Article 82 GDPR · CJEU C-655/23 (2025)

GDPR Compensation Claims: When Does Non-Material Damage Qualify?

Grounded in Regulation (EU) 2016/679 and CJEU case law · Stand: 07/2026

Article 82 GDPR gives anyone who suffers damage from a GDPR infringement the right to compensation — and, since a 4 September 2025 ruling from the Court of Justice of the EU (Case C-655/23, IP v Quirin Privatbank), it is clearer than ever that this can include pure distress, with no minimum severity and no need to show the controller acted deliberately. Building on our complete GDPR guide and our deep dive on legitimate interest, this guide walks through exactly what the case law requires for a valid claim.

Key facts at a glance

Legal basis
Article 82(1)–(6), Regulation (EU) 2016/679
Required elements
3 — infringement, damage, causal link (CJEU C-300/21)
Seriousness threshold
None — confirmed twice (C-300/21, 2023; C-655/23, 2025)
Fault relevance
Irrelevant to the amount of compensation (C-655/23)
Injunction vs. compensation
Independent remedies — one does not reduce the other (C-655/23)
Who can be liable
Controller always; processor only for its own breaches (Art. 82(2))
Latest follow-up
C-526/24, Brillen Rottler (19 Mar 2026) — damage still can’t be presumed; self-manufactured claims break the causal link

On this page

  1. What Article 82 actually gives you
  2. Do you have to prove financial loss?
  3. Is there a minimum severity threshold?
  4. Does loss of control alone count?
  5. Does the controller’s fault matter?
  6. Injunction and compensation together?
  7. Controller, processor, or both?
  8. Checklist: do you have a claim?
  9. FAQ

What does Article 82 GDPR actually give you?

Article 82(1) GDPR gives "any person who has suffered material or non-material damage as a result of an infringement of this Regulation" the right to receive compensation from the controller or processor responsible. Material damage covers quantifiable losses like fraud or fees you had to pay; non-material damage covers everything else — distress, loss of control over your data, reputational harm. The GDPR treats the two as equals: neither is a lesser or "backup" category, and Article 82(1) does not require you to have suffered financial loss before non-material damage becomes available to you.

Do you have to prove you lost money to claim compensation?

No — non-material damage is enough on its own. The CJEU's first Article 82 ruling, Case C-300/21 (Österreichische Post AG, 4 May 2023), set out three cumulative conditions a claimant must meet: (1) an infringement of the GDPR, (2) damage — material or non-material — actually suffered, and (3) a causal link between the two. Mere infringement of the GDPR, without any of these being shown, does not by itself create a right to compensation; but where all three are shown, no separate proof of financial loss is required.

Is there a minimum level of seriousness your distress must reach?

No formal "de minimis" threshold exists. Case C-300/21 already held that Article 82(1) does not require non-material damage to reach any particular degree of seriousness, and Case C-655/23 (IP v Quirin Privatbank AG, 4 September 2025) confirmed this again: national courts cannot make compensation conditional on the harm being sufficiently severe. This does not mean any complaint automatically succeeds — you still have to actually demonstrate that you experienced real damage and that it was caused by the specific infringement, not merely assert that a breach happened. A more recent ruling, Case C-526/24 (Brillen Rottler, 19 March 2026), reinforced exactly this point: the Court held, in substance, that damage cannot be presumed merely because a violation took place, and that simply asserting fear or anxiety is not on its own enough — you have to prove concrete negative consequences, not just state that you felt worried.

Liability and remedies come up in every DPO exam

Article 82 sits alongside breach notification and enforcement as one of the most tested "what happens when it goes wrong" topics. Practise recognising it in realistic multiple-choice questions.

Start free Try 30 questions free — no time limit, no credit card.

Does losing control of your data count, even without proven misuse?

Yes — the CJEU has confirmed that a mere loss of control over personal data can itself be non-material damage, even if no one is shown to have actually misused it. In Case C-655/23, the Court held that negative feelings such as fear or annoyance caused by a loss of control over data are capable of constituting non-material damage under Article 82(1), provided the data subject demonstrates that they are actually experiencing those feelings and that this is precisely because of the infringement in question. A purely abstract, hypothetical worry that something bad might one day happen is not the same as demonstrating you actually feel that way because of what occurred.

Does it matter how careless or reckless the controller was?

Not for how much you receive. Case C-655/23 held that the degree of the controller’s fault must not be taken into account when a court assesses the amount of compensation payable under Article 82(1). Article 82 is compensatory, not punitive: it exists to make good the damage you actually suffered, not to punish sloppier controllers with bigger payouts — that punitive function belongs to the administrative fines regime under Article 83 instead.

Can you get a court injunction and compensation at the same time?

Yes — they are independent remedies. Case C-655/23 confirmed that obtaining a court order to stop further unlawful processing does not reduce or replace compensation for damage you have already suffered. An injunction is forward-looking (it prevents new harm); compensation is backward-looking (it repairs harm already done). Winning one does not use up or diminish your entitlement to the other.

Controller, processor, or both: who do you actually sue?

Usually the controller — a processor is only liable in narrower circumstances. Under Article 82(2), a controller is liable for damage caused by processing that infringes the GDPR, while a processor is liable only for damage caused by processing where it has not complied with obligations specifically addressed to processors, or where it has acted outside or contrary to the controller’s lawful instructions. Either can escape liability under Article 82(3) by proving it is "not in any way responsible for the event giving rise to the damage." Where more than one controller or processor was involved in the same processing, Article 82(4) makes each of them liable for the entire damage, so you do not have to work out and apportion blame yourself — whoever you claim against can later use Article 82(5) to recover its share back from the others. As for where and when: Article 82(6) only points you to the courts competent under Article 79(2) (broadly, the Member State where the defendant is established, or where you have your habitual residence) — the GDPR itself sets no EU-wide limitation period, so how long you have to actually bring the claim depends on the civil procedure rules of that Member State.

Checklist: do you have a viable Article 82 claim?

Run through these six cumulative questions, built directly from the C-300/21, C-655/23 and C-526/24 case law above — a "no" on any of the first three, or a "yes" on the last one, is normally fatal to the claim.

Preparing for a DPO / GDPR certification exam?

GDPR Exam Trainer turns material like this into hundreds of practice questions, chapter training and a timed exam simulation, with AI explanations for every answer.

Create your free account No in-person course required · Cancel anytime.

Frequently asked questions

Do I have to prove I lost money to claim GDPR compensation?

No. Article 82(1) GDPR gives a right to compensation for "material or non-material damage" — the two are separate and neither takes priority. The Court of Justice of the EU confirmed in Case C-655/23 (IP v Quirin Privatbank, 4 September 2025) that negative feelings such as fear or annoyance caused by a loss of control over your data are capable of constituting non-material damage on their own, provided you demonstrate you actually experienced them and that they were caused by the specific infringement.

Is there a minimum level of seriousness my distress has to reach?

No formal threshold exists. The CJEU has twice rejected a "de minimis" requirement for non-material damage — first in Case C-300/21 (Österreichische Post, 4 May 2023) and again in Case C-655/23 (2025), which held that Article 82(1) precludes national rules that make compensation conditional on the damage reaching a certain degree of seriousness. That said, you must still demonstrate real, causally linked damage; a purely hypothetical or abstract worry is not enough.

Does it matter how careless or reckless the controller was?

Not for the amount you receive. Case C-655/23 held that the degree of the controller’s fault must not be taken into account when assessing the compensation payable under Article 82(1) — the provision is compensatory, not punitive, so it repairs the damage you actually suffered rather than punishing bad behaviour.

If I get a court order stopping the unlawful processing, can I still claim compensation too?

Yes. The CJEU confirmed in Case C-655/23 that a prohibitory injunction and a compensation claim are independent remedies: obtaining an injunction to prevent future unlawful processing does not reduce or replace compensation for damage you have already suffered, because one is preventive and the other is compensatory.

Can I claim against a data processor instead of the controller?

Only in limited circumstances. Under Article 82(2) GDPR, the controller is liable for damage caused by processing that infringes the GDPR, while a processor is liable only where it has not complied with obligations specifically addressed to processors, or where it acted outside or contrary to the controller’s lawful instructions. Where several controllers and/or processors were involved in the same processing, Article 82(4) makes each of them liable for the entire damage, so the data subject can be compensated in full without having to apportion blame themselves.

Does the GDPR set a time limit for bringing a compensation claim?

No — the GDPR itself does not set a limitation period. Article 82(6) only says proceedings must be brought before the courts competent under Article 79(2) (broadly: the Member State where the defendant is established, or where the data subject has their habitual residence). How long you actually have to sue is a matter of each Member State’s own civil procedure rules, not the Regulation.

Primary sources

This guide summarises the GDPR and CJEU case law for study and general information. It is not legal advice, and it does not tell you whether any specific situation qualifies for compensation. Article numbers, holdings and thresholds are simplified for clarity. For a binding interpretation or advice on an actual claim, consult the official judgment text on EUR-Lex, your competent supervisory authority, or a qualified data protection lawyer.