Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Case law August 11, 2026 7 min

Damages under the GDPR: what a claimant actually has to prove

In three years the Court of Justice has built a clear line on Article 82. An infringement alone is not enough, but there is no minimum threshold either - and the fear of misuse can itself be compensable harm

TL;DR for the DPO

Your clients' financial exposure is not only the regulator's fine. It is the sum of many small civil claims arising from a single breach, multiplied by the number of data subjects involved. What decides those cases is almost always one thing: being able to show that the security measures were appropriate before anything happened.

What Article 82 actually says

Article 82(1) gives anyone who has suffered material or non-material damage as a result of an infringement of the Regulation the right to compensation from the controller or the processor. It is a short provision that national courts read in opposite ways for years: some required serious, documented harm, others treated the infringement itself as sufficient. Between 2023 and 2024 the Court of Justice closed almost all of those divergences.

Three elements, and the threshold that does not exist

In Osterreichische Post (Case C-300/21, 4 May 2023) the Court held that the right to compensation requires three cumulative conditions: an infringement of the Regulation, actual damage, and a causal link between the two. The infringement on its own does not create the right. So far, good news for controllers. The second half of the same judgment takes back much of what the first half gave.

No minimum threshold of seriousness

The Court ruled out making compensation conditional on the harm reaching a certain level of gravity. A small harm remains compensable harm. Which means the argument 'not much happened, nothing serious' is not a defence: it moves the discussion to the amount, not to whether anything is owed at all.

Fear can be damage. But not always

In Case C-340/21 (14 December 2023), arising from a cyberattack on the Bulgarian tax agency, the Court held that the fear of possible misuse of personal data by third parties, following an infringement, can in itself constitute non-material damage. The misuse need not already have occurred. Shortly afterwards, in MediaMarktSaturn (Case C-687/21, 25 January 2024), it set the limit: a purely hypothetical fear, with no concrete adverse consequence, is not enough. The line runs between fear grounded in a real loss of control and generalised worry.

Who has to prove what

This is the part closest to the DPO's daily work. In the same C-340/21 the Court made clear that where the adequacy of the technical and organisational measures under Article 32 is in dispute, the burden of proof lies with the controller. It is not for the data subject to show the measures were insufficient: it is for the controller to show they were appropriate. And the exemption in Article 82(3) applies only where the controller proves that it is in no way responsible for the event - a high bar which, in juris (Case C-741/21, 11 April 2024), the Court confirmed is not met simply because the error was made by an employee.

Compensate, not punish

In Case C-590/22 (20 June 2024) the Court restated that Article 82 serves a purely compensatory function: it repairs the harm suffered, it does not punish the controller or deter the market. Two opposite consequences follow. The first is that punitive amounts cannot be claimed. The second, less comfortable, is that a fine already imposed by the authority does not reduce the compensation owed to the individual: they are separate tracks, and they add up.

What to do with this on Monday morning

Turning this case law into concrete work is less dramatic than it sounds, but it has to happen before, not after. Five things, none of which requires a project.

  • Check that every client has dated documentation of the Article 32 measures and of why they were considered appropriate: that is what shifts the burden of proof in your favour, and it must exist before the incident.
  • In the breach register, always record the risk assessment for data subjects even when you decide not to notify: it is the trace showing an assessment was made.
  • Where a breach affects many data subjects, remember that civil exposure multiplies by their number: a modest sum per person becomes the largest financial item of the incident.
  • Informing data subjects promptly is not only an Article 34 duty: it reduces fear, and fear is precisely what the Court treats as compensable damage.
  • Put in writing the advice you give the controller when you counsel against a choice: if the controller decides otherwise, that document is the line separating their liability from yours.

The question to ask your client

Not 'are we compliant?', but: 'if a data subject sues us tomorrow, what do we hand the lawyer to show the measures were appropriate?'. If the answer is a list of installed tools rather than a dated document explaining the choices, that is the work to do.

Official source:CJEU, Case C-300/21, Osterreichische Post (4 May 2023)Official source:CJEU, Case C-340/21 (14 December 2023)Official source:CJEU, Case C-687/21, MediaMarktSaturn (25 January 2024)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Case law
200 €for the loss of control

Real employee data inside the test system: what loss of control is worth

Testing a new HR system with real data is not forbidden: transferring more fields than the test needs is. The German Federal Labour Court ordered an employer to pay two hundred euro because it had uploaded salary, home address, tax ID and marital status although it had agreed a list of nine fields with the works council. And it confirmed that a delayed answer to an access request is not, in itself, a damage.

Aug 21, 2026New 5 min
Case law
7i criteri di bilanciamento CEDU

You don't delete the article, you delete the name

On 5 August 2026 the CNIL clarified the boundaries of a right that is often exercised and widely misunderstood. Against a press organisation, objection and erasure remain available; access and rectification do not. And a refusal must be reasoned concretely: six generic formulas are named as inadmissible.

Aug 05, 2026New 4 min
Case law
3condizioni cumulative del test

Legitimate interest is not the fallback legal basis

In Case C-621/22 the Court of Justice held that a commercial interest can constitute a legitimate interest under Article 6(1)(f). Many people read only that line. The rest of the judgment recalls that the conditions remain three and cumulative, and that the third - the balancing against the data subject's reasonable expectations - is where the case at hand was lost. For the DPO the consequence is practical: legitimate interest exists only if it is written down somewhere.

Aug 12, 2026New 6 min