Liability
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Legal responsibility for GDPR violations and damages
Overview
28 sources · Sep 25, 2026Legal Framework
Article 82 GDPR is the governing provision for compensation and liability allocation. Under Article 82(1), any person who has suffered material or non-material damage as a result of a GDPR infringement may claim compensation from the controller or processor responsible.
"Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered."
— GDPR Art. 82(1)
The liability regime draws a critical distinction between controllers and processors. Article 82(2) makes a controller liable for damage caused by any infringing processing, whereas a processor's liability is narrower—attaching only where it failed to comply with processor-specific obligations or acted outside or contrary to lawful instructions. Both controllers and processors may invoke the exemption under Article 82(3), which shifts the burden of proof to the defendant:
"A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage."
— GDPR Art. 82(3)
Where multiple parties participate in the same processing, Article 82(4) imposes liability for the entire damage on each responsible party, with a corresponding right of recourse under Article 82(5) based on respective shares of responsibility.
Key Developments
Enforcement decisions confirm that inadequate technical and organisational measures directly generate liability exposure. In the Permanent TSB enforcement action, the Irish DPA linked organisational failures to concrete vulnerability of data subjects, reinforcing that supervisory authorities treat the severity and likelihood of harm as key parameters when assessing consequences of infringement.
"A breach can potentially have a range of significant adverse effects on individuals, which can result in physical, material, or non-material damage."
— EDPB Guidelines 9/2022 §24
National DPAs have imposed substantial fines where controllers failed to prevent such damage: the Lithuanian DPA fined two medical companies €450,000 following data breaches involving unauthorised access to internal systems, while the Croatian DPA fined a gas station operator €940,000. These decisions signal that both the number of affected individuals and the level of damage suffered inform supervisory assessment of liability consequences.
Status of the Debate
This topic is contested in court. While Article 82 provides a structured liability framework, member state courts diverge on key thresholds—particularly the standard for proving causation between an infringement and actual damage, and the precise scope of the Article 82(3) exemption. The CJEU has addressed adjacent questions in Mousse (C-394/23) regarding legitimate interests and risk to data subjects, but has not yet ruled definitively on the boundaries of the Article 82 liability regime. No court split has been formally resolved through a preliminary reference on the meaning of "not in any way responsible" or on whether non-material damage requires concrete manifestation. A CJEU reference on those questions would settle the most pressing open issues.
Practical Guidance
- Document accountability for each processing operation: Controllers bear broader liability under Article 82(2) than processors; maintain records demonstrating lawfulness and adequacy of measures to support a potential Article 82(3) exemption defence.
- Allocate liability precisely in processor contracts: Under Article 82(5), a party paying full compensation may reclaim from co-responsible parties; contracts should pre-define responsibility shares to streamline recourse claims.
- Maintain evidence of compliance for the Article 82(3) exemption: The burden of proving non-responsibility rests on the controller or processor; risk assessments, security audit logs, and incident response records are essential to discharge that burden.
- Assess damage severity proactively following breaches: EDPB guidelines and national enforcement confirm that both the number of affected individuals and the level of damage suffered inform supervisory action; breach impact assessments should document both dimensions.
- Prepare for joint liability scenarios: Where multiple controllers or processors share a processing activity, Article 82(4) makes each liable for the entire damage; contractual indemnities should reflect this exposure.
why this is here
Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation
The provision directly establishes the core liability regime for GDPR violations, including who is liable, exemptions, joint liability, and recourse among parties, which are the central elements of the liability topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
Where an administrative fine is chosen, its value can be up to 10,000,000 EUR or up to 2 % if the total worldwide annual turnover of an undertaking under Article 83(4)(a) of the GDPR.
The document mentions fines and sanctions for failure to notify, which touches on liability, but it does not discuss the broader legal responsibility or compensation for GDPR violations.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the controller shall be responsible for the compliance with the principles set out in Article 5(1) GDPR
The document mentions responsibility for compliance but does not discuss liability for damages or compensation between parties.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the measures and safeguards should be designed to be robust and the controller should be able to implement further measures in order to scale to any increase in risk
The document discusses implementing measures to protect data subjects' rights, which could indirectly affect liability, but does not directly address liability rules or compensation for GDPR violations.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
may facilitate the exercise of their rights flowing from, for example, Art. 16 to 19, 21 to 22 and 82 GDPR
The document mentions Article 82 GDPR in the context of the right of access facilitating other rights, but does not analyze liability or compensation provisions.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
heeft het recht om van de verwerkingsverantwoordelijke of de verwerker schadevergoeding te ontvangen voor de geleden schade
The document directly analyzes the liability framework for damages under Article 82 GDPR, including which parties can be held liable and the conditions for compensation.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data
The sanction demonstrates legal responsibility for GDPR violations, though the document does not detail liability doctrines or compensation mechanisms.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
proposed rules will allow consumers to bring claims for damages
The document directly addresses liability for damages caused by AI, which is the core of the 'aansprakelijkheid' topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the new ICT supplier cannot be held liable for any damages suffered by the client as a result of data loss from the old ICT environment
This case directly addresses liability for damages from data loss, though it is general contractual liability rather than GDPR-specific liability. It is a primary source on liability for data loss in an ICT context.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Garðabær.
The document reports a fine but does not discuss liability principles or compensation; it is incidental to the penalty imposed.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The Icelandic DPA has imposed a fine of EUR 20,000 on the city of Kópavogur.
The document mentions a fine but focuses on the underlying violations, not the legal liability framework.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður.
The document concerns enforcement action and a fine, but does not discuss liability doctrines, compensation to data subjects, or fault allocation.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the fact that attempts to remove it were ineffective determined the imposition of a penalty
The document discusses a fine imposed, touching on liability aspects, but focuses on processing without legal basis rather than damages or compensation.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Data was not processed in a manner that ensures appropriate security of the personal data
The document concerns a violation of the security principle but does not discuss liability, compensation, or legal responsibility for the breach.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 63 Case Law · all 32 Enforcement · all 23 Literature · all 31 News