CHAPTER VIIIREMEDIES, LIABILITY AND PENALTIES

Article 79Right to an effective judicial remedy against a controller or processor

Official text

(1)Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.

(2)Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.

Commentary

Article 79 gives an individual a direct route to court where they believe that a controller or processor has infringed their GDPR rights. The individual does not first have to obtain a decision from a supervisory authority, and a pending regulatory complaint does not ordinarily prevent the person from pursuing judicial proceedings at the same time.

In its simplest form:

Article 79 allows a person to sue the organisation that is allegedly processing their personal data unlawfully and to ask a court for an effective remedy.

The Article has two main functions:

  1. Paragraph 1 creates the substantive right to a judicial remedy against a controller or processor.
  2. Paragraph 2 determines the Member States in which those proceedings may be brought.

The official wording confirms that the remedy exists alongside administrative and non-judicial remedies, including an Article 77 complaint, and that the data subject may generally sue either where the defendant has an establishment or where the data subject habitually resides.


1. Position of Article 79 within the GDPR’s remedial system

The GDPR creates several interconnected remedies:

  • Article 77: a complaint to a supervisory authority;
  • Article 78: judicial review of a supervisory authority’s binding decision or inactivity;
  • Article 79: direct judicial proceedings against a controller or processor;
  • Article 80: representation by an eligible non-profit organisation;
  • Article 82: compensation for material or non-material damage.

These remedies perform different functions.

Illustration

A social-media platform unlawfully discloses a person’s health information. The person may:

  • complain to a supervisory authority under Article 77;
  • sue the platform directly under Article 79 for an order stopping the disclosure;
  • claim compensation under Article 82 if the legal conditions are satisfied;
  • challenge an unsatisfactory supervisory-authority decision under Article 78. Article 79 concerns direct judicial protection against the controller or processor. It does not merely provide an appeal against a regulator.

2. Article 79 is based on Article 47 of the Charter

Article 79 gives practical effect to the right to an effective remedy and a fair trial under Article 47 of the Charter of Fundamental Rights of the European Union.

A right is not effectively protected if the individual can complain only to an administrative authority but has no meaningful access to a court. Supervisory authorities are independent administrative bodies, not courts merely because they exercise investigative or corrective powers.

An effective judicial remedy normally requires access to:

  • an independent and impartial tribunal;
  • a fair procedure;
  • a reasoned decision;
  • appropriate interim and final relief;
  • procedures that do not make enforcement practically impossible;
  • judicial interpretation of disputed law.

[!example] Illustration A controller intends to publish a person’s precise home address tomorrow. A complaint to a supervisory authority may be useful, but it may not be fast enough. Article 79 should permit access to a court capable of granting urgent interim relief where the applicable national procedure allows and effectiveness requires it. The remedy must be practical, not merely theoretical.

3. Article 79(1): “Without prejudice” to other remedies

Paragraph 1 begins:

“Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77…”

This means that the Article 79 court remedy exists independently of an Article 77 complaint.

The data subject may ordinarily:

  • complain to a supervisory authority only;
  • go directly to court only;
  • use both routes concurrently;
  • begin one route and later begin the other.

The CJEU confirmed in BE v Nemzeti Adatvédelmi és Információszabadság Hatóság, Case C-132/21, that the remedies in Articles 77, 78 and 79 may be exercised concurrently and independently. Member States may regulate their relationship, but national rules must preserve effective protection, equivalent treatment and consistent GDPR application.

Illustration

A person asks an online platform to erase an inaccurate medical profile. The platform refuses. The person may:

  1. file an Article 77 complaint;
  2. sue under Article 79 for erasure;
  3. pursue both simultaneously.

The controller cannot insist that the person wait for the supervisory authority before going to court.


3.1 No automatic priority between authority and court

The GDPR does not establish a general rule that:

  • the supervisory authority must decide first;
  • the court must decide first;
  • filing before one automatically excludes the other.

On 18 June 2026, the CJEU reinforced this in Case C-414/24. It held that a supervisory authority cannot reject an Article 77 complaint solely because judicial proceedings under Article 79 concerning the same subject matter have already been brought.

[!example] Illustration A doctor asks a rating platform to erase personal data. The doctor first sues the platform and later complains to the supervisory authority. The authority cannot reject the complaint merely because the court case already exists. This also works in the other direction. The existence of a regulatory complaint does not ordinarily extinguish the Article 79 judicial remedy.

3.2 Coordination remains necessary

Parallel proceedings can produce conflicting outcomes.

Illustration

The supervisory authority concludes that the processing is lawful. A civil court considering the same processing concludes that it is unlawful. The CJEU permits Member States to establish procedural mechanisms to reduce this risk, provided those mechanisms do not destroy the independence or effectiveness of the remedies. Possible coordination mechanisms may include:

  • exchanging information about related proceedings;
  • staying one proceeding temporarily;
  • considering a final judgment;
  • consolidating related cases where national law permits;
  • applying res judicata rules;
  • referring uncertain EU-law questions to the CJEU. A proportionate stay may sometimes be acceptable. An automatic dismissal of one remedy merely because the other exists is much more difficult to justify.

4. “Each data subject”

Article 79 is expressly a data subject’s remedy.

A data subject is an identified or identifiable natural person to whom the relevant personal data relate.

This may include:

  • customers;
  • employees;
  • job applicants;
  • patients;
  • website users;
  • children;
  • sole traders;
  • company directors;
  • persons who are indirectly identifiable;
  • persons inferred or profiled by a system.

Nationality is not the decisive issue. A non-EU citizen may use Article 79 if the disputed processing falls within the GDPR and the proceedings satisfy the jurisdictional rules.

[!example] Illustration A Brazilian student habitually living in Portugal is profiled by an educational platform covered by the GDPR. The student is a data subject and may invoke Article 79 even though the student is not an EU citizen.

A company cannot normally sue under Article 79 merely because information about the company has been processed.

Illustration

A database contains:

  • the company’s annual revenue;
  • its registered address;
  • the names and evaluations of its directors. The company’s revenue and corporate address do not ordinarily constitute personal data of the company. But the directors may bring Article 79 proceedings where the records relate to them as identifiable natural persons. A company may have other legal remedies. Article 79 itself is framed as a data subject right.

4.2 Representation under Article 80

A data subject may mandate an eligible non-profit body to exercise Article 79 rights on their behalf.

Such an organisation generally must:

  • be properly constituted under Member State law;
  • pursue public-interest objectives;
  • operate in the field of protecting data subject rights and freedoms;
  • satisfy Article 80’s other requirements.

[!example] Illustration A visually impaired person cannot practically challenge an inaccessible automated benefits system alone. The person may mandate an eligible digital-rights organisation to pursue judicial relief. Member States may also permit certain representative actions without an individual mandate under Article 80(2), subject to national implementation.

5. Who may be sued?

Article 79 allows proceedings against:

  • a controller;
  • a processor.

Correctly identifying the defendant is technically important.

5.1 Controller

A controller determines the purposes and essential means of processing.

Illustration

An employer decides:

  • that employee biometrics will be collected;
  • that they will be used for attendance;
  • how long they will be kept;
  • who may access them. The employer is likely the controller for that processing.

5.2 Processor

A processor processes personal data on behalf of a controller.

[!example] Illustration The employer hires a technology vendor to store the biometric templates according to the employer’s documented directions. The vendor may be a processor. However, a processor that uses the data for its own unrelated purpose may become a controller for that processing.

5.3 Suing the processor

The fact that a processor acts on behalf of a controller does not place it entirely outside Article 79.

A processor may be sued where its own conduct allegedly infringes GDPR rights, for example because it:

  • acts outside lawful instructions;
  • fails to implement required security;
  • appoints an unauthorised subprocessor;
  • unlawfully transfers data;
  • uses data for its own purposes;
  • refuses obligations directly applicable to processors.

Illustration

A payroll provider receives employee data to calculate salaries but secretly sells the data for advertising. For the advertising use, the provider is likely acting for its own purpose and may be treated as a controller. Even where it remains a processor for some activities, Article 79 expressly permits proceedings against processors.

5.4 The plaintiff should identify the relevant role operation by operation

A defendant may be:

  • controller for one operation;
  • processor for another;
  • joint controller for a third.

Illustration

A travel platform independently decides how to profile customers for advertising but processes booking data on a hotel’s instructions for reservation fulfilment. The role must be examined separately for:

  • booking fulfilment;
  • advertising profiling;
  • analytics;
  • payment processing. The court should assess actual influence and purpose rather than relying solely on contract labels.

6. “Where he or she considers”

This wording means that the data subject does not have to prove the whole case as a precondition for accessing the court.

The person must make an arguable claim that:

  1. personal data relating to them were processed;
  2. the processing did not comply with the GDPR;
  3. their GDPR rights were infringed as a result.

Whether the claim succeeds is determined by the court.

Illustration

A person suspects that a credit agency created an undisclosed risk score because several lenders simultaneously refused credit. The person may not initially possess:

  • the score;
  • the model;
  • the data sources;
  • the controller’s internal records. The individual must plead enough facts to establish an arguable case under the applicable national procedure. The individual need not possess the defendant’s hidden evidence before proceedings can begin. The phrase does not allow purely imaginary claims.

[!example] Illustration A person says: “A company that does not exist may process my data someday.” That is not a concrete Article 79 dispute.

7. The rights protected are broader than Chapter III alone

The most obvious Article 79 cases concern rights under Chapter III:

  • transparency;
  • access;
  • rectification;
  • erasure;
  • restriction;
  • portability;
  • objection;
  • automated decision-making protections.

But Article 79 refers to“rights under this Regulation.”

The protected legal position may also derive from:

  • lawful and fair processing;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • confidentiality;
  • special-category protections;
  • breach communication;
  • international-transfer protections;
  • privacy by design where the failure affects the individual.

Illustration

A hospital has never refused an access or erasure request, but it transfers the patient’s medical record to a third country without an adequate transfer mechanism. The patient may argue that the unlawful transfer infringed the patient’s GDPR-protected legal position even though no classic Chapter III request was refused.

7.1 Purely institutional obligations

Some GDPR obligations are primarily organisational, such as:

  • records of processing under Article 30;
  • designation of a DPO under Article 37;
  • preparation of a DPIA under Article 35.

A bare technical failure may not automatically give every data subject an Article 79 claim.

[!example] Illustration A controller keeps a fully compliant processing record but stores it in the wrong internal format. The defect may not have any material connection with the plaintiff’s rights. Compare a controller that failed to carry out a DPIA before deploying a facial-recognition system, resulting in systematic misidentification and denial of access to a service. The Article 35 failure is then connected with concrete interference with the individual’s rights. Article 79 should not be interpreted so narrowly that the person is denied judicial protection merely because the underlying obligation is formally addressed to the controller. The appropriate question is: Does the alleged GDPR breach concern or impair the claimant’s legally protected position as a data subject?

8. “As a result of processing”

Article 79 requires a connection between:

  • non-compliant processing; and
  • infringement of the person’s GDPR rights.

“Processing” is very broad. It includes:

  • collection;
  • recording;
  • organisation;
  • storage;
  • consultation;
  • use;
  • disclosure;
  • transmission;
  • alteration;
  • restriction;
  • erasure;
  • destruction.

Illustration

A company publishes inaccurate information about the person. The publication is processing. If it breaches accuracy and harms the person’s right to rectification, the necessary connection exists.

8.1 Refusal of access where processing is disputed

A difficulty arises where a person uses Article 15 to ask whether any data are processed and the controller simply ignores the request.

A rigid interpretation could say that Article 79 is unavailable unless the person first proves processing. But proving processing is often the purpose of the access request.

That interpretation would create a circular problem:

  1. The person needs access to discover whether processing exists.
  2. The controller refuses.
  3. The person cannot sue because processing is not yet proved.

A purposive reading avoids this result.

[!example] Illustration A former employee asks whether the employer still holds disciplinary records. The employer gives no response. The individual should be able to seek enforcement of the Article 15 right even if the final result shows that no data remain. The right includes obtaining confirmation whether personal data are being processed.

9. Non-compliance may arise under several layers of law

“Non-compliance with this Regulation” includes violation of the GDPR’s directly applicable rules.

It may also involve:

  • delegated acts;
  • implementing acts;
  • Member State laws adopted under GDPR opening clauses;
  • sector-specific rules interacting with the GDPR;
  • judicial interpretations of GDPR provisions.

Illustration

National law validly specifies conditions for processing employee data under Article 88. An employer’s processing may be non-compliant because it violates:

  • Article 5;
  • Article 6;
  • the valid Article 88 national rule. Article 79 proceedings may require the national court to interpret both EU and national data protection law. If uncertainty arises concerning EU law, the national court may request a preliminary ruling from the CJEU under Article 267 TFEU.

10. What relief may be requested?

Article 79 guarantees an effective judicial remedy but does not provide a closed list of judicial orders.

National procedure determines the precise remedies, subject to EU-law effectiveness.

Possible relief may include:

  • declaration of infringement;
  • injunction stopping processing;
  • order to provide access;
  • rectification;
  • erasure;
  • restriction;
  • prohibition of disclosure;
  • suspension of transfer;
  • removal of content;
  • compliance with an objection;
  • interim relief;
  • preservation of evidence.

Illustration

A company is about to transfer the person’s genetic data abroad. A final judgment delivered three years later would be ineffective if the transfer occurred immediately. Effective judicial protection may require urgent interim relief.

10.1 Article 79 and compensation

Article 79 permits judicial proceedings, while Article 82 specifically governs compensation.

A claimant may combine claims, depending on national procedure:

  • Article 79 claim for erasure or injunction;
  • Article 82 claim for material or non-material damage.

Illustration

A controller unlawfully discloses a person’s debt information. The person may seek:

  • removal of the information under Article 79;
  • compensation under Article 82 if damage and the other legal conditions are established. Article 79 does not mean that every infringement automatically produces damages. It may support non-monetary relief even where no compensable damage is proved.

11. Effective access to court

Member States determine procedural details, including:

  • pleadings;
  • evidence;
  • limitation periods;
  • court fees;
  • representation;
  • appeal levels;
  • interim measures.

But those rules must satisfy:

  • the principle of equivalence;
  • the principle of effectiveness;
  • Article 47 of the Charter.

11.1 Equivalence

GDPR claims must not be treated less favourably than comparable domestic claims.

Illustration

National consumer claims may be filed using a simple online process, but GDPR claims require expensive notarisation without objective justification. That may breach equivalence.

11.2 Effectiveness

A national rule must not make Article 79 rights practically impossible or excessively difficult.

Illustration

A Member State requires a person to bring an Article 79 claim within forty-eight hours after hidden profiling began, even where the person could not reasonably know about it. That would seriously undermine effectiveness.

11.3 Costs

Article 79 proceedings do not have to be universally free.

However, prohibitive court fees or cost exposure may undermine access to justice.

Relevant safeguards may include:

  • legal aid;
  • fee waivers;
  • proportionate costs;
  • representative actions;
  • limits on adverse-cost liability.

12. Evidence and burden of proof

National evidential rules apply, but accountability under Article 5(2) is highly relevant.

The controller must be able to demonstrate compliance with the GDPR’s principles.

Illustration

The controller says that the data subject consented but cannot produce:

  • the consent wording;
  • timestamp;
  • collection interface;
  • withdrawal mechanism;
  • record linking consent to the person. The data subject should not be expected to prove the internal absence of consent records. The controller’s accountability obligation is directly relevant. This does not mean that the controller bears every evidential burden in every Article 79 proceeding. The claimant must still establish an arguable factual and legal basis under national procedure. But courts should avoid placing impossible proof requirements on individuals where the relevant evidence is controlled exclusively by the defendant. Possible tools include:
  • disclosure orders;
  • document production;
  • expert evidence;
  • inspection;
  • adverse inferences;
  • preservation orders.

13. Article 79(2): Jurisdiction

Paragraph 2 determines where Article 79 proceedings may be brought.

The data subject generally has two options:

  1. courts of the Member State where the controller or processor has an establishment;
  2. courts of the Member State where the data subject habitually resides.

The habitual-residence option does not apply where the defendant is a Member State public authority acting in the exercise of public powers.

This forum choice is designed to make judicial protection accessible.

Illustration

A person habitually living in France sues a private company established in Ireland. The person may generally choose:

  • Ireland, based on the defendant’s establishment;
  • France, based on habitual residence. The individual is not automatically forced to litigate in the controller’s home state.

14. Meaning of “establishment”

Recital 22 explains that an establishment requires the effective and real exercise of activity through stable arrangements. Its legal form is not decisive.

An establishment may be:

  • headquarters;
  • branch;
  • subsidiary;
  • permanent office;
  • another stable operational arrangement.

A website merely accessible in a country does not automatically create an establishment there.

Illustration

A US platform has:

  • no office;
  • no employees;
  • no stable facilities in Greece;
  • a website accessible in Greece. Mere accessibility is not necessarily an establishment. Compare a platform with:
  • a permanent Athens office;
  • local employees;
  • local advertising operations;
  • stable commercial activity. That is much more likely to be an establishment.

14.1 Connection with the disputed processing

A major grey area is whether the processing must be connected with the chosen establishment.

Article 79(2) says where the controller or processor“has an establishment.” It does not expressly say “the establishment responsible for the processing.”

But unlimited selection of any minor establishment could create arbitrary forum shopping.

A sound interpretation should consider:

  • whether the establishment is genuine;
  • whether the defendant operates through it;
  • whether the proceedings can reasonably be brought against the defendant there;
  • the relationship between the establishment and conduct at issue;
  • predictability for the defendant;
  • Article 79’s protective purpose.

[!example] Illustration A global company has a small unrelated sales office in Finland, while the disputed health-data system is operated entirely through its Spanish entity. Whether Finland is available merely because of the unrelated office is legally less certain than a case where the Finnish office promotes or supports the disputed service. The statement that a data subject can always select any establishment, regardless of connection, should therefore be treated cautiously.

15. Main establishment is not the only possible establishment

Article 79(2) uses “an establishment,” not “main establishment.”

The one-stop-shop test under Article 56 and the judicial jurisdiction rule under Article 79 perform different functions.

[!example] Illustration A controller’s main establishment for regulatory cooperation is in Ireland, but it has a genuine operational establishment in Germany connected with the service. The Irish authority may act as lead regulator. That does not necessarily mean that every private Article 79 proceeding must be brought in Ireland. A German court may have jurisdiction under Article 79(2), depending on the establishment and national allocation rules. This distinction prevents the one-stop-shop administrative system from becoming a private-litigation monopoly in the lead authority’s state.

16. Habitual residence

The alternative forum is the Member State where the data subject has habitual residence.

Habitual residence is a factual and autonomous EU-law concept. It generally refers to the stable or regular centre of the person’s life.

Relevant factors may include:

  • duration of residence;
  • regularity;
  • family connections;
  • work;
  • housing;
  • social integration;
  • intention to remain;
  • overall circumstances.

Illustration

A Spanish citizen has lived, worked and maintained a home in Belgium for five years. Belgium is likely the habitual residence even though the person remains a Spanish national.

16.1 Temporary presence is insufficient

A brief stay ordinarily does not establish habitual residence.

Illustration

A tourist spends three weeks in Italy. That stay does not ordinarily make Italy the person’s habitual residence for Article 79.

16.2 Multiple residences

A person may divide life between Member States.

The court may need to determine where the person has the more stable centre of interests.

Illustration

A cross-border worker spends weekdays in Luxembourg and weekends with family in France. Relevant facts may include:

  • length of each stay;
  • family home;
  • employment;
  • registration;
  • intention;
  • regularity. The term should not be manipulated through artificial short-term relocation solely to create a favourable forum.

17. Public-authority exception

The habitual-residence option does not apply where the controller or processor is a public authority of a Member State acting in the exercise of its public powers.

The purpose is to avoid subjecting a sovereign public authority to the courts of another Member State for official governmental action.

Illustration

A French resident challenges official tax processing by the German tax authority. The person cannot necessarily rely on French habitual residence to sue the German tax authority in France. Proceedings should ordinarily be brought in the Member State connected with the public authority.

17.1 The exception is activity-specific

A public body does not act in the exercise of public powers in everything it does.

Illustration

A municipality processes personal data while:

  • issuing statutory permits;
  • collecting taxes;
  • exercising police powers. Those activities involve public powers. The same municipality operates a commercial conference centre and processes customer data under ordinary contracts. That activity may be commercial rather than an exercise of public authority. The court should examine:
  • nature of the activity;
  • legal basis;
  • special public powers;
  • whether a private operator could perform the same activity;
  • whether the authority acted through sovereign powers. The exception should not be expanded merely because the defendant is publicly owned.

18. Relationship with Brussels I Recast

Recital 147 states that the GDPR’s specific jurisdiction rules should not be prejudiced by general jurisdiction rules such as Regulation 1215/2012, commonly called Brussels I Recast.

Article 79(2) is therefore a special jurisdiction rule for GDPR judicial remedies against controllers and processors.

This does not mean that Brussels I Recast becomes irrelevant to every procedural question.

It may still matter for matters not fully regulated by Article 79, such as:

  • recognition and enforcement of judgments;
  • lis pendens;
  • related actions;
  • procedural coordination;
  • questions outside Article 79’s precise scope.

The safest analysis is issue-by-issue:

  1. Does Article 79 specifically regulate the question?
  2. If yes, the GDPR’s specific rule prevails.
  3. If not, another applicable EU instrument may fill the gap.

18.1 Article 79 is not primarily designed to eliminate forum choice

The supplied commentary suggests that Article 79 aims to guard against forum shopping.

That is only partly true.

Article 79 deliberately gives the data subject a choice between at least two connected fora. This is protective jurisdiction.

The Article seeks to prevent arbitrary litigation in wholly unrelated states while giving the individual a practical forum close to home.


19. Cross-border judgments and inconsistent outcomes

A controller may face Article 79 proceedings in several Member States brought by different individuals.

Illustration

A platform applies one profiling system across Europe.

  • A French user sues in France.
  • A German user sues in Germany.
  • A Dutch user sues in the Netherlands. The courts may reach different interpretations. Consistency can be promoted through:
  • CJEU preliminary references;
  • recognition of judgments;
  • lis pendens rules;
  • related-action rules;
  • EDPB guidance;
  • supervisory cooperation. One national judgment does not automatically bind every data subject who was not party to it. But final judgments may have important legal and evidential influence.

20. Article 79 and representative or competitor actions

Article 79 gives data subjects a direct judicial remedy. It does not necessarily exhaust every national enforcement route.

In Lindenapotheke, Case C-21/23, the CJEU held that the GDPR does not preclude national law from permitting a competitor to challenge GDPR infringements as unfair commercial practices. The case concerned online pharmacy sales and health data.

Illustration

Pharmacy A alleges that Pharmacy B unlawfully processes customers’ health data and thereby gains an unfair commercial advantage. Pharmacy A is not exercising the customers’ Article 79 rights as a data subject. It may nevertheless have standing under national unfair-competition law if that law permits the action. This distinction is important:

  • Article 79 protects the data subject;
  • Article 80 concerns eligible representative bodies;
  • national law may create additional actions for competitors or consumer bodies. The GDPR’s remedial system is not necessarily completely exhaustive.

21. Limitation periods

Article 79 does not establish a uniform EU limitation period.

National law may set deadlines, provided they satisfy:

  • equivalence;
  • effectiveness;
  • legal certainty;
  • Article 47.

The starting point is critical.

Illustration

A controller secretly profiles a person for six years. The person discovers the profiling only after an access request. A limitation period that expired before the person could reasonably know of the processing may undermine effective judicial protection. Different claims may have different timing questions:

  • ongoing processing;
  • one-off disclosure;
  • refusal of access;
  • continuing retention;
  • damages;
  • injunction;
  • imminent processing. A continuing unlawful retention may not be treated in precisely the same way as a completed historic disclosure.

22. Court judgments and supervisory proceedings

An Article 79 judgment may influence a supervisory authority, and a supervisory decision may influence a court, but neither relationship should be oversimplified.

A court is responsible for independently deciding the Article 79 dispute.

A supervisory authority is responsible for performing its statutory tasks.

[!example] Illustration A supervisory authority found the processing lawful. The data subject then sues the controller. The court should consider the authority’s reasoning where relevant, but a supervisory decision does not automatically prevent judicial examination of the data subject’s claim. Conversely, a non-final court judgment may not automatically extinguish an Article 77 complaint. The CJEU’s 2026 ruling confirms that the authority cannot reject solely because the Article 79 case already exists. National rules may coordinate the proceedings, but cannot hollow out either remedy.

23. Complete practical illustration

Assume that a person habitually living in Belgium uses a fitness platform whose parent company is based outside the EU but which has stable establishments in Ireland and France.

The person discovers that the platform:

  • inferred a pregnancy;
  • shared the inference with advertisers;
  • denied access;
  • transferred data to another country;
  • continued processing after objection.

Step 1: Identifying defendants

The person examines whether:

  • the Irish entity determines purposes and means;
  • the French entity supports the disputed advertising service;
  • a cloud vendor acts as processor;
  • the parent company is a controller;
  • two entities jointly determine the advertising processing.

The correct defendants depend on factual roles, not labels alone.

Step 2: Choosing remedies

The person may:

  • lodge an Article 77 complaint;
  • sue directly under Article 79;
  • seek urgent interim relief;
  • add an Article 82 compensation claim where appropriate.

The complaint and court claim may proceed concurrently.

Step 3: Choosing a Member State

The person may consider:

  • Belgium, based on habitual residence;
  • Ireland, based on a relevant defendant’s establishment;
  • France, if the French establishment supports the disputed processing.

The person should distinguish jurisdiction over each defendant rather than assuming that one entity’s establishment automatically creates jurisdiction over every other group company.

Step 4: Claims

The person may seek:

  • access;
  • cessation of advertising use;
  • erasure of the pregnancy inference;
  • objection compliance;
  • restriction of transfer;
  • declaration of unlawfulness;
  • compensation where damage is established.

Step 5: Evidence

The person provides:

  • screenshots;
  • advertisements;
  • correspondence;
  • access request;
  • privacy notice;
  • technical observations.

The defendants may be required to demonstrate:

  • lawful basis;
  • Article 9 condition;
  • consent records;
  • retention;
  • transfer safeguards;
  • role allocation;
  • security measures.

Step 6: Judicial relief

The court may:

  • grant interim protection;
  • order access;
  • prohibit specified processing;
  • require erasure;
  • award compensation under Article 82 if its requirements are met;
  • refer an unresolved EU-law question to the CJEU.

This example shows that Article 79 combines a substantive remedy with a claimant-friendly jurisdiction rule.


24. Corrections and qualifications to the supplied commentary

24.1 Article 79 should not be reduced to an overly rigid two-step test

The text requires non-compliant processing connected with infringement of the data subject’s GDPR rights. It should be interpreted in light of Article 47 to include procedural rights such as access and transparency.

24.2 The plaintiff need not prove processing fully before obtaining access to a court

A person may need Article 15 precisely to discover whether processing exists.

24.3 Organisational obligations are not automatically excluded

Failures concerning Articles 25, 30, 35 or 37 may support Article 79 relief where they materially affect the individual’s GDPR-protected position.

24.4 The controller’s main establishment is not the only possible jurisdictional connection

Article 79 uses “an establishment,” while the administrative one-stop-shop uses “main establishment.”

24.5 Not every unrelated minor office necessarily creates a sensible forum

The establishment must be genuine, and the relationship between the establishment, defendant and dispute may require careful analysis.

24.6 The habitual-residence forum is unavailable against a Member State public authority acting through public powers

But the exception should be assessed activity by activity.

24.7 Article 79 does not automatically award compensation

Compensation is governed by Article 82 and may be combined with Article 79 relief.

24.8 Parallel complaints cannot simply be dismissed

Articles 77 and 79 operate concurrently and independently, as confirmed by the CJEU in 2023 and again in 2026.

24.9 The GDPR does not necessarily exclude additional national actions

National law may permit competitors to challenge GDPR-related conduct as unfair commercial practices, as confirmed in Lindenapotheke.

24.10 Article 79 is a special jurisdiction rule, but other EU procedural instruments may still fill gaps

Recital 147 gives priority to specific GDPR rules, not a universal exclusion of Brussels I Recast from every connected procedural question.


Conclusion

Article 79 gives data subjects direct access to a court against controllers and processors whose processing allegedly violates their GDPR rights. The individual does not ordinarily have to:

  • complain to a supervisory authority first;
  • wait for a regulatory decision;
  • abandon an Article 77 complaint;
  • sue only in the defendant’s home state;
  • prove the complete internal processing structure before filing. The person must nevertheless present an arguable case that:
  • personal data relating to them are involved;
  • the processing is not GDPR-compliant;
  • their GDPR-protected legal position has been infringed. The Article is deliberately broad enough to protect:
  • classic Chapter III rights;
  • lawfulness;
  • fairness;
  • data minimisation;
  • security;
  • special-category protections;
  • transfer safeguards;
  • other obligations where their breach affects the data subject. The data subject generally has a jurisdictional choice between:
  1. the courts of a Member State where the controller or processor has a genuine establishment; or
  2. the courts of the Member State of the data subject’s habitual residence.

The second option does not apply against a Member State public authority acting through public powers.

The remedy must be effective in practice. National rules may govern procedure, costs, evidence and limitation periods, but they cannot make the EU right practically impossible or excessively difficult.

The core relationship among the GDPR remedies is:

Article 77 allows the person to ask a regulator to investigate. Article 78 allows judicial review of that regulator. Article 79 allows the person to proceed directly against the controller or processor. Article 82 addresses compensation.

The essential principle is therefore:

A controller’s or processor’s GDPR compliance is not enforceable only by regulators. The person whose data are affected has an independent right to place the alleged infringement before a court and seek practical, effective relief.