Data breach: can you get compensation?
Your data leaked through a company's fault? The GDPR right to compensation, what you must prove, and your options (alone or in a collective action).
A company that fails to protect your data may have to compensate the harm you suffer. The right exists, but it comes with precise conditions: it is worth knowing them before you start.
The GDPR right to compensation
Article 82 of the GDPR provides that anyone who has suffered material or non-material damage as a result of an infringement of the regulation has the right to receive compensation from the controller.
What you must show
- A failure by the organisation, for example inadequate security measures.
- Damage: according to the Court of Justice of the European Union (2023), a GDPR infringement alone is not enough, there must be harm. It does not have to reach a seriousness threshold, and a genuine fear that your data will be misused can amount to non-material damage.
- A link between the failure and the damage.
Keep all evidence: the breach notification from the company, phishing messages, fraudulent payments, time spent on your steps, costs incurred.
Your options
- A written claim to the company, putting a figure on your loss.
- Court action on your own, often after an attempt at settlement for small amounts.
- A collective action: in many EU countries, approved associations can act for several victims of the same breach. Ask consumer associations.
A complaint to your data protection authority can lead to a penalty for the company, but does not pay you compensation: the two steps complement each other.
Practical advice
- First limit the damage: see the steps after a breach.
- Get advice from a lawyer or consumer association before starting proceedings.
- Be wary of canvassers promising guaranteed compensation for an upfront fee.