Skip to content
Call, 0511 – 47 55 58 11

Damages under Article 82 GDPR

The infringement is one of three conditions and does not prove the damage. Conversely, loss of control suffices as damage, so a defence as a rule does not start with whether there is damage but with how much.

A letter is in the inbox. It names an incident, identifies an infringement and demands a sum, often through a lawyer and sometimes for several data subjects at once. The deadline in it is short.

The first reflex goes in one of two directions, and both are expensive. Paying for peace creates a reference point for the letters that follow. Rejecting the claim wholesale gives up the objections that matter.

The infringement is one of three conditions

What the other side can actually demand turns on what the letter does not establish. The Court of Justice of the European Union has repeatedly held that an infringement does not in itself constitute damage (4 October 2024, C-507/23).

  1. Condition 1: Infringement

    An infringement of the Regulation. This is usually the only point a letter of claim sets out.

  2. Condition 2: Damage

    Material or non-material damage that actually arose. It falls to the data subject to establish it.

  3. Condition 3: Causal link

    The damage must result from that very infringement. Where data was taken from several sources, this is the weakest point of the claim.

The three conditions are cumulative and at the same time exhaustive. A further requirement, such as an unjustified interference with the protected interest, cannot be placed alongside them.

Loss of control suffices as damage, the expectation as to the amount does not

Whether the sum demanded is realistic is not decided by whether damage arose, since the threshold there is low. On 18 November 2024 the Federal Court of Justice held that even the mere and short-lived loss of control over one’s own data can be non-material damage, without misuse and without further tangible consequences (VI ZR 10/24).

What the claim rests on

  • Loss of control over the data concerned
  • Well-founded fear of future use
  • Demonstrable material disadvantage, such as effort spent averting loss

What does not carry the amount

  • The gravity of the infringement taken on its own
  • The turnover or size of the controller
  • Attitude and motives, which belong to Article 83 GDPR
  • An uplift for deterrence

The end of a processing engagement is the overlooked source of claims

Where a claim comes from that nobody reckoned with is shown by a decision of 11 November 2025. On the ending of a processing engagement too, the controller has to ensure that no data remains with the processor, and has to contribute what is required to that end (VI ZR 396/24). Where data left behind is later taken from the processor and offered for sale on the darknet, that is damage, and it remains so even where the same data had already been taken unlawfully before.

Article 28(3)(g) GDPR requires erasure or return after the end of the services. Contract wording alone does not discharge it, because what is owed is a contribution to the actual result.

  1. 04.05.2023

    CJEU C-300/21

    Three cumulative conditions, and damage is a potential rather than an automatic consequence.

  2. 20.06.2024

    CJEU C-182/22

    Where severity is lacking, a minor amount suffices for full compensation.

  3. 04.10.2024

    CJEU C-507/23

    The infringement alone is not damage. The function of the claim is exclusively compensatory.

  4. 18.11.2024

    BGH VI ZR 10/24

    The mere and short-lived loss of control can be non-material damage.

  5. 11.11.2025

    BGH VI ZR 396/24

    The controller’s duty extends to actual erasure at the processor.

What belongs in the reply to the letter

How the demand is to be answered is decided before the first line, because every statement will be read in any later proceedings.

Where the damage lies at the lower end, an apology comes into consideration as compensation, provided it compensates the damage in full. It does not serve as a tactical concession, but it does serve as a gauge of the order of magnitude the case moves in.

How we help

Not covered here is the claim from the data subject’s side. In these matters we act for controllers.

A demand has arrived, and the clock is running?

Get in touch before anything is answered. The first reply binds further than intended.

Have the claim reviewed

Frequently asked questions

What order of magnitude has to be expected?

There is no table, and the Court of Justice expressly left the matter to the member states. The direction is settled: Article 82 GDPR has an exclusively compensatory function, a punitive element is ruled out, and where the damage lacks severity a minor amount suffices. The attitude and motives of the controller are left out of account, because those criteria belong to Article 83 GDPR and the administrative fine.

Can we argue that no damage arose at all?

Rarely with success. On 18 November 2024 the Federal Court of Justice held that even the mere and short-lived loss of control over one's own data can be non-material damage, without any misuse and without further tangible consequences (VI ZR 10/24). The objection has a prospect where the loss of control is itself doubtful, for instance because the data never left the circle of recipients.

Does an apology suffice?

It comes into consideration. On 4 October 2024 the Court of Justice held that an apology can constitute adequate compensation, provided it is capable of compensating the damage in full (C-507/23). That presupposes damage at the lower end. Its legal significance lies above all in showing what the assessment is oriented towards.

When are we not liable?

Under Article 82(3) GDPR liability falls away where the controller proves it is not in any way responsible for the event giving rise to the damage. The threshold is high and the burden of proof is ours. In practice it turns on the documentation of the measures taken, which had to exist at the time of the incident.

Are we liable for the processor?

For our own selection and supervision, and beyond that for what happens at the end of the engagement. On 11 November 2025 the Federal Court of Justice held that the controller has to contribute what the circumstances require so that the data is returned or erased when the engagement ends (VI ZR 396/24). Contract wording alone does not achieve that.

Related