involve:

consumer preferences;

financial behaviour;

political opinions;

health predictions;

employment assessments;

credit scoring.

The legal analysis asks:

What data was used?

What was the purpose?

What legal basis existed?

Was the data accurate?

Was the person informed?

Was automated decision-making involved?

Did profiling have legal or similarly significant effects?

Was sensitive information inferred?

The SCHUFA cases are particularly important for algorithmic scoring.

35. Data Protection and AI

AI systems can create data-protection claims through:

training-data collection;

inaccurate personal information;

automated profiling;

facial recognition;

biometric identification;

AI-generated personal profiles;

automated decisions;

data retention;

disclosure of personal information.

The basic GDPR principles remain relevant even when an AI system is responsible for processing.

36. Remedies

An individual may potentially seek:

A. Access

Obtain information about processing.

B. Rectification

Correct inaccurate data.

C. Erasure

Request deletion where Article 17 applies.

D. Restriction

Limit processing.

E. Objection

Object to specified processing.

F. Judicial remedy

Challenge unlawful processing before a court.

G. Compensation

Claim material or non-material damage under Article 82.

Article 82 is compensatory rather than punitive. (EUR-Lex)

37. Evidence

A claimant should preserve:

privacy notices;

consent records;

data-access responses;

emails;

screenshots;

breach notifications;

account records;

automated decision notices;

correction requests;

erasure requests;

evidence of financial loss;

evidence of disclosure;

communications with the controller.

The defendant may need to demonstrate:

processing records;

legal basis;

security measures;

risk assessments;

processor agreements;

data-retention policies;

incident-response procedures.

38. Defences

A controller may argue:

1. Lawful processing

A valid Article 6 legal basis existed.

2. Valid consent

The individual consented.

3. Legitimate interest

The processing was justified by a legitimate interest.

4. No infringement

The GDPR obligation was not breached.

5. No damage

The claimant suffered no compensable harm.

6. No causation

The alleged loss was not caused by the processing.

7. Legal obligation

Processing was required by law.

8. Applicable exception

A GDPR exception or derogation applies.

39. Claimant's Arguments

A claimant may argue:

No lawful basis existed.

Consent was invalid.

Processing exceeded the original purpose.

Data was inaccurate.

Data was retained excessively.

Information was disclosed without authorisation.

Sensitive information was unlawfully processed.

Profiling was unlawful.

An automated decision violated Article 22.

Security measures were inadequate.

Access or erasure rights were improperly refused.

The violation caused material or non-material damage.

40. Important Distinction: Regulatory Fine vs Civil Compensation

This distinction is essential.

Regulatory enforcement

A supervisory authority may impose:

warnings;

reprimands;

corrective orders;

administrative fines.

Civil compensation

The individual seeks:

compensation for damage actually suffered.

Article 82 has a compensatory, not punitive, function. (EUR-Lex)

Therefore:

A large regulatory fine does not automatically mean that every affected individual receives damages.

41. Practical Example

Suppose a European online platform collects customer information without a valid legal basis.

It:

stores the data for five years;

sells behavioural profiles to advertisers;

refuses an access request;

refuses to delete the information;

suffers a subsequent data breach.

The individual may potentially raise several claims:

Article 6

Was there a lawful basis?

Article 5

Were purpose limitation and data minimisation respected?

Article 15

Was the access request properly answered?

Article 17

Was the erasure request properly handled?

Article 32

Were appropriate security measures implemented?

Article 82

Did the unlawful processing cause compensable damage?

The claims should be analysed separately rather than treating the entire dispute as one undifferentiated privacy violation.

42. Exam-Oriented Test

Use the following sequence:

D-L-P-D-D-R

D — Data
What personal data is involved?

L — Lawfulness
What legal basis permits processing?

P — Purpose
Was the data used consistently with the permitted purpose?

D — Damage
What material or non-material harm occurred?

D — Direct Causation
Did the GDPR violation cause that harm?

R — Remedy
Access, rectification, erasure, restriction, objection, injunction or compensation?

43. Quick Revision Table

IssueRelevant GDPR Area
Lawful processingArticle 6
Sensitive dataArticle 9
TransparencyArticles 12–14
AccessArticle 15
RectificationArticle 16
ErasureArticle 17
RestrictionArticle 18
PortabilityArticle 20
ObjectionArticle 21
Automated decisionsArticle 22
Controller responsibilityArticle 24
Privacy by designArticle 25
Processor obligationsArticle 28
SecurityArticle 32
Data breach notificationArticles 33–34
CompensationArticle 82
Administrative finesArticle 83

44. Core Case-Law Principles

Österreichische Post

GDPR infringement alone does not establish compensation; damage and causation are required. (curia)

NAP

A cyberattack does not automatically prove inadequate security; security must be assessed concretely. (InfoCuria)

MediaMarktSaturn

An employee's accidental disclosure does not automatically establish inadequate organisational measures. (InfoCuria)

Gemeinde Ummendorf

Loss of control over personal data can be relevant to non-material damage. (InfoCuria)

Scalable Capital

Article 82 provides full compensation for actual damage and does not impose an additional seriousness threshold. (EUR-Lex)

Nowak

The concept of personal data includes information involving assessments and evaluations relating to a person.

Google Spain

Online intermediaries can have independent data-protection responsibilities.

Breyer

Technical identifiers such as dynamic IP addresses can constitute personal data.

45. Conclusion

Data protection claims in Europe combine statutory data-protection rights with civil remedies and judicial protection. The GDPR gives individuals extensive rights concerning how their personal information is collected, used, stored, disclosed and deleted.

The most important principle for a civil compensation action is:

GDPR Infringement + Actual Material/Non-Material Damage + Causal Link = Potential Article 82 Compensation

The CJEU's recent case law has clarified that infringement alone is not enough, while at the same time rejecting an additional minimum seriousness threshold for non-material damage. (InfoCuria)

For practical litigation, the strongest authorities to remember are Österreichische Post (C-300/21), Natsionalna agentsia za prihodite (C-340/21), MediaMarktSaturn (C-687/21), Gemeinde Ummendorf (C-456/22), Scalable Capital (C-182/22 and C-189/22), Krankenversicherung Nordrhein (C-667/21), PS (C-590/22), Nowak (C-434/16), Google Spain (C-131/12) and Breyer (C-582/14). These collectively cover lawfulness, access, erasure, profiling, security, breaches, personal-data definition, damage, causation and remedies.

LEAVE A COMMENT