TL;DR for the DPO
Your clients' financial exposure is not only the regulator's fine. It is the sum of many small civil claims arising from a single breach, multiplied by the number of data subjects involved. What decides those cases is almost always one thing: being able to show that the security measures were appropriate before anything happened.
What Article 82 actually says
Article 82(1) gives anyone who has suffered material or non-material damage as a result of an infringement of the Regulation the right to compensation from the controller or the processor. It is a short provision that national courts read in opposite ways for years: some required serious, documented harm, others treated the infringement itself as sufficient. Between 2023 and 2024 the Court of Justice closed almost all of those divergences.
Three elements, and the threshold that does not exist
In Osterreichische Post (Case C-300/21, 4 May 2023) the Court held that the right to compensation requires three cumulative conditions: an infringement of the Regulation, actual damage, and a causal link between the two. The infringement on its own does not create the right. So far, good news for controllers. The second half of the same judgment takes back much of what the first half gave.
No minimum threshold of seriousness
The Court ruled out making compensation conditional on the harm reaching a certain level of gravity. A small harm remains compensable harm. Which means the argument 'not much happened, nothing serious' is not a defence: it moves the discussion to the amount, not to whether anything is owed at all.
Fear can be damage. But not always
In Case C-340/21 (14 December 2023), arising from a cyberattack on the Bulgarian tax agency, the Court held that the fear of possible misuse of personal data by third parties, following an infringement, can in itself constitute non-material damage. The misuse need not already have occurred. Shortly afterwards, in MediaMarktSaturn (Case C-687/21, 25 January 2024), it set the limit: a purely hypothetical fear, with no concrete adverse consequence, is not enough. The line runs between fear grounded in a real loss of control and generalised worry.
Who has to prove what
This is the part closest to the DPO's daily work. In the same C-340/21 the Court made clear that where the adequacy of the technical and organisational measures under Article 32 is in dispute, the burden of proof lies with the controller. It is not for the data subject to show the measures were insufficient: it is for the controller to show they were appropriate. And the exemption in Article 82(3) applies only where the controller proves that it is in no way responsible for the event - a high bar which, in juris (Case C-741/21, 11 April 2024), the Court confirmed is not met simply because the error was made by an employee.
Compensate, not punish
In Case C-590/22 (20 June 2024) the Court restated that Article 82 serves a purely compensatory function: it repairs the harm suffered, it does not punish the controller or deter the market. Two opposite consequences follow. The first is that punitive amounts cannot be claimed. The second, less comfortable, is that a fine already imposed by the authority does not reduce the compensation owed to the individual: they are separate tracks, and they add up.
What to do with this on Monday morning
Turning this case law into concrete work is less dramatic than it sounds, but it has to happen before, not after. Five things, none of which requires a project.
- Check that every client has dated documentation of the Article 32 measures and of why they were considered appropriate: that is what shifts the burden of proof in your favour, and it must exist before the incident.
- In the breach register, always record the risk assessment for data subjects even when you decide not to notify: it is the trace showing an assessment was made.
- Where a breach affects many data subjects, remember that civil exposure multiplies by their number: a modest sum per person becomes the largest financial item of the incident.
- Informing data subjects promptly is not only an Article 34 duty: it reduces fear, and fear is precisely what the Court treats as compensable damage.
- Put in writing the advice you give the controller when you counsel against a choice: if the controller decides otherwise, that document is the line separating their liability from yours.
The question to ask your client
Not 'are we compliant?', but: 'if a data subject sues us tomorrow, what do we hand the lawyer to show the measures were appropriate?'. If the answer is a list of installed tools rather than a dated document explaining the choices, that is the work to do.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free