Showing posts with label art 82. Show all posts
Showing posts with label art 82. Show all posts

Thursday, 26 March 2026

Construction of art 82 (1) GDPR: Case C‑590/22 AT and another v PS GbR and others

Wesel Court House
Author KingKurt  Licence CC BY-SA 4.0  Source Wikimedia Commons

 











Jane Lambert

Court of Justice of the European Union (K. Jürimäe, President of the Chamber, K. Lenaerts, President of the Court, N. Piçarra, N. Jääskinen (Rapporteur) and M. Gavalec, Judges) Case C‑590/22 AT and another v PS GbR and others ECLI:EU: C:2024:536, [2024] EUECJ C-590/22, EU: C:2024:536

This was a request by the Wesel Amtsgericht for a preliminary ruling on the interpretation of art 82 (1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ 2016 L 119, p. 1) (‘the GDPR’) pursuant to art 267 of the Treaty on the Functioning of the European Union.  The request was made in proceedings between AT and BT against PS Gesellschaft bürgerlichen Rechts ("PS GbR") and its members for compensation for the disclosure of their personal data to third parties without their consent as a result of an error by the firm.

The Proceedings

PS GbR was a tax consultancy, and AT and BT were two of its clients.  AT and BT instructed PS GbR to draw up their tax return.  The consultancy carried out their instructions but sent the return to AT and BT's previous address.  AT and BT recovered the envelope that had contained the tax return but found that it contained only a covering letter and a copy of the return.  The missing documents contained the names, dates of birth, tax identification numbers, religious denominations, bank details, professions, places of work and disability status of AT and BT, as well as their children's personal data.  AT and BT sued PS GbR and its members for €15,000 compensation in the Wesel Amtsgericht, the lowest civil court in the German legal system.

The Reference

The court decided that it could not decide the claim without referring the following questions to the Court of Justice of the European Union:

"(1) Is it sufficient for the establishment of a claim for compensation under Article 82 (1) of [the GDPR] that a provision of [that regulation] serving to protect the claimant has been infringed or is it necessary that a further adverse effect on the claimant has occurred, beyond the infringement of the provision as such?
(2) Under EU law, does the establishment of a claim for compensation for non-material damage under Article 82 (1) of the GDPR require an adverse effect of a certain magnitude?
(3) In particular, is it sufficient for the establishment of a claim for compensation for non-material damage under Article 82(1) of the GDPR that the claimant fears that his or her personal data have come into the hands of third parties as a result of infringements of provisions of the GDPR, even though that circumstance cannot be positively established?
(4) Is it in conformity with EU law for the national court to apply mutatis mutandis the criteria of the second sentence of Article 83 (2) of the GDPR - which, according to the wording, apply only to administrative fines - when assessing compensation for non-material damage under Article 82 (1) of the GDPR?
(5) Must the amount of a claim for compensation for non-material damage under Article 82 (1) of the GDPR also be assessed by reference to the fact that the amount of the claim awarded serves to have a deterrent effect and/or to prevent the “commercialisation” (calculated acceptance of administrative fines/compensation payments) of infringements?
(6) Is it in conformity with EU law, when assessing the amount of a claim for compensation for non-material damage under Article 82(1) of the GDPR, to take into account simultaneous infringements of national provisions which have as their purpose the protection of personal data but which are not delegated or implementing acts adopted in accordance with that regulation or Member State laws [specifying rules] of that regulation?’

Legislative Context

The CJEU considered recitals (85), (146) and (148) and  arts 4 (1), (7), (10) and (12), 79 (1) and 83 (3) and (5) of the GDPR as well as the following paragraphs of art 82:

"1. Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.
2. Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.
3. A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.
......."

Judgment

The CJEU delivered judgment on 20 June 2024 (Case C‑590/22 AT and another v PS GbR and others ECLI:EU: C:2024:536, [2024] EUECJ C-590/22, EU: C:2024:536).

The First and Second Questions

The Court took the 1st and 2nd questions together.  In its view, the Amstgericht was asking whether art 82 (1) should be interpreted as meaning that the mere infringement of the GDPR would be sufficient to give rise to compensation or whether a claimant had also to show that the infringement had led to damage of a sufficient degree of seriousness.  

The CJEU has already held in para [32] of Case C‑300/2 UI v Österreichische Post AG [2023] WLR(D) 221, EU: C:2023:370, [2023] EUECJ C-300/21, ECLI: EU: C:2023:370 and para [34] of Case C‑741/21, GP v juris GmbH [2024] EUECJ C-741/21, ECLI: EU: C:2024:288, EU: C:2024:288 that it is clear from the wording of the article that the existence of ‘damage, whether material or non-material, constitutes one of the conditions for compensation under art 82 (1).  So, too, does the existence of an infringement and of a causal link between that damage and the infringement.  The three conditions are cumulative.

It follows that it cannot be held that any ‘infringement’ of the provisions of the GDPR, by itself, confers a right to compensation.  The answer to question 1 is that art 82 (1) of the GDPR must be interpreted as meaning that the mere infringement of the provisions of that regulation is not sufficient to confer a right to compensation.

The Third Question

The 3rd question was reframed as to whether art 82 (1) should be interpreted as meaning that a data subject's fear that his or her personal data had been disclosed to third parties without any certainty as to whether that had actually happened is sufficient to give rise to a claim for non-material damage under that article.  

Citing paras [30] and [44] of UI v Österreichische Post AG and para [64] of Case C‑687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH, [2024] 1 WLR 2597, [2024] EUECJ C-687/21, ECLI: EU: C:2024:72, EU: C:2024:72, [2024] WLR(D) 53, the CJEU noted that the concept of ‘non-material damage’, within the meaning of art 82 (1), must be given an autonomous and uniform definition specific to EU law.  

The Court has already held in Case C‑340/21VB v Natsionalna agentsia za prihodite EU: C:2023:986, ECLI:EU: C:2023:986, [2024] WLR(D) 17, [2023] EUECJ C-340/21 and BL v MediaMarktSaturn Hagen-Iserlohn GmbH that the fear experienced by a data subject with regard to a possible misuse of his or her personal data by third parties as a result of an infringement of that regulation is capable, in itself, of constituting ‘non-material damage’, within the meaning of art 82 (1).  It added that the loss of control over personal data, even for a short period of time, may constitute ‘non-material damage’, within the meaning of art 82 (1), giving rise to a right to compensation, provided that the data subject can show that he or she has actually suffered such damage, however slight.

A person who considers that his or her personal data has been processed in breach of the relevant provisions of the GDPR and seeks compensation on the basis of art 82 (1)  must therefore prove that he or she has actually suffered material or non-material damage.  However,  a mere allegation of fear, with no proven negative consequences, cannot give rise to compensation.

The CJEU concluded at para [36] that the answer to the 3rd question is that art 82 (1) must be interpreted as meaning that a person’s fear that his or her personal data have, as a result of an infringement of that regulation, been disclosed to third parties, without it being possible to establish that that was in fact the case, is sufficient to give rise to a right to compensation, provided that that fear, with its negative consequences, is duly proven.

The Fourth and Fifth Questions

In the 4th and 5th questions the Amtsgericht asked whether art 82 (1) should be interpreted as meaning that, to determine the amount of damages due as compensation for damage based on that provision, it is necessary, to apply the criteria for setting the amount of administrative fines laid down in art 83 mutatis mutandis and that a dissuasive function be conferred on the right to compensation.  The CJEU observed that arts 82 and 83 pursue different objectives. While art 83 determines the "general conditions for imposing administrative fines", art 82 governs the "right to compensation and liability."   The criteria set out in art 83 for the purposes of determining the amount of administrative fines cannot be used to assess the amount of damages under art 82 thereof (see para [57] ) of C‑741/21, GP v juris GmbH).  The answer to the 4th and 5th questions is that art 82 (1) must be interpreted as meaning that, in order to determine the amount of damages due as compensation for damage based on that provision, it is not necessary, first, to apply mutatis mutandis the criteria for setting the amount of administrative fines laid down in art 83, and, second, to confer on that right to compensation a dissuasive function.

The Sixth Question

In its 6th question, the Amtsgericht was asking whether art 82 (1) must be interpreted as meaning that, to determine the amount of damages due as compensation for damage based on that provision, account must be taken of simultaneous infringements of national provisions relating to the protection of personal data, but not intended to specify the rules of that regulation.  The Court ruled that it was not necessary to take account of simultaneous infringements of national provisions that relate to the protection of personal data, but which are not intended to specify the rules of that regulation.

The Ruling

The CJEU ruled as follows:
"1. Article 82 (1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), must be interpreted as meaning that an infringement of that regulation is not, in itself, sufficient to give rise to a right to compensation under that provision. The data subject must also establish the existence of damage caused by that infringement, without, however, that damage having to reach a certain degree of seriousness.
2. Article 82 (1) of Regulation 2016/679 must be interpreted as meaning that a person’s fear that his or her personal data have, as a result of an infringement of that regulation, been disclosed to third parties, without it being possible to establish that that was in fact the case, is sufficient to give rise to a right to compensation, provided that that fear, with its negative consequences, is duly proven.
3. Article 82 (1) of Regulation 2016/679 must be interpreted as meaning that, in order to determine the amount of damages due as compensation for damage based on that provision, it is not necessary, first, to apply mutatis mutandis the criteria for setting the amount of administrative fines laid down in Article 83 of that regulation and, second, to confer on that right to compensation a dissuasive function.
4. Article 82 (1) of Regulation 2016/679 must be interpreted as meaning that, in order to determine the amount of damages due as compensation for damage based on that provision, it is not necessary to take account of simultaneous infringements of national provisions which relate to the protection of personal data but which are not intended to specify the rules of that regulation."

Comment

As this ruling was delivered after IP completion day, courts in England and Wales, Scotland and Northern Ireland are not bound by it or the principles contained in this judgment.  However, s.6 (2) of the European Union (Withdrawal) Act 2018, as amended, permits courts in those jurisdictions to have regard to it insofar as it is relevant to any matter before them.   This judgment will therefore be cited and considered in cases on the meaning and effect of art 82 of the UK GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)).

Anyone wishing to discuss this case may call me on +44 (0)20 7404 5252 or send me a message through my contact form.

Friday, 20 March 2026

Data Protection Litigation: Pre-action Protocol for Media and Communications Claims

Jane Lambert

 


















There has recently been a surge in claims by individuals seeking to enforce their rights under data protection legislation through litigation.  I have appeared in two such claims this week, one in London and another in the Thames Valley.  I have also advised in writing and in conference on several more. A surprising aspect of the surge is that the United Kingdom General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 are much more complicated than the Data Protection Act 1998 and the Data Protection Act 1984, which preceded them. Those Acts also provided rights of action, but they were used much less frequently than the present legislation.  Another surprise is the infrequency with which parties refer to the Pre-action Protocol for Media and Communications Claims, even though that protocol applies to all data protection claims.  In both of the cases in which I appeared this week, observance of the protocol would have made a significant difference to the outcome of the litigation.  

Effective Judicial Remedy
Art 79 (1) of the UK GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) as modified by The Data Protecion, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019) entitles data subjects to an effective judicial remedy if they consider that their rights under the Regulation have been infringed as a result of the processing of their personal data in non-compliance with the regulation.  That includes a right under art 82 (1) to compensation from a controller or processor for any material or non-material damage that may arise as a result of such non-compliance.

Pre-action Protocols
Para 1 of Practice Direction - Pre-action Conduct and Protocols states that pre-action protocols explain the conduct and set out the steps the court would normally expect parties to take before commencing proceedings for particular types of civil claims. Para 2 warns that a person who knowingly makes a false statement in a pre-action protocol letter or other document prepared in anticipation of legal proceedings may be subject to proceedings for contempt of court.  Para 3 states that the objectives of pre-action conduct and protocols are to enable parties to disputes to:
"(a) understand each other’s position;
(b) make decisions about how to proceed;
(c) try to settle the issues without proceedings;
(d) consider a form of Alternative Dispute Resolution (ADR) to assist with settlement;
(e) support the efficient management of those proceedings; and
(f) reduce the costs of resolving the dispute."

Para 4 stresses that a pre-action protocol must not be used by a party as a tactical device to secure an unfair advantage over another party. Only reasonable and proportionate steps should be taken by the parties to identify, narrow and resolve the legal, factual or expert issues.  Para 5 adds that disproportionate costs in complying with any pre-action protocol are likely to be irrecoverable.  Para 6 states that where there is a relevant pre-action protocol, the parties should comply with it before commencing proceedings.  Para 8 reminds parties that litigation should be a last resort. As part of a relevant pre-action protocol, the parties should consider whether negotiation or some other form of ADR might enable them to settle their dispute without commencing proceedings.

Non-compliance with a protocol can be penalized in several ways.  For example, para 16 states that a party at fault may be ordered to pay costs on an indemnity basis or a successful party may be deprived of some or all of his or her costs.

Pre-action Protocol for Media and Communications Claims
Although it is not listed among the "Protocols in Force" in para 18 of PD-Pre-action Conduct and Protocols, para 1.1 of the Pre-action Protocol for Media and Communications Claims states that it applies to data protection claims, including those brought by litigants in person. If a party to a claim becomes aware that another party is a litigant in person, he or she should send a copy of the protocol to the litigant in person at the earliest opportunity.

The aims of the protocol listed in para 2.1 are similar to those of the practice direction, namely enabling parties to prospective claims to:
"(a) understand and properly identify the issues in dispute and to share information and relevant documents;
(b) make informed decisions as to whether and how to proceed;
(c) try to settle the dispute without proceedings or reduce the issues in dispute;
(d) avoid unnecessary expense and control the costs of resolving the dispute; and
(e) support the efficient management of proceedings where court proceedings cannot be avoided."

Para 3.1 requires intending claimants to notify intended defendants of their claims in writing at the earliest reasonable opportunity.   They are also reminded of the need for proportionality in formulating both the letter of claim and response in para 2.2:

"In formulating both the Letter of Claim and Response and in taking any subsequent steps, the parties should act reasonably to keep costs proportionate to the nature and gravity of the case and the stage the complaint has reached."

The following information should be included in the letter of claim: 

  • the name of the claimant;
  • the nature of and basis for the entitlement to the remedies sought by the claimant;
  • any facts or matters relevant to England and Wales being the most appropriate forum for the dispute; and
  • details of any funding arrangement in place.
Para 3.4 adds that letters of claim in data protection cases should also include:

  •  "any further information necessary to identify the data subject;
  • the data controller to which the claim is addressed;
  • the information or categories of information which is claimed to constitute personal data including, where necessary, the information which is said to constitute sensitive personal data or to fall within a special category of personal data;
  • sufficient details to identify the relevant processing;
  • the identification of the duty or duties which are said to have been breached and details of the manner in which they are said to have been breached, including any positive case on behalf of the Claimant;
  • why the personal data ought not to be processed/further processed, if applicable;
  • the nature and any available details as to any particular damage caused or likely to be caused by the processing/breach of duty complained of; and
  • Where a representative data protection claim is intended to be brought on behalf of data subjects, the letter of claim should also: set out the nature of the entity which intends to bring the claim and explain how it fulfils the relevant suitability criteria – see Article 80 of the General Data Protection regulation (GDPR); include details of the data subjects on whose behalf the claim would be brought; and, confirmation that they have mandated the representative body to represent them and receive compensation, where applicable."
Defendants are required by para 3.6 to provide a full response to the letter of claim, as soon as reasonably possible. If a defendant believes that he or she will be unable to respond within 14 days (or such shorter time limit as specified in the letter of claim), then he or she should specify the date by which he/she intends to respond.

Para 3.7 requires letters of response to include:

  • "whether or to what extent the Claimant’s claim is accepted, whether more information is required or whether it is rejected;
  • if the claim is accepted in whole or in part, the Defendant should indicate which remedies it is willing to offer;
  • if more information is required, then the Defendant should specify precisely what information is needed to enable the claim to be dealt with and why;
  • if the claim is rejected, then the Defendant should explain the reasons why it is rejected, including a sufficient indication of any statutory exemptions or facts on which the Defendant is likely to rely in support of any substantive defence;
  • in a defamation or malicious falsehood claim, the defamatory or false imputation(s) the Defendant contends was conveyed by the statement complained of, if any; and
  • where the Claimant to a proposed action has indicated his/her intention to make an application to bring the claim anonymously, the Defendant should indicate whether the Defendant accepts such an order would be appropriate and give an indication of the basis for the Defendant’s position."
Para 3.8 reminds parties that litigation should be a last resort, while para 3.9 suggests the following options for parties to data protection disputes:

"(a) without prejudice discussions and negotiations between the parties;
(b) mediation – a form of facilitated negotiation assisted by an independent neutral third party; [and]
(c) early neutral evaluation (ENE) – a third party giving an informed opinion on the dispute (for example, a lawyer experienced in the field of [data protection] or an individual experienced in the subject matter of the claim)......."

Para 3.10 mentions the need to consider offers under CPR Part 36.  If a dispute is not settled, para 3.11 encourages parties to undertake a further review of their respective positions, to consider the state of the papers and the evidence in order to see if proceedings can be avoided and, at least, narrow the issues between them which can assist efficient case management.  

Finally, parties are referred to other provisions which they might find useful, such as CPR Part 25: Interim Remedies and Security for Costs and CPR PD48 paragraphs 3.1 and 3.2: Part 2 of the Legal Aid, Sentencing and Punishment of Offenders Act 2012 Relating to Civil Litigation Funding and Costs.

Further Information
Anyone wishing to discuss this article further may call me on 020 7404 5252 during UK office hours or send me a message through my contact form at any time.

Wednesday, 7 February 2018

Judicial Remedies under the GDPR and other Data Protection Legislation

Jane Lambert











A lot of attention has focused on the massive increase in the Information Commissioner's and other supervisory authorities' power to fine under art 83 (4) and (5) of the GDPR but she acquires no new powers to compensate.  If a data subject requires compensation from a data controller or processor under art 82 (1) or some other judicial remedy pursuant to art 79, he or she will have to sue.

The Data Protection Bill, which has now completed its passage through the Lords and is now awaiting its second reading in the House of Commons, makes provision for that judicial remedy.  The courts of the United Kingdom are to have the power to make compliance orders under clause 165 and award compensation under clause 166 and clause 167.

Clause 165 (2) defines a compliance order as
"an order for the purposes of securing compliance with the data protection legislation which requires the controller in respect of the processing, or a processor acting on behalf of that controller—
(a) to take steps specified in the order, or
(b) to refrain from taking steps specified in the order."
This would seem to include an order by the court to a data controller to comply with a subject access request under clause 94 (11), an order not to process personal data under clause 99 (5) and rectification and erasure under clause 100 (4). Though there is no specific provision in the Bill for the court to restrain the transfer of personal data abroad under clause 109 (1) or to order a controller to take steps to implement the data protection principles or minimize the risks to the rights and freedoms of data subjects under clause 103 (2) there seems to be no reason why it should not do so.

As I mentioned in Claims by Data Subjects against Data Controllers and Processors under the GDPR 5 Jan 2018, the provisions relating to subject access, rectification and erasure stipulate that the High Court of England and Wales has exclusive jurisdiction to make such orders. However, there seems to be a contradiction in that clause 177 (1) and (2) seems to suggest that compliance orders as well as compensation may be awarded by the County Court as well as the High Court.

Clause 166 (1) provides for compensation for material or non-material damage including distress under art 82 GDPR for contravention of that regulation and clause 167 (1)  for compensation for material or non-material damage including distress under any other data protection legislation.

In future articles I shall discuss pleading claims  for judicial remedies for alleged breaches of the GDPR and other legislation and possible defences.  Anyone wishing to discuss this article should call me on 020 7404 5252 during office hours or send me a message through my contact form.