What follows from the GDPR?
Right from the outset, we face a fundamental question: do the provisions of the GDPR allow for the possibility of bringing a civil lawsuit regarding violations of the regulation? The answer to this question is affirmative. It should be noted that according to Article 79 of the GDPR, every individual whose data is concerned has the right to an effective legal remedy before a court if they believe that their rights under the regulation have been violated as a result of the processing of their personal data in a manner inconsistent with it. This individual may report the violation to the court regardless of filing a complaint with the supervisory authority, which in this case is the President of the Polish Data Protection Authority. It should be mentioned that in such cases, the competent court will be the district court.
On the other hand, Article 82 of the GDPR provides that any natural person who has suffered material or non-material damage as a result of a violation of the regulation has the right to obtain compensation from the data controller or data processor for the damage incurred. It is worth emphasizing that this damage can be both material and non-material. In the case of non-material damage, the violation will concern personal rights, and thus any potential lawsuit will be a claim for compensation.
Judgments of Polish Courts under Article 82 of the GDPR
An analysis of the latest case law of Polish courts shows that Article 82 of the GDPR is increasingly being applied in cases concerning the protection of personal data.
In a judgment dated March 17, 2022 (case no. II C 1228/19), the District Court of Warsaw-Praga found that the erroneous sending of a file containing someone else's personal data to a client constituted a violation of data protection. Importantly, the court emphasized the convergence of grounds for liability – both under the GDPR and under civil law regarding the protection of personal rights (Articles 23 and 24 in connection with Article 448 of the Civil Code). At the same time, due to the prompt remedial actions taken by the company and the lack of actual use of the data, only 1000 PLN was awarded as compensation instead of the requested 20,000 PLN.
A similar approach was presented in the judgment of the District Court in Warsaw dated February 7, 2023 (case no. III C 280/22), concerning a mass data leak from a loan portal. The plaintiff, who sought 30,000 PLN in compensation, received 1500 PLN. The court confirmed the liability of the data controller, indicating that they could not invoke the fault of the data processor, as the provisions provide for joint liability.
On the other hand, the judgment of the Court of Appeal in Warsaw dated June 22, 2023 (case no. I ACa 352/23) was particularly significant as it concerned a public institution – the Supreme Administrative Court. The lack of anonymization of the name of the court enforcement officer in the database of court rulings led to the awarding of PLN 20,000 by the court of first instance. Following the appeal, the amount was reduced to PLN 10,000, but the liability of the State Treasury was upheld. This ruling confirmed that non-material damage, in the sense of Article 82 of the GDPR, also includes stress and the risk of reputational harm, without the need to demonstrate material losses.
The cited cases indicate several common elements in judicial practice. Firstly, the liability of the data controller is broadly understood, and the possibility of being exempted from it is exceptional. Secondly, courts recognize that non-material harm, such as fear, stress, or loss of trust, constitutes damage in the sense of the GDPR. Thirdly, the amount of compensation awarded is, however, moderate and typically amounts to several thousand zlotys.
It therefore seems that Polish courts adopt a balanced compensatory model: compensation is intended to have a real and perceptible dimension, but it cannot lead to the unjust enrichment of the injured party. This direction is consistent with the EU case law, which emphasizes the necessity of proportionality in compensation.
Position of the CJEU – new guidelines on compensation claims for GDPR violations
The judgment of the Court of Justice of the European Union dated June 20, 2024 (case no. C-590/22) serves as an important point of reference for individuals seeking claims under Article 82 of the GDPR. The case concerned a situation in which tax declarations were inadvertently disclosed to a third party. The German court, considering this case, referred questions to the CJEU regarding the principles of liability and the conditions for compensation.
The CJEU clearly indicated that a mere violation of the GDPR is not a sufficient basis for awarding compensation. For a claim to be effective, the data subject must prove both the occurrence of material or non-material damage and the existence of a causal link between the violation and the damage. These three elements – violation, damage, and causal link – must occur together.
At the same time, the CJEU emphasized that the law does not provide for a minimum threshold of damage. This means that even the smallest violation, if it leads to perceptible harm or discomfort, may justify a compensation claim. Furthermore, the mere fact of fear of data misuse by a third party may be considered non-material damage, provided it is credibly demonstrated.
An important element of the ruling was also the separation of civil damages from administrative fines. The Court of Justice of the European Union (CJEU) clearly indicated that the criteria applied when imposing administrative monetary penalties cannot be automatically transferred to the context of Article 82 of the GDPR. Compensation is of a compensatory nature, rather than preventive or deterrent.
The CJEU also pointed out that Article 82 of the GDPR covers only violations arising from the regulation. If there has also been a breach of national law, any potential extension of liability and the amount of compensation can only be considered based on national provisions, and not solely on the GDPR.
The CJEU ruling has significant practical implications, as it delineates clear boundaries of liability for data controllers and organizes the manner of handling claims. On one hand, it protects entities from automatic awarding of compensation for every violation; on the other hand, it provides individuals with the opportunity to effectively seek compensation even for minor, but actual harm.
Conclusions from the CJEU ruling
In the discussed ruling of June 20, 2024 (case no. C-590/22), the CJEU clearly stated that a mere violation of the GDPR provisions is not sufficient to claim compensation. It is necessary to prove the damage and establish a causal link between the violation and its occurrence. Importantly, there is no minimum threshold for losses – even very minor damage may justify a claim. The CJEU also emphasized that non-material damage can be recognized as the mere fear of data misuse, provided it is reliably proven by the injured party.
At the same time, the CJEU severed civil damages from the logic of administrative penalties. The criteria applied when imposing financial penalties do not apply when determining the amount of compensation, as it serves solely a compensatory function, rather than a deterrent one. Furthermore, Article 82 of the GDPR covers only violations directly arising from the regulation. If there has also been a breach of national law, this may justify additional claims, but only if provided for by national provisions.
Does a mere violation of the GDPR grant the right to seek compensation?
Not every violation of the GDPR provisions automatically gives rise to a claim for monetary compensation. According to Article 82 of the GDPR, the condition for effectively seeking damages or compensation is to demonstrate not only the violation itself but also the occurrence of damage – whether material or non-material – and the existence of a causal link between the violation and that damage.
In the judgment of May 4, 2023 (case no. C-300/21), the Court of Justice of the European Union (CJEU) unequivocally ruled that merely establishing a violation is not sufficient to grant compensation. It is necessary to demonstrate specific harm, such as a sense of loss of control over data, stress, fear of unauthorized use of data, or actual financial loss. It is important to note that the harm does not need to be significant – it is sufficient for it to be real and appropriately documented. In other words, a claim under Article 82 of the GDPR is justified only when the violation of data protection law has resulted in measurable consequences for the data subject.
At the same time, the CJEU emphasized that the GDPR does not provide for a threshold of "minimal severity" of harm, which means that even minor non-material violations can give rise to a right to compensation. The GDPR does not regulate the method of determining the amount of compensation – this is left to the member states, which must respect the principles of equivalence and effectiveness, so that the protection afforded by EU law is not illusory. Compensation is intended to provide "full and effective" redress for harm, but it does not serve a punitive function. Its role is to compensate for the loss, not to punish the perpetrator of the violation.
Harm under the GDPR – what is it and how to prove it?
Non-material harm (injury) in the context of the GDPR refers to negative psychological and emotional effects resulting from a violation of personal data protection. This may include a sense of loss of privacy, stress, fear regarding the future of the data, as well as a decrease in the sense of security. Harm does not require the demonstration of financial losses, but it must be real and perceptible. In judicial practice, evidence may include testimonies from the injured party, medical or psychological documentation, correspondence confirming the effects of the incident, or other circumstances showing the impact of the violation on daily life. Case law indicates that even prolonged stress or a sense of threat, if proven, may be a sufficient basis for awarding compensation.
What evidence to collect for a claim for compensation after a data breach?
Effective pursuit of claims under Article 82 of the GDPR requires careful preparation of evidence. Documents confirming the very fact of the breach are of key importance, such as notifications sent by the data controller, correspondence regarding the incident, or official statements about the data leak. It is equally important to document the consequences of the breach – this may include messages indicating unauthorized use of data, evidence of attempted fraud (e.g., phishing, identity theft), or invoices confirming expenses incurred for additional security measures. In the case of non-material damage, medical and psychological opinions are of evidential significance. The more complete and coherent the set of evidence, encompassing both the fact of the breach and its consequences, the greater the chances of obtaining satisfactory compensation in civil proceedings.
Joint Liability under the GDPR – Should You Sue the Data Controller or the Processor?
Free knowledge about GDPR.
Use it freely!
Limitation Period for Claims for Compensation for GDPR Breaches
Claims arising from violations of the GDPR are treated under Polish law as tort claims, thus Article 442¹ of the Civil Code applies to them. This means that the injured party has three years from the date they became aware of the damage and the person responsible to file a lawsuit. Regardless of this deadline, the claim is subject to a maximum limitation period of 10 years from the event causing the damage. If the data breach simultaneously constitutes a criminal offense (e.g., illegal acquisition of data for fraudulent purposes), this period extends up to 20 years. Such a position is confirmed both in doctrine and in the case law of the courts, which consistently apply the provisions of the Civil Code to claims under Article 82 of the GDPR.
Complaint to the Polish DPA or a lawsuit for compensation – or perhaps both?
The injured party may choose two paths to assert their rights – administrative and civil. Both of these paths are independent of each other. A complaint to the President of the Polish DPA (under Article 77 of the GDPR) initiates administrative proceedings, which may result in ordering the data controller to rectify the violations or imposing a fine on them, but does not grant compensation. A civil lawsuit (according to Article 82 of the GDPR), on the other hand, allows for the pursuit of monetary compensation or damages. These procedures can be conducted in parallel – there is no obligation to wait for the decision of the Polish DPA before filing a lawsuit. In practice, however, a decision by the President of the Polish DPA confirming the violation constitutes very strong evidence in the civil case, which is why it is often recommended to first file a complaint and then submit a lawsuit if the violation has caused damage.
How do courts calculate the amount of harm in GDPR violations?
The amount of compensation for a GDPR violation is determined individually each time and is based on criteria developed in the context of personal rights protection. Courts primarily assess: the extent of data disclosure (whether it was available to a narrow circle of recipients or widely publicized, e.g., on the Internet), the type and sensitivity of the data (health, financial, or other particularly protected data are treated as more severe), as well as the duration of the violation and its consequences (long-term stress, loss of a sense of security, shame, risk of abuse). The attitude of the data controller is also significant – prompt and effective remedial actions can limit the extent of harm, while passivity or disregard for obligations increases the scope of liability.
It should be noted that compensation under the GDPR is exclusively compensatory in nature. This means that its amount should be adjusted to the actual extent of the harm suffered. It must be significant enough to constitute a tangible compensation, but at the same time, it cannot lead to unjust enrichment of the injured party.
Summary
It is indeed possible to pursue claims – both for compensation and for redress – under the GDPR, and this can be done through civil proceedings. However, it is important to remember that a mere violation is not sufficient. For a court to grant a remedy, it is necessary to demonstrate the actual impact of the incident on the situation of the injured party – in the form of material damage (e.g., financial losses, costs of data protection) or non-material harm (e.g., stress, loss of privacy, concerns about data misuse). It is equally important to prove the causal link between the violation and the effect, as well as to correctly identify the addressee of the claim – the data controller, the data processor, or both jointly. When considering the lawsuit, the court will assess not only the fact of the violation and the infringement of personal rights but also what actions the responsible entity took to mitigate the damage and what the actual consequences were for the injured party. In other words – a well-prepared lawsuit, supported by credible evidence and directed to the appropriate entity, provides a real chance for successfully obtaining compensation or redress.


