Tuesday, 2 September 2025
Key GDPR Fines in Mid-2025: Luka (Replika), TikTok, and ING Bank Śląski
Sunday, 6 April 2025
Do you really need my title? The CJEU says no – a win for consumer privacy in case C‑394/23
(Source: Freepik) |
The facts
“Commercial communication may constitute a purpose forming an integral part of the contractual service concerned, since the provision of such a rail transport service involves, in principle, communicating with the customer in order, inter alia, to send him or her a travel document by electronic means, to inform him or her of any changes affecting the corresponding journey, and to allow exchanges with the after-sales service. That communication may require adherence to accepted practices and may include, in particular, forms of addressing a customer, in order to show that the undertaking concerned respects its customer and thereby to safeguard that undertaking’s brand image. However, it appears that such communication does not necessarily have to be personalised based on the gender identity of the customer concerned” (paras. 37–38).
Tuesday, 4 March 2025
Credit reference agencies, consumer profiling and the GDPR: the CJEU in C-203/22
On February 27, 2025, the CJEU delivered an important judgment on the interpretation of Article 15(1)(h) and Article 22 of Regulation (EU) 2016/679 on General Data Protection (GDPR) in C-203/22 CK Magistrat der Stadt Wien v Dun & Bradstreet Austria GmbH.
The facts
The mobile phone operator refused CK’s request
to conclude or extend the mobile telephone contract for a monthly payment of a
mere EUR 10. The refusal was justified with CK not passing a
creditworthiness check with the credit reference agency D & B,
which carried out an automated assessment. Unsurprisingly, CK was unhappy with
the decision; her credit score was good. She brought the matter to the Austrian
data protection authority and, with this, started a long way to the preliminary
reference, going through various instances and avenues for protection.
The referring court raised several questions,
which the CJEU grouped into essentially two questions:
The
first question
Must Article 15(1)(h) be interpreted as
meaning that, in the case of automated decision-making, including profiling,
within the meaning of Article 22(1), the data subject may require the
controller to provide, ‘meaningful information about the logic involved’ in the
decision making, which would mean an exhaustive explanation of the procedure
and principles actually applied in using personal data to obtain a specific
result, in this case, a creditworthiness assessment.
According
to Article 15 (h), the data subject has the right to obtain from the
controller confirmation as to whether his/her personal data is being processed,
information on the use of automated decision-making where applicable, including
profiling, referred to in Article 22(1) and (4), and meaningful
information about the logic involved, as well as the significance and
the envisaged consequences of such processing for the data subject.
Article 22 provides that the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, and that certain data enlisted in Article 9(1) GDPR such as racial or ethnic origin, religious beliefs cannot be considered in data processing.
Profiling, in this context, means automated processing of personal data, consisting of using personal data to analyse or predict the consumer's economic situation.
In its analysis, the CJEU first turned to a literal interpretation of the wording of Article 15 (h) and concluded that the concept of ‘meaningful information’ under that provision may have various meanings in different language versions of GDPR, which should be taken to be complementary to each other. In addition, the ‘logic involved’ in automated decision-making, which constitutes the subject matter of ‘meaningful information’ is capable of covering a wide range of ‘logics’ concerning the use of personal data and other data with a view to obtaining a specific result by automated means. The CJEU held, that the provision covers all relevant information concerning the procedure and principles relating to the use, by automated means, of personal data with a view to obtaining a specific result.
The CJEU next turned to contextual analysis of the concept of ‘meaningful information about the logic involved’, within the meaning of Article 15(1)(h). In this analysis the CJEU looked at the Guidelines on automated individual decision-making and profiling for the purposes of Regulation 2016/679 and other provisions of the GDPR providing information duties of data controllers. The CJEU concluded that information duties relate to all relevant information that should be provided in clear, concise, transparent, intelligible and easily accessible form, using plain and clear language
Finally, the CJEU looked at the purpose of the provision, asserting that the purpose of the data subject’s right to obtain the information provided for in Article 15(1)(h) is to enable him or her to effectively exercise the rights conferred on him or her by Article 22(3), namely, the right to express his or her point of view and to contest the relevant decision. This, in turn, requires the right to obtain an explanation of the decision.
The CJEU then concluded that under Article 15(1)(h) the right to obtain ‘meaningful information about the logic involved’ in automated decision-making must be understood as a right to an explanation of the procedure and principles actually applied in order to use, by automated means, the personal data of the data subject with a view to obtaining a specific result, such as a credit profile. In order to enable the data subject to effectively exercise the rights conferred on him/her by the GDPR and, in particular, Article 22(3), that explanation must be provided by means of relevant information in a concise, transparent, intelligible and easily accessible form. Notably, the court further provided guidance on what is considered to be ‘meaningful information about the logic involved’ in automated decision-making. The procedures and principles actually applied must be explained in such a way that the data subject can understand which of his/her personal data have been used in the automated decision-making and the extent to which a variation in the personal data taken into account would have led to a different result. The requirements of Article 15(h) cannot be met by the mere communication of a complex mathematical formula, such as an algorithm, or by the detailed description of all the steps in automated decision-making since neither of those would constitute a sufficiently concise and intelligible explanation.
Second legal question
Another important contribution of the present judgment is the consideration of the relationship between Article 15(1)(h) and Directive 2016/943 on trade secrets, given that D&B argued that the logic of their automated decision-making, including what information is considered in which way, is a trade secret and should, therefore, not be disclosed.
The CJEU highlighted that the protection of personal data is not an absolute right. Restrictions are possible of the scope of the obligations and rights provided for in, inter alia, Article 15 of the GDPR, but only when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate to safeguard the protection of the rights and freedoms of others. However, the result of any consideration on the limits of the protection of personal rights should not be a refusal to provide all information to the data subject.
The CJEU concluded that Article 15(1)(h) must be interpreted as meaning that, where the controller takes the view that the information to be provided to the data subject is a trade secrets, within the meaning of point 1 of Article 2 of Directive 2016/943, that controller is required to provide the allegedly protected information to the competent supervisory authority or court, which must balance the rights and interests at issue with a view to determining the extent of the data subject’s right of access provided for in Article 15 of the GDPR.
Our analysis
This decision is significant in addressing the
long-standing problem of the lack of transparency in automated decision-making
by credit reference agencies, an important
problem
in the EU. Given that in most countries we have access to our credit reports we
can know what data is considered in their decision making in producing a credit
score and a credit report, however, credit reference agencies have refused disclosing
the way this data is processed, the logic behind their decision making, in what
way and to what extent various data is considered (weighted) in their decision making.
Although based on this decision, consumers
are still not entitled to get hold of that information directly, but a first
step has been made by mandating disclosure to the relevant authority who then
makes a decision on whether or not to disclose it to the consumer, balancing
the rights and interests of the two parties. This and other judgments of the
CJEU (see C-634/21
SCHUFA Holding) may be gradually bringing transparency into this traditionally
very untransparent area.
As credit reference agencies nowadays use artificial
intelligence for automated decision-making, the judgment is relevant for advancing
transparency considerations of AI systems.
Finally, given that the judgment tackles the
operation of credit reference agencies, which are frequently used by creditors
to assess the affordability of loan applications, it is relevant for
responsible lending rules in Directive 2023/2225 on consumer credit (CCD2),
which in Article 18 refers to creditworthiness assessment based on automated processing
of personal data.
Tuesday, 2 April 2024
How the CJEU's ruling in C-604/22 may transform online advertising: a closer look at the IAB Europe case
Facts of the case
![]() |
Image by "storyset" (Freepik) |
The Court has confirmed the key aspects of the DPA’s decision, emphasizing, among other things that:
1. the TC String holds information that pertains to an identifiable user and, thus, qualifies as personal data under Article 4(1) of the GDPR. Even if it doesn't contain any direct factors that allow the data subject to be identified, it does contain the preferences of a specific user relating to their consent to data processing. This information is considered to be related to a natural person (para. 43). If the information in a TC String is linked to an identifier, such as the IP address of the device, it could be possible to create a profile of that user and identify a particular person (para. 44). The fact that IAB Europe cannot combine the TC String with the IP address of a user's device and doesn't have direct access to the data processed by its members is irrelevant. As the Court stated, IAB Europe can require its members to provide it with the necessary information to identify the users whose data is being processed in a TC String (para. 48). This means that IAB Europe has reasonable means to identify a particular natural person from a TC String (para. 49).
2. IAB Europe, together with its members, is considered a 'joint controller' when it determines the purposes and ways of data processing. Why? According to the Court, the TCF framework aims to ensure that the processing of personal data by certain operators that participate in the online auctioning of advertising space complies with the GDPR. Consequently, it aims to promote and allow the sale and purchase of advertising space on the Internet by such operators. It means that IAB Europe has control over the personal data processing operations for its own purposes and, jointly with its members, determines the purposes of such operations (para. 62-64). Moreover, the TCF contains technical specifications relating to the processing of the TC String, such as how CMPs need to collect users' preferences, how such preferences must be processed to generate a TC String, etc. (para. 66). If any of IAB's members do not comply with the TCF rules, IAB Europe may adopt a non-compliance and suspension decision, which could result in the exclusion of that member from the TCF (para. 65). Therefore, the Court concluded that IAB Europe also determines the means of data processing operations jointly with its members (para. 68), so it meets the criteria of a data controller under Article 4(7) of the GDPR. However, this should not automatically make IAB Europe responsible for the subsequent processing of personal data carried out by operators and third parties based on information about the users' preferences recorded in a TC String (para. 74-76).
Saturday, 28 October 2023
EDPS Opinion on AI Act proposal
![]() |
Photo by julien Tromeur on Unsplash |
The EDPS takes a tough stance as regards some of the solutions envisaged in the proposal. For instance, the authority once again emphasized that classifying several uses of AI as "high risk" is not enough in cases where such uses pose unacceptable risks to fundamental rights (see para. 7 of the opinion). This includes a.o.:
- any use of AI to carry out any type of "social scoring";
- any use of AI for automated recognition of human features in publicly accessible spaces, such as of faces, gait, fingerprints, DNA, voice, keystrokes and other biometric or behavioural signals;
- the use of AI to infer emotions of a natural person except for certain well-specified use-cases, namely for health or research purposes;
- any use of AI systems categorising individuals from biometrics into clusters according to ethnicity, gender, political or sexual orientation, or other grounds for discrimination prohibited under Article 21 of the EU Charter of Fundamental Rights.
According to the EDPS, such uses should be prohibited as they are intrusive and affect human dignity.
The EDPS also notes that the AI Act proposal exempts operators of high-risk AI systems already on the market or in use before the AI Act's applicability, except in cases when these systems are subject to significant changes in their design or purpose or in case of "substantial modifications" (para. 12 of the opinion, see also Article 83(2) of the AI Act proposal). However, the EDPS finds this solution unclear, leading to legal uncertainty and some high-risk AI systems never falling within the scope of the AI Act. The EDPS recommends removing this exemption and applying the AI Act to existing high-risk AI systems on the date of its applicability.
What is more, the EDPS suggests that the notion of AI "providers" should be further clarified, and probably (explicitly?) include AI operators who retrain pre-trained AI systems. Although training is a fundamental part of AI development, the current proposal does not clearly state whether activities such as retraining or continuous training should be considered as part of AI system 'development'. As a result, it is uncertain whether operators taking part in such activities could be assigned the status of "providers" of AI systems (para. 15-19 of the opinion).
Finally, the authority shared specific recommendations on how to clarify the proposal's provisions on EDPS roles and tasks as a notified body, market surveillance authority and competent authority for the supervision of the development, provision or use of AI systems by EU institutions, bodies, offices and agencies (para. 29 et seq.).
* Updated information on the legislative process you can find here.
Wednesday, 19 April 2023
EDPB updated guidelines on right of access to personal data
The European Data Protection Board (EDPB) a few days ago published updated (second version) guidelines on the rights of data subjects, specifically the right of access to personal data. Any person whose personal data is processed is entitled to the right of access under Art. 15 of the GDPR. The right of access to data is considered one of the key rights under the GDPR, as it allows you to maintain control over what personal data is being processed, by whom, on what legal basis, to whom it has been made available, etc. Although the guidelines are primarily addressed to data controllers, they contain valuable tips for data subjects, providing insight into the actual scope of our rights. It's good to familiarize yourself with them, because as consumers, we leave digital footprints almost everywhere, and as a result, it's good to know what rights we have.
Just not to sound groundless, here are some noteworthy points from the guidelines:
1. If you ask for access to your data the controller should give you access to all your personal data that are processed, unless you expressly limit your request (e.g. to identification data or data concerning a contract concluded on a particular day). The controller is not entitled to narrow the scope of your request arbitrarily, but may ask you to specify the request if he processes a large quantity of data.
2. Before granting access to personal data, the controller should confirm your identity in order to ensure the security of processing and minimise the risk of unauthorised disclosure of personal data. In this regard the EDPB emphasized that "as a rule, the controller cannot request more personal data than is necessary to enable this authentication, and that the use of such information should be strictly limited to fulfilling the data subjects’ request" (p. 25). The GDPR does not precise how to identify the data subject, so it is up to the controller to decide which authentication method is the most appropriate. However, the method must be proportionate to the circumstances of the processing, including the type of personal data being processed (e.g. special categories of data), the context within which the request is being made, potential damage that could result from improper disclosure of data). It happens that controllers fail to meet this requirement and choose methods that are convenient for them, but disproportionate. The EDPB states: "In practice, authentication procedures often exist and controllers do not need to introduce additional safeguards to prevent unauthorised access to services. In order to enable individuals to access the data contained in their accounts (such as an e-mail account, an account on social networks or online shops), controllers are most likely to request the logging through the login and password of the user, which in such cases should be sufficient to authenticate a data subject. [...] Consequently, it is disproportionate to require a copy of an identity document in the event where the data subject making a request is already authenticated by the controller. [...] Taking into account the fact, that many organisations (e.g. hotels, banks, car rentals) request copies of their clients’ ID card, it should generally not be considered an appropriate way of authentication" (p. 27).
3. Information requested as part of data access right should be provided to the data subject without undue delay and in any event within one month of receipt of the request. This deadline can be extended by a maximum of two months taking into account the complexity and the number of the requests that the controller receives. In such a situation the data subject must be informed about the reasons for delay. But the rule is that the controller should act "without undue delay", which means that the information should be given as soon as possible - "if it is possible to provide the requested information in a shorter amount of time than one month, the controller should do so" (p. 50).
4. Sometimes the controller may limit or refuse to give access to personal data. According to Art. 15(4) GDPR, the right to obtain a copy of data shall not adversely affect the rights and freedoms of others. Another restriction results from Art. 12(5) GDPR which enables controllers to override requests that are manifestly unfounded or excessive, in particular because of their repetitive character. These concepts must be interpreted narrowly. Data access right may be exercised more the once, but as it was indicated in recital 63 of the GDPR - "at reasonable intervals". It is not possible to determine in advance how often it is permissible to make requests for access to data, because it depends on processing circumstances. The EDPB remarks that "the more often changes occur in the database of the controller, the more often data subjects may be permitted to request access to their personal data without it being excessive". For example, "in the case of social networks, a change in the data set will be expected at shorter intervals than in the case of land registers or central company registers" (p. 56).
These are just a few examples worth keeping in mind. For more, I recommend checking out the guidelines.
Saturday, 28 January 2023
It is your right to know the actual identity of recipients to whom your personal data have been or will be disclosed (C-154/21 Österreichische Post)
The General Data Protection Regulation (GDPR) provides individuals (data subjects) with a number of rights. These are listed in Chapter III of the GDPR and include, inter alia, the right to be informed of the processing of personal data (Articles 13 and 14 of the GDPR), right of access (Article 15 of the GDPR), right to rectification (Article 16 of the GDPR), right to erasure (Article 17 of the GDPR) etc. In mid-January 2023, the Court of Justice in Case C-154/21 Österreichische Post answered a question concerning one of those rights, namely the right of access.
As stated in Article 15(1) of the GDPR „the data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information: […]
(c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; […].
The dispute concerned the fact that the data subject requested from the controller the actual identity of the recipients to whom he was disclosing his personal data. However, the controller did not reveal the identity of the recipients, but informed the data subject of the "categories of recipients", indicating that they were „customers, including advertisers trading via mail order and stationary outlets, IT companies, mailing list providers and associations such as charitable organisations, non-governmental organisations (NGOs) or political parties” (para. 20).
Indeed, doubts arise when applying Article 15(1) of the GDPR in practice. The main question is whether it is necessary to inform about the particular recipients of the data, or would it be enough to notice about general categories of these recipients? Similar doubts arise in the context of Articles 13(1e) and 14(1e) of the GDPR, which oblige the controller, as part of its information obligations performed at the time of data collection, to inform about "the recipients or categories of recipients of the personal data, if any".
In the Court's view, Article 15(1) of the GDPR gives the right to be informed about the specific recipients of personal data and thus to know their actual identity. The Court cites several arguments in this regard:
(1) The data subjects should be guaranteed the right to know and be informed about the processing of their personal data, in particular about the recipients to whom the data are made available. This is emphasised in Recital 63 of the GDPR, which, nota bene, does not refer to the right to information about "categories of recipients of data", but generally to the right to information about "recipients of personal data" (para. 33).
(2) The controller must process personal data in accordance with the principle of transparency, which from the data subject's perspective means that information on how his or her personal data is processed should be easily accessible and comprehensible (para. 35).
(3) „Article 15 of the GDPR lays down a genuine right of access for the data subject, with the result that the data subject must have the option of obtaining either information about the specific recipients to whom the data have been or will be disclosed, where possible, or information about the categories of recipient” (para. 36).
(4) The right of access is often exercised to verify the accuracy of the data or the lawfulness of the processing. In this sense, the right of access frequently determines further actions of the data subject, i.e. the exercise of other rights under the GDPR, e.g. the right to erasure or the right to object to processing. Therefore, the complete and diligent exercise of the right of access is essential to guarantee the effectiveness of the data subject's rights (para. 38).
Saturday, 31 December 2022
December wrap-up of data protection cases (Google, Österreichische Datenschutzbehörde and Pankki S)
The end of the month (and the end of the year as well) is a good moment for summaries. This time we are taking a closer look at events in the area of data protection law. December was a month with a couple of interesting events, so here is a brief recap.
Dereferencing allegedly inaccurate content (C-460/20 Google)
The case concerned two executives of a group of investment companies (a board member and a proxy) who asked Google to remove search results linking their names to certain articles criticising the group's investment model. They exercised the so-called right to be forgotten, guaranteed under Article 17(1) of the GDPR, claiming that the information presented contained false claims and defamatory opinions. They also wanted Google to remove their thumbnail images from the search results. Google rejected these requests, arguing that it does not know whether the information contained in the articles is true or not.
In cases involving the erasure of data from a search engine operator's search results, two rights usually collide: the public's right of access to information (especially about persons holding public positions) and the individual's right to protection of his or her personal data, including the right to erasure, protection of his or her good name, image, etc. The same problems were considered in this case, as we wrote about when reporting on the AG's opinion issued in the proceedings. In the ruling of 8th December 2022 the Court held that the person requesting the deletion of data is obliged to show that the information is manifestly inaccurate. "However, in order to avoid imposing on that person an excessive burden which is liable to undermine the practical effect of the right to de-referencing, that person has to provide only evidence that, in the light of the circumstances of the particular case, can reasonably be required of him or her to try to find in order to establish that manifest inaccuracy" (para. 68). It means that such a person cannot be required to present a judicial decision made against the publisher of the website in question, even in the form of a decision given in interim proceedings, since it would be an unreasonable burden imposed on such a person. At the same time "the operator of the search engine concerned cannot be required to investigate the facts and, to that end, to organise an adversarial debate with the content provider seeking to obtain missing information concerning the accuracy of the referenced content" (para. 71). Therefore, if the person who made a request for de-referencing submits relevant and sufficient evidence showing the manifest inaccuracy of the information found in the referenced content, the operator of the search engine is required to accede to that request for de-referencing. But an operator should not grant a request if the inaccurate character of the information is not obvious in the light of the evidence presented (para. 72&73).
As regards the thumbnails the Court concluded that "a separate weighing-up of competing rights and interests is required depending on whether the case concerns, on the one hand, articles containing photographs which are published on an internet page and which, when placed into their original context, illustrate the information provided in those articles and the opinions expressed in them, or, on the other hand, photographs displayed in the list of results in the form of thumbnails by the operator of a search engine outside the context in which they were published on the original internet page" (para. 101). The Court also stated that the informative value of those images should be taken into account independently of the context of their publication on the website from which they originate, nevertheless taking into account all the content that directly accompanies the display of those images in the search results and that can explain the informative value of those images (para. 108).
The concept of a "copy of personal data" under the Article 15(3) of the GDPR. AG Pitruzzella opinion on Österreichische Datenschutzbehörde case (C‑487/21)
The dispute arose over the interpretation of Article 15(3) of the GDPR, which provides that a data subject, as part of the right of access to one's personal data, may obtain a copy of that data. The complainant requested an exact copy of the data processed by the controller, including full copies of documents containing his personal data. However, the controller provided only some of the requested information as an aggregate that reproduced the stored personal data of the data subject in a table broken down by name, date of birth, street, postal code, and place, and in a statement summarising corporate functions and powers of representation. As part of the proceedings, the national court decided to refer several questions concerning the interpretation of Article 15(3) of the GDPR to the Court.
On 15 December 2022, the AG delivered an opinion stating that the concept of “copy” referred to in Article 15(3) of the GDPR must be understood as "a faithful reproduction in intelligible form of the personal data requested by the data subject, in material and permanent form, that enables the data subject effectively to exercise his or her right of access to his or her personal data in full knowledge of all his or her personal data that undergo processing – including any further data that might be generated as a result of the processing, if those also undergo processing – in order to be able to verify their accuracy and to enable him or her to satisfy himself or herself as to the fairness and lawfulness of the processing so as to be able, where appropriate, to exercise further rights conferred on him or her by the GDPR". The AG underlined that this provision does not, in principle, entitle the data subject to obtain a full copy of documents containing the personal data, but, at the same time, does not exclude the need to provide that person with extracts from documents, whole documents or extracts from databases if that is necessary to ensure that the personal data undergoing processing are fully intelligible.
Right to know the identity of the persons who had access to one's personal data. AG Campos Sánchez-Bordona on Pankki S case (C-579/21)
The third case also concerned the right of access to personal data, but from a different perspective. Data subject wanted to know who exactly (among the employees of the financial institution) had access to his personal data at the time when he was a customer of that institution and an employee thereof. The controller refused to provide names of the employees arguing that Article 15 of the GDPR does not apply to log data of the institution's data processing system and that the information requested does not relate to personal data of the data subject, but to the personal data of the employees.
The AG approved the controller's view and stated that Article 15(1) of the GDPR "does not give the data subject the right to know, from among the information available to the controller (where applicable, through records or log data), the identity of the employee or employees who, under the authority and on the instructions of the controller, have consulted his or her personal data". In justifying his opinion, he pointed out that "the identity of individual employees who have handled the processing of customer data is particularly sensitive information from a security point of view, at least in certain economic sectors" (para. 76). Disclosure of employees' data could expose them to attempts by customers of the banking institution to exert pressure and influence. Nevertheless, the AG noted that if a data subject has reasonable doubts about the integrity or impartiality of an individual who has participated on behalf of the controller in the processing of his or her data, this could justify the interest of that customer in knowing the identity of the employee in order to exercise the customer's right to take an action against that employee (para. 78; nb. in the relevant case the data subject made his request, in particular, in order to clarify the reasons for his dismissal).
Thursday, 24 November 2022
Can we seek compensation for a GDPR breach if it caused great upset or inner discomfort? The AG Opinion in C-300/21, Österreichische Post
"1. Does the award of compensation under Article 82 of the GDPR also require, in addition to infringement of provisions of the GDPR, that an applicant must have suffered harm, or is the infringement of provisions of the GDPR in itself sufficient for the award of compensation?
2. Does the assessment of the compensation depend on further EU-law requirements in addition to the principles of effectiveness and equivalence?
3. Is it compatible with EU law to take the view that the award of compensation for non-material damage presupposes the existence of a consequence of the infringement of at least some weight that goes beyond the upset caused by that infringement?"
Opinion of the AG
The AG presented an interesting analysis of Article 82 of the GDPR, taking into account different types of interpretation (literal, historical, contextual and purposive). There are several important statements that deserve attention:
1. Assuming that under Article 82 of the GDPR a data subject could be awarded compensation for a breach of the Regulation, despite the absence of any damage, would be inconsistent with the fundamental purpose of civil liability. This purpose is to compensate for the damage suffered by the data subject. If the damage could not be identified, the compensation then awarded would not fulfil the aforementioned function, but would be more like a punishment and a sanction for the infringer (paras 29-30). It is true that punitive damages may exist in both EU and national law, but the GDPR does not contain this type of reference (paras 39, 44, 49-50).
2. The AG's position is that a mere breach of the GDPR does not give rise to a presumption of automatic harm to the data subject (paras 56-59). As can be inferred from the Opinion, this is the presumption made by the parties to the proceedings, indicating that a breach leads to a loss of control over the data and thus causes harm to the data subject. However, the AG considers that not every loss of control over data necessarily leads to harm (para. 62) and, furthermore, that giving data subjects as much control over data as possible may not necessarily be derived from the GDPR provisions (para. 74). He states: „where a data subject does not consent to processing and processing is carried out without another legitimate legal basis, that is not a ground for the data subject to receive financial compensation on account of the loss of control over his or her data, as though that loss of control itself amounted to damage that is eligible for compensation” (para. 77).