GDPR Article 82: who can claim compensation for a data breach?
Article 82(1) of the GDPR gives any person who has suffered material or non-material damage as a result of an infringement the right to receive compensation from the controller or processor. It is a private claim brought in court, separate from the administrative fines a supervisory authority imposes under Article 83.
Applies to: Controllers and processors subject to the GDPR. Article 82 creates exposure that runs alongside regulatory fines rather than instead of them, and unlike Article 83 it is driven by claimants rather than by a supervisory authority.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanGDPR risk is usually discussed in terms of the headline fine figures in Article 83. Those are the numbers that appear in board papers. They are also the exposure a business has the least control over, because a supervisory authority decides whether to act at all.
Article 82 works the other way. It hands the decision to the affected individual, and it does not require a regulator to be involved.
What Article 82(1) says
Article 82(1) reads: any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.
Three features of that sentence carry most of the weight.
It says any person, not any data subject, so the class of potential claimants is wider than the class whose data was processed.
It says material or non-material damage. Financial loss is not required. Distress and loss of control over personal data fall within the wording.
And it says as a result of an infringement of this Regulation, not as a result of a breach. Any infringement can found the claim, including a failure that never involved unauthorised access at all.
Who is liable, and for what: Article 82(2)
Article 82(2) separates the two roles.
Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation.
A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.
The controller's exposure is broad and the processor's is conditional. A processor that stayed within lawful instructions and met its own Article 28 and Article 32 duties has a structural answer to a claim that the controller does not have.
The corollary matters for anyone drafting a data processing agreement: "lawful instructions" is doing real work in that sentence. Instructions that are themselves unlawful do not shield the processor, and they do not transfer the controller's liability either.
The Article 82(3) exemption
Article 82(3) provides that a controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.
The burden sits on the defendant, and the standard is absolute: not in any way responsible. Partial responsibility is not a partial defence under this paragraph. In practice the paragraph rewards contemporaneous records, because a party arguing it bears no responsibility at all is arguing about what it did before the event, not after it.
Joint and several liability: Article 82(4) and (5)
Article 82(4) states that where more than one controller or processor, or both a controller and a processor, are involved in the same processing and are, under paragraphs 2 and 3, responsible for any damage caused by processing, each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject.
The stated purpose is in the text: effective compensation of the data subject. The claimant does not have to apportion blame before suing, and can recover the whole amount from whichever responsible party is most convenient or most solvent.
Article 82(5) then provides the recovery route between defendants. Where a controller or processor has, in accordance with paragraph 4, paid full compensation for the damage suffered, that party is entitled to claim back from the other controllers or processors involved in the same processing that part of the compensation corresponding to their part of responsibility for the damage, in accordance with the conditions set out in paragraph 2.
So apportionment happens, but it happens second, between the defendants, after the claimant has been paid. For a small SaaS business acting as a processor for a large controller, that ordering is the commercial risk: being liable for the entire damage first and recovering afterwards is a cash-flow event even when the eventual apportionment is favourable.
Where a claim is brought: Article 82(6)
Article 82(6) provides that court proceedings for exercising the right to receive compensation shall be brought before the courts competent under the law of the Member State referred to in Article 79(2).
Compensation is a court matter. It is not something a supervisory authority awards, which is why an authority closing a complaint without action says nothing about the viability of a claim under Article 82.
Why this changes how breaches should be handled
A business that treats breach notification as a regulatory formality tends to write the notification for the regulator alone. Article 82 means that record has a second audience.
The facts established during the 72-hour Article 33 process, and the description given to affected individuals under Article 34, are the material a claimant starts from. Accuracy and care at that stage is not only about the supervisory authority's view of the incident.
It also means the exposure arithmetic differs from the Article 83 fine calculation. Fines are capped by the percentages and absolute figures in Article 83. Article 82 has no cap in the Regulation. Its scale is set by the number of affected people and the damage each can show, so a modest per-person figure across a large affected population is the shape the exposure usually takes.
Compliance checklist
- Treat Article 82 exposure as separate from fine exposure when assessing an incident, because a supervisory authority declining to act does not close off private claims.
- Record and keep the evidence that would support the Article 82(3) defence: a controller or processor is exempt from liability under Article 82(2) if it proves it is not in any way responsible for the event giving rise to the damage.
- Read your processor contracts against Article 82(4) and (5). Each controller or processor responsible for damage in the same processing is liable for the entire damage, and the one that pays in full may then claim back from the others under Article 82(5) in proportion to responsibility.
- Make sure instructions to processors are documented and lawful, because Article 82(2) ties processor liability to acting outside or contrary to the controller's lawful instructions.
- Note that non-material damage is expressly compensable under Article 82(1), so the absence of financial loss does not end a claim.
- Build the Article 33 and Article 34 breach workflow with Article 82 in mind, since the facts recorded during notification become the record a claimant works from.
Sources
Last verified: 2026-09-18
Informational, not legal advice.