Liability
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Legal responsibility for GDPR violations and damages
Overview
24 sources · Jul 23, 2026Legal Framework
Article 82 GDPR establishes the right to compensation and the liability framework for GDPR violations. Controllers are liable for damage caused by processing that infringes the Regulation, while processors face liability only for damage resulting from their failure to comply with processor-specific obligations or from acting outside or contrary to lawful controller instructions. Both controllers and processors are exempt from liability if they demonstrate they were not in any way responsible for the event giving rise to damage — placing the burden of proof on the defendant rather than the claimant for the question of responsibility.
Recital 85 underscores that personal data breaches can produce physical, material, or non-material damage, including loss of control over personal data, identity theft, reputational harm, and financial loss. This broad conception of damage is central to the compensation regime: Article 82(1) explicitly covers both material and non-material damage, and Recital 146 confirms that data subjects need not suffer material harm to qualify for compensation.
The liability regime interacts with the substantive obligations in Article 6 (lawful basis), Articles 15–17 (data subject rights), and Article 28 (processor contracts). A breach of any of these provisions can trigger Article 82 liability if it causes compensable damage. Article 29 reinforces processor accountability by requiring that processors and their personnel process personal data only on the controller's documented instructions.
Key Developments
Dutch courts have begun setting practical thresholds for non-material damage claims under Article 82. In the Rechtbank Amsterdam decision (C/13/677172 / HA RK 19-435), the court rejected a claim for €500 in non-material damage based on loss of control over personal data, finding the claimant had insufficiently substantiated how the loss of control actually caused harm. The court also noted that, unlike prior cases where compensation was awarded, the defendant had not disclosed the claimant's data to third parties. This signals that bare assertions of lost control are inadequate; claimants must demonstrate a concrete nexus between the infringement and the harm suffered.
The CJEU's reasoning in Rijkeboer (C-553/07) remains relevant for liability analysis: disproportionate retention limitations that prevent data subjects from exercising access rights can themselves constitute an infringement capable of generating damage. The Nikolaou line of authority on non-contractual EU liability is instructive on evidentiary burdens — while the general rule places the burden on the applicant, that burden shifts to the institution where multiple causes could explain the damage and the institution fails to provide exculpatory evidence.
Enforcement actions by DPAs further illustrate the financial exposure. The Icelandic DPA fined Reykjanesbær municipality €16,600 and the City of Reykjavik €13,300 for inadequate safeguards when deploying Google Education systems — demonstrating that insufficient diligence in processor selection and assessment translates directly into administrative fines and potential civil liability.
Practical Guidance
Document every lawful basis decision under Article 6 with a proportionality assessment — particularly for legitimate interests and public task bases, which carry the broadest discretion and the highest risk of challenge. Courts will scrutinize whether the balancing test was genuinely performed.
Ensure processor contracts under Article 28(3)(a) explicitly restrict processing to documented instructions — this creates the contractual and statutory parallel required by Article 29 and defines the boundary of processor liability under Article 82(2).
Maintain evidence of data breach detection, notification, and remediation — Recital 85 makes clear that failure to address breaches promptly aggravates liability; demonstrable timely response is a key defense against claims for both material and non-material damage.
Substantiate non-material damage claims with specificity — the Amsterdam court's rejection of generic "loss of control" claims means that data subjects must articulate concrete harm, while controllers can defend by showing no third-party disclosure occurred and no demonstrable adverse consequence resulted.
Prepare for burden-shifting scenarios — following Nikolaou, where multiple causes could explain damage, controllers and processors should proactively gather and present evidence isolating the cause, as failure to do so shifts the evidentiary burden against them.