This Article has been first published in Polish in the European Judicial Review (Europejski Przegląd Sądowy) 2026/8/11-20

Agnieszka Grzelak, PhD,

Professor at Kozminski University1

Deputy President of the Office for Personal Data Protection (ORCID: 0000-0002-5867-8135).

Maciej Gawroński

Attorney-at-law, CIPP/E; managing partner at GP Partners Gawroński, Biernatowski sp.k.; expert with the European Data Protection Board’s Support Pool of Experts; awardee of the Michał Serzycki Award from the Polish Office for Personal Data Protection

Alicja Tengli-Dobska

Associate at GP Partners Gawroński, Biernatowski sp.k

Illusory Compensation under Article 82 of the GDPR

– ‘the Emperor’s New Clothes’ of Digital Fundamental Rights

In this article, the authors analyse the claim for damages under Article 82 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)2 in the light of the case-law of the Court of Justice of the European Union and the principle of the effectiveness of Union law. The starting point is the finding that the framework of liability has, in essence, been stabilised: the Court has rejected both the automatic imposition of liability for the infringement itself and the possibility of introducing thresholds for the seriousness of non-pecuniary damage. The problem, however, arises at the practical level.

The authors point out that the award of symbolic damages undermines the effectiveness of protection, particularly where the pursuit of claims entails a significant burden on the individual. In response, they propose clarifying the criteria for determining the amount of compensation, including, amongst other things, the nature of the data, the scale and duration of the infringement, and the prolonged state of uncertainty.

In conclusion, it is emphasised that Article 82 of the GDPR retains a compensatory nature; however, the compensation awarded must not be negligible. Otherwise, the compensation mechanism becomes illusory, and the protection of digital fundamental rights loses its practical dimension.

.

1. Introduction

The widespread nature of breaches of data protection regulations has become a permanent feature of the modern digital environment. This is not merely a matter of high-profile security incidents or data breaches, but of everyday, recurring practices: unsolicited direct marketing, excessive data collection, the consistent disregard of objections to processing, the chronic failure to comply with the right of access, extensive profiling, and intensive tracking of online activity. These phenomena affect a vast number of people simultaneously; however, at an individual level, they most often result in non-pecuniary harm that is diffuse and difficult to quantify.

This gives rise to a structural paradox in data protection: the scale of infringements is growing, whilst individuals’ willingness to pursue claims remains low. In judicial practice, non-pecuniary damage associated with a breach of data protection rights – such as a loss of control over information, anxiety, frustration or the need to take protective measures – is sometimes classified as an inconvenience of everyday life, not warranting actual compensation3 . Civil liability for breaches of data protection regulations thus takes on a symbolic (i.e. in practice, nominal) character, incapable of producing a systemic effect.

During the period when Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data(4),attention was drawn to the limited effectiveness of judicial protection of the right to privacy and the protection of personal data, in particular due to the limited practical availability of claims for damages. The GDPR was intended to address these shortcomings by combining a strengthened regime of administrative liability with a direct, EU-wide right of individuals to seek compensation before a national court (Article 82 of the GDPR), in conjunction with the right to an effective remedy (Article 79 of the GDPR and Article 47 of the Charter of Fundamental Rights of the European Union5 )6 .

The Court of Justice of the European Union has clarified in its case-law the conditions for liability under Article 82 of the GDPR, emphasising the need to demonstrate actual damage and a causal link between the infringement and the harm7 . At the same time, the Court rejected the concept of automatic compensation merely for a breach of the GDPR and ruled out the possibility of attributing a punitive character to this mechanism8 . Consequently, Article 82 of the GDPR has been shaped as a classic civil liability regime with a compensatory function9 .

The problem, therefore, does not lie in the lack of a legal basis for bringing claims, but in how non-pecuniary damage and the function of compensation are understood in the context of infringements of fundamental rights in the digital environment10 . Assessing each infringement in isolation, without taking into account its recurrence and cumulative impact on the individual’s situation, and without considering the context (e.g. the mass scale of infringements, the reality of the fear of recurrence and their impact on the accumulation of psychological harm, including the intensity of the ‘information overload’11), leads to a systematic underestimation of the significance of the harm suffered12 . In circumstances where infringements are widespread, even ‘minor’ intrusions into the sphere of privacy can generate a growing sense of loss of agency and control over one’s own data.

Furthermore, the low and token nature of the awards not only fails to provide real compensation for the harm suffered, but also fails to create an economic incentive for data controllers to change their practices. Compensation that can be factored into the costs of doing business does not fulfil a stabilising or preventive function, even if it formally retains the appearance of a compensatory function. Consequently, the question arises as to whether a system that consistently awards minimal compensation for breaches of the right to data protection leads, de facto, to a normative self-depreciation, that is, a weakening of its practical and axiological significance.

The cost of pursuing claims – in financial, time and psychological terms – is also a significant factor. If the burden of conducting court proceedings is clearly disproportionate to the compensation that can be obtained, the right to compensation loses its practical utility and becomes a mere formality13. From this perspective, the issue of the effectiveness of Article 82 of the GDPR must be considered not only in terms of the structure of the grounds for liability, but also in the context of an individual’s actual ability to enforce the protection of their fundamental right.

The aim of this study is therefore to answer the question of whether the entrenched practice of awarding symbolic damages for breaches of data protection legislation leads to the right to privacy in the digital environment being merely a sham. This analysis will be conducted against the backdrop of the function of damages in civil law, the standard of effective judicial protection under EU law, and the latest case law of the Court of Justice concerning Article 82 of the GDPR.

2. The conditions and function of liability under Article 82 of the GDPR following the CJEU judgments

In the case-law of the CJEU, Article 82 of the GDPR has been interpreted as a provision on liability for damages with strictly defined, cumulative conditions, whilst at the same time aiming to provide genuinely effective protection for the individual14 . The Court consistently reconstructs the doctrinal core of this institution, distinguishing it both from the administrative sanctions regime (Article 83 of the GDPR) and from intuitive – yet unauthorised under EU law – attempts to ‘minimise’ non-pecuniary damage by introducing materiality thresholds15 . In this context, the ‘effectiveness’ Article 82 of the GDPR, as consistently emphasised by the CJEU, is to be achieved not by conferring a punitive function on compensation, but by ensuring the practical enforceability of the compensation model: without a materiality threshold for the damage, subject to the requirement to demonstrate actual harm and a causal link, and under the control of the principles of proportionality and effectiveness applied by national courts16 .

Firstly, the CJEU assumes that Article 82 of the GDPR does not create an automatic claim ‘for an infringement’, but rather a claim for compensation for the damage caused by the infringement17 . In its judgment in Case C-741/21, the Court explicitly emphasises that the mere classification of conduct as contrary to the GDPR – even where it concerns the rights of the data subject – does not in itself establish the existence of ‘non-pecuniary damage’ within the meaning of Article 82(1) of the GDPR. An infringement constitutes an element of liability, but does not replace damage – the mere infringement of the provisions is not sufficient to constitute ‘non-pecuniary damage’18 . In this sense, the three-part test of ‘infringement – damage

Secondly, therefore, the CJEU rejects any national rules or practices introducing a materiality threshold (de minimis threshold) for non-pecuniary damage. In its judgment of 4 September 2025, C-655/23, IP v Quirin Privatbank AG20 , the Court recalls that Article 82(1) of the GDPR precludes any national provision or practice making compensation conditional upon the harm reaching a certain level of seriousness; non-pecuniary damage need not ‘exceed a threshold’ – even minimal harm, if genuinely suffered, falls within the scope of the concept21 . Here, an important, often overlooked subtlety emerges: the absence of a materiality threshold does not imply automatic compensation22 . The Court does not turn Article 82 of the GDPR into a tariff for infringements, but constructs a model in which the threshold is removed at the stage of qualifying the harm, whilst the burden of proving that it has actually occurred remains real (and – as a rule – rests with the claimant). In its judgment in Case C-655/23, Quirin, the Court of Justice explicitly states that a mere infringement is not sufficient to give rise to damage; however, negative feelings may constitute non-pecuniary damage where they are duly established, together with negative consequences and a causal link23 . Thirdly, the CJEU is gradually fleshing out the concept of non-pecuniary damage, drawing on recitals 75, 85 and 146 of the GDPR as a ‘roadmap’ for typical forms of harm in the sphere of informational autonomy24 . In the judgment in Case C-655/23, Quirin, the Court emphasises that categories such as ‘loss of control’ over data or ‘damage to reputation’ are expressly mentioned in the recitals of the GDPR as examples of possible harm; therefore – depending on the facts of the case – they may form the core of non-pecuniary harm, even if there has been no further ‘tangible’ use of the data25 . At the same time, the CJEU has brought a degree of rationality to the discussion on emotions and discomfort: not every instance of irritation is automatically compensable, but nor should it be dismissed out of hand as part of the general risk of everyday life (general risk of life)26 . What is decisive is the specific circumstances: whether the individual actually experiences negative feelings and their consequences precisely because of the infringement in question, and not merely on a subjective basis—

discriminatory hostility27 .

Fourthly, the element of liability on the part of the data controller is equally important28 . In Case C-741/21, juris, – ‘causal link’ is not a didactic shorthand, but a dogmatic filter designed to distinguish compensatory liability from purely ‘declaratory’ liability. At the same time, the Court precludes the opposite extreme: since damage is a necessary element, it must not be reduced to an exceptional category reserved for ‘above-average’ or ‘serious’ harm19 .The Court of Justice clarifies the issue of exculpation under Article 82(3) of the GDPR: the data controller does not ‘escape’ liability merely by pointing to an error committed by a person acting under its authority. In other words, an employee’s error is not in itself a defence unless it is demonstrated that the controller ‘is in no way responsible’ for the causative event29 . This approach reinforces the systemic purpose of Article 82 of the GDPR as an instrument designed to operate at the level of the controller’s organisational responsibility for processing operations, rather than merely at the level of individual operational errors.

Fifthly, the CJEU consistently characterises the function of Article 82 of the GDPR as purely compensatory, distinguishing it from the punitive and preventive function of administrative fines. In its judgment in Case C-741/21, the Court explicitly states that Article 82 of the GDPR serves a compensatory, rather than a punitive, function, whilst Articles 83 and 84 of the GDPR are essentially punitive in nature30. This gives rise to several practical legal consequences. First and foremost, since compensation is intended to be full and effective, it cannot be replaced by instruments of a different nature (e.g. by ‘sneaking’ sanction criteria into the determination of the amount of compensation). The Court explicitly rules out the application, mutatis mutandis, of the criteria set out in Article 83 of the GDPR to the quantification of compensation under Article 82 of the GDPR31 . Furthermore: since Article 82 of the GDPR does not serve a deterrent or punitive function, the gravity of the infringement as such cannot lead to the amount of compensation exceeding the extent of the actual damage suffered; compensation is not a tool

‘additional punishment’32 .

Finally, the CJEU rounds off this framework by leaving national legal systems free to choose methods for assessing damage, subject, however, to the principles of equivalence and effectiveness33 . It is the national courts – in the absence of an EU ‘table’ – that must determine the criteria for assessing compensation so that it corresponds to the actual harm suffered and does not render the exercise of the right under Article 82 of the GDPR unduly difficult in practice34 . It is precisely within this tension (the procedural autonomy of Member States versus the requirement of effectiveness) that the fundamental problem we highlighted in the introduction lies: the ‘channelling’ of Article 82 of the GDPR down to the level of symbolic compensation does not stem from a lack of a normative basis, but may be the result of national interpretative and mitigating practices – formally permissible, but materially eroding full and effective compensation35.

To reiterate, a reconstruction of the normative core of Article 82 of the GDPR leads to the conclusion that the Court of Justice has clearly attributed a classic, compensatory character to this provision in nature. Liability does not arise from the infringement itself, but from the damage caused by the infringement; there is no threshold for the seriousness of non-pecuniary damage, but nor is its award automatic; the function of compensation is restitutory, not punitive. This model is internally consistent and systemically coherent with the distinction between the civil compensation mechanism (Article 82 of the GDPR) and the administrative sanctions regime (Article 83 of the GDPR).

It is precisely in this consistency, however, that a fundamental tension becomes apparent. Since Article 82 of the GDPR is intended to ensure ‘full and effective compensation’, whilst at the same time not serving a punitive or deterrent function, the burden of ensuring the real effectiveness of the protection of the right to privacy shifts to the level of specific case-law practice regarding the classification and quantification of non-pecuniary damage. For if such damage is interpreted narrowly, and the amounts awarded are purely symbolic, the compensatory framework – though formally declared – may prove materially insufficient.

This therefore raises the question of the relationship between Article 82 of the GDPR and the standard of effective judicial protection arising from Article 47 of the Polish Constitution36 . If the right to compensation exists in a normative sense, but its enforcement is economically and practically unfeasible, and the compensation has no impact whatsoever on processing practices, then the protection of the fundamental right takes on a purely declaratory character. This is not a matter of attributing a punitive function to Article 82 of the GDPR contrary to the explicit guidance of the CJEU, but rather of assessing whether a purely compensatory model, applied in the context of mass and repetitive infringements, is capable of ensuring the actual effectiveness of the law.

It is precisely here that the central thesis of this study emerges: the discrepancy between a formally comprehensive framework of liability and its practical, limited implementation may lead to a situation in which digital fundamental rights retain an impressive normative form but lose their real impact. In other words, the problem does not lie in the absence of a legal instrument, but in the manner of its application – and in whether the compensation awarded actually gives effect to the constitutional weight of the right to data protection37 .

3. Non-pecuniary damage as a test of the individual’s legal standing in the digital environment

Non-pecuniary damage within the meaning of Article 82 of the GDPR is not limited solely to psychological distress, but concerns the individual’s status as a legal subject in the digital environment38 . A breach of the right to data protection interferes with informational autonomy and may lead to actual weakening of the individual’s agency. If the system’s response is compensation of a purely symbolic nature, the loss of agency is further exacerbated – no longer by the infringement itself, but by its normative trivialisation39 . If non-pecuniary damage is understood in a reductive manner, as short-term psychological distress, without taking into account the context—such as its mass nature, repetitiveness or the lack of persuasive power of the compensation—the consequence will be the award of purely symbolic compensation. In such cases, the secondary deprivation of agency no longer stems solely from the infringement itself, but from the reaction of the legal system, which trivialises that infringement.

3.1. Loss of control as an infringement of informational autonomy

The first and most fundamental dimension of non-pecuniary damage is the loss of control over one’s own personal data. Recitals 75 and 85 of the GDPR explicitly identify the ‘loss of control over personal data’ as one of the typical negative consequences of a breach40 . The case law of the CJEU also emphasises that this type of detriment – if proven – may constitute non-pecuniary damage within the meaning of Article 82 of the GDPR41 .

Loss of control is not a purely abstract concept42 . It can be graded and objectified by analysing factors such as the scope of the data no longer under the individual’s control, the duration of the breach, or the number of entities that gained access to the information. An incidental, short-term breach involving a limited set of data must be assessed differently from profiling lasting several months and based on a broad spectrum of information concerning private life.

In this context, non-pecuniary damage consists of a breach of informational self-determination – understood as an individual’s ability to decide on the disclosure, use and further processing of data concerning them. The protection of this sphere is of a constitutional nature, rooted in Articles 7 and 8 of the Polish Constitution43 . If the infringement leads to the individual being effectively deprived of any influence over the circulation of information about them, the harm concerns their personhood, and not merely their psychological well-being.

3.2. Justified fear of future abuse

The second dimension of non-pecuniary damage is a state of fear regarding further, future consequences of the infringement. The Court of Justice has clearly indicated that negative feelings, such as fear or anxiety, may constitute non-pecuniary damage, provided they are genuine and have a causal link to the infringement 44 .

In particular, the fear is more justified where the breach concerns sensitive data, the data has been made available to third parties of unknown identity, the perpetrator has a history of unlawful practices, or the individual is in a situation of increased vulnerability (e.g. holds public office or carries out activities in which reputation is of fundamental importance). In such circumstances, the harm does not consist solely of subjective fear, but of a real state of uncertainty regarding the future use of the data47 . The situation is similar where the amount of compensation makes it reasonable to expect that it will not be in the infringer’s interests to change their practice, and thus compliance with the law will not be restored.

3.3. Stigmatisation, violation of dignity and instrumentalisation

The third dimension of non-pecuniary damage manifests itself in situations where data processing leads to the objectification of the individual. This concerns cases in which data – particularly those falling within special categories within the meaning of Article 9 of the GDPR – are used in a manner leading to stigmatisation, exclusion, manipulation or discrimination. Profiling, automated decision-making or the disclosure of information concerning health, sexual orientation or political opinions may lead to a violation of an individual’s dignity, understood as the foundation of the Union’s legal order (Article 1 of the Charter of Fundamental Rights of the European Union)48 . In such situations, non-pecuniary damage is not merely an emotional consequence, but

affects the very status of the individual as a subject of law49 .

The subjective aspect of the infringement and the manner in which the data is used may also be relevant. An intentional act aimed at exerting pressure, discrediting or economically exploiting a person differs qualitatively from an incident of a purely technical nature. Although Article 82 of the GDPR does not provide for punitive measures, these circumstances may influence the assessment of the extent of the non-pecuniary damage suffered, as they affect the scope of the infringement of an individual’s autonomy and dignity.

3.4. From the loss of agency to ‘negligible compensation’

If non-pecuniary damage is understood in a reductive manner – as short-term psychological discomfort devoid of greater significance – the consequence will be the award of purely symbolic damages50 . In such a model, the infringement of the right to data protection is reduced to an incident of minor significance, and the data subject is relegated to the role of a passive participant in the flow of information. Consequently, the application of Article 82 of the GDPR serves to intensify the individual’s sense of powerlessness, which is contrary to both the content and the purpose of the provision in question. On the one hand, the data subject affected by the breach is awarded compensation; however, the amount of such compensation exacerbates the sense of injustice.

In the context of widespread, systemic data processing, the loss of control, a state of permanent uncertainty and the risk of instrumentalisation are not marginal phenomena. If compensation does not reflect the actual burden of these harms, the right to data protection loses its subjective dimension and is transformed into a declaration of limited practical value51 . ‘Negligible compensation’ not only fails to restore subjectivity – it further undermines it, as it conveys the message that the infringement of the right has no real normative weight52 . It is precisely in this tension between the normative status of the right to data protection and its practical enforceability that the fundamental problem addressed in this paper.

4. Enforcement of the law and the principle of effectiveness (effet utile)

Considerations regarding the difficulties of enforcing the law must be set against the standard of the effectiveness of EU law. Article 82 of the GDPR – as a provision granting an individual a direct right to compensation – must be interpreted in the light of the principle of effectiveness (effet utile) and Article 47 of the Charter of Fundamental Rights, which guarantees the right to an effective remedy53 . This does not, however, mean equating damage with the costs of proceedings within the meaning of national law54 . These costs are subject to separate regulation and do not constitute a constituent element of liability under Article 82 of the GDPR. The problem arises, however, at a different level: a breach of the right to data protection may give rise to a prolonged state of uncertainty, forcing the individual to take protective measures, monitor the legal situation, reorganise their professional and private activities, and also to endure the mental and organisational strain associated with pursuing claims55 . This dimension damage – as a consequence of the infringement – is not synonymous with the ‘cost of the proceedings’, but rather with a restriction on the actual freedom to dispose of one’s own time and energy56 . This does not involve automatically including procedural steps or the costs of proceedings within the scope of damage within the meaning of Article 82 of the GDPR, but rather taking into account – provided they are demonstrated and have an adequate causal link to the infringement – long-term consequences in the form of a state of uncertainty, disruption to one’s life and the psychological strain caused by the need to enforce the infringed right.

From the perspective of the principle of effectiveness, what is crucial is whether the mechanism under Article 82 of the GDPR constitutes a genuine, rather than an illusory, means of protection57 . If the enforcement of a right entails a long-lasting and significant burden on the individual, whilst the potential compensation remains symbolic, a rational barrier to the pursuit of claims arises. In such a situation, the formal existence of a right to compensation does not translate into its practical exercise. The standard of effectiveness requires not only the availability of a legal remedy in a formal sense, but also that its design and application do not make the exercise of that right unduly difficult58 .

The issue can also be framed in more conservative terms. Even if the consequences associated with pursuing claims are not treated as a separate element of non-pecuniary damage, they should influence the assessment of whether the compensation awarded meets the requirement of ‘full and effective’ protection59 . Compensation of a purely symbolic nature, in the context of costly and time-consuming proceedings, does not provide an incentive to enforce the law and thus does not strengthen its effective protection60 . This reveals a broader systemic problem.

The GDPR is based on the premise that, alongside the supervisory model of enforcement (administrative fines), there also operates a private-law model in which an individual may independently enforce respect for their rights61 . However, if case-law leads to the award of minimal sums, disproportionate to the gravity of the infringement and the effort involved in pursuing it, the mechanism of private enforcement loses its stabilising function. Consequently, the problem is not merely a matter of the amount of a single compensation payment, but concerns the structural relationship between the normative status of the right to data protection and its practical enforceability. If an individual, having rationally weighed up the costs and potential benefits, decides not to pursue a claim, then protection takes on a declaratory character62. The right remains within the system but does not generate any real consequences.

The tension outlined in this way constitutes the direct starting point for the conclusions of this study. If digital fundamental rights are to retain their substantive character, the redress mechanism must be applied in a manner that ensures genuine, rather than merely symbolic, protection. Otherwise, there is a risk that the impressive normative framework – including Article 82 of the GDPR – will remain a framework of limited impact, and the right to data protection will lose its practical significance63 .

4. The compensatory function versus the deterrent function– a contrast with the US model

The discussion on the amount of damages awarded under Article 82 of the GDPR requires a clear distinction to be made between two functional orders which, in private law, may – but need not – overlap: the compensatory function and the deterrent function.

Within the European Union legal system, the Court of Justice has unequivocally ruled that Article 82 of the GDPR is not of a punitive nature64. Damages are not a sanctioning instrument, nor do they serve to impose an additional penalty for an infringement; the deterrent function is primarily fulfilled by the regime of administrative fines under Article 83 of the GDPR65 . The EU legal framework is therefore based on a clear distinction between public-law sanctions and private-law compensation66 .

A different model of compensation operates in the US system, where the institution of punitive damages allows for the award of sums exceeding strict compensation, with the intention of punishing the wrongdoer and deterring similar infringements in the future. There, the deterrent function and the compensatory function may be combined in a single court ruling. Damages become not only a means of redressing harm, but also a regulatory tool67 .

However, this contrast does not lead to the conclusion that the European model requires ‘Americanisation’. The thesis of this paper does not seek to confer a punitive character on Article 82 of the GDPR nor to introduce an equivalent of punitive damages into the EU legal order. The problem lies elsewhere: in the practical effect of applying a purely compensatory mechanism in the context of mass and repetitive infringements68 .

Two extremes can be identified. At one end are systems in which the admissibility of remedies going beyond strict compensation may lead to excessive penalisation and a shift in the burden regulatory framework on private-law judicial mechanisms. The second is a system in which damages are symbolic in nature and do not alter either the individual’s situation or the practices of data controllers. Both models may give rise to dysfunctions, albeit of a different kind69 .

The European legal order – whilst maintaining the purely compensatory nature of Article 82 of the GDPR – does not require payments exceeding the actual extent of the harm suffered. It does, however, require that the amounts awarded should not be negligible70 . Compensation that genuinely reflects the extent of the loss of informational autonomy, the duration of the state of uncertainty and the burden of enforcing the law need not be punitive in nature to influence processing practices71 . The compensatory function and the preventive effect are not identical, but at an economic level they may partly coincide: real compensation may indirectly influence the risk calculation on the part of the controller72 .

In this sense, the European model does not require the adoption of the American approach to sanctions, but rather the consistent application of its own principles. If compensation is to restore an individual’s agency – understood as the real capacity to enforce one’s rights – it cannot be reduced to a purely symbolic payment73 . The absence of a punitive element does not, after all, imply that a fictitious element is permissible74 .

A comparison with the American model therefore serves as a counterpoint: it shows that between ‘private fines running into millions’ and illusory compensation, there is scope for moderate yet genuinely effective solutions. It is precisely within this space that Article 82 of the GDPR should be situated if it is to serve as a genuine instrument for the protection of digital fundamental rights75 .

6. Criteria for determining the amount of compensation – a proposal to standardise practice

If Article 82 of the GDPR is to retain its compensatory nature whilst avoiding the accusation that the protection is merely fictitious, it is necessary to define more precisely the factors that should be taken into account when determining the amount of compensation for non-pecuniary damage76. This is not a matter of creating neither a fixed scale nor the introduction of punitive elements, but rather to ensure that the compensation genuinely corresponds to the extent of the harm suffered77 .

The starting point should be the components of non-pecuniary damage identified in the previous section of this study: loss of informational autonomy, a state of justified fear, and any stigmatisation or instrumentalisation of the individual78 . Each of these elements may vary in intensity and should be assessed on a case-by-case basis.

In particular, the following should be taken into account:

6.1. The sensitivity and nature of the data

An interference concerning ordinary data is not equivalent to an interference involving special categories of data within the meaning of Article 9 of the GDPR, nor data relating to children or the elderly. The stronger the link between the data and an individual’s identity, health, beliefs or private life, the greater the potential extent of the infringement of their personal autonomy79 .

6.2. The scale and permanence of the disclosure

An incident of a local and reversible nature must be assessed differently from a public, global or practically irreversible disclosure. Both the number of recipients and the possibility of the information remaining in circulation permanently (e.g. online) are significant. The permanence of the effects of the breach directly translates into the long-term nature of the harm80 .

6.3. Degree of regained control

It is important whether the victim has regained actual control over their data and whether the effects of the breach have been effectively mitigated. If the breach leaves a lasting state of uncertainty or makes it impossible to fully ‘close’ the matter (including a legitimate fear of a recurrence), the extent of non-pecuniary damage is increased81 .

6.4. The data controller’s conduct following disclosure of the breach

When assessing the harm, the data controller’s conduct following the disclosure of the breach should also be taken into account. Not in terms of sanctions, but as a factor influencing the extent of the harm. Transparent conduct, prompt notification of the data subject and the taking of genuine remedial measures may reduce the sense of uncertainty and fear82 . Conversely, dragging one’s feet

Inaction, a lack of information or downplaying the problem can exacerbate the harm.

6.5. Asymmetry between the parties as a systemic context

The status of the infringer should not influence the amount of damages awarded in a punitive sense. However, in a relationship between an individual and an entity with a dominant market position (e.g. a large digital platform), the extent of the loss of agency and real opportunities to counteract the infringement may be greater than in a relationship with a small, local entity. Organisational and informational asymmetry may therefore influence the severity of the harm suffered, though it should not be treated as a criterion for ‘punishment’83 . However, the asymmetry of power between the parties does affect the psychological element of the harm in the sense that negligible compensation awarded against a large entity allows the individual to reasonably conclude that the behemoth will not change its practices. After all, it is not uncommon for infringers of digital fundamental rights to adopt an attitude of ‘We don’t have your coat, so what are you going to do about it?’. This kind of asymmetry – reinforced by low or token compensation – may lead to the individual becoming convinced that there are no real means of protecting their rights.

6.6. The period of uncertainty and the burden of enforcing the law

The duration of proceedings and the need to take protective measures do not constitute the costs of the proceedings in the formal sense, but may increase the extent of non-pecuniary damage if the infringement causes a prolonged state of uncertainty and the need to reorganise the individual’s life84. We do not advocate an automatic increase in compensation for each subsequent infringement. This would undoubtedly be an overly mechanical and potentially unfair solution. Such a model would lead to a punitive ‘repeat offence’ logic, which is at odds with the compensatory nature of Article 82 of the GDPR. The repetition of conduct may be relevant only insofar as it affects the actual extent of the harm suffered by a specific individual – for example, by perpetuating a state of uncertainty – and not as an independent basis for increasing the compensation85 .

Of course, one must also approach the differentiation of compensation amounts according to the economic status of the parties with caution. Compensation cannot be a linear function

of the infringer’s ‘financial strength’ nor a source of inequality between Member States86 . At the same time, completely disregarding the social context could lead to an underestimation of the harm in situations where the infringement particularly severely interferes with the individual’s functioning in public or professional life. Nevertheless, the absence of a punitive element in the European model of compensation should not mean that, when assessing the damage, the impact of the so-called ‘cost of compliance’ on the sense of objectification experienced by the person affected by the infringement can be overlooked. As we have pointed out above, symbolic or negligible compensation will exacerbate the victim’s sense of powerlessness and objectification⁸⁷. The proposed criteria do not constitute an exhaustive list or a rigid methodology⁸⁸. Their aim is to ensure the transparency and predictability of decisions, whilst maintaining the flexibility necessary when assessing non-pecuniary damage⁸⁹. If applied consistently and reasonably, compensation under Article 82 of the GDPR can retain its purely compensatory nature whilst avoiding the criticism that it is illusory.

This should mean that, when assessing the damage, the impact of the so-called ‘cost of compliance’ on the sense of objectification felt by the person affected by the breach may be disregarded. As we have pointed out above, symbolic or negligible compensation will exacerbate the victim’s sense of powerlessness and objectification87 . The proposed criteria do not constitute an exhaustive list or a rigid methodology88 . Their aim is to ensure the transparency and predictability of decisions, whilst maintaining the flexibility necessary when assessing non-pecuniary damage89 . If they are applied consistently and reasonably, compensation under Article 82 of the GDPR may retain its essentially compensatory nature, whilst at the same time avoiding the accusation of being illusory.

In this sense, the aim is not to raise compensation to the level of a penalty, but to ensure that the compensation is not negligible from the individual’s perspective, whilst also taking into account their belief as to whether the compensation will ‘make a difference’. Only then will the mechanism of private-law enforcement be capable of effectively restoring the individual’s agency and maintaining the credibility of the protection of digital fundamental rights90 .

7. Conclusions: how to ‘demystify’ the fiction of digital fundamental rights

The analysis carried out leads to the conclusion that the problem with Article 82 of the GDPR does not lie in the absence of a normative basis or in a deficiency in its doctrinal framework. The case law of the CJEU has clearly defined the conditions for liability and its compensatory nature, rejecting both the automatic imposition of liability for the infringement itself and attempts to introduce a ‘seriousness’ threshold for non-pecuniary damage91 . The normative core of the provision is therefore well-established.

The tension arises at the practical level – in the way non-pecuniary damage is classified and assessed. If the compensation awarded for a breach of the right to data protection is purely symbolic, that right begins to function as a declaration devoid of any real impact92 . Negligible compensation is not so much ‘insufficient’ as it confirms that the breach does not give rise to any significant legal consequence. In such a model, the data subject formally remains the addressee of the protective provision, but lacks an effective means of enforcing compliance with it.

From the perspective of EU law, this issue must be considered in the light of the principle of effectiveness and Article 47 of the Code of Civil Procedure 93 . Effective legal protection does not consist solely in the existence of a claim within the text of a legal act, but in its actual effectiveness. If a reasonable individual, taking into account the cost and duration of the proceedings as well as the anticipated amount of the payment, decides not to pursue a claim, this means that the protection mechanism is not functioning effectively. A law that does not generate real consequences loses its substantive dimension.

‘Demystifying’ the fiction of digital fundamental rights does not require Article 82 of the GDPR to be given a punitive function, nor does it require the transplantation of the concept of punitive damages. The European model remains a compensatory model and should remain so. However, it requires the refinement of methods for assessing non-pecuniary damage in a way that takes into account the full spectrum of harms already recognised in the case-law of the CJEU – in particular, the loss of informational autonomy, a state of justified fear of further use of data and a recurrence of the infringement94, as well as consequences such as stigmatisation or infringement of dignity. This assessment should also include the burden of prolonged uncertainty and the effort involved in enforcing the law, provided that these are reasonably linked to the infringement.

As we have indicated, we do not propose the introduction of a fixed scale for calculating compensation for breaches of data protection legislation. However, it would be reasonable to develop a realistic model of the legally relevant elements of non-pecuniary damage associated with such breaches.

The elimination of purely symbolic compensation is a prerequisite for maintaining the genuine effectiveness not only of the right to data protection, but also, more broadly, of the protection of fundamental rights in the digital environment95 . Compensation need not be a sanction in order to have an impact on practice. It is sufficient that it is not negligible. Only then can Article 82 of the GDPR serve as a genuine instrument of private-law enforcement, restoring the individual’s status as a subject, rather than merely an object, of data processing. In this sense, the issue concerns not merely the amount of individual sums, but the credibility of the entire data protection system.

The application of Article 82 of the GDPR must not result in reinforcing the individual’s sense of powerlessness in the face of a breach of their rights. The compensation mechanism should not only exist in form, but also restore to the individual a real ability to enforce their rights.

If digital fundamental rights are to retain their constitutional weight, their infringement must entail real consequences96 . Otherwise, the impressive normative framework will remain – to use the metaphor contained in the title – a structure with limited effectiveness.

Bibliography/References

Barta P., Kawecki M., Litwiński P. [in:] General Data Protection Regulation. Personal Data Protection Act. Selected sector-specific provisions. Commentary, ed. P. Litwiński, Warsaw 2025.

Beermann J.M., Punitive Damages in the United States, ‘Newsletter of the German-American Lawyers’ Association

*Zeitschrift für Deutsches und Amerikanisches Recht* 2007/140. De Gregorio G., *Digital Constitutionalism in Europe*, Cambridge 2022.

Fajgielski P., General Data Protection Regulation. Act on the Protection of Personal Data. Commentary, Warsaw 2025. Górski M. [in:] General Data Protection Regulation: Commentary, ed. M. Sakowska-Baryła, Warsaw 2018. Gumularz M., The impact of the provisions on liability for damages in the General Data Protection Regulation on the private law systems of Member States,

‘European Judicial Review’ 2017/5.

Li S., ‘Compensation for non-material damage under Article 82 of the GDPR: A review of Case C-300/21’, *Maastricht Journal of European and Comparative Law* 2023/30(3).

Mulders S., The relationship between the principle of effectiveness under Article 47 CFR and the concept of damages under Article 82 GDPR, *International Data Privacy Law* 2023/13(3). Pawełko A., Jamiołkowska M., Liability for damage suffered as a result of a breach of the GDPR and private law regulations arising from national legal systems – using the Polish system of protection of personal rights as an example, ‘Palestra’ 2025/1. The GDPR. A Guide with Templates, ed. M. Gawroński, Warsaw 2018.

Salziger S., ‘Between Data Protection and AI: Civil Liability for Non-Material Damage in Article 82 of the GDPR’, *European Data Protection Law Review* 2024/10(4).

Schabowski J., Markowski J., The Justification for Courts Awarding Compensation under Article 82 of the GDPR for Non-pecuniary Damage, ‘Monitor Prawniczy’ 2024/4.

Sebok A.J., Punitive Damages: From Myth to Theory, *Iowa Law Review* 2006/92(3).

Stępień A., Anxiety as non-pecuniary damage under personal data protection legislation, *Monitor Prawniczy* 2023/11.

Strugała R., The GDPR and liability for damages. Fundamental issues regarding liability for damage caused by the improper processing of personal data, *Monitor Prawniczy* 2018/17.

Zanfir-Fortuna G. [in:] The EU General Data Protection Regulation (GDPR): A Commentary, eds. Ch. Kuner, L.A. Bygrave et al., Oxford 2020.

Endnotes

  1. The views expressed are solely those of the author.
  2. OJ (EU) L 119, p. 1, as amended – hereinafter the GDPR.
  3. See S. Li, ‘Compensation for non-material damage under Article 82 GDPR: A review of Case C-300/21’, *Maastricht Journal of European and Comparative Law* 2023/3(30), p. 342, where the author points out that traditional national approaches relying on a threshold of seriousness for non-material damage remain at odds with the objectives of Article 82 of the GDPR; similarly, the judgment of the Court of Justice of 14 December 2023, C-456/22, VX and AT v Gemeinde Ummendorf, EU:C:2023:988, paragraphs 18 and 22 – hereinafter the judgment in Case C-456/22, Gemeinde Ummendorf.
  4. OJ EC L 281, p. 31, as amended; the act has been repealed – hereinafter ‘Directive 95/46/EC’.
  5. Consolidated version: OJ (EU) C 202, 2016, p. 389 – hereinafter the KPP.
  6. See S. Salziger, ‘Between Data Protection and AI: Civil Liability for Non -Material Damage in Article 82 of the GDPR, ‘European Data Protection Law Review’ 2024/10(4), p. 324, or R. Strugała, The GDPR and Liability for Damages. Fundamental Issues of Liability for Damage Caused by the Incorrect Processing of Personal Data, ‘Monitor Prawniczy’ 2018/17, p. 914; cf. also S. Mulders, The relationship between the principle of effectiveness under Art. 47 CFR and the concept of damages under Art. 82 GDPR, ‘International Data Privacy Law’ 2023/3(13), p. 169.
  7. Judgments of the Court of Justice: of 4 May 2023, C-300/21, UI v Österreichische Post AG, EU:C:2023:370, paragraph 32 – hereinafter the judgment in Case C-300/21, Österreichische Post; of 4 October 2024, C-507/23, A v Patērētāju tiesību aizsardzības centrs, EU:C:2024:854, paragraphs 24–27 – hereinafter the judgment in Case C-507/23, A.
  8. Judgments of the Court of Justice: of 11 April 2024, C-741/21, GP v juris GmbH, EU:C:2024:288, paragraph 40 – hereinafter the judgment in Case C-741/21, juris; of 20 June 2024, joined cases C-182/22 and C-189/22, JU and SO v Scalable Capital GmbH, EU:C:2024:531, paragraph 43 – hereinafter the judgment in C-182/22 and C-189/22, Scalable; judgment in C-507/23, A, paragraph 34.
  9. Judgment of the Court of Justice of 25 January 2024, C-687/21, BL v Media Markt Saturn Hagen-Iserlohn GmbH, EU:C:2024:72, paragraph 47 – hereinafter the judgment in C-687/21, Media Markt; judgment in C-741/21, juris, paragraphs 59–60.
  10. In this context, we are referring to digital fundamental rights. Cf.

G. De Gregorio, *Digital Constitutionalism in Europe*, Cambridge 2022,

p. 18 et seq.

  1. By the term ‘information overload’, we mean here the number of digital stimuli and messages that every individual must currently cope with.
  2. See S. Mulders, The relationship..., p. 169, where the author points out that the harm resulting from breaches of the GDPR is often intangible, dispersed and, individually, ‘minor’, although when occurring on a massive scale it can have a significant cumulative impact.
  3. See S. Mulders, The relationship..., p. 179, where the author links Article 82 of the GDPR to the requirement of a real possibility of obtaining redress in the light of Article 47 of the Charter of Fundamental Rights; see also judgment C-507/23, A, paragraphs 32–34.
  4. See S. Salziger, *Between...*, pp. 324–325; R. Strugała, *GDPR...*, pp. 914–915.
  5. Judgment of the Court of Justice of 21 December 2023, C-667/21, ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, EU:C:2023:1022, paragraphs 84–86 – hereinafter the judgment in Case C-667/21, ZQ; the judgment in Case C-507/23, A, paragraphs 40–41; and the judgment in Case C-456/22, Gemeinde Ummendorf, paragraph 18.
  6. See S. Li, *Compensation...*, pp. 335–336; S. Mulders, *The relationship...*, p. 169; Judgment C-507/23, A, paragraphs 32–34.
  7. Judgment in Case C-300/21, Österreichische Post, paragraph 32; Judgment in Case C-741/21, juris, paragraph 40; Judgment in Case C-507/23, A, paragraphs 24–27.
  8. Judgment in Case C-741/21, juris, paragraph 32 and operative part, point 1.
  9. See also R. Strugała, GDPR..., pp. 914–915, who regards Article 82 of the GDPR as an independent basis for liability for damages and identifies the classic elements of a tort.
  10. EU:C:2025:655 – hereinafter the judgment in Case C-655/23, Quirin,
  11. Judgment C-655/23, Quirin, paragraphs 58–60.
  12. See S. Li, *Compensation...*, pp. 335–336, where the author rightly emphasises that the rejection of the threshold of seriousness of the damage does not remove the requirement to prove it; see also Judgment C-507/23, A, paragraphs 24–27.
  13. Judgment in Case C-655/23, Quirin, paragraphs 56–57 and 61–62.
  14. See S. Salziger, Between..., pp. 325–326; M. Górski [in:] General Data Protection Regulation: Commentary, ed. M. Sakowska-Baryła, Warsaw 2018, Article 82, pp. 586 et seq.; the author points out that compensation under Article 82 of the GDPR covers both pecuniary and non-pecuniary damage, and that the concept of damage should be interpreted broadly; cf. also Judgment C-655/23, Quirin, paragraphs 59–60.
  15. Judgment C-655/23, Quirin, paragraphs 59–60.
  16. See A. Stępień, ‘Fear as non-pecuniary damage under data protection legislation’, *Monitor Prawniczy* 2023/11, pp. 65–71, particularly in the light of the judgment in Case C-300/21, Österreichische Post, and the judgment of the Court of Justice of 14 December 2023, Case C-340/21, VB v Natsionalna agentsia za priho-dite, EU:C:2023:986, paragraphs 77–80 – hereinafter the judgment in Case C-340/21, VB.
  17. Judgment in Case C-655/23, Quirin, paragraphs 61–62.
  18. Judgment in Case C-741/21, Juris, paragraph 47 and paragraph 2 of the operative part; see also M. Górski [in:] General Regulation..., Article 82, p. 588, where the controller’s exculpation is linked to the need to demonstrate that they bear ‘no responsibility whatsoever’ for the harmful event.
  19. Judgment in Case C-741/21, Juris, paragraph 47 and operative part, paragraph 2.
  20. Judgment in Case C-741/21, Juris, paragraphs 59–60; judgment in Case C-667/21, ZQ, paragraphs 84–86; see also S. Salziger, *Between...*, pp. 326–327.
  21. Judgment in Case C-741/21, ECR, paragraphs 56–58, 62; see also Judgment in Case C-507/23, A,                                                                                                                             

paragraphs 41–43.

  1. Judgment in Case C-741/21, juris, paragraphs 60–61.
  2. Judgment in Case C-741/21, Juris, para. 59; Judgment in Case C-507/23, A, paras. 32–34; cf. S. Li, *Compensation...*, pp. 335–336.
  3. Judgment in Case C-741/21, Juris, paragraphs 58 and 63–65.
  4. See J. Schabowski, J. Markowski, ‘The Legitimacy of Courts Awarding Compensation under Article 82 of the GDPR for Non-pecuniary Damage’, *Monitor Prawniczy* 2024/4, pp. 253–256; A. Pawełko, M. Jamiołkowska, ‘Liability for damage suffered as a result of a breach of the GDPR and private-law regulations arising from national legal systems – the example of the Polish system for the protection of personal rights’, *Palestra* 2025/1, pp. 132–157.
  5. See S. Mulders, The relationship..., p. 169; S. Li, Compensation..., pp. 335–336; cf. also judgment C-507/23, A, paras. 32–34.
  6. cf. R. Strugała, GDPR..., pp. 914–915. See also M. Gumularz, ‘The impact of the provisions on liability for damages in the General Data Protection Regulation on the private law systems of Member States’, *European Judicial Review* 2017/5, pp. 31 et seq.
  7. See M. Górski [in:] General Data Protection Regulation..., Article 82, p. 587, where it is pointed out that non-pecuniary damage encompasses infringements of an individual’s informational autonomy, and not merely transient emotional states; cf. also S. Salziger, Between..., pp. 324–325
  8. See J. Schabowski and J. Markowski, *The Legitimacy...*, pp. 253–256, where a tendency to award low amounts of compensation is highlighted; see also A. Pawełko and M. Jamiołkowska, *Liability...*, pp. 132–157.
  9. See recitals 75 and 85 of the GDPR; see also M. Górski, [in:] General Regulation..., Article 82, p. 588, where the loss of control over data is cited as a typical example of non-pecuniary damage.
  10. Judgment C-655/23, Quirin, paragraphs 59–60.
  11. See S. Li, *Compensation...*, pp. 335–336, where the need to specify non-pecuniary damage by analysing the consequences of the infringement is highlighted; see also S. Mulders, *The relationship...*, p. 169.
  12. See Articles 7 and 8 of the Code of Civil Procedure; cf. M. Górski [in:] General Regulation..., Article 82,

p. 586 or other commentaries.

  1. Judgment C-655/23, Quirin, paragraphs 56–57.
  2. See A. Stępień, *Fear...*, pp. 65–71, which analyses the limits of recognising fear as damage; see also judgment C-340/21, VB, paragraphs 77–80.
  3. See A. Stępień, ‘Fear…’, pp. 65–71.
  4. See S. Mulders, The relationship..., p. 169, where it is pointed out that non-pecuniary damage may consist of a state of persistent uncertainty regarding the fate of the data.
  5. See S. Salziger, *Between...*, pp. 326–327, which highlights the link between data processing and the risk of discrimination and infringement of dignity; see also Recital 75 of the GDPR.
  6. See M. Górski [in:] General Data Protection Regulation..., Art. 82, p. 587, where it is emphasised that non-pecuniary damage encompasses infringements of personal rights and the individual’s dignity; see also A. Pawełko, M. Jamiołkowska, Liability..., pp. 132–157.
  7. See J. Schabowski, J. Markowski, *The Legitimacy...*, pp. 253–256; S. Li, *Compensation..., pp. 335–336
  8. See S. Mulders, The relationship..., p. 169; cf. also judgment C-507/23,

A, paragraphs 32–34 (principle of effectiveness).

  1. cf. R. Strugała, GDPR..., pp. 914–915; S. Salziger, Between..., pp. 324–327;

S. Mulders, *The relationship...*, p. 169.

  1. For further details, see P. Barta, M. Kawecki, P. Litwiński [in:] General Data Protection Regulation. Personal Data Protection Act. Selected Sectoral Provisions. Commentary, ed. P. Litwiński, Warsaw 2025, Article 82 of the GDPR, pp. 619–628; cf. also P. Fajgielski, General Data Protection Regulation. Act on the Protection of Personal Data. Commentary, Warsaw 2025, Article 82 of the GDPR, as well as S. Mulders, The relationship...,

p. 169; see also judgment C-507/23, A, paragraphs 32–34.

  1. See M. Górski [in:] General Data Protection Regulation..., Article 82, p. 588, where the distinction between the concept of damage and the costs of proceedings is highlighted, as well as the need to demonstrate harm that has an adequate causal link to the infringement.
  2. See S. Mulders, The relationship..., p. 169, where it is pointed out that non-pecuniary damage may include a state of permanent uncertainty and the need to take protective measures; see also S. Li, Compensation...,pp. 335–336.
  3. See S. Li, *Compensation...*, pp. 335–336, where the author clearly distinguishes non-pecuniary damage from the costs of pursuing a claim, whilst pointing out that the consequences of an infringement may encompass a wider range of adverse effects than those traditionally recognised under national law.
  4. Judgment in Case C-507/23, A, paragraphs 32–34; see also S. Mulders, The relationship..., p. 169.
  5. See Judgment C-741/21, Juris, paragraphs 63–65; see also S. Mulders, The relationship..., p. 169.
  6. See S. Salziger, *Between...*, pp. 326–327, where the need to interpret Article 82 of the GDPR in a manner that ensures the compensation is genuinely effective is highlighted; see also the judgment in Case C-741/21, Juris, paragraphs 59–60.
  7. See J. Schabowski, J. Markowski, The Legitimacy..., pp. 253–256; A. Pawełko,

M. Jamiołkowska, Liability..., pp. 132–157.

  1. See R. Strugała, The GDPR..., pp. 914–915, where the dual nature of enforcement mechanisms (administrative and civil) is highlighted; cf. also S. Salziger, Between..., pp. 324–325.
  2. Cf. S. Mulders, The relationship..., p. 169, where it is pointed out that a legal remedy must not only be formally available but also practically enforceable; see also judgment C-507/23, A, paragraphs 32–3
  3. See S. Salziger, *Between...*, pp. 324–327; R. Strugała, *GDPR...*, pp. 914–915.
  4. Judgment C-741/21, juris, paragraphs 59–60; judgment C-667/21, ZQ, paragraphs 84–86.
  5. Judgment C-741/21, Juris, paras. 59–61; Judgment C-507/23, A, paras. 40–42; see also S. Salziger, *Between...*, pp. 324–335.
  6. See also G. Zanfir-Fortuna [in:] The EU GDPR: A Commentary, ed. Ch. Kuner, L.A. Bygrave et al., Oxford 2020, Article 82, pp. 1160–1179.
  7. For a more detailed discussion of the US system, see, for example, A. J. Sebok, ‘Punitive Damages: From Myth to Theory’, *Iowa Law Review* 2006/92(3), p. 957. Cf. also J.M. Beermann, ‘Punitive Damages in the United States’, *Newsletter of the German-American Lawyers’ Association / Zeitschrift für Deutsches und Amerikanisches Recht* 2007/140.
  8. See S. Mulders, The relationship..., pp. 169–181; S. Li, Compensation...,pp. 335–345.
  9. See J. Schabowski, J. Markowski, *The Legitimacy...*, pp. 253–256; A. Pawełko,

M. Jamiołkowska, Liability..., pp. 132–157.

  1. Judgment C-741/21, Juris, paragraphs 60–61; judgment C-507/23, A, paragraphs 34–35.
  2. See Judgment C-507/23, A, paragraphs 34–35, from which it follows that a small amount of compensation may be permissible only on condition that it fully compensates for the damage suffered; see also Judgment C-182/22 and C-189/22, Scalable, paragraph 43.
  3. See the judgment in Case C-741/21, Juris, paragraph 59, which distinguishes the compensatory function of Article 82 of the GDPR from the punitive purpose of Articles 83 and 84 of the GDPR; see, however, also paragraph 59 of that judgment, where the Court points out that the right to compensation ‘reinforces the operational nature’ of the protective provisions and may deter the repetition of unlawful conduct.
  4. Cf. S. Mulders, The relationship.., pp. 169–181; S. Salziger, Between...,

pp. 324–335.

  1. See judgment in Case C-507/23, A, paragraphs 32–35; S. Mulders, The relationship...,

pp. 169–181.

  1. See S. Mulders, The relationship..., pp. 169–181; S. Salziger, Between...,

pp. 324–335; R. Strugała, GDPR..., pp. 914–922.

  1. See Judgment C-741/21, Juris, paragraphs 63–65, where the Court leaves it to the national courts to determine the methods for calculating the amount of compensation, whilst observing the principles of equivalence and effectiveness; see also S. Li, Compensation...,

pp. 335–336.

  1. Judgment C-741/21, Juris, paragraphs 60–61 (the compensatory nature of damages and the absence of a punitive function).
  2. See M. Górski [in:] General Data Protection Regulation..., Article 82, p. 588, where a broad understanding of non-pecuniary damage is highlighted, encompassing infringements of information autonomy; see also S. Salziger, *Between...*, pp. 324–326.
  3. See Recital 75 of the GDPR (risk to the rights and freedoms of natural persons depending

the nature of the data); cf. also Judgment C-655/23, Quirin, paragraphs 59–60 (loss of control and non-pecuniary damage).

  1. See S. Mulders, The relationship..., p. 169, which highlights the significance of the long-term effects of a breach for the assessment of non-pecuniary damage.
  2. Judgment C-655/23, Quirin, paragraphs 56–57, 61–62 (negative feelings and a state of uncertainty as possible non-pecuniary damage, if actual and proven).
  3. See M. Górski [in:] General Regulation..., Article 82, p. 587, where the importance of the overall circumstances of the infringement for the assessment of the extent of non-pecuniary damage is emphasised.
  4. See S. Mulders, The relationship..., pp. 169–181, where it is pointed out that the effectiveness of protection depends on the individual’s actual ability to enforce their rights; see also S. Li, Compensation..., pp. 335–336.
  5. See S. Mulders, The relationship..., p. 169; Judgment C-507/23, A, paragraphs 32–34 (the requirement of practical effectiveness of a protective measure).
  6. Judgment in Case C-741/21, Juris, paragraphs 60–61 (prohibition on attributing a punitive function to compensation and linking it to the ‘gravity of the infringement’ as such).
  7. Judgment in Case C-741/21, Juris, paragraphs 56–58, 60 (exclusion of the application of sanction-based criteria and analogy with Article 83 of the GDPR when determining compensation).
  8. See J. Schabowski, J. Markowski, ‘The Legitimacy...’, pp. 253–256; A. Pawełko,

M. Jamiołkowska, Liability..., pp. 132–157.

  1. See P. Fajgielski, commentary on Article 82 of the GDPR, p.....
  2. See judgment C-741/21, Juris, paragraphs 63–65; S. Li, *Compensation...*, pp. 335–336.
  3. See S. Mulders, The relationship..., pp. 169–181; S. Salziger, Between...,

pp. 324–327; Judgment C-507/23, A, paragraphs 32–34.

  1. Judgment in Case C-300/21, Österreichische Post, para. 32; Judgment in Case C-741/21, juris, para. 40; Judgment in Case C-655/23, Quirin, paras. 56–57.
  2. See J. Schabowski, J. Markowski, *The Legitimacy...*, pp. 253–256; A. Pawełko,

M. Jamiołkowska, Liability..., pp. 132–157.

  1. See S. Mulders, *The relationship...*, p. 169; Judgment C-507/23, A, paras. 32–34.
  2. As one of the authors of this text put it, referring to his repeated and unsuccessful attempts to object to direct marketing by a certain bank: ‘One might say, in the words of Oscar Wilde, that until now, lodging an objection in Poland has been as easy as giving up smoking – I’ve done it many times. Let us hope that the GDPR will improve this situation somewhat’ – see GDPR. A Guide with Templates, ed. M. Gawroński, Warsaw 2018, p. 237.
  3. Cf. S. Salziger, *Between...*, pp. 324–327; S. Li, *Compensation...*, pp. 335–336.
  4. See S. Mulders, The relationship..., pp. 169–181; Judgment C-507/23, A, paras. 32–34; Judgment C-741/21, Juris, paras. 63–65.