Right to indemnity for non-patrimonial harms resulting from violations of the General Data Protection Regulation (GDPR) a brief analysis of the decisions of The Court of Justice of the European Union (CJEU) in cases C-300/21 and C-590/22
Main Article Content
Abstract
The article examines the right to compensation for non-material damages resulting from violations of the General Data Protection Regulation (GDPR), with a focus on the rulings of the Court of Justice of the European Union (CJEU) in cases C-300/21 and C-590/22. The analysis covers the interpretation of the concept of "damage" within the context of the GDPR, the need to prove actual harm, and the causal link required to establish the right to compensation. The CJEU decisions emphasize that a mere violation of the GDPR is not, by itself, sufficient to automatically confer a right to compensation—there must be demonstrable actual damage. Moreover, the CJEU clarifies that there is no requirement for a minimum threshold of severity for the damage to be compensable. The article concludes with reflections on the implications of these decisions for the protection of personal data and the right to indemnity in cases of GDPR breaches.