Civil Law And Dataset Provenance Verification Disputes In Europe .
Civil Law And Dataset Provenance Verification Disputes In Europe
1. Introduction
Dataset provenance means the ability to establish where data came from, who collected it, how it was verified, what transformations were applied, who subsequently used it, and whether the resulting dataset can legally and factually be trusted.
In European civil-law and EU law, disputes concerning dataset provenance usually arise through several overlapping legal fields:
GDPR and personal-data accuracy
Right to know the source of personal data
Right to rectification
Database rights and unlawful extraction
Copyright and text/data mining
Contractual warranties concerning datasets
AI-training dataset disputes
Evidence, audit trails and authenticity
Confidentiality and trade secrets
Compensation for inaccurate or unlawfully processed data
There is not yet a single European cause of action called “dataset provenance liability.” Instead, courts determine provenance-related disputes by applying existing rules on data protection, database rights, copyright, contract, evidence and civil liability.
The GDPR is particularly important because its principles include accuracy, transparency, accountability and traceability of processing, while Articles 14 and 15 expressly address the source of personal data. (European Data Protection Board)
2. Meaning of Dataset Provenance
A provenance dispute can concern:
A. Origin
Who originally created or collected the dataset?
B. Chain of custody
How did the data move from:
Original source → collector → processor → aggregator → database → AI/model → end user?
C. Verification
Was the information checked before being incorporated into the dataset?
D. Transformation
Was data:
cleaned,
translated,
labelled,
aggregated,
anonymised,
pseudonymised,
deduplicated,
enriched,
inferred,
synthetically generated?
E. Legal entitlement
Did the dataset owner have a lawful basis or contractual right to obtain and use the data?
F. Accuracy
Is the information factually correct for the purpose for which it is being used?
G. Traceability
Can an affected person or court identify the original source?
These questions become especially important when datasets are used for credit scoring, employment screening, medical research, automated decision-making or AI training.
3. Main European Legal Framework
3.1 GDPR Article 5 — Accuracy and Accountability
Article 5(1)(d) requires personal data to be accurate and, where necessary, kept up to date, with reasonable steps taken to rectify or erase inaccurate data.
Article 5(2) establishes the principle of accountability: the controller must be able to demonstrate compliance. (EUR-Lex)
Therefore, provenance is legally important because a controller may have difficulty demonstrating accuracy where it cannot establish:
where the information came from;
when it was obtained;
whether it was independently verified;
whether it was subsequently modified.
4. GDPR Article 14 — Right to Know the Source
Where personal data are not obtained directly from the data subject, Article 14 requires information concerning the source from which the data originated.
This makes source verification a direct legal issue.
The CJEU has emphasised that the source of data is important to the distinction between direct and indirect collection and to transparency toward the data subject. (EUR-Lex)
5. GDPR Article 15 — Access to Source Information
Article 15 gives a data subject a right to obtain available information about the source of personal data.
This can be crucial where someone says:
“This dataset contains incorrect information about me. I need to know where that information came from.”
The right, however, is not necessarily an unlimited right to discover every earlier person or document involved in the creation of the information.
That distinction is particularly important in provenance litigation.
6. GDPR Article 16 — Rectification
Where dataset information about an individual is inaccurate, Article 16 provides a right to rectification.
This is one of the most important remedies in provenance disputes because an incorrect upstream source can create a chain of downstream errors:
Incorrect source → incorrect database → incorrect profile → incorrect decision → financial/reputational damage.
7. Database Directive
The EU Database Directive 96/9/EC provides protection for qualifying databases through the sui generis database right.
Dataset provenance disputes can therefore concern:
extraction of data;
repeated extraction;
reuse;
substantial investment;
verification;
presentation;
systematic copying.
The CJEU has developed a substantial body of law in this field.
8. Case Law
Case 1 — British Horseracing Board Ltd v William Hill Organization Ltd
CJEU, Case C-203/02, 9 November 2004
Facts
The British Horseracing Board maintained a large database containing information relating to horse racing.
William Hill used racing information derived from that database for betting purposes.
The dispute concerned the scope of the database maker's sui generis right.
Principle
The CJEU distinguished between:
investment in creating data, and
investment in obtaining, verifying or presenting existing data.
Investment directed merely toward creating the materials contained in a database does not automatically constitute the investment protected by the sui generis right.
Provenance significance
This case demonstrates that a dataset owner must be able to explain what investment was actually made in obtaining and verifying the dataset.
Therefore:
Dataset ownership does not automatically establish an exclusive right over every underlying fact.
9. Case 2 — Innoweb BV v Wegener ICT Media BV
CJEU, Case C-202/12, 19 December 2013
Facts
Wegener operated an online vehicle-advertising database.
Innoweb operated a dedicated metasearch engine that effectively searched and reused information from Wegener's database.
Holding
The CJEU examined whether systematic use of database contents through a dedicated metasearch engine constituted prohibited re-utilisation.
The Court recognised that repeated and systematic exploitation of database contents can interfere with the normal exploitation of the database.
Provenance significance
The case is important for modern datasets because provenance is not merely about the first collection of data.
It also concerns:
Who subsequently copied, aggregated or re-used the dataset?
A dataset may therefore have a provenance chain involving several successive databases.
(EUR-Lex)
10. Case 3 — Veronsaajien oikeudenvalvontayksikkö v A
CJEU, Case C-215/19, 2 July 2020
Significance
This case concerned the treatment of data-centre/server-related services under EU VAT law rather than a direct provenance claim.
It is useful by analogy because modern datasets are often maintained through complex technical infrastructure involving:
servers;
data storage;
processing;
hosting;
technical environments.
Provenance significance
It illustrates an important principle:
A dataset is not merely an abstract collection of information; its legal treatment can depend upon the technical and contractual environment in which it is collected, stored and processed.
This is an analogical authority, not a direct dataset-provenance judgment.
11. Case 4 — FF v Österreichische Datenschutzbehörde and CRIF GmbH
CJEU, Case C-487/21, 4 May 2023
This is one of the most important authorities for provenance-related data disputes.
Facts
The claimant requested access to personal data held by CRIF, including information contained in databases and documents.
The issue concerned the scope of the GDPR right of access.
Holding
The CJEU held that the right to obtain a copy of personal data can require a faithful and intelligible reproduction of the personal data.
Depending on circumstances, this may include extracts from documents or even entire documents/database extracts where necessary to allow the data subject effectively to exercise GDPR rights, while respecting the rights and freedoms of others. (EUR-Lex)
Provenance significance
This is highly relevant to dataset provenance.
A person challenging a dataset may need more than a general statement such as:
“We obtained this information from a third-party database.”
They may need sufficient underlying information to understand:
what information was processed;
how it appeared in the relevant record;
whether it was inaccurate;
whether rectification is necessary.
Principle
Access can be an evidentiary mechanism for investigating provenance.
12. Case 5 — Nowak v Data Protection Commissioner
CJEU, Case C-434/16, 20 December 2017
Facts
The case concerned examination-related information and whether information appearing in examination scripts could constitute personal data.
Principle
The CJEU adopted a broad understanding of personal data.
It also emphasised that whether information is accurate or complete must be assessed in light of the purpose for which the data were collected.
This principle was later expressly relied upon in the CJEU's 2025 accuracy jurisprudence. (EUR-Lex)
Provenance significance
Dataset accuracy is therefore not necessarily an abstract question of whether a statement is objectively true.
The relevant question may be:
Is the information accurate and complete for the purpose for which the dataset processes it?
This is highly important for:
AI datasets;
employment datasets;
credit databases;
medical datasets;
consumer profiles.
13. Case 6 — Google (De-referencing of allegedly inaccurate content)
CJEU, Case C-460/20, 8 December 2022
Issue
The case concerned allegedly inaccurate information appearing online and requests for removal/de-referencing.
Principle
The CJEU addressed the relationship between:
accuracy of information;
evidence of alleged inaccuracy;
freedom of expression;
protection of personal data.
A person seeking correction cannot simply assert that information is inaccurate without regard to evidentiary requirements.
The Court recognised the importance of relevant and sufficient evidence concerning alleged inaccuracies. This approach was subsequently cited in VP, Case C-247/23. (DPcuria)
Provenance significance
In a dataset dispute, the claimant may therefore need to establish:
Dataset entry → alleged error → evidence of error.
The provenance record can itself become evidence.
14. Case 7 — VP v Országos Idegenrendészeti Főigazgatóság
CJEU, Case C-247/23, 13 March 2025
This is a particularly important modern accuracy and verification authority.
Facts
Personal data concerning the claimant's gender identity had been recorded in a public register.
The claimant sought rectification.
Holding
The CJEU held that Article 16 GDPR requires a controller maintaining a public register to rectify inaccurate personal data.
The Court also stated that the person requesting rectification may be required to provide relevant and sufficient evidence reasonably required to establish inaccuracy.
But restrictions on the right must satisfy Article 23 GDPR. (EUR-Lex)
Provenance significance
The case demonstrates that dataset verification is a two-sided evidentiary process:
Controller: must maintain accurate information.
Data subject: may need to provide reasonable evidence showing that the information is inaccurate.
Important principle
A controller cannot use an excessively burdensome evidentiary requirement simply to make correction practically impossible.
15. Case 8 — CK v Dun & Bradstreet Austria GmbH
CJEU, Case C-203/22, 27 February 2025
This is particularly relevant to commercial datasets and automated profiling.
Facts
The dispute concerned automated creditworthiness scoring and information about how personal data were used to produce a particular result.
Holding
The CJEU interpreted Article 15(1)(h) GDPR as requiring meaningful information about the logic involved in automated decision-making.
The information must explain, in a concise, transparent and intelligible form, the procedure and principles actually applied to personal data to obtain a specific result such as a credit profile. (FRA)
The Court also addressed the relationship between access rights and:
third-party data;
trade secrets;
competing rights and interests.
Provenance significance
For AI and algorithmic datasets, provenance is not limited to:
“Where did the original data come from?”
It can also include:
“How did the data become part of the process that produced my profile?”
Thus, provenance can extend into the processing and transformation chain.
16. Case 9 — Digi Communications NV v Nemzeti Adatvédelmi és Információszabadság Hatóság
CJEU, Case C-77/21, 20 April 2023
Facts
Digi had copied personal data from one database into a test database for testing and troubleshooting.
The test database was retained for a lengthy period.
Holding
The CJEU examined purpose limitation and storage limitation.
It held that copying personal data into a testing database can be compatible with the original purpose in appropriate circumstances, but retaining such data longer than necessary for testing can breach the storage-limitation principle. (EUR-Lex)
Provenance significance
This is important because provenance includes the history of data movement.
A controller should be able to explain:
Original database → test database → purpose → retention period → deletion.
A failure to maintain that chain can create GDPR liability.
17. Case 10 — RS v TS (Waldfelber)
CJEU Case C-185/25 — Advocate General's Opinion, 18 June 2026
This case should currently be treated carefully because the material located is an Advocate General's Opinion, not a final CJEU judgment.
Issue
The case concerns Article 15(1)(g) GDPR and information about the source of personal data, including an opinion about an individual that was based on a discussion with another person.
The Advocate General considered the ordinary meaning of “source” and treated it primarily as the origin of the personal data, while warning against turning the right into an unlimited right to investigate every upstream source. (EUR-Lex)
Provenance significance
This is directly relevant to dataset provenance.
It suggests a potentially important distinction between:
Source of data
and
sources that influenced the source.
For example:
Database record → employee's report → third-party conversation → original event.
The Article 15 source right does not necessarily create an unlimited right to discover every person or document somewhere in that chain.
Because this remains an AG Opinion unless and until the Court rules, it should not be treated as binding CJEU precedent.
18. Dataset Provenance and AI Training
Modern European litigation increasingly connects dataset provenance with AI.
A typical dispute may allege:
Copyrighted works → scraped website → aggregated dataset → training dataset → AI model.
The legal questions can include:
Who collected the material?
Was it lawfully obtained?
Was it copied?
Was it transformed?
Was consent required?
Was copyright infringed?
Was a database right infringed?
Was personal data included?
Can the source be identified?
Can the claimant prove that its material entered the training dataset?
European database jurisprudence is therefore increasingly relevant to AI dataset litigation.
The CJEU's database cases establish that extraction and reutilisation must be analysed carefully, rather than simply assuming that any use of information constitutes infringement. (InfoCuria)
19. Dataset Provenance and Copyright
A provenance dispute may also concern the difference between:
Facts
Raw facts are generally treated differently from protected creative expression.
Database structure
The selection or arrangement of information may receive copyright protection where the relevant originality requirements are satisfied.
Database investment
A qualifying database may receive sui generis protection.
Source documents
The documents from which data were extracted may have separate copyright protection.
Therefore:
Data ownership ≠ database ownership ≠ copyright in source material.
This distinction is fundamental in dataset litigation.
20. Dataset Provenance and Contract Law
Many commercial datasets are supplied under contracts.
A dataset contract may contain warranties concerning:
accuracy;
completeness;
lawful collection;
licensing;
provenance;
absence of third-party claims;
regulatory compliance;
updating;
cybersecurity;
auditability.
A buyer may therefore bring a contractual claim where:
Seller represents that dataset is lawfully sourced → buyer discovers unlicensed or inaccurate data → dataset becomes unusable → buyer suffers economic loss.
Potential remedies include:
damages;
price reduction;
termination;
indemnification;
replacement dataset;
specific performance;
reimbursement of remediation costs.
The governing national contract law and choice-of-law rules will normally determine these remedies.
21. Dataset Provenance and Civil Liability
A civil claim can be expressed through the following chain:
Wrongful collection
↓
Defective provenance
↓
Unverified or unlawful data
↓
Inclusion in dataset
↓
Downstream use
↓
Damage
↓
Causation
↓
Civil liability
The claimant generally needs to connect the provenance defect to the legally recognised loss.
22. Important Evidentiary Issues
Dataset provenance disputes are highly evidence-intensive.
Courts may consider:
1. Metadata
timestamps;
file origins;
hashes;
creation dates;
modification history.
2. Audit logs
Who accessed or modified the data?
3. Data lineage
What systems processed the information?
4. Version control
Which version of the dataset was used?
5. Hash verification
Does the disputed dataset correspond to the alleged original?
6. Expert evidence
Technical experts may reconstruct:
source → transformation → output.
7. Contracts
Licences and data-supply agreements can establish lawful provenance.
8. Internal policies
Data-governance documentation may show whether verification procedures existed.
23. Burden of Proof
The burden varies according to the legal claim.
GDPR
The controller has significant accountability obligations and must demonstrate compliance with Article 5(1).
Rectification
The data subject may need to provide relevant and sufficient evidence showing that information is inaccurate, although requirements must remain reasonable. VP is important here. (EUR-Lex)
Database infringement
The claimant normally must establish the relevant database right and the defendant's extraction/re-utilisation.
Contract
The claimant normally needs to establish:
contractual obligation;
breach;
causation;
recoverable damage.
Copyright
The claimant generally must establish protected subject matter and the relevant infringing act.
24. Provenance Versus Accuracy
These concepts must not be confused.
| Issue | Meaning |
|---|---|
| Provenance | Where did the data come from? |
| Accuracy | Is the data correct? |
| Authenticity | Is the dataset what it claims to be? |
| Integrity | Has it been altered improperly? |
| Completeness | Is relevant information missing? |
| Lawfulness | Was collection/use legally permitted? |
| Traceability | Can the data's lifecycle be reconstructed? |
| Accountability | Can the controller demonstrate compliance? |
A dataset can therefore have good provenance but inaccurate information, or accurate information but unlawful provenance.
25. Trade Secrets and Provenance
A company may argue:
“We cannot disclose our complete dataset-generation methodology because it is a trade secret.”
European data-protection law does not automatically allow such an argument to defeat data-subject rights.
In CK v Dun & Bradstreet, the CJEU required a balance between access rights and competing interests such as trade secrets and third-party rights. (FRA)
Therefore, courts may need to balance:
Transparency
against
Trade secrecy
and
Privacy of third parties.
26. Cross-Border Dataset Disputes
Dataset provenance litigation can involve several jurisdictions:
German company collects data in France → dataset stored in Ireland → processing in Netherlands → AI provider in another Member State → customer in Spain.
Questions can then arise concerning:
GDPR territorial scope;
lead supervisory authority;
Brussels I bis jurisdiction;
Rome I contractual law;
Rome II non-contractual liability;
intellectual-property jurisdiction;
database rights;
evidence gathering;
cross-border enforcement.
The GDPR's one-stop-shop system is particularly relevant for cross-border supervisory enforcement. The EDPB maintains a register of final one-stop-shop decisions designed to promote harmonised enforcement. (European Data Protection Board)
27. Civil Remedies
Depending upon the cause of action, possible remedies include:
A. Rectification
Correction of inaccurate dataset information.
B. Erasure
Removal of unlawfully processed information.
C. Restriction
Temporary limitation on processing.
D. Injunction
Stopping unlawful extraction or use.
E. Damages
Compensation for legally recognised material or non-material loss.
F. Contractual indemnity
Recovery under a data-supply agreement.
G. Database remedies
Protection against unlawful extraction/re-utilisation.
H. Copyright remedies
Depending upon applicable national and EU copyright law.
I. Disclosure
Orders requiring production of relevant provenance information or evidence.
28. Direct and Analogical Authorities
| Case | Jurisdiction | Main relevance |
|---|---|---|
| British Horseracing Board v William Hill, C-203/02 | CJEU | Database investment, obtaining and verification |
| Innoweb v Wegener, C-202/12 | CJEU | Extraction and reutilisation |
| FF v CRIF, C-487/21 | CJEU | Access to database/document information |
| Nowak, C-434/16 | CJEU | Personal data and purpose-based accuracy |
| Google v CNIL/Google, C-460/20 | CJEU | Evidence concerning inaccurate information |
| VP, C-247/23 | CJEU | Accuracy and rectification |
| Digi, C-77/21 | CJEU | Data copying, purpose and retention |
| CK v Dun & Bradstreet, C-203/22 | CJEU | Automated profiling and meaningful information |
| RS v TS, C-185/25 | CJEU/AG Opinion | Source of personal data; provenance |
| Veronsaajien oikeudenvalvontayksikkö, C-215/19 | CJEU | Technical data-centre environment; analogical only |
29. Key Legal Principles
Principle 1 — Provenance is legally significant
Knowing the source of data can be necessary to assess its accuracy and legality.
Principle 2 — Accuracy is purpose-dependent
Information must be assessed in relation to the purpose for which it was collected and processed. Nowak and VP are important authorities. (EUR-Lex)
Principle 3 — Access can assist verification
Article 15 can provide information necessary for a person to investigate and challenge personal-data processing. FF v CRIF is particularly important. (EUR-Lex)
Principle 4 — Source disclosure is not unlimited
The right to know the source does not necessarily mean a right to discover every upstream contributor to a piece of information. This issue is especially visible in the pending RS v TS reference and the Advocate General's 2026 Opinion. (EUR-Lex)
Principle 5 — Database rights protect investment, not automatically facts
British Horseracing Board remains fundamental. (InfoCuria)
Principle 6 — Repeated extraction can itself be legally significant
Innoweb demonstrates the importance of systematic reuse. (EUR-Lex)
Principle 7 — Data copying creates a provenance trail
Digi shows that movement of personal data between databases can itself constitute relevant processing and must respect GDPR principles. (EUR-Lex)
Principle 8 — AI increases the importance of provenance
AI datasets can create multiple layers of:
collection → aggregation → transformation → training → output.
Determining which stage created the legal defect may be decisive.
30. Exam-Oriented Legal Test
For a dataset provenance dispute, use this sequence:
1. IDENTIFY DATA
What exactly is contained in the dataset?
2. IDENTIFY SOURCE
Who originally supplied or created it?
3. TRACE DATA
How did it reach the defendant?
4. VERIFY
Was the information checked?
5. CLASSIFY
Personal data? Copyright? Database contents? Trade secrets? Contractual information?
6. CHECK LAWfulness
Was collection and subsequent processing lawful?
7. CHECK ACCURACY
Is the information accurate for its purpose?
8. CHECK TRANSFORMATION
Was it copied, modified, aggregated or inferred?
9. ESTABLISH CAUSATION
Did the provenance defect cause the claimant's loss?
10. DETERMINE REMEDY
Rectification, erasure, injunction, damages, contractual compensation or database/copyright relief.
31. Conclusion
European law does not yet recognise a unified standalone tort of “dataset provenance failure.” Instead, provenance disputes are resolved through a combination of GDPR accuracy and transparency rules, database rights, copyright, contract, evidence and general civil liability.
The strongest legal pattern is:
SOURCE → COLLECTION → VERIFICATION → TRANSFORMATION → STORAGE → USE → ACCURACY → DAMAGE → REMEDY
The most directly useful authorities are British Horseracing Board, Innoweb, FF v CRIF, Nowak, Google (C-460/20), Digi, VP, and CK v Dun & Bradstreet. The 2026 RS v TS Advocate General's Opinion is especially interesting for the future development of the meaning of “source” under Article 15(1)(g), but it should not yet be treated as a final judgment. (EUR-Lex)
Ultra-Short Revision Keywords
Dataset Provenance – Source – Data Lineage – Traceability – Accuracy – Verification – Accountability – GDPR Art. 5 – Art. 14 Source – Art. 15 Access – Art. 16 Rectification – Database Directive – Extraction – Re-utilisation – Copyright – Trade Secrets – Metadata – Audit Trail – Chain of Custody – AI Training Data – Causation – Damages – Injunction – Cross-Border Processing.

comments