24.9 The GDPR does not necessarily exclude additional national actions
National law may permit competitors to challenge GDPR-related conduct as unfair commercial practices, as confirmed in Lindenapotheke.
24.10 Article 79 is a special jurisdiction rule, but other EU procedural instruments may still fill gaps
Recital 147 gives priority to specific GDPR rules, not a universal exclusion of Brussels I Recast from every connected procedural question.
Conclusion
Article 79 gives data subjects direct access to a court against controllers and processors whose processing allegedly violates their GDPR rights.
The individual does not ordinarily have to:
- complain to a supervisory authority first;
- wait for a regulatory decision;
- abandon an Article 77 complaint;
- sue only in the defendant’s home state;
- prove the complete internal processing structure before filing.
The person must nevertheless present an arguable case that:
- personal data relating to them are involved;
- the processing is not GDPR-compliant;
- their GDPR-protected legal position has been infringed.
The Article is deliberately broad enough to protect:
- classic Chapter III rights;
- lawfulness;
- fairness;
- data minimisation;
- security;
- special-category protections;
- transfer safeguards;
- other obligations where their breach affects the data subject.
The data subject generally has a jurisdictional choice between:
- the courts of a Member State where the controller or processor has a genuine establishment; or
- the courts of the Member State of the data subject’s habitual residence.
The second option does not apply against a Member State public authority acting through public powers.
The remedy must be effective in practice. National rules may govern procedure, costs, evidence and limitation periods, but they cannot make the EU right practically impossible or excessively difficult.
The core relationship among the GDPR remedies is:
Article 77 allows the person to ask a regulator to investigate. Article 78 allows judicial review of that regulator. Article 79 allows the person to proceed directly against the controller or processor. Article 82 addresses compensation.
The essential principle is therefore:
A controller’s or processor’s GDPR compliance is not enforceable only by regulators. The person whose data are affected has an independent right to place the alleged infringement before a court and seek practical, effective relief.