# Right to compensation and liability — GDPR — context bundle

> Focused context for a single provision, curated from overview.legal on 2026-07-23. Canonical page: https://overview.legal/laws/gdpr/art-82
> Every item cites its source. Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

## Provision

### Right to compensation and liability — Right to compensation and liability

*GDPR, gdpr-art-82-en — https://overview.legal/laws/gdpr/art-82*

1. Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.

2. Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.

3. A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.

4. Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and where they are, under paragraphs 2 and 3, responsible for any damage caused by processing, each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject.

5. Where a controller or processor has, in accordance with paragraph 4, paid full compensation for the damage suffered, that controller or processor shall be entitled to claim back from the other controllers or processors involved in the same processing that part of the compensation corresponding to their part of responsibility for the damage, in accordance with the conditions set out in paragraph 2.

6. Court proceedings for exercising the right to receive compensation shall be brought before the courts competent under the law of the Member State referred to in Article 79(2).

## Enforcement

18 decision(s) on record cite Article 82, totalling approximately €1,258,275,000 in fines (median €60,000,000).

Top fines:
- **GOOGLE LLC: Insufficient legal basis for data processing** (FRANCE, €200,000,000) — https://overview.legal/posts/48977
- **GOOGLE LLC: Onvoldoende juridische basis voor de verwerking van gegevens.** (FRANCE, €200,000,000) — https://overview.legal/posts/52125
- **INFINITE STYLES SERVICES CO. LIMITED: Insufficient legal basis for data processing** (FRANCE, €150,000,000) — https://overview.legal/posts/48979
- **INFINITE STYLES SERVICES CO. LIMITED: Onvoldoende juridische basis voor de verwerking van persoonsgegevens.** (FRANCE, €150,000,000) — https://overview.legal/posts/52123
- **GOOGLE IRELAND LIMITED: Insufficient legal basis for data processing** (FRANCE, €125,000,000) — https://overview.legal/posts/48978

## Guidance

### Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (‘‘LED’’) under Article 62 LED

*EDPB — https://overview.legal/posts/53750*

EDPB, Contribution of the EDPB to the European Commission’s evaluation of the Data Protection Law Enforcement Directive (‘‘LED’’) under Article 62 LED

### VERSIEGESCHIEDENIS

*EDPB — https://overview.legal/posts/38079*

De EDPB heeft op 20 juni 2023 de aanbevelingen 1/2022 inzake bindende bedrijfsvoorschriften voor verwerkingsverantwoordelijken (artikel 47 AVG) vastgesteld, ter vervanging van de eerdere WP 256 rev.01 en WP 264. Het document voorziet in een standaardaanvraagformulier voor goedkeuring van bindende bedrijfsvoorschriften en geeft uitleg bij de vereiste inhoudelijke elementen en beginselen, waaronder de afbakening tussen wat in de bindende bedrijfsvoorschriften zelf en wat in de aanvraag bij de leidende toezichthoudende autoriteit moet worden opgenomen. De aanbevelingen zijn bedoeld om ondernemingen die persoonsgegevens doorgeven aan groepsentiteiten in derde landen zonder passend beschermingsniveau (artikel 45 AVG) te ondersteunen bij het voldoen aan de passende waarborgen van artikel 46 AVG.

### Versiegeschiedenis

*EDPB — https://overview.legal/posts/38081*

De Europese Raad voor gegevensbescherming (EDPB) heeft deze richtsnoeren uitgebracht betreffende de accreditatie van certificeringsorganisaties onder artikel 43 van de AVG. Het document biedt interpretatieve guidance over de rol van lidstaten, nationale accreditatie-instanties en toezichthoudende autoriteiten bij het accreditatieproces, alsmede over de wisselwerking met Verordening (EG) nr. 765/2008 en de daaruit voortvloeiende accreditatie-eisen. De richtsnoeren zijn in versie 3.0 vastgesteld op 4 juni 2019, waarbij Bijlage 1 werd toegevoegd na openbare raadpleging.

### Versiegeschiedenis

*EDPB — https://overview.legal/posts/38090*

Het Europees Comité voor gegevensbescherming (EDPB) heeft versie 2.0 van de richtsnoeren 2/2020 vastgesteld op 15 december 2020, na een openbare raadpleging. De richtsnoeren betreffen de toepassing van artikel 46, lid 2, onder a), en lid 3, onder b), van de GDPR inzake passende waarborgen voor doorgiften van persoonsgegevens tussen overheidsinstanties binnen en buiten de EER, waaronder wettelijk bindende instrumenten en bestuurlijke regelingen. Het document biedt interpretatieve leidraad over de vereiste waarborgen, zoals beginselen voor gegevensbescherming, rechtsmiddelen voor betrokkenen en toezichtmechanismen, zonder een boete op te leggen.

### Versiegeschiedenis

*EDPB — https://overview.legal/posts/38093*

De Europese Toezichthoudersautoriteit (EDPB) heeft op 28 maart 2023 versie 2.0 van Richtsnoeren 9/2022 betreffendede melding van inbreuken in verband met persoonsgegevens uit hoofde van de AVG vastgesteld, na een gerichte openbare raadpleging. De richtsnoeren, een geactualiseerde versie van het eerdere WP250-advies van de Artikel 29-werkgroep, bieden praktische uitleg over de meldingsverplichtingen van artikel 33 en 34 AVG, waaronder de definities van persoonsgegevensinbreuken, het tijdstip van melden en de informatieverstrekking aan toezichthouders en betrokkenen. De update bevat specifieke aandacht voor de meldingsverplichtingen van buiten de EER gevestigde verwerkingsverantwoordelijken.

## Related topics

- **Liability** — https://overview.legal/topics/aansprakelijkheid
  ## Legal Framework

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-82 · 2026-07-23
