Skip to content
Topic Contested in court

Liability

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Legal responsibility for GDPR violations and damages

178 linked items 11 Laws63 Case Law18 Guidance32 Enforcement31 News

Overview

28 sources · Sep 25, 2026

Legal Framework

Article 82 GDPR is the governing provision for compensation and liability allocation. Under Article 82(1), any person who has suffered material or non-material damage as a result of a GDPR infringement may claim compensation from the controller or processor responsible.

"Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered."
— GDPR Art. 82(1)

The liability regime draws a critical distinction between controllers and processors. Article 82(2) makes a controller liable for damage caused by any infringing processing, whereas a processor's liability is narrower—attaching only where it failed to comply with processor-specific obligations or acted outside or contrary to lawful instructions. Both controllers and processors may invoke the exemption under Article 82(3), which shifts the burden of proof to the defendant:

"A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage."
— GDPR Art. 82(3)

Where multiple parties participate in the same processing, Article 82(4) imposes liability for the entire damage on each responsible party, with a corresponding right of recourse under Article 82(5) based on respective shares of responsibility.

Key Developments

Enforcement decisions confirm that inadequate technical and organisational measures directly generate liability exposure. In the Permanent TSB enforcement action, the Irish DPA linked organisational failures to concrete vulnerability of data subjects, reinforcing that supervisory authorities treat the severity and likelihood of harm as key parameters when assessing consequences of infringement.

"A breach can potentially have a range of significant adverse effects on individuals, which can result in physical, material, or non-material damage."
— EDPB Guidelines 9/2022 §24

National DPAs have imposed substantial fines where controllers failed to prevent such damage: the Lithuanian DPA fined two medical companies €450,000 following data breaches involving unauthorised access to internal systems, while the Croatian DPA fined a gas station operator €940,000. These decisions signal that both the number of affected individuals and the level of damage suffered inform supervisory assessment of liability consequences.

Status of the Debate

This topic is contested in court. While Article 82 provides a structured liability framework, member state courts diverge on key thresholds—particularly the standard for proving causation between an infringement and actual damage, and the precise scope of the Article 82(3) exemption. The CJEU has addressed adjacent questions in Mousse (C-394/23) regarding legitimate interests and risk to data subjects, but has not yet ruled definitively on the boundaries of the Article 82 liability regime. No court split has been formally resolved through a preliminary reference on the meaning of "not in any way responsible" or on whether non-material damage requires concrete manifestation. A CJEU reference on those questions would settle the most pressing open issues.

Practical Guidance

  • Document accountability for each processing operation: Controllers bear broader liability under Article 82(2) than processors; maintain records demonstrating lawfulness and adequacy of measures to support a potential Article 82(3) exemption defence.
  • Allocate liability precisely in processor contracts: Under Article 82(5), a party paying full compensation may reclaim from co-responsible parties; contracts should pre-define responsibility shares to streamline recourse claims.
  • Maintain evidence of compliance for the Article 82(3) exemption: The burden of proving non-responsibility rests on the controller or processor; risk assessments, security audit logs, and incident response records are essential to discharge that burden.
  • Assess damage severity proactively following breaches: EDPB guidelines and national enforcement confirm that both the number of affected individuals and the level of damage suffered inform supervisory action; breach impact assessments should document both dimensions.
  • Prepare for joint liability scenarios: Where multiple controllers or processors share a processing activity, Article 82(4) makes each liable for the entire damage; contractual indemnities should reflect this exposure.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 82 Right to compensation and liability Laws GDPR Apr 2016 damages and liability allocation
why this is here
Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation

The provision directly establishes the core liability regime for GDPR violations, including who is liable, exemptions, joint liability, and recourse among parties, which are the central elements of the liability topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Guidance EDPB Apr 2023 consequences of failure to notify
why this is here
Where an administrative fine is chosen, its value can be up to 10,000,000 EUR or up to 2 % if the total worldwide annual turnover of an undertaking under Article 83(4)(a) of the GDPR.

The document mentions fines and sanctions for failure to notify, which touches on liability, but it does not discuss the broader legal responsibility or compensation for GDPR violations.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Accountability principle allocation
why this is here
the controller shall be responsible for the compliance with the principles set out in Article 5(1) GDPR

The document mentions responsibility for compliance but does not discuss liability for damages or compensation between parties.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Measures to protect rights, not liability
why this is here
the measures and safeguards should be designed to be robust and the controller should be able to implement further measures in order to scale to any increase in risk

The document discusses implementing measures to protect data subjects' rights, which could indirectly affect liability, but does not directly address liability rules or compensation for GDPR violations.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Guidance EDPB Apr 2023 Liability through other rights
why this is here
may facilitate the exercise of their rights flowing from, for example, Art. 16 to 19, 21 to 22 and 82 GDPR

The document mentions Article 82 GDPR in the context of the right of access facilitating other rights, but does not analyze liability or compensation provisions.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

An analysis of Dutch case law: what factors play a role in awarding (or not) and determining the extent of damages under the GDPR? ⇄ Since May 2018, the GDPR has been directly applicable in the European Economic Area, including the member states of the European Union, Liechtenstein, Norway, and Iceland. Four… News News Nov 2022 liability and compensation for damages
why this is here
heeft het recht om van de verwerkingsverantwoordelijke of de verwerker schadevergoeding te ontvangen voor de geleden schade

The document directly analyzes the liability framework for damages under Article 82 GDPR, including which parties can be held liable and the conditions for compensation.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

€2,560 T.K. EOOD: Insufficient technical and organisational measures to ensure information security The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data of data subject I.S. by failure to adopt technical and organizational measures to… BULGARIA ·CPDP ·Art. 25, 32 Enforcement Data Protection Commision of Bulgaria (KZLD) Feb 2020 fine imposed for breach
why this is here
The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data

The sanction demonstrates legal responsibility for GDPR violations, though the document does not detail liability doctrines or compensation mechanisms.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

European Commission introduces AI liability redress proposal > The European Commission adopted a proposal for harmonizing rules around consumer redress in the Artificial Intelligence Liability Directive. The proposed rules will allow… News European Commission Sep 2022 damages liability for AI-related harm
why this is here
proposed rules will allow consumers to bring claims for damages

The document directly addresses liability for damages caused by AI, which is the core of the 'aansprakelijkheid' topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Is the new ICT vendor liable for loss of data from old ICT environment? District Court of North Holland February 15, 2023, IT 4241; ECLI:NL:RBNHO:2023:2471 (Pit v. OfficeGrip Holding c.s.) This case deals with the question of whether a new ICT… News IT en Recht Mar 2023 ICT supplier liability for data loss
why this is here
the new ICT supplier cannot be held liable for any damages suffered by the client as a result of data loss from the old ICT environment

This case directly addresses liability for damages from data loss, though it is general contractual liability rather than GDPR-specific liability. It is a primary source on liability for data loss in an ICT context.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€16,600 Garðabær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Garðabær. The municipality had used the Google Education system without sufficiently complying with data… ICELAND ·Persónuvernd ·Art. 5, 24, 28 Enforcement Icelandic data protection authority ('Persónuvernd') Dec 2023 Fine for non-compliance
why this is here
The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Garðabær.

The document reports a fine but does not discuss liability principles or compensation; it is incidental to the penalty imposed.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€18,600 City of Hafnarfjörður: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Persónuvernd ·Art. 5, 24, 28 Enforcement Icelandic data protection authority ('Persónuvernd') Dec 2023 fine imposed by DPA
why this is here
The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður.

The document concerns enforcement action and a fine, but does not discuss liability doctrines, compensation to data subjects, or fault allocation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€12,950 Sports association: Insufficient legal basis for data processing One sports association published personal data referring to judges who were granted judicial licenses online. However, not only their names were provided, but also their exact… POLAND ·UODO ·Art. 6 Enforcement Polish National Personal Data Protection Office (UODO) Apr 2019 fine penalty for breach
why this is here
the fact that attempts to remove it were ineffective determined the imposition of a penalty

The document discusses a fine imposed, touching on liability aspects, but focuses on processing without legal basis rather than damages or compensation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 63 Case Law · all 32 Enforcement · all 23 Literature · all 31 News