CHAPTER VIIIREMEDIES, LIABILITY AND PENALTIES

Article 80Representation of data subjects

Official text

(1)The data subject shall have the right to mandate a not-for-profit body, organisation or association which has been properly constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest, and is active in the field of the protection of data subjects’ rights and freedoms with regard to the protection of their personal data to lodge the complaint on his or her behalf, to exercise the rights referred to in Articles 77, 78 and 79 on his or her behalf, and to exercise the right to receive compensation referred to in Article 82 on his or her behalf where provided for by Member State law.

(2)Member States may provide that any body, organisation or association referred to in paragraph 1 of this Article, independently of a data subject’s mandate, has the right to lodge, in that Member State, a complaint with the supervisory authority which is competent pursuant to Article 77 and to exercise the rights referred to in Articles 78 and 79 if it considers that the rights of a data subject under this Regulation have been infringed as a result of the processing.

Commentary

Article 80 recognises that individuals often cannot enforce data protection rights effectively on their own. A person may lack legal knowledge, technical expertise, financial resources or the confidence needed to challenge a powerful platform, employer, bank or public authority. Article 80 therefore permits qualifying not-for-profit organisations to act on behalf of data subjects and, where national law allows, to act independently in the collective interest.

In the simplest terms:

A data subject may ask a suitable non-profit organisation to enforce GDPR rights for them. A Member State may also permit such an organisation to act without waiting for an individual mandate, but it cannot obtain compensation for an individual without that individual’s authority.

Article 80 creates two different models:

  1. Mandated representation under paragraph 1: a specific data subject authorises an organisation to act on their behalf.
  2. Independent representative action under paragraph 2: national law may permit the organisation to act without a mandate from a specific individual.

The distinction between these two models is the key to understanding the Article.


1. Why representative enforcement is necessary

Many GDPR infringements affect thousands or millions of people in the same way. Examples include:

  • manipulative cookie banners;
  • unlawful behavioural advertising;
  • undisclosed profiling;
  • biometric surveillance;
  • automated credit scoring;
  • unlawful employee monitoring;
  • large-scale data breaches;
  • unlawful international transfers;
  • opaque processing of children’s data.

For an individual, the cost and complexity of enforcement may be disproportionate to the immediate personal benefit.

Illustration

A mobile application unlawfully shares every user’s advertising identifier with several data brokers. Each user may suffer only a small or difficult-to-measure interference. Bringing an individual court case may require:

  • technical analysis of the application;
  • knowledge of advertising systems;
  • identification of multiple parties;
  • legal advice;
  • payment of court fees;
  • willingness to face litigation risk. Most users will do nothing, even though the processing affects millions of people. A specialised digital-rights organisation can:
  • investigate the application once;
  • obtain technical expertise;
  • prepare a coherent legal argument;
  • represent affected users;
  • seek an injunction capable of stopping the practice. Article 80 therefore addresses a structural enforcement problem. Rights written in legislation have little practical value if affected people cannot realistically enforce them.

2. Article 80 does not create one single form of collective action

It is important not to describe Article 80 simply as an EU class-action rule. It supports representation, but it does not by itself create one uniform European class-action procedure.

Paragraph 1 is based on an individual mandate. The organisation acts for the particular person who authorised it.

Paragraph 2 permits a broader public-interest model, but only if a Member State chooses to implement it. The organisation can then act without identifying or obtaining permission from a particular data subject.

The Article also distinguishes between:

  • complaints to supervisory authorities;
  • judicial review of supervisory authorities;
  • direct proceedings against controllers or processors;
  • claims for compensation.

The official text makes representation under Articles 77, 78 and 79 available under paragraph 1, while representation for Article 82 compensation depends on Member State law. Independent action under paragraph 2 covers Articles 77, 78 and 79, but does not include compensation under Article 82.


3. Paragraph 1 creates a directly recognised right to give a mandate

Article 80(1) begins:

“The data subject shall have the right to mandate…”

The word“shall” is significant. For complaints and remedies under Articles 77, 78 and 79, the GDPR itself recognises the data subject’s right to use a qualifying organisation.

Member States may regulate practical matters such as:

  • form of the mandate;
  • proof of authority;
  • court procedure;
  • signature requirements;
  • withdrawal of authority;
  • costs;
  • communication with the represented person.

However, national rules cannot make the right meaningless.

Illustration

A Member State cannot validly say: “A data subject may use Article 80 representation only if the controller agrees.” That would allow the defendant to defeat the statutory right. Similarly, a national rule requiring an expensive notarised mandate in every minor regulatory complaint may make representation excessively difficult, particularly if comparable domestic representation requires only a written authorisation. National rules remain subject to:

  • the principle of equivalence;
  • the principle of effectiveness;
  • Article 47 of the Charter;
  • the GDPR’s objective of effective protection.

4. Who may give the mandate?

The person giving the mandate must be a data subject.

That means an identified or identifiable natural person whose personal data are involved.

The person may be:

  • an adult;
  • a child acting through an appropriate representative;
  • an employee;
  • a consumer;
  • a patient;
  • a website user;
  • a job applicant;
  • a person affected by profiling;
  • a non-EU citizen whose processing falls within the GDPR.

A company is not itself a data subject.

Illustration

A small business alleges that a platform processed information about the company’s sales figures. The business cannot invoke Article 80 as a data subject merely because it is a legal person. However, the company’s owner may give a mandate if the processing concerns:

  • the owner’s personal financial position;
  • name;
  • communications;
  • professional reputation;
  • personal account information. The organisation must ensure that the mandate concerns the rights of an actual natural person.

5. Meaning and scope of the mandate

A mandate is an authorisation to act on another person’s behalf.

The scope may be broad or narrow.

Narrow mandate

“You may lodge an Article 77 complaint concerning the disclosure of my medical information.”

Broader mandate

“You may represent me before the supervisory authority, challenge its decision under Article 78, bring Article 79 proceedings and take necessary procedural steps concerning this processing.”

The mandate should be clear enough to establish:

  • the represented person;
  • the organisation;
  • the processing concerned;
  • the rights or proceedings covered;
  • whether settlement is permitted;
  • whether judicial proceedings are authorised;
  • whether compensation is included where national law permits;
  • how the mandate may be withdrawn.

A mandate to file a regulatory complaint should not automatically be interpreted as permission to settle a compensation claim or publish the person’s identity.


6. The mandate does not transfer ownership of the rights

Under paragraph 1, the organisation acts on behalf of the data subject.

The underlying rights remain those of the individual.

Illustration

A person authorises an organisation to pursue erasure of an unlawful medical profile. The organisation does not become the data subject. It exercises the person’s procedural rights as a representative. This has several consequences:

  • the individual remains the holder of the substantive right;
  • the organisation must act within the mandate;
  • the individual may usually withdraw the mandate;
  • the organisation should keep the person informed;
  • a settlement affecting the person should not exceed the authority given;
  • personal compensation belongs to the person, not the organisation. The representative may make professional procedural decisions, but it should not pursue objectives contrary to the represented person’s interests.

7. Which organisations qualify?

Article 80 does not permit any commercial claims business or interested person to act as a representative. It sets cumulative conditions.

The representative must be:

  1. a not-for-profit body, organisation or association;
  2. properly constituted under the law of a Member State;
  3. pursuing statutory objectives in the public interest;
  4. active in protecting data subjects’ rights and freedoms regarding personal data.

All these requirements matter.


8. The not-for-profit requirement

A qualifying organisation must not pursue profit-making objectives.

This does not mean that it must:

  • work without employees;
  • provide every service free;
  • have no income;
  • rely entirely on volunteers;
  • refuse donations;
  • avoid recovering legal costs.

A genuine non-profit organisation may charge reasonable fees, recover expenses or receive grants, provided that profits are not distributed to private owners or used as the organisation’s primary commercial objective.

Illustration

A digital-rights association charges €30 to cover administrative expenses for a complex complaint. That does not automatically destroy its not-for-profit status. Compare a company whose business model is:

  1. obtain claims from large numbers of people;
  2. litigate only high-value cases;
  3. retain 40 percent of every recovery;
  4. distribute profits to shareholders.

That entity is unlikely to qualify merely because it calls itself a privacy association.

8.1 Third-party funding

An organisation may receive external funding, but funding creates potential conflicts.

Illustration

A consumer association brings proceedings against Platform A while most of its funding comes from Platform A’s principal competitor. Questions may arise about:

  • independence;
  • commercial motivation;
  • litigation strategy;
  • settlement incentives;
  • whether the stated public-interest objective is genuine. Article 80 does not contain a detailed funding code. National law, professional rules and the Representative Actions Directive may impose additional transparency and conflict safeguards. The EU collective-redress framework requires qualified entities in cross-border consumer actions to be non-profit, independent, transparent about funding and protected against influence by market operators.

9. Proper constitution under Member State law

The body must be properly constituted in accordance with the law of an EU Member State.

This requirement ensures that the representative is a legally recognisable and accountable entity rather than an informal online group with no stable existence.

Evidence may include:

  • registration;
  • legal personality;
  • articles of association;
  • statutory rules;
  • governing documents;
  • authorised officers;
  • compliance with national organisational law.

Illustration

Several activists create a social-media account named “European Privacy Justice” but form no association, adopt no constitution and identify no responsible officeholders. The group may undertake advocacy or provide information. It may not satisfy Article 80’s requirement of a properly constituted body. By contrast, a legally registered consumer association with governing statutes and designated representatives may qualify.

9.1 Must the organisation be constituted in the claimant’s Member State?

The text requires constitution under the law of a Member State, not necessarily the same Member State in which the data subject lives.

Illustration

A Belgian data subject mandates a properly constituted Austrian digital-rights association to bring proceedings against a controller in Ireland. Article 80 does not automatically disqualify the association simply because it was established in Austria. However, national procedural rules may regulate:

  • standing;
  • representation before courts;
  • authorised legal professionals;
  • language;
  • cross-border recognition. Those rules must not nullify the right that Article 80 grants.

9.2 Non-EU organisations

An organisation formed only under the law of a third country does not satisfy the literal requirement of constitution under Member State law.

It may still:

  • support evidence gathering;
  • finance research;
  • cooperate with an EU organisation;
  • provide technical expertise.

But it cannot rely on Article 80 status unless it also has a qualifying entity properly constituted under relevant Member State law.


10. Statutory objectives in the public interest

The organisation’s founding documents must show objectives serving the public interest.

Examples

may include:

  • protecting privacy;
  • protecting consumers;
  • safeguarding children;
  • defending workers’ rights;
  • promoting digital rights;
  • protecting patients;
  • combating discrimination;
  • protecting civil liberties. The organisation need not necessarily be devoted exclusively to data protection.

Illustration

A consumer association’s statutes state that it protects consumers against unfair digital practices, including misuse of personal data. Its objectives may meet Article 80 even though consumer protection is broader than privacy. The CJEU confirmed inMeta Platforms Ireland, Case C-319/20, that a consumer protection association may have a qualifying public-interest objective connected with safeguarding data subjects in their capacity as consumers. The GDPR did not preclude the national representative action considered in that case.

10.1 The objective must be statutory, not invented for the case

An organisation should not amend its public description only after identifying profitable litigation.

Illustration

A sports club’s constitution concerns only organising local competitions. After a large breach, it states on its website that it now “protects privacy,” without amending its governing statutes or conducting relevant work. That is unlikely to satisfy the statutory-objective requirement. The court or authority should examine:

  • formal objectives;
  • actual activities;
  • history;
  • expertise;
  • organisational independence.

11. Active in protecting data subjects’ rights and freedoms

The representative must be active in the relevant field.

This requirement prevents dormant or opportunistic entities from relying on Article 80.

Relevant activities may include:

  • legal representation;
  • public education;
  • policy advocacy;
  • privacy research;
  • strategic litigation;
  • technical investigations;
  • complaint assistance;
  • support for affected communities;
  • publication of guidance.

Illustration

A disability-rights organisation investigates inaccessible automated systems that process disability data and assists affected persons with privacy complaints. It may qualify even though its primary public identity is disability rights rather than data protection, because its activities directly involve the protection of data subjects’ rights concerning their personal data. By contrast, a newly incorporated shell entity with no staff, expertise or history may have difficulty demonstrating that it is genuinely active in the field.

11.1 Exclusivity is not required

The organisation does not have to work only on data protection.

Consumer groups, trade unions, patient organisations and civil-liberties bodies may qualify where their work has a real connection with personal data protection.


12. Representation under Article 77

A qualifying organisation may lodge a complaint with a supervisory authority on behalf of the data subject.

It may:

  • prepare the complaint;
  • submit evidence;
  • communicate with the authority;
  • answer requests;
  • receive progress information;
  • make legal arguments;
  • participate within national procedural rules.

Illustration

An employee believes that an employer’s biometric system is unlawful. A workers’ rights association with relevant privacy expertise may:

  1. examine the system;
  2. collect the employee’s documents;
  3. identify Articles 5, 6, 9, 13, 25 and 35 issues;
  4. lodge the Article 77 complaint;
  5. communicate with the authority.

The complaint remains the employee’s complaint, pursued through the representative.

The authority may reasonably require proof of the mandate and may sometimes need direct confirmation of identity. It should not disregard the authorised organisation and communicate only with the individual without good reason.


13. Representation under Article 78

The organisation may exercise Article 78 rights on behalf of the data subject.

This includes challenging:

  • rejection of a complaint;
  • partial dismissal;
  • a binding decision concerning the data subject;
  • failure to handle the complaint;
  • failure to provide progress or outcome information within three months.

Illustration

The supervisory authority rejects a complaint about automated credit scoring without investigating the model. The mandated organisation may challenge that decision before the competent national court. Article 78 proceedings remain subject to:

  • national filing rules;
  • court deadlines;
  • legal representation requirements;
  • costs;
  • jurisdiction where the authority is established. Article 80 gives the organisation representative standing, but it does not eliminate every ordinary procedural requirement.

14. Representation under Article 79

The organisation may bring proceedings directly against the controller or processor on the individual’s behalf.

Possible relief may include:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • cessation of processing;
  • prohibition of disclosure;
  • compliance with an objection;
  • interim relief;
  • declaration of infringement.

Illustration

A platform intends to publish the person’s home address. The organisation may seek an urgent court injunction under Article 79 rather than waiting for a supervisory investigation. The relevant jurisdiction remains governed by Article 79(2), including:

  • a Member State where the defendant has an establishment; or
  • the Member State of the person’s habitual residence, subject to the public-authority exception. The organisation’s own registered office does not automatically create jurisdiction.

15. Compensation under Article 82 requires national permission

Article 80(1) treats compensation differently.

A data subject may mandate the organisation to exercise the Article 82 right to receive compensation“where provided for by Member State law.”

This means that Article 80 itself does not uniformly require every Member State to permit qualifying organisations to pursue compensation on behalf of represented individuals.

Illustration

An organisation is clearly authorised to lodge the person’s complaint and obtain an injunction. Whether it may also claim €5,000 in compensation for the person depends on the applicable Member State framework. This distinction reflects additional complexities surrounding monetary claims, including:

  • proof of damage;
  • distribution of awards;
  • settlement authority;
  • litigation funding;
  • assignment of claims;
  • multiple recovery;
  • individual consent.

15.1 Assignment is different from representation

National law may permit a person to assign a damages claim to an organisation or claims vehicle.

In that situation, the assignee may sue in its own name rather than acting as an Article 80 representative.

The arrangement must be assessed under:

  • national assignment law;
  • procedural law;
  • professional rules;
  • rules against abusive litigation;
  • Article 82 requirements.

Article 80 does not automatically validate every assignment or commercial claims-purchasing structure.


16. Paragraph 2: Independent action without a mandate

Article 80(2) permits Member States to authorise qualifying organisations to act independently, without permission from a specific data subject.

Unlike paragraph 1, paragraph 2 is optional. It begins:

“Member States may provide…”

Therefore:

  • the GDPR permits this model;
  • each Member State decides whether and how to implement it;
  • in a state that has not implemented it, Article 80(2) alone does not create independent standing.

Illustration

A children’s rights organisation discovers that an educational application profiles thousands of pupils. No parent has formally mandated the organisation. If national law implements Article 80(2), the organisation may be able to:

  • complain to the supervisory authority;
  • challenge the authority’s decision;
  • bring Article 79 proceedings. Without national implementation, it must generally obtain mandates or rely on another national cause of action.

17. No specific named data subject may be required

Independent actions often address processing practices that affect a class of people rather than one identified claimant.

In Meta Platforms Ireland, the CJEU held that Article 80(2) does not require the representative association to identify an individual data subject in advance where the processing is capable of affecting identifiable persons and the organisation has reasons to consider that GDPR rights have been infringed.

Illustration

A platform’s application centre provides users with misleading information about sharing data with third-party games. A consumer organisation may challenge the practice as affecting users as a class without naming one particular user in the originating action, where national law permits the representative route. But the case cannot be entirely abstract. The organisation must identify:

  • a real processing practice;
  • a category of affected data subjects;
  • GDPR rights that may be infringed;
  • a sufficient factual basis. A hypothetical concern about a product that does not yet exist would be insufficient.

18. Remedies available without a mandate

Paragraph 2 refers to:

  • an Article 77 complaint;
  • an Article 78 remedy;
  • an Article 79 remedy.

It does not include Article 82 compensation.

Recital 142 expressly states that an organisation may not claim compensation on a data subject’s behalf independently of a mandate.

Illustration

An organisation proves that a platform used unlawful tracking across one million accounts. Without individual mandates, it may be able to seek:

  • an injunction;
  • cessation;
  • regulatory investigation;
  • judicial review;
  • a declaration of infringement. It cannot under Article 80(2) collect one million personal compensation awards for unidentified individuals. Compensation requires a separate lawful basis, such as:
  • individual mandates;
  • national collective-redress rules;
  • a qualifying representative action under another EU or national framework;
  • lawful assignment.

19. Relationship with the Representative Actions Directive

Directive 2020/1828 requires Member States to maintain representative-action mechanisms through qualified entities for collective consumer interests. Its material scope includes data protection where infringements harm consumers, and it supports both injunctive and redress measures under the applicable legal framework.

Article 80 and the Directive overlap, but they are not identical.

Article 80 focuses specifically on:

  • GDPR rights;
  • qualifying not-for-profit bodies;
  • complaint and judicial remedies;
  • mandated and optional non-mandated representation.

The Directive focuses more broadly on:

  • collective consumer interests;
  • designated qualified entities;
  • domestic and cross-border representative actions;
  • injunctions;
  • redress;
  • funding and independence safeguards.

Illustration

A digital service unlawfully profiles consumers. A consumer organisation may potentially rely on:

  • Article 80 implementation;
  • national consumer-protection law;
  • the Representative Actions Directive’s national mechanism;
  • more than one legal basis. The court must determine which procedural framework applies and avoid:
  • double recovery;
  • conflicting representation;
  • duplicated proceedings;
  • abusive litigation.

20. Additional national actions remain possible

The GDPR’s enforcement routes are not necessarily exhaustive.

In Lindenapotheke, Case C-21/23, the CJEU held that the GDPR does not preclude national legislation allowing a competitor to challenge GDPR-related conduct as an unfair commercial practice. The case involved the processing of health data in online pharmacy transactions.

A competitor’s action is not the same as Article 80 representation.

Illustration

Pharmacy A sues Pharmacy B because Pharmacy B’s unlawful handling of customers’ health data gives it an unfair commercial advantage. Pharmacy A:

  • is not acting as the customers’ Article 80 representative;
  • may be using national unfair-competition law;
  • pursues its own commercial legal interest. The existence of such actions shows that Article 80 does not necessarily occupy the entire field of private GDPR enforcement.

21. Conflict of interest and loyalty to the data subject

A mandated organisation must act in the represented person’s interests and within the authority given.

Potential conflicts may arise where the organisation:

  • receives funding from a competitor;
  • seeks publicity contrary to the person’s wishes;
  • prefers a broad precedent over the person’s immediate remedy;
  • wants to settle on terms benefiting the organisation;
  • represents several individuals with incompatible objectives.

Illustration

A data subject wants immediate deletion of an embarrassing record. The organisation prefers to keep the record online temporarily to create a strategically useful test case. The organisation cannot sacrifice the individual’s interests merely because the case might advance its broader campaign. Good representation requires:

  • informed authority;
  • transparent funding;
  • communication;
  • confidentiality;
  • conflict checks;
  • clear settlement powers;
  • proper handling of personal data.

22. The representative becomes a data handler itself

An organisation acting under Article 80 may receive:

  • medical records;
  • employment files;
  • identity documents;
  • complaint correspondence;
  • financial information;
  • litigation evidence.

It must comply with data protection law in its own handling of that information.

Illustration

A privacy organisation collects health records from claimants to prepare a representative action. It should address:

  • lawful basis;
  • special-category condition;
  • security;
  • retention;
  • access control;
  • confidentiality;
  • onward sharing with lawyers and experts;
  • deletion when the case ends. An organisation cannot claim to protect privacy while handling represented persons’ data carelessly.

23. Withdrawal, settlement and continuation

Under paragraph 1, the data subject may normally withdraw the mandate, subject to procedural consequences under national law.

Illustration

A person settles with the controller and withdraws authority. The organisation may no longer represent that person in the mandated claim. However, the organisation might continue separately if:

  • national law implements Article 80(2);
  • it has another valid mandate;
  • it has standing under consumer law;
  • the supervisory authority continues an own-initiative investigation. The organisation should explain which legal capacity it is using. It should not claim to represent a person after the authority has been withdrawn.

24. Key grey areas

Several areas remain dependent on national law and case-specific interpretation.

First, Article 80 does not prescribe the exact form of a mandate. A Member State may require writing, but formalities must remain proportionate.

Second, the meaning of “active in the field” is factual. A court may examine real activity rather than accepting statutory wording alone.

Third, the Article does not fully regulate litigation funding, fee structures or conflicts. Other national and EU rules may apply.

Fourth, paragraph 2 is optional and therefore uneven across the EU. An organisation may possess independent standing in one Member State but not another.

Fifth, Article 80 does not itself establish a complete mass-compensation mechanism. Article 82 representation depends on national law, while non-mandated compensation is excluded under paragraph 2.

Sixth, several legal routes may overlap:

  • Article 80;
  • consumer collective redress;
  • unfair-competition law;
  • assignment of claims;
  • supervisory enforcement.

Courts must coordinate these routes without weakening effective GDPR protection.


25. Corrections and qualifications to the supplied commentary

The supplied commentary is broadly helpful, but several propositions need qualification.

The list of qualifying entities is not necessarily limited to incorporated private legal persons

The decisive requirement is that the body, organisation or association is properly constituted under Member State law and capable of performing the representative role. Its exact legal form depends on national law.

“Not-for-profit” does not mean free of charge

Reasonable cost recovery and funding are possible, provided the entity does not pursue profit distribution or commercial claims generation as its objective.

A general consumer or workers’ organisation does not qualify automatically

It must have statutory public-interest objectives and actual activity connected with data subjects’ rights and personal data protection.

Paragraph 2 requires national implementation

An entity cannot rely solely on Article 80(2) for independent standing where the relevant Member State has not enabled that route.

Paragraph 2 does not permit compensation without mandates

Its remedies stop at Articles 77, 78 and 79. Recital 142 confirms the exclusion of non-mandated compensation.

A specific named data subject is not invariably necessary under paragraph 2

The Meta Platforms Ireland judgment permits representative action concerning a category of affected persons where national law allows and the organisation identifies processing capable of infringing their rights.

Article 80 does not exclude other national enforcement actions

The Lindenapotheke judgment confirms that national law may permit competitor actions based on unfair commercial practices.

Collective redress and Article 80 are related but distinct

Directive 2020/1828 may provide additional consumer representative mechanisms, including redress, subject to its own qualification and procedural rules.


Conclusion

Article 80 strengthens GDPR enforcement by allowing individuals to use the expertise and resources of qualified public-interest organisations. Under paragraph 1, a data subject has the right to mandate a qualifying not-for-profit organisation to:

  • lodge an Article 77 complaint;
  • pursue Article 78 judicial review;
  • bring Article 79 proceedings;
  • pursue Article 82 compensation where Member State law permits. Under paragraph 2, a Member State may go further and allow the organisation to act independently, without a mandate, where it considers that data subject rights have been infringed by processing. That independent route may cover complaints and judicial remedies, but not personal compensation without a mandate. A qualifying organisation must be:
  • genuinely not-for-profit;
  • properly constituted under Member State law;
  • committed by its statutes to public-interest objectives;
  • genuinely active in protecting data subjects’ rights concerning personal data. The Article seeks to combine accessibility with safeguards. It opens enforcement to expert organisations but excludes purely commercial claims businesses from relying on Article 80 merely for profit. It allows collective protection but preserves individual control over personal compensation. The simplest summary is:

Paragraph 1 allows an individual to say, “Please enforce my GDPR rights for me.” Paragraph 2 may allow a qualifying organisation to say, “This practice threatens data subjects’ rights, so we will act even though no particular person has instructed us.” Only the first model, together with enabling national law, can support claiming an individual’s compensation on that person’s behalf.