Compensation for leaked data vital to GDPR compliance
Compensation for leaked data vital to GDPR compliance

Compensation for leaked data vital to GDPR compliance

Is it possible that you could soon expect to receive compensation of tens or hundreds of euros for the next data breach committed by Facebook, LinkedIn or a random web shop? According to Tim Walree, it should certainly be easier to get compensation. Although the General Data Protection Regulation (GDPR) has been demanding better protection of personal data since 2018, it seems as though the number of data breaches has only increased. According to Walree, who will obtain his PhD on this topic from Radboud University on 30 June, compensation for damages could ensure more effective enforcement of the GDPR.

Every year, thousands of complaints are submitted to the Dutch Data Protection Authority, for example, because an organisation has failed to handle their personal data safely. Due to limited manpower and resources, however, only a relatively small proportion of these cases are treated, and in complex cases it can take years before a decision is announced. In his PhD research, Tim Walree consequently examined whether and how the right to compensation for damages through civil proceedings can assist enforcement of the GDPR.

“The rules as they apply in the GDPR are worthless if they cannot be enforced. There are in fact two ways in which this can be done: either through a supervisory body or through civil law,” explains Walree. “We are now actually seeing that the supervisory body lacks sufficient resources to enforce the GDPR properly. But if the consumers themselves are able to claim compensation for damages through civil law from organisations that have handled their data carelessly, this will also create a financial incentive for those organisations, which will eventually result in increased compliance.”

Difficultly in determining damages caused by data breaches

At present, judges are often still reluctant to award compensation for damages, because there is usually a lack of actual damage. “Infringement of the GDPR will not normally affect a victim’s assets, and when it comes to immaterial damages, we’re talking about distress or frustration at the very most, which is not legally relevant damage.

And if there is obvious damage, this could be difficult to translate into an amount, or the amount could be so low that it’s hardly even worth going to court. Walree: “If millions of pieces of personal data leak out, one piece of data may be worth a few cents at the most. But you never know where this data will eventually end up, which criminals get hold of it and which purpose they have in mind for the data. As a result, it may sometimes take years before the exact nature of the damage is revealed.”

“Suppose that someone is ultimately able to assemble several stolen, anonymous data sets. The smallest bit of data could then provide an important piece of the puzzle when it comes to constructing extremely personal user profiles. These could subsequently be worth a great deal of money, which could lead to a revelation of both the material and immaterial damages at that point in time.”

The need for a different approach

We therefore need to gravitate towards a new understanding of compensable damage, argues Walree. “The concept of damages needs to be more focused on the nature of the data protection law. As a rule, violating the data protection law will not immediately eat into your income, or result in a scratch on your car or a broken arm. The consequences are often abstract, uncertain, and they cannot be measured. That’s why it’s unjust to cling to the traditional concept of damages. In the case of preliminary rulings, judges should therefore not wait too long before they appeal to the Court of Justice, which will enable them to reach a new, more modern understanding of damages more quickly. When it comes to the concept of damages, the Court of Justice ultimately has the final say.

"In addition, predefined amounts could be set, and these could be paid out in the event of a substantial GDPR violation. “For example, consider a company that has resold your data without informing you, or leaked information about your medical appointments.

“If an organisation is forced to pay immediate compensation of, say, a few hundred euros in such a case, this will also dispel apathy in people. It’s a double-edged sword: if people know which amount is attached to a violation, they’ll take action sooner, which means that organisations will also be forced to take the GDPR more seriously.”

Image source: Pexels

Contact information

Theme
Law, Current affairs