CHAPTER VIIIREMEDIES, LIABILITY AND PENALTIES

Article 82Right to compensation and liability

Official text

(1)Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.

(2)Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.

(3)A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.

(4)Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and where they are, under paragraphs 2 and 3, responsible for any damage caused by processing, each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject.

(5)Where a controller or processor has, in accordance with paragraph 4, paid full compensation for the damage suffered, that controller or processor shall be entitled to claim back from the other controllers or processors involved in the same processing that part of the compensation corresponding to their part of responsibility for the damage, in accordance with the conditions set out in paragraph 2.

(6)Court proceedings for exercising the right to receive compensation shall be brought before the courts competent under the law of the Member State referred to in Article 79 (2).

Commentary

Article 82 is the GDPR’s principal civil compensation provision. It answers six connected questions: when compensation is available, who may be liable, how controllers and processors may escape liability, what happens when several actors caused the same damage, how they divide liability among themselves, and where proceedings may be brought.

In the simplest terms:

A GDPR infringement does not automatically produce compensation. The claimant must show actual material or non-material damage caused by that infringement. Once those elements are established, the responsible controller or processor must compensate the damage fully, subject to the detailed liability rules in Article 82.

The CJEU has developed Article 82 considerably. The central principles now include:

  1. An infringement, damage and causation are three separate cumulative requirements.
  2. There is no minimum seriousness threshold for non-material damage.
  3. The claimant must nevertheless prove that some actual damage was suffered.
  4. Compensation is restorative, not punitive.
  5. Fear, anxiety, loss of control, reputational harm and uncertainty can qualify, but they must be real rather than invented or purely hypothetical.
  6. A controller cannot escape liability merely by blaming a hacker, employee or processor.
  7. Where several responsible actors are involved in the same processing, the claimant can normally recover the entire loss from any one of them.
  8. The actor that pays may later recover appropriate contributions from the others.

The Article’s official structure reflects these principles. Paragraph 1 creates the right to compensation, paragraph 2 allocates liability between controllers and processors, paragraph 3 provides a narrow exoneration defence, paragraphs 4 and 5 regulate multiple responsible actors, and paragraph 6 determines jurisdiction.


1. The purpose of Article 82

Article 82 is meant to compensate, not to punish.

This distinction is fundamental. Administrative fines under Article 83 are imposed to punish and deter unlawful conduct. Compensation under Article 82 is paid to restore, as fully as money or another recognised remedy can, the person who actually suffered damage.

Illustration

A company deliberately sells medical information without a lawful basis. The supervisory authority may impose a substantial fine because the conduct was intentional and serious. The affected person may separately claim compensation for:

  • financial loss;
  • reputational harm;
  • distress;
  • loss of control;
  • other proven consequences. The compensation amount is not automatically increased merely to punish the company. Its amount should correspond to the damage actually suffered. The CJEU confirmed in Scalable Capital that Article 82 has an exclusively compensatory function. The seriousness or intentional character of the infringement is not itself a basis for increasing compensation beyond the actual damage. This does not mean that the circumstances of the infringement are irrelevant. They may affect the nature or intensity of the claimant’s harm.

Illustration

Two persons’ addresses are disclosed.

  • In the first case, one address is accidentally seen by a trusted employee for a few minutes.
  • In the second, the address of a person escaping domestic violence is deliberately published online. The second person may suffer substantially greater fear and disruption. The larger award would compensate that greater harm, not punish the controller for being more morally blameworthy.

2. Article 82(1): The three cumulative requirements

The CJEU’s foundational judgment in Österreichische Post, Case C-300/21, established that an Article 82 claim requires three cumulative elements:

  1. an infringement of the GDPR;
  2. material or non-material damage;
  3. a causal link between the infringement and the damage.

An infringement without damage is insufficient. Damage unconnected with a GDPR infringement is also insufficient.

A useful formula is:

GDPR infringement + actual damage + causal connection = potential Article 82 compensation

Each part must be examined separately.


3. The first requirement: an infringement of the GDPR

Article 82 is not confined to any particular GDPR chapter.

The infringement may concern:

  • Article 5 processing principles;
  • lack of lawful basis under Article 6;
  • special-category data under Article 9;
  • criminal-offence information under Article 10;
  • transparency under Articles 12 to 14;
  • access under Article 15;
  • rectification, erasure or restriction;
  • objection or automated decision-making;
  • security under Article 32;
  • breach notification;
  • international transfers;
  • privacy by design and default;
  • processor obligations;
  • another rule whose breach caused compensable damage.

Recital 146 also explains that infringing processing includes violations of delegated or implementing acts adopted under the GDPR and Member State laws that specify GDPR rules. The concept is therefore broader than refusal of a classic Chapter III request.

Illustration

A hospital processes a patient’s medical information without satisfying Article 9. If that unlawful processing causes loss, distress or reputational harm, Article 82 may apply.

Illustration

A controller lawfully collected an individual’s data but ignored a valid erasure request after the retention purpose expired. If continued retention caused actual damage, the infringement may support compensation.

3.1 An infringement does not require a regulatory decision first

The claimant does not necessarily need:

  • a supervisory-authority finding;
  • an administrative fine;
  • a completed Article 77 complaint;
  • a prior Article 79 judgment.

The civil court hearing the compensation claim may determine whether the GDPR was infringed.

Illustration

A recipient mistakenly receives a claimant’s tax return. The claimant may bring an Article 82 action for the resulting damage even if no supervisory authority has investigated the incident. A supervisory decision may be useful evidence, but Article 82 does not make it a mandatory precondition.

3.2 Personal data breach does not automatically prove infringement

A personal data breach is not, by itself, conclusive proof that the controller violated Article 32.

Article 32 requires security measures appropriate to risk. It does not guarantee that every attack will be successfully prevented.

In Natsionalna agentsia za prihodite, the CJEU held that the occurrence of a cyberattack and unauthorised disclosure does not automatically prove that the controller’s security measures were inappropriate. The national court must conduct a concrete assessment, while the controller bears the burden of showing that the measures it implemented were appropriate.

Illustration

A sophisticated attacker defeats a carefully designed security system that included:

  • strong encryption;
  • multi-factor authentication;
  • patch management;
  • tested incident response;
  • access controls;
  • monitoring. The breach alone does not establish an Article 32 infringement. Compare a controller that:
  • used default passwords;
  • ignored known vulnerabilities;
  • stored sensitive data unencrypted;
  • gave every employee unrestricted access;
  • had no security testing. The breach is then much more likely to reflect inadequate measures.

4. Rights infringements that do not look like “processing”

A technical issue arises because Article 82(2) refers to damage caused by processing that infringes the GDPR. Some violations arise when a controller fails to act rather than when it positively collects, stores or discloses information.

Examples

include:

  • ignoring an access request;
  • refusing rectification;
  • failing to provide confirmation whether data are processed;
  • failing to act on a restriction request;
  • refusing portability. In Brillen Rottler, Case C-526/24, decided on 19 March 2026, the CJEU recognised that Chapter III infringements may result from refusal to act on a request rather than from a particular underlying processing operation. Interpreting Article 82 so narrowly that such infringements could never lead to compensation would undermine its effectiveness.

[!example] Illustration A person asks a former employer whether disciplinary information is still retained. The employer unlawfully refuses to answer. The person experiences proven anxiety and uncertainty because they cannot determine whether the record is being disclosed to prospective employers. It would be artificial to say that Article 82 can never apply because the immediate wrong is a failure to respond. The refusal concerns the employer’s handling of personal data and the person’s right to control or understand that handling.

5. The second requirement: actual damage

The claimant must establish damage distinct from the infringement itself.

This is the most important limit on Article 82.

Illustration

A privacy notice omitted a technical detail for one day. No one relied on the omission, no rights exercise was obstructed and no claimant suffered any financial, emotional or practical consequence. There may have been a GDPR infringement, but compensation does not automatically follow. The CJEU has repeatedly rejected the proposition that every infringement is itself compensable damage.Österreichische Post, MediaMarktSaturn, Gemeinde Ummendorf and PTAC all confirm that actual damage must be established independently.

5.1 “No automatic compensation” does not mean “serious harm only”

Two propositions must be kept separate:

  • mere infringement is insufficient;
  • no minimum seriousness threshold may be imposed.

A claimant must prove some damage, but it does not need to cross a nationally invented threshold such as:

  • serious distress;
  • medically recognised illness;
  • substantial inconvenience;
  • major reputational injury;
  • measurable financial loss.

In Österreichische Post, the Court held that a national rule requiring non-material damage to reach a certain degree of seriousness is incompatible with Article 82. Gemeinde Ummendorf reaffirmed that result.

The correct distinction is:

  • No damage: no compensation.
  • Small but genuine damage: compensation may be available.
  • Serious damage: compensation should reflect the greater harm.

6. Material damage

Material damage is economic or financially measurable loss.

It may include:

  • money stolen following identity fraud;
  • expenses incurred to restore accounts;
  • credit-monitoring costs where reasonably necessary;
  • loss of employment;
  • denial of credit;
  • increased borrowing costs;
  • lost business;
  • costs of correcting inaccurate records;
  • lost income;
  • reasonable expenses incurred in mitigating harm.

Illustration: identity fraud

A data breach reveals a person’s bank and identification details. A fraudster obtains a loan in the person’s name. Potential material damage may include:

  • unauthorised debits;
  • professional costs required to challenge the loan;
  • reasonable expenses for replacing documents;
  • additional interest caused by damaged credit;
  • lost working time, where recoverable and proved. The claimant must show that these losses were caused by the GDPR infringement.

6.1 Reasonable mitigation costs

A person should generally take proportionate steps to reduce foreseeable loss.

Illustration

After payment-card data are leaked, the person promptly cancels the card and pays a reasonable replacement fee. That cost may be recoverable if it was a reasonable response to the risk created. But if the person spends an unreasonable amount on unrelated services with no evidence of necessity, the court may find that some expenditure was not caused by the infringement or was not reasonably incurred.

6.2 Future material loss

Future loss may be recoverable where it is sufficiently established rather than speculative.

[!example] Illustration An unlawful health disclosure causes a signed employment offer to be withdrawn. The claimant may be able to prove expected salary loss. By contrast: “A future employer might somehow see the data and might pay me less someday” may be too uncertain without supporting evidence.

7. Non-material damage

Non-material damage concerns harm that is not directly economic.

It may include:

  • distress;
  • fear;
  • humiliation;
  • loss of control;
  • reputational harm;
  • anxiety about misuse;
  • exposure of intimate information;
  • uncertainty about how data are being used;
  • discrimination-related harm;
  • restriction of personal autonomy;
  • social disadvantage.

Recitals 75 and 85 identify examples such as discrimination, identity theft, fraud, reputational damage, loss of confidentiality, loss of control and significant social disadvantage. These examples guide interpretation but do not turn every listed risk into automatically proved damage.

7.1 Emotional harm does not require medical illness

A claimant should not necessarily have to prove:

  • psychiatric diagnosis;
  • clinical treatment;
  • medication;
  • inability to work.

Ordinary but genuine fear, distress or uncertainty may qualify.

However, the court must be satisfied that the experience was real and caused by the infringement.

Illustration

A fertility clinic sends treatment information to the claimant’s employer. The claimant experiences:

  • humiliation;
  • fear of workplace gossip;
  • altered treatment by colleagues;
  • anxiety about career consequences. Those consequences may constitute non-material damage without a psychiatric diagnosis.

8. Loss of control over personal data

Loss of control is a particularly important form of potential non-material damage.

A person may lose control when data are:

  • disclosed to an unauthorised recipient;
  • published online;
  • stolen;
  • transferred unlawfully;
  • retained against their wishes;
  • used for an unexpected purpose;
  • made inaccessible to the person;
  • processed without adequate information.

The CJEU has recognised that loss of control, even for a short period, may constitute non-material damage, provided the claimant shows that actual damage was suffered.

Illustration

A municipality publishes the person’s name and home address online for three days. Even if the page is later removed and no fraud occurs, the person may have experienced:

  • inability to know who accessed it;
  • loss of control over further copying;
  • fear about future use;
  • upset caused by public exposure. If those consequences are demonstrated, compensation may be available.

8.1 Loss of control is not an automatic formula

A claimant cannot merely repeat the phrase “loss of control” without explaining what occurred.

Useful facts include:

  • which data were involved;
  • who received them;
  • duration;
  • sensitivity;
  • whether online copying was possible;
  • whether the recipient was known;
  • whether the data could be changed;
  • steps taken to regain control;
  • practical and emotional consequences.

A temporarily misplaced document recovered unopened may produce a different assessment from permanent exposure of health data on the internet.


9. Fear of future misuse

Fear that stolen or disclosed data may be misused can itself be non-material damage. Actual fraud is not always necessary.

In Natsionalna agentsia za prihodite, the CJEU held that fear of possible future misuse following a cyberattack can qualify, provided the national court verifies that the fear is well founded in the particular circumstances.

In PS (Incorrect address), the Court held that fear that data may have been disclosed can qualify even where actual disclosure cannot be conclusively established, provided the fear and its negative consequences are duly proved.

Illustration: well-founded fear

A breach exposes:

  • passport number;
  • bank information;
  • tax identifier;
  • home address;
  • date of birth. The claimant receives targeted phishing messages referring to those details and becomes reasonably concerned about identity fraud. That fear is concrete and contextually supported.

[!example] Illustration: purely hypothetical fear A paper containing only the claimant’s first name is handed to the wrong person and immediately recovered unopened. The claimant asserts that international criminals may now steal their identity, without explaining how this could occur. A court may conclude that the alleged fear is not sufficiently established.

10. MediaMarktSaturn and purely hypothetical risk

In MediaMarktSaturn, a customer’s purchase documents were accidentally given to another customer but quickly recovered. There was no evidence that the information had been used. The CJEU reiterated that the claimant must establish actual damage rather than relying solely on the infringement.

The case illustrates an important distinction:

A risk may generate genuine compensable fear, but a remote or purely hypothetical risk does not automatically do so.

Courts should examine:

  • duration of unauthorised possession;
  • recipient’s conduct;
  • whether data were viewed or copied;
  • sensitivity;
  • steps taken to recover the information;
  • evidence of fear and consequences.

The same technical incident may affect different persons differently. A minor disclosure may be particularly serious for a protected witness or abuse survivor.


11. Identity theft and theft of personal data

The Scalable Capital judgment distinguishes between:

  • theft of personal data;
  • identity theft or identity fraud.

A third party merely obtaining data is not necessarily “identity theft.” Identity theft generally requires actual use of the data to impersonate the person. But compensation is not confined to cases of completed identity theft. Data theft can cause other non-material harm, including fear and loss of control.

Illustration

A hacker steals a copy of the claimant’s passport. If the hacker never uses it, there may be data theft but no completed identity theft. The claimant may still recover for proven:

  • fear;
  • loss of control;
  • replacement-document expenses;
  • disruption;
  • monitoring burden. If the hacker opens accounts in the claimant’s name, completed identity fraud creates additional material and non-material damage.

12. Reputational damage

Reputational damage may occur where unlawful processing causes others to form an adverse view of the person.

Illustration

An algorithm incorrectly labels someone as:

  • dishonest;
  • politically extremist;
  • financially unreliable;
  • medically unfit;
  • likely to commit fraud. If that label is disclosed or used in decision-making, the person may suffer:
  • refusal of services;
  • workplace stigma;
  • loss of social standing;
  • humiliation;
  • professional loss. Evidence may include:
  • messages from recipients;
  • withdrawal of opportunities;
  • online publication statistics;
  • witness testimony;
  • changed treatment by others. The claimant need not always prove widespread public exposure. Disclosure to one highly relevant recipient, such as an employer or licensing authority, may have substantial impact.

13. Confidential professional information

Loss of confidentiality may be especially harmful where the information is protected by professional secrecy, such as:

  • medical records;
  • lawyer-client communications;
  • tax documents;
  • social-work records;
  • counselling notes;
  • religious information.

Illustration

A tax adviser sends a family’s tax return to their old address. The documents contain:

  • bank details;
  • disability status;
  • religious affiliation;
  • children’s details;
  • income information. The sensitivity and concentration of the data may support a credible claim of fear, loss of control and distress. The CJEU’s PS judgment arose from this type of incorrect-address incident.

14. Quantifying non-material damage

The GDPR does not contain a mathematical tariff for distress, fear or loss of control.

National courts apply domestic rules for quantifying compensation, subject to:

  • equivalence;
  • effectiveness;
  • full compensation;
  • the autonomous EU meaning of damage.

The CJEU confirmed in Österreichische Post that Member States determine the detailed assessment criteria because the GDPR contains no specific calculation method.

Relevant factors may include:

  • sensitivity of the data;
  • duration;
  • number and identity of recipients;
  • scale of disclosure;
  • recoverability;
  • actual misuse;
  • effect on daily life;
  • intensity and duration of distress;
  • reasonable mitigation efforts;
  • consequences for reputation or relationships;
  • whether the information was already public;
  • age and vulnerability of the claimant.

14.1 Small damage may justify a small award

The absence of a seriousness threshold does not mean every award must be large.

In Scalable Capital, the CJEU explained that minimal compensation may be appropriate for non-serious damage, provided it fully compensates the actual harm.

The correct rule is not:

“Small harm gets nothing.”

It is:

“Small harm may receive a small amount, but the amount must genuinely compensate it.”

14.2 Courts must not award symbolic compensation where it is inadequate

A nominal award cannot be used to trivialise serious harm.

[!example] Illustration Publishing a survivor’s protected address causes relocation, prolonged fear and disruption. A token amount would not constitute full and effective compensation.

15. Non-monetary compensation and apologies

Compensation does not necessarily have to consist solely of money if national law recognises another form capable of fully repairing the harm.

In PTAC, Case C-507/23, the CJEU held that an apology may constitute sufficient compensation for non-material damage, including where restoration of the prior situation is impossible, provided the apology compensates the damage in full.

Illustration

A public authority uses a journalist’s identity in a campaign without permission and damages the journalist’s reputation. An effective public apology:

  • on the same channels;
  • with comparable prominence;
  • clearly acknowledging the error;
  • correcting the false impression may repair some or all of the reputational harm. But an apology would not be sufficient if the claimant also suffered:
  • financial loss;
  • continuing serious distress;
  • loss of employment;
  • ongoing exposure. The adequacy of non-monetary redress depends on the particular damage.

16. No punitive damages under Article 82

Article 82 does not authorise damages exceeding the actual harm merely to:

  • punish the controller;
  • deter the industry;
  • express moral condemnation;
  • mirror an Article 83 fine.

In Scalable Capital and PTAC, the Court emphasised the exclusively compensatory nature of Article 82.

Illustration

Two controllers cause identical harm to two claimants.

  • One controller acted negligently.
  • The other acted deliberately. If both claimants suffered the same actual damage, Article 82 does not automatically require a higher payment from the deliberate wrongdoer simply as punishment. Intent may matter under:
  • Article 83 fines;
  • national penalties;
  • costs;
  • another lawful cause of action. But Article 82 itself is directed toward repair.

17. The number of infringements does not multiply compensation automatically

One processing operation may violate several GDPR provisions.

Illustration

A controller:

  • has no Article 6 lawful basis;
  • violates Article 5 fairness;
  • fails to provide Article 13 information;
  • ignores an Article 21 objection. The claimant does not automatically receive four separate compensation awards for one undivided injury. In juris, the CJEU addressed multiple infringements and confirmed that Article 83 fine criteria do not determine Article 82 compensation. The court should compensate actual damage rather than mechanically multiplying the amount by the number of legal provisions infringed. Multiple infringements may nevertheless cause separate harms.

[!example] Illustration An unlawful marketing campaign causes annoyance, while a separate disclosure causes reputational damage and financial loss. The court should identify each actual harm while avoiding double recovery for the same consequence.

The claimant must show that the GDPR infringement caused the damage.

The infringement need not always be the only factual event involved, but the claimed loss must be sufficiently attributable to it.

Illustration

A controller discloses an individual’s credit data to a fraudster. The fraudster uses it to obtain a loan in the individual’s name. The causal chain is:

  1. unlawful disclosure;
  2. fraud enabled by the disclosure;
  3. financial and emotional damage.

Broken or weak causal connection

A company sends one unwanted marketing email. The recipient later loses employment for unrelated reasons and claims a year’s salary.

Unless the email somehow caused that loss, Article 82 cannot support it.

18.1 Conduct of the claimant

A claimant’s own voluntary conduct may, in exceptional circumstances, break causation if it is the determining cause of the damage.

The 2026 Brillen Rottler judgment recognised that a claimant’s conduct may break the causal link where that conduct was the determining cause and the person was not obliged to act that way.

[!example] Illustration A person deliberately publishes their own previously undisclosed data to create publicity and then attributes the resulting exposure entirely to an earlier private technical error. The court must identify the actual determining cause of the claimed harm. This should be applied carefully. A claimant does not break causation merely by taking reasonable steps to protect themselves or enforce their rights.

19. Burden of proof

The burdens are divided.

Typically, the claimant must establish:

  1. an infringement;
  2. actual damage;
  3. causation.

The controller or processor bears the paragraph 3 burden of proving that it was not in any way responsible for the event giving rise to the damage.

Accountability may also affect evidence. A controller must be able to demonstrate compliance with the principles under Article 5(2), and security obligations place significant compliance evidence within the controller’s possession.

Illustration

The claimant cannot see the defendant’s internal security architecture. The claimant establishes:

  • personal data were held;
  • the data were stolen;
  • subsequent targeted misuse occurred. The controller may need to produce evidence concerning:
  • risk assessments;
  • access controls;
  • encryption;
  • patching;
  • monitoring;
  • incident response. In Natsionalna agentsia, the CJEU held that the controller bears the burden of proving that the security measures were appropriate.

19.1 Damage must not simply be presumed

The claimant should explain the harm.

Evidence for non-material damage may include:

  • personal testimony;
  • contemporaneous correspondence;
  • altered behaviour;
  • account closures;
  • document replacement;
  • medical evidence where available;
  • suspicious contacts;
  • witness evidence;
  • time spent resolving consequences.

A medical report can strengthen a serious distress claim but is not always legally necessary.


20. Who may claim? Meaning of “any person”

Article 82(1) uses “any person,” while paragraph 4 refers to effective compensation of the data subject.

Most Article 82 litigation concerns natural persons whose personal data were processed.

The phrase “any person” is broader than “every data subject” used in Articles 77 and 79. It may support a claim by someone who suffered legally relevant damage from infringing processing even if that person’s own data were not the direct object of the processing.

Illustration

A controller unlawfully discloses a child’s medical condition. The disclosure causes the parent direct financial loss because the parent must relocate the family urgently. Whether the parent can claim under Article 82 for their own loss will depend on interpretation of:

  • “any person”;
  • the scope of the infringement;
  • causation;
  • the purpose of the GDPR;
  • applicable national procedure.

Whether “any person” includes a company claiming its own corporate damage remains contested.

The GDPR’s primary purpose is to protect natural persons in relation to personal data. A company is not a data subject. Therefore, a legal person should not automatically be assumed to have an Article 82 claim merely because unlawful personal-data processing caused it economic loss.

A company may instead rely on:

  • contract;
  • tort;
  • trade-secret law;
  • unfair competition;
  • another national or EU cause of action.

The question should be treated cautiously rather than asserting categorically that all legal persons are either included or excluded.


21. From whom may compensation be claimed?

Article 82 identifies:

  • controllers;
  • processors.

The claimant must identify the defendant’s actual role.

A controller determines purposes and essential means. A processor acts on behalf of a controller.

A single actor may be:

  • controller for one processing operation;
  • processor for another;
  • joint controller for another.

[!example] Illustration A payroll company receives employee data to calculate wages under the employer’s instructions. For payroll calculation, it may be a processor. If it independently uses the information to sell financial products, it becomes a controller for that own-purpose use. Liability must be assessed operation by operation.

22. Article 82(2): Controller liability

A controller involved in processing is liable for damage caused by processing that infringes the GDPR, subject to the paragraph 3 defence.

The word “involved” prevents automatic liability for every controller loosely connected with a commercial ecosystem. The controller must be involved in the processing relevant to the infringement and damage.

Illustration

A hotel independently determines how guest records are collected and retained. Its payment provider separately determines fraud screening for its own regulatory purposes. If the damage arose from the hotel’s indefinite retention, the payment provider is not automatically liable merely because it processed related payment information.

22.1 Joint controllers

Joint controllers determine purposes and means through common or converging decisions.

Where joint controllers are involved in the same damaging processing, Articles 82(2), (4) and (5) may produce full external liability, followed by internal contribution.

Their Article 26 arrangement cannot deprive the claimant of Article 82 protection.

Illustration

Two companies jointly design a loyalty platform and decide:

  • data categories;
  • profiling purposes;
  • recipients;
  • retention. Their contract says Company A handles transparency and Company B handles security. If insecure architecture causes a breach, an affected person is not necessarily required to navigate their private allocation and recover only small portions from each. Article 82(4) protects full recovery, assuming the liability conditions are satisfied.

23. Processor liability is narrower

A processor is not liable under paragraph 2 for every controller infringement.

It is liable where:

  1. it failed to comply with GDPR obligations specifically directed to processors; or
  2. it acted outside or contrary to lawful controller instructions.

Processor-specific obligations may include:

  • Article 28 requirements;
  • confidentiality of authorised persons;
  • subprocessor controls;
  • assistance obligations;
  • deletion or return of data;
  • audit cooperation;
  • security under Article 32;
  • breach notification to the controller;
  • records under Article 30(2);
  • transfer obligations where applicable.

Illustration

A controller instructs a hosting provider to store encrypted records in the EU. The provider:

  • disables encryption;
  • transfers the records elsewhere;
  • appoints an unauthorised subprocessor;
  • suffers a breach. The processor may be liable because it violated direct obligations and acted contrary to lawful instructions.

23.1 Unlawful instructions

A processor is not protected merely by saying:

“The controller told us to do it.”

Article 82(2) refers to acting outside or contrary to lawful instructions.

A processor must inform the controller where an instruction infringes the GDPR or other applicable data protection law under Article 28.

Illustration

A controller instructs a processor to sell patient records for advertising without a lawful basis. The processor cannot treat the unlawfulness as a complete defence merely because the direction was documented.

23.2 Processor becomes controller

Under Article 28(10), a processor that determines purposes and means in violation of the GDPR is treated as a controller for that processing.

[!example] Illustration A cloud provider receives customer records for storage but independently mines them to train its own commercial model. For the training activity, the provider may be treated as controller and subject to controller liability.

24. Article 82(3): The exoneration defence

A controller or processor is exempt if it proves that it is“not in any way responsible” for the event giving rise to the damage.

This is a narrow defence.

The defendant bears the burden of proof.

It is not enough to show:

  • the breach was accidental;
  • an employee made the mistake;
  • a processor handled the system;
  • a hacker committed the attack;
  • the defendant did not intend harm;
  • written policies existed.

The defendant must demonstrate absence of responsibility for the damaging event.

24.1 Not absolute strict liability

Article 82 is not simply automatic liability whenever:

  • an infringement;
  • damage;
  • causation

exist.

Paragraph 3 expressly permits exoneration.

But it is also not an ordinary system in which the claimant must prove every aspect of the defendant’s fault. Responsibility is presumed unless the defendant proves the statutory exemption.

The CJEU’s case law describes a liability regime based on responsibility, with the defendant carrying the exoneration burden.


25. Employee mistakes

A controller cannot escape liability merely by saying that an employee disobeyed internal instructions.

In juris, the CJEU held that a controller is not exempted simply because a person acting under its authority failed to comply with instructions. Controllers must organise, train and supervise staff appropriately.

Illustration

A marketing employee ignores a recorded objection and sends another campaign. The company cannot simply respond: “Our policy was correct; the employee made a mistake.” Relevant questions include:

  • Were systems designed to enforce objections?
  • Was access restricted?
  • Was training effective?
  • Were checks in place?
  • Was the error foreseeable?
  • Did the controller respond properly? Paragraph 3 requires more than producing a policy manual.

26. Cyberattacks and criminal third parties

A controller is not automatically exempt because a criminal attacker caused the immediate disclosure.

In Natsionalna agentsia, the CJEU held that third-party unauthorised access does not by itself relieve the controller. The controller must prove that it was not in any way responsible.

[!example] Illustration A hacker exploits a vulnerability that the controller knew about and left unpatched. The criminal act does not break the controller’s responsibility. Compare an unprecedented attack defeating measures that were properly selected, maintained and monitored. The controller may have a stronger paragraph 3 defence, though the assessment remains factual. The important principle is: A third party’s wrongdoing is relevant, but it is not an automatic liability shield.

27. Compliance with Article 32 does not guarantee exoneration from every claim

A controller may demonstrate appropriate security under Article 32 yet face a different GDPR infringement.

Illustration

A database is technically secure, but the controller had no lawful basis to collect the information. Strong encryption does not remedy unlawful collection. Conversely, a breach does not automatically prove inadequate security. Courts must identify:

  • which provision was violated;
  • how the event occurred;
  • which obligation applied;
  • what caused the damage.

28. Article 82(4): Multiple responsible actors

Paragraph 4 addresses situations where:

  • multiple controllers;
  • multiple processors;
  • or controllers and processors

are involved in the same processing and are responsible under paragraphs 2 and 3.

Each may be held liable for the entire damage to ensure effective compensation.

This is joint-and-several style liability.

Illustration

A retailer, analytics company and cloud processor are involved in one profiling system. Their combined failures cause a database leak. The claimant suffers €10,000 in compensable damage. If the paragraph 4 conditions are satisfied, the claimant may seek the entire €10,000 from one responsible actor instead of proving:

  • retailer caused 40 percent;
  • analytics company caused 35 percent;
  • processor caused 25 percent. The burden of internal allocation is shifted away from the injured individual.

29. Paragraph 4 does not make every participant automatically liable

Before full liability applies, each defendant must satisfy the relevant conditions under paragraphs 2 and 3.

For a controller, this requires involvement in relevant infringing processing and responsibility.

For a processor, it requires:

  • breach of processor-specific GDPR duties; or
  • action outside or contrary to lawful instructions;

together with the rest of the liability requirements.

Illustration

A processor securely stored one unrelated dataset but had no involvement in the processing that caused the claimant’s harm. Paragraph 4 does not make it liable merely because it provided another service to the same controller. The phrase“same processing” matters. Courts should examine whether the actors participated in:

  • the same operation;
  • an interconnected set of operations;
  • the damaging data flow;
  • a common processing system.

30. What counts as the same processing?

The GDPR defines processing broadly and includes individual operations or sets of operations.

Illustration

A customer profile moves through:

  1. collection by a retailer;
  2. enrichment by an analytics provider;
  3. storage by a cloud processor;
  4. advertising disclosure by a marketing partner.

These stages may form one connected processing chain for Article 82(4).

Compare a payroll processor handling employee salaries and an unrelated marketing provider handling customer preferences. Their activities are probably not the same processing merely because the same corporate group hired both.

The analysis should focus on:

  • shared data;
  • common purpose;
  • operational connection;
  • causal contribution;
  • role in the damage.

31. The claimant is entitled to one full recovery, not several full recoveries

Paragraph 4 protects full compensation, not overcompensation.

If the total damage is €10,000, the claimant cannot recover:

  • €10,000 from Controller A;
  • another €10,000 from Controller B;
  • another €10,000 from Processor C

for the same injury.

Payments must be credited against the total loss.

Illustration

Controller A pays the full court-awarded amount. The claimant’s loss has been compensated. The remaining dispute is between A and the other responsible parties under paragraph 5. This distinction separates:

  • the external relationship with the injured person;
  • the internal contribution relationship among defendants.

32. Why full external liability exists

The claimant may have no practical way to determine each defendant’s percentage of responsibility.

Evidence about:

  • system design;
  • contracts;
  • security controls;
  • internal instructions;
  • subprocessor conduct;
  • data flows

is usually held by the defendants.

Requiring the claimant to allocate precise shares could make compensation impossible.

Recital 146 therefore emphasises full and effective compensation and permits internal apportionment without weakening the claimant’s recovery.

[!example] Illustration A hospital blames the hosting provider. The hosting provider blames a subprocessor. The subprocessor blames the hospital’s settings. The patient should not be trapped indefinitely between these arguments. Paragraph 4 permits recovery from a qualifying responsible actor, leaving the defendants to resolve contribution later.

33. Article 82(5): Internal contribution

A controller or processor that has paid full compensation may recover from other responsible actors the portion corresponding to their responsibility.

This is a recourse or contribution claim.

Illustration

A controller pays the claimant €100,000. The court later determines internal responsibility as:

  • controller: 50 percent;
  • processor: 30 percent;
  • joint controller: 20 percent. The paying controller may seek:
  • €30,000 from the processor;
  • €20,000 from the joint controller. The claimant keeps the full €100,000 and is not required to participate in the defendants’ internal dispute unless procedural law requires limited involvement.

34. Factors relevant to internal allocation

The GDPR does not provide a complete allocation formula.

Relevant factors may include:

  • actual decision-making power;
  • contractual allocation;
  • breach of legal obligations;
  • security responsibilities;
  • causative contribution;
  • ability to prevent the event;
  • conduct after discovery;
  • compliance with instructions;
  • role in selecting subprocessors;
  • extent of involvement.

A contract is relevant but not conclusive.

[!example] Illustration A contract says the processor is responsible for encryption. The controller nevertheless disables encryption through its configuration panel despite repeated warnings. The contractual wording alone may not determine responsibility. Courts should examine the factual contribution. Conversely, a processor cannot avoid contribution by inserting a clause stating it has no liability for GDPR breaches if mandatory law makes it responsible.

35. Contractual indemnities

Controllers and processors often include indemnity clauses in Article 28 agreements.

These clauses may regulate:

  • defence costs;
  • notification costs;
  • compensation payments;
  • contribution;
  • breaches of instructions;
  • subprocessor failures.

Such provisions operate internally and cannot deprive the injured claimant of paragraph 4 protection.

Illustration

A processor contract limits liability to €5,000. The processor’s Article 82 responsibility to the claimant cannot necessarily be reduced to €5,000 through a contract to which the claimant was not party. The contractual cap may affect the internal relationship only if:

  • national law permits it;
  • it does not conflict with mandatory GDPR rules;
  • its interpretation covers the loss;
  • public policy does not invalidate it. Private allocation cannot override effective compensation.

36. Insolvency and claimant protection

Paragraph 4 reduces the risk that the claimant bears the insolvency of one responsible actor.

[!example] Illustration A small processor caused much of the technical failure but becomes insolvent. A financially stable controller was also responsible. The claimant may seek full compensation from the stable controller if paragraph 4 applies. The controller may then attempt contribution through insolvency proceedings. This deliberately places more insolvency risk on responsible processing participants rather than on the injured person.

37. Compensation and administrative fines may coexist

A controller may face:

  • Article 82 compensation;
  • Article 83 administrative fine;
  • Article 58 corrective order;
  • national penalties under Article 84.

These measures serve different purposes.

Illustration

A breach affects one million people. The supervisory authority imposes a fine reflecting:

  • seriousness;
  • duration;
  • intentional or negligent character;
  • cooperation;
  • mitigation. Individual claimants seek Article 82 compensation for their particular harm. The fine does not compensate them. Compensation does not replace the regulatory penalty. However, a claimant cannot use Article 83 fine-calculation criteria to inflate Article 82 damages. The CJEU rejected that approach in juris and PS.

38. Declaratory relief and injunctions remain separate

A person may establish a GDPR infringement but fail to prove Article 82 damage.

That does not mean the infringement has no legal consequence.

The person may still seek, where available:

  • declaration;
  • injunction;
  • erasure;
  • access;
  • restriction;
  • supervisory enforcement;
  • administrative fine;
  • costs or another national remedy.

[!example] Illustration A controller unlawfully retains data, but the claimant proves no material or non-material damage. The compensation claim may fail. A court may nevertheless order erasure under Article 79 or applicable national procedure. Article 82 is a compensation mechanism, not the sole enforcement route.

39. Collective claims

Large data breaches may generate many Article 82 claims.

Possible mechanisms include:

  • individual claims;
  • joined proceedings;
  • Article 80 mandated representation, where national law permits compensation representation;
  • representative actions under Directive 2020/1828;
  • assignment models permitted by national law.

Each claimant must ordinarily satisfy the requirements of:

  • infringement;
  • damage;
  • causation.

A common infringement does not mean every person suffered identical damage.

Illustration

A breach exposes one million email addresses. Among those affected:

  • some see no consequences;
  • some receive persistent targeted fraud;
  • some lose money;
  • some suffer proven anxiety;
  • some addresses were already public. The court should not automatically award the same amount to everyone without considering actual damage, unless an applicable collective procedure lawfully permits a reliable common assessment consistent with full compensation.

40. Evidence in mass claims

Mass cases create practical evidential challenges.

Courts may use:

  • common evidence for the infringement;
  • class-wide technical findings;
  • individual evidence for damage;
  • representative samples where lawful;
  • standardised questionnaires;
  • expert evidence;
  • presumptions permitted under national law.

But national methods must not:

  • presume damage from infringement alone;
  • impose an unlawful seriousness threshold;
  • make proof practically impossible;
  • overcompensate claimants who suffered no loss.

The central CJEU distinction remains applicable at scale:

Common infringement may be proved collectively; actual harm and causation must still be established in a legally sufficient manner.


41. Article 82(6): Jurisdiction

Compensation proceedings must be brought before courts competent under the Member State law referred to in Article 79(2).

Article 79(2) generally allows proceedings:

  1. in the Member State where the controller or processor has an establishment; or
  2. alternatively, in the Member State of the claimant’s habitual residence.

The habitual-residence option does not apply where the defendant is a Member State public authority acting in the exercise of public powers. Article 82(6) incorporates that jurisdictional framework.

Illustration

A person habitually living in France claims compensation from a private controller established in Ireland. The person may generally sue:

  • in Ireland, based on the defendant’s establishment;
  • in France, based on habitual residence. National law then identifies the particular competent court.

41.1 Several defendants

Where several controllers or processors are sued, jurisdiction can become more complex.

The claimant should examine:

  • where each defendant has an establishment;
  • whether one court has jurisdiction over all defendants;
  • the connection among claims;
  • Brussels I Recast rules filling procedural gaps;
  • Article 81 related-proceeding rules;
  • national joinder requirements.

Article 82(4) establishes substantive full liability but does not automatically give every court territorial jurisdiction over every actor.


42. Public-authority defendants

Where the defendant is a public authority exercising public powers, the claimant generally cannot use habitual residence to sue that authority in another Member State.

[!example] Illustration A German tax authority unlawfully processes the data of a person habitually living in France while exercising statutory tax powers. The person would generally need to use the competent German courts rather than rely on habitual residence in France. If the public body acts commercially rather than through sovereign powers, the exception requires closer analysis.

43. Limitation periods

The GDPR does not provide a uniform limitation period for Article 82 claims.

Member State law may establish:

  • length;
  • starting point;
  • suspension;
  • interruption;
  • knowledge rules.

Those rules must comply with:

  • equivalence;
  • effectiveness;
  • legal certainty.

Illustration

A hidden profiling system operates for years. The claimant discovers it only after obtaining an access response. A national rule that expired before the claimant could reasonably discover the processing may make Article 82 excessively difficult to exercise. Relevant questions include:

  • when the infringement occurred;
  • when damage occurred;
  • when the claimant knew or should have known;
  • whether processing is continuing;
  • whether negotiations or complaints suspend time.

44. Applicable law and national procedural autonomy

Article 82’s substantive requirements have an autonomous EU meaning.

Member States cannot redefine them by imposing:

  • a minimum seriousness threshold;
  • automatic damages for every infringement;
  • punitive multipliers under Article 82 itself;
  • exclusion of genuine minor damage.

But national law supplies many procedural details, including:

  • court procedure;
  • evidence;
  • limitation;
  • cost rules;
  • damage valuation;
  • interest;
  • enforcement;
  • appeals.

Those rules must preserve equivalence and effectiveness.

[!example] Illustration National law may allow courts to estimate non-material damages where exact proof is impossible. That may support effective compensation. But a rule saying that non-material privacy harm is never compensable without medical evidence would likely conflict with the autonomous broad concept of damage.

45. A complete practical illustration

Assume that a hospital uses a cloud provider and an analytics company.

The hospital uploads patient records. The cloud provider stores them. The analytics company receives a pseudonymised dataset.

Several failures occur:

  1. The hospital uploads more information than necessary.
  2. The cloud provider disables encryption contrary to instructions.
  3. The analytics company reverses pseudonymisation for its own advertising purpose.
  4. A breach exposes medical information.
  5. A patient suffers fraud, distress and workplace reputational harm.

Step 1: Infringements

Possible infringements include:

  • data minimisation;
  • unlawful purpose expansion;
  • inadequate security;
  • processor acting outside instructions;
  • unlawful special-category processing;
  • transparency failures.

Step 2: Damage

Material damage may include:

  • fraudulent charges;
  • credit-repair costs;
  • reasonable document-replacement expenses;
  • lost employment income.

Non-material damage may include:

  • humiliation;
  • fear;
  • loss of control;
  • reputational harm;
  • distress from exposure of health information.

Step 3: Causation

The patient must connect the damage to the infringements.

For example:

  • disclosure enabled targeted fraud;
  • workplace recipient saw the medical record;
  • anxiety followed the inability to know who downloaded the dataset.

Step 4: Roles

The hospital is a controller.

The cloud provider may be a processor, liable if it breached direct security duties or lawful instructions.

The analytics company may have become a controller for its own advertising use.

Step 5: Paragraph 3

Each actor may try to prove that it was not in any way responsible.

The hospital cannot rely solely on the processor contract. The cloud provider cannot rely solely on employee error. The analytics company cannot call its own-purpose processing an instruction from the hospital.

Step 6: Paragraph 4

If all three were involved in the same damaging processing and responsible, the patient may seek full recovery from one or more of them.

Step 7: Paragraph 5

The actor paying full compensation may pursue contribution based on each party’s responsibility.

Step 8: Jurisdiction

The patient may generally sue in:

  • a Member State where the relevant defendant has an establishment; or
  • the patient’s Member State of habitual residence, subject to Article 79(2).

This example demonstrates every major component of Article 82.


46. Corrections and qualifications to the supplied commentary

Several propositions in the supplied commentary need careful refinement.

46.1 Article 82 does not leave Member States “no room for manoeuvre at all”

The substantive conditions are governed by EU law, but Member States retain procedural autonomy regarding:

  • valuation;
  • evidence;
  • limitation;
  • court organisation;
  • costs;
  • forms of redress;

subject to equivalence and effectiveness.

46.2 “Any infringement” satisfies only the first requirement

Even where a GDPR infringement is established, the claimant must separately prove actual damage and causation.

46.3 There is no seriousness threshold, but there must still be actual damage

The absence of a de minimis threshold does not collapse damage into infringement.

46.4 Non-material damage is broader than emotional distress

It may include:

  • loss of control;
  • reputational harm;
  • uncertainty;
  • social disadvantage;
  • fear of misuse.

But each must be genuine and sufficiently demonstrated.

46.5 Loss of control may be damage, but it is not automatically presumed

The court must examine what control was lost and what adverse consequence the person actually experienced.

46.6 Fear can qualify without actual misuse

But the fear must be established and cannot be wholly speculative.

46.7 Article 82 is not punitive

Intent, gravity and multiple infringements do not automatically multiply compensation. They matter only where they affect actual damage or another applicable legal rule.

46.8 Liability is not absolute

Article 82(3) permits exoneration, but the defendant must prove that it was not in any way responsible.

46.9 Employee or hacker conduct is not an automatic defence

The controller remains responsible for organisation, security, instructions and supervision.

46.10 Processors are not liable on exactly the same basis as controllers

Their paragraph 2 liability is limited to processor-specific GDPR obligations and conduct outside or contrary to lawful controller instructions.

46.11 Paragraph 4 does not impose liability on every participant in an ecosystem

Each actor must be involved in the same relevant processing and satisfy paragraphs 2 and 3.

46.12 Paragraph 5 protects fairness among defendants, not the claimant’s recovery

The claimant receives full compensation first. Internal allocation happens afterwards.

46.13 “Any person” should be interpreted cautiously

It is broader than “data subject,” but extending Article 82 to legal persons claiming purely corporate damage remains legally uncertain in light of the GDPR’s natural-person protection objective.

46.14 Apologies may sometimes compensate

Money is not invariably the only form of compensation, but any alternative must fully repair the proven damage.


Conclusion

Article 82 establishes a claimant-protective but not automatic compensation regime. The claimant must prove:

  1. a GDPR infringement;
  2. actual material or non-material damage;
  3. a causal connection between the two.

The CJEU has carefully balanced access to compensation with protection against automatic damages claims.

On one hand:

  • no minimum seriousness threshold is permitted;
  • fear and loss of control may qualify;
  • actual misuse is not always required;
  • minor but genuine harm remains compensable;
  • multiple responsible actors may each be liable for the full loss;
  • hackers and employees cannot be used as automatic liability shields.

On the other hand:

  • infringement alone is insufficient;
  • damage must be real;
  • purely hypothetical fear does not automatically qualify;
  • compensation cannot exceed actual harm merely to punish;
  • claimants cannot recover multiple times for the same injury;
  • processors have a narrower statutory liability basis than controllers.

Article 82’s six paragraphs work as a complete liability structure:

  • Paragraph 1: creates the right to compensation.
  • Paragraph 2: defines controller and processor liability.
  • Paragraph 3: permits exoneration where absence of responsibility is proved.
  • Paragraph 4: protects the claimant through full liability where several responsible actors are involved.
  • Paragraph 5: permits contribution among those actors.
  • Paragraph 6: incorporates the claimant-friendly jurisdiction rules of Article 79(2).

The simplest summary is:

A person does not receive money merely because the GDPR was broken. They must prove that the infringement caused real harm. But once even modest genuine harm is proved, national law cannot dismiss it as too trivial. The responsible controller or processor must provide full compensation, and where several actors caused the same harm, they must resolve their respective shares among themselves rather than forcing the injured person to do so.