Article 82 is the GDPR’s principal civil compensation provision. It answers six connected questions: when compensation is available, who may be liable, how controllers and processors may escape liability, what happens when several actors caused the same damage, how they divide liability among themselves, and where proceedings may be brought.
In the simplest terms:
A GDPR infringement does not automatically produce compensation. The claimant must show actual material or non-material damage caused by that infringement. Once those elements are established, the responsible controller or processor must compensate the damage fully, subject to the detailed liability rules in Article 82.
The CJEU has developed Article 82 considerably. The central principles now include:
- An infringement, damage and causation are three separate cumulative requirements.
- There is no minimum seriousness threshold for non-material damage.
- The claimant must nevertheless prove that some actual damage was suffered.
- Compensation is restorative, not punitive.
- Fear, anxiety, loss of control, reputational harm and uncertainty can qualify, but they must be real rather than invented or purely hypothetical.
- A controller cannot escape liability merely by blaming a hacker, employee or processor.
- Where several responsible actors are involved in the same processing, the claimant can normally recover the entire loss from any one of them.
- The actor that pays may later recover appropriate contributions from the others.
The Article’s official structure reflects these principles. Paragraph 1 creates the right to compensation, paragraph 2 allocates liability between controllers and processors, paragraph 3 provides a narrow exoneration defence, paragraphs 4 and 5 regulate multiple responsible actors, and paragraph 6 determines jurisdiction.