Article 82 GDPR: loss of control, burden of proof and damages after the BGH ruling
Analysis of BGH VI ZR 10/24: when loss of control constitutes damage, which facts must be pleaded and why EUR 100 is not a fixed compensation tariff.
Three requirements remain distinct
The doctrinal significance of the judgment of 18 November 2024, VI ZR 10/24, lies in placing loss of control within the EU-law concept of damage. Following the Court of Justice, the BGH requires a GDPR infringement, material or non-material damage and a causal link cumulatively. An infringement alone does not establish damage, and damage alone does not establish unlawful processing.
The allocation of pleading and proof is equally important. In paragraph 21, the BGH generally assigns the elements establishing the claim to the affected person. They do not, however, have to positively prove fault by the controller: Article 82(3) allows the controller to escape liability by proving that it was not in any way responsible for the event giving rise to the damage. This is not a blanket reversal of the burden for all elements of the claim.
Loss of control as non-material damage in its own right
Under paragraphs 29 to 31, even a brief loss of control can constitute non-material damage. Once that loss is proven, additional particular anxiety, identity theft or another tangible consequence is unnecessary. Such effects may increase the assessment but are not a compulsory second threshold.
This also limits an oversimplified reading. Merely alleging a data protection infringement does not establish a loss of control. Which personal data left the sphere of control? Were they made available to unauthorised parties, linked with further information or published? Does that event concern this particular claimant? The facts must fit the damage relied upon.
If loss of control cannot be proven, a justified fear of future misuse may be relevant as another form of damage. In paragraph 32, however, the BGH requires proper proof of that fear and its negative consequences. A purely hypothetical risk is insufficient. Loss of control and fear of misuse should therefore not be conflated.
Why public profile data do not settle the issue
The underlying scraping incident involved linking telephone numbers to other profile data. The legal question was not limited to whether a name had already been publicly visible. Linking it to a telephone number may involve different processing and a different loss of control from publishing the name alone.
In paragraphs 43 and 44, the BGH requires a specific examination of possible consent: does it cover the processing at issue, including the searchability function? Was the information transparent and the consent informed, unambiguous and freely given? Registration or a default setting cannot, without examination, establish valid consent to every later use of data.
Standardised proceedings still require individual facts
The judgment also matters procedurally. The BGH rejects excessive pleading requirements without dispensing with the individual case. Accounts can naturally share similarities where one incident affects many people. What matters is whether and how this individual’s data were affected and which consequences are claimed, particularly under paragraphs 34 to 36.
In our analysis, structured intake should distinguish common incident facts from individual information. The technical description of the data escape may be reusable. Actual exposure, previous publications, settings and alleged consequences must be established for each person. Standardised assertions of sleeplessness or fear without a factual basis would be professionally and procedurally unsound.
- Exposure: which notification, access response or other reliable information connects this person to the incident?
- Scope: which specific data and new associations are affected?
- Control: what public availability or access existed before and after the event?
- Consequences: which additional effects are actually alleged, since when and supported by which evidence?
EUR 100 is neither a compensation table nor the operative award
In paragraph 100, the BGH refers to approximately EUR 100 for loss of control itself in a case such as the one before it. This is neither a guaranteed payment for every incident nor a general ceiling. The Court remitted the case to the extent it set aside the lower judgment; it did not finally award EUR 100 to the claimant or to every affected person.
Paragraph 99 identifies assessment factors: data sensitivity, typical use, a limited or unlimited circle of recipients, duration of lost control and possible recovery of control. The hypothetical effort required for a proportionate means of recovery may also provide an indication. This is an assessment framework, not a mechanical multiplier per record.
For quantification, the BGH refers to section 287 ZPO, subject to the EU principles of equivalence and effectiveness. Proven additional psychological effects may justify a higher award; the court may need to hear the person concerned. Removing a seriousness threshold therefore entails neither substantial compensation in every case nor dispensing with factual findings.
Several GDPR breaches do not automatically produce several awards
Article 82 serves full compensation, not punishment of the controller. In this case, the BGH treats the alleged non-material damage from the connected sequence of events as a single procedural claim. Several infringements relating to the same processing operation cannot simply be divided into cumulative compensation items, as explained in paragraph 18.
The administrative fine criteria in Article 83 are likewise not a tariff for civil damages. The seriousness of an infringement as such and a desire to punish do not replace assessment of the damage suffered. Additional losses actually caused must be examined on their own requirements; naming more infringed provisions does not create them.
Declaratory and injunctive relief require their own analysis
A payment claim does not cover every protective interest. In paragraphs 46 to 50, the BGH addresses a declaration of liability for future losses. For the interference with an absolutely protected right at issue, the possibility of future harm may suffice. Application to another incident depends on the right infringed, continuing loss of control and the specific future risk.
For injunctive relief, the judgment illustrates a different limit: the BGH rejected one request for lack of specificity. Technical complexity does not remove the need to define the conduct to be prohibited. An abstract wish for secure data processing cannot replace that definition. Payment, declaratory and injunctive claims should each be developed from the relevant facts and protective objectives.
Sources & further information
- BGH judgment of 18 November 2024, VI ZR 10/24: full text on Curia ↗
- GDPR: in particular Articles 6, 7, 25, 82 and 83 ↗
- Section 287 ZPO: judicial assessment of damages ↗
This article provides general guidance. The options available depend on your specific situation.