# Compensation Mechanisms and Remedies — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/compensation-mechanisms-dsa-ai
> Sources are cited per item. Verify against the official texts before relying on them.

The content specifically addresses 'Compensation' as a standalone topic from the DSA, which requires dedicated coverage for compensation procedures, eligibility criteria, calculation methods, and enforcement mechanisms for both individual and collective remedies.

## Overview

## Legal Framework

Article 54 DSA establishes a standalone right to compensation, entitling any natural or legal person that has suffered damage due to an infringement of the Regulation by an intermediary service to claim compensation from the provider. This provision operates alongside existing national liability frameworks without prejudice to other Union law remedies (AI Act Recital 170). Article 60 DSA imposes mutual obligations on Digital Services Coordinators and the Commission to exchange all relevant information and make utmost efforts to reach consensus when handling cross-border matters, though Guidelines 02/2022 clarify this does not require consensus in every individual case (par. 39). Recital 64 DSA further clarifies that platform suspension powers for illegal content must be transparently detailed in terms of service, ensuring users understand available remedies including compensation pathways.

## Key Developments

The CJEU in *Nikolaou v Commission* established critical burden-of-proof principles applicable to compensation claims: while claimants normally bear the burden of proving illegal action, damages, and causation, this burden shifts to the defendant institution when the damage could result from various causes and the institution controls the relevant evidence. *College van burgemeester en wethouders van Rotterdam v Rijkeboer* (C-553/07) requires that limitations on information storage periods strike a fair balance between data protection rights and compensation claimants' interests, rejecting arbitrary retention limits that impede evidence preservation necessary for establishing damages. Recent enforcement by the Italian DPA (Autostrade per l'Italia, €1,000,000) and Polish DPA (PIONIER, €9,600) demonstrates that inadequate data preservation practices affecting evidentiary chains attract significant penalties, establishing practical thresholds for record-keeping in liability contexts. The ongoing proceedings OGS Zagreb (Pn-877/2023-29) and OLG Bamberg (10 U 61/25 e) indicate continued judicial refinement of these standards.

## Practical Guidance

• **Preserve evidentiary records** for periods sufficient to satisfy compensation claims under Article 54 DSA, ensuring retention policies reflect the *Rijkeboer* fair balance test rather than arbitrary deletion schedules that could destroy evidence of causation or damages.  
• **Document causal chains** meticulously when platform conduct may give rise to liability, recognizing that under *Nikolaou* principles, gaps in evidence controlled by the platform may shift the burden of proof regarding damages.  
• **Exchange authority information** promptly when compensation claims involve cross-border elements, complying with Article 60 DSA and Guidelines 02/2022 by providing Digital Services Coordinators with all relevant case materials to facilitate consensus-building efforts.  
• **Detail remedy procedures** transparently in terms of service as required by Recital 64 DSA, specifically outlining suspension measures and compensation pathways for users affected by content moderation decisions.  
• **Integrate complaint mechanisms** that satisfy AI Act Recital 170 standards, ensuring users can lodge complaints with market surveillance authorities as a procedural step that preserves their position for subsequent compensation claims under Article 54 DSA.

## Recent developments

### De Europese Commissie presenteert een voorstel voor een regeling over aansprakelijkheid bij schade veroorzaakt door kunstmatige intelligentie.

*Source: European Commission, 2022-09-28 — https://overview.legal/posts/51811*

De Europese Commissie heeft een voorstel aangenomen om de regels te harmoniseren met betrekking tot de compensatie van consumenten in de Richtlijn over aansprakelijkheid voor kunstmatige intelligentie. De voorgestelde regels maken het consumenten mogelijk om schadeclaims in te dienen voor schade die "veroorzaakt is door onrechtmatig gedrag" met behulp van AI-technologieën. De Commissie heeft aangegeven dat de basis voor dergelijke claims onder meer "schendingen van de privacy of schade veroorzaakt door veiligheidsproblemen" kan omvatten, en tegelijkertijd opgemerkt dat claims ook kunnen worden ingediend "als iemand gediscrimineerd is tijdens een wervingsproces waarbij AI-technologie wordt gebruikt."

### European Commission introduces AI liability redress proposal

*Source: European Commission, 2022-09-28 — https://overview.legal/posts/6268 — original: https://ec.europa.eu/commission/presscorner/detail/en/ip%5F22%5F5807#entry-823*

> The European Commission adopted a proposal for harmonizing rules around consumer redress in the Artificial Intelligence Liability Directive. The proposed rules will allow consumers to bring claims for damages "caused due to wrongful behaviour" with AI technologies. The Commission said the basis for claims could include "breaches of privacy, or damages caused by safety issues," while also noting claims can be brought "if someone has been discriminated in a recruitment process involving AI techn

### Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations

*Source: Hunton Andrews Kurth, 2022-09-07 — https://overview.legal/posts/6284 — original: https://www.huntonprivacyblog.com/2022/09/07/irish-data-protection-commissioner-fines-instagram-for-children-privacy-violations/#entry-216*

> The fine is the result of an investigation that began in 2020 and focused on the company’s processing of children’s personal data. Based on press reports, the investigation focused on children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts. As a result, children’s phone numbers and email addresses were publicly accessible.

### De Ierse autoriteit voor gegevensbescherming heeft Instagram een boete van 405 miljoen euro opgelegd vanwege schendingen van de privacy van kinderen.

*Source: Hunton Andrews Kurth, 2022-09-07 — https://overview.legal/posts/51825*

De boete is het resultaat van een onderzoek dat in 2020 is begonnen en zich richtte op de manier waarop het bedrijf persoonlijke gegevens van kinderen verwerkte. Op basis van berichten in de media richtte het onderzoek zich op kinderen tussen de 13 en 17 jaar oud die toestemming hadden om zakelijke of creatieve Instagram-accounts te gebruiken. Hierdoor waren telefoonnummers en e-mailadressen van kinderen openbaar toegankelijk.

### CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR

*Source: Hunton Andrews Kurth, 2022-08-05 — https://overview.legal/posts/6291 — original: https://www.huntonprivacyblog.com/2022/08/17/cnil-proposes-60-million-euros-fine-against-french-adtech-company-for-non-compliance-with-gdpr/#entry-12*

> The proposed fine follows complaints filed by privacy NGO ‘Privacy International’ against Criteo. […]
Under the CNIL’s sanction procedure, Criteo has the right to respond to the report, both with respect to the alleged infringements and the proposed sanction.

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **AI Act Violations** — https://overview.legal/topics/non-compliance-violations-ai-act
  The content specifically addresses 'Non-compliance' as a distinct legal concept under the DSA/AI Act framework. This requires a dedicated topic to comprehensive
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data
- **Liability** — https://overview.legal/topics/aansprakelijkheid
  Legal responsibility for GDPR violations and damages
- **DPIA** — https://overview.legal/topics/dpia
  Data Protection Impact Assessment - systematic evaluation of processing risks
- **Fairness & Transparency** — https://overview.legal/topics/fairness-transparency-principle
  Fairness and transparency are co-principles with lawfulness in Article 5(1)(a) GDPR and are inseparable from the concept of lawful processing, deserving dedicat

---
Generated by overview.legal · https://overview.legal/topics/compensation-mechanisms-dsa-ai · 2026-08-22
