Skip to main content
Category: Data Subject Rights

Right to Compensation

Also known as: Right to Claim Compensation, Right to Damages
Simply put

The right to compensation generally allows a person who has suffered harm because of unlawful conduct to recover money for that harm. In a data protection setting, it refers to a data subject's ability to claim compensation when they suffer damage as a result of processing that breaches applicable data protection law. The evidence packet provided here does not contain data-protection-specific sources, so the description below draws only on the general legal concept it supports.

Formal definition

In general legal terms, a right to compensation entitles a party who has sustained injury or financial loss through another's wrongful conduct or negligence to a monetary award, whether by settlement or adjudication; the specific standards, measure of damages, and liable party vary by jurisdiction and cause of action. The sources in this evidence packet address the concept only in general civil, constitutional, and statutory contexts (for example, negligence-based personal injury, just compensation for condemned property under the U.S. Fifth Amendment, and statutory workers' compensation), and do not establish the data-protection-specific parameters of this right. Because no data protection instrument (such as the EU GDPR, UK GDPR, CCPA/CPRA, or HIPAA) is present in the evidence provided, this entry does not scope how a right to compensation operates for data subjects, how liability is allocated between a controller and a processor, or what threshold of material or non-material damage applies under any such regime; those matters are out of scope pending sources that address them directly.

Why it matters

A right to compensation is one of the more consequential remedies available when data protection obligations are breached, because it moves accountability beyond regulatory fines and into direct redress for the individuals affected. For organizations, this means that non-compliance can generate liability owed to data subjects themselves, not only to supervisory authorities. Under the EU GDPR (and identically under the UK GDPR), Article 82 provides data subjects with a right to claim compensation for material and non-material damage suffered as a result of an infringement, which is significant because it recognizes that harm from unlawful processing is not always financial and can include distress or reputational effects.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads should understand that a right to compensation exposes the organization to direct claims from individuals in addition to regulatory enforcement. Under the EU and UK GDPR, this right attaches to both material and non-material damage, so remediation planning and breach response should account for the possibility of individual claims, not only supervisory authority scrutiny. The precise thresholds and procedures depend on the applicable regime and are out of scope here.
Data Controllers and Processors
Because the EU GDPR and UK GDPR under Article 82 address how liability is allocated between controllers and processors, both parties have an interest in understanding their respective exposure. Contractual arrangements between them should be reviewed in light of how compensation liability can be attributed, though the detailed allocation rules should be assessed against the relevant instrument and legal advice rather than assumed.
Legal and Compliance Teams
Legal and compliance professionals advising on data protection matters need to distinguish the right to compensation from regulatory penalties, since the former is a remedy pursued by or on behalf of affected individuals. They should scope claims against the specific regime in question, as the general civil-law concept of compensation differs from the data-protection-specific right, and treatment varies across jurisdictions.

Inside Right to Compensation

Right to Compensation (EU GDPR Article 82)
Under the EU GDPR, any person who has suffered material or non-material damage as a result of an infringement of the Regulation has the right to receive compensation from the controller or processor responsible. The UK GDPR contains an equivalent provision. This entry is scoped to that regime; other frameworks such as the CCPA/CPRA, HIPAA, or ISO/IEC 27701 handle remedies and liability differently and should not be assumed to mirror this right.
Material and non-material damage
The right generally covers both material damage (such as financial loss) and non-material damage (such as distress or reputational harm). The precise scope of recoverable non-material damage is interpreted by courts and can vary; this entry does not resolve those interpretive questions or quantify awards.
Allocation of liability between controller and processor
A controller is generally liable for damage caused by processing that infringes the Regulation. A processor is typically liable only where it has not complied with obligations specifically directed at processors, or where it acted outside or contrary to lawful instructions of the controller. This distinction preserves the separate accountability of each party rather than treating them interchangeably.
Joint and several liability
Where more than one controller or processor is involved in the same processing and is responsible for damage, each may generally be held liable for the entire damage to ensure the data subject is effectively compensated. A party that has paid full compensation may typically seek to recover from other responsible parties the portion corresponding to their share of responsibility. This entry does not detail the mechanics of such recovery claims.
Exemption from liability
A controller or processor is generally exempt from liability if it proves it is not in any way responsible for the event giving rise to the damage. The burden of demonstrating this typically rests on the controller or processor, reflecting the GDPR's accountability principle that evidence, not merely stated intent, is required.
Relationship to enforcement and administrative fines
The right to compensation is a private-law remedy pursued by or on behalf of the data subject and is distinct from administrative fines or enforcement action imposed by a supervisory authority. This entry does not cover fine levels, enforcement procedure, or the interaction between compensation claims and regulatory penalties.

Common questions

Answers to the questions practitioners most commonly ask about Right to Compensation.

Does the right to compensation require proof of financial loss, or is that a misconception?
It is a misconception that only financial loss qualifies. Under the EU GDPR (and the UK GDPR), the right to compensation covers both material damage (such as financial loss) and non-material damage (such as distress). A data subject who has suffered non-material harm may still have a claim, though whether such harm is recoverable, and to what extent, depends on the jurisdiction and how national courts interpret the threshold for compensable damage. Treatment differs outside these regimes, and this answer does not address how damages are quantified.
If a processor caused the harm, does that mean only the processor is liable to the data subject?
Not necessarily, and assuming so is a common error. Under the EU and UK GDPR, a controller is generally liable for damage caused by processing that infringes the regulation, while a processor is liable only where it has not complied with obligations specifically directed at processors or where it acted outside or against the controller's lawful instructions. Both may be involved in a claim, and rules allowing a data subject to claim full compensation from one party, with subsequent apportionment between them, typically apply. This does not address the internal contractual allocation of liability between the parties.
Which lawful instrument should we reference when handling a compensation claim?
For processing within the scope of the EU GDPR, the relevant provision addressing compensation is found in the GDPR itself; the UK GDPR contains an equivalent right. Other regimes, such as the CCPA and CPRA, HIPAA, or sector-specific laws, address remedies and private rights of action differently and should not be treated as interchangeable. Identify the applicable regime for the specific processing and jurisdiction before responding, as the basis, scope, and available remedies vary.
What evidence should a controller retain to defend against or respond to a compensation claim?
Accountability under data protection frameworks generally requires demonstrable evidence rather than stated intent. Controllers typically maintain records showing the lawful basis for processing, records of processing activities, security and governance measures in place, and documentation of any incident and the response taken. Where a controller seeks to argue it is not responsible for the event giving rise to damage, contemporaneous evidence of compliance and of the measures implemented is generally central. This answer does not address litigation procedure or the standard of proof in any specific court.
How does the right to compensation interact with regulatory fines and enforcement?
Compensation to a data subject is a civil remedy pursued by or on behalf of the affected individual and is separate from administrative fines or enforcement action taken by a supervisory authority. A controller or processor may face both, or either, depending on the circumstances. This entry does not cover the calculation of administrative fines, enforcement thresholds, or penalty amounts, which are governed by separate provisions and authority discretion.
Should responsibility for compensation claims sit with governance, security, or legal functions?
Responding to a compensation claim generally requires coordination across functions rather than ownership by a single one. Legal typically leads on assessing liability and defending claims, information governance provides evidence of processing records and accountability measures, and information security provides evidence of the confidentiality, integrity, and availability controls relevant to the underlying incident. These functions overlap but remain distinct, and the specific allocation should be defined in advance through documented roles and responsibilities. This answer does not prescribe an organizational structure.

Common misconceptions

No data protection instrument gives individuals a right to claim compensation; it is purely a matter of regulatory fines.
The EU GDPR expressly provides a right to compensation for material and non-material damage, and the UK GDPR contains an equivalent provision. This is a private remedy that exists alongside, and separately from, administrative fines imposed by supervisory authorities.
Only the data controller can ever be liable to pay compensation.
Under the GDPR a processor can also be liable, generally where it breached obligations directed specifically at processors or acted outside or against the controller's lawful instructions. Liability allocation depends on each party's role and conduct, and joint and several liability may apply where multiple parties are responsible for the same processing.
A controller or processor can avoid a compensation claim simply by asserting it did nothing wrong.
Exemption generally requires the controller or processor to prove it is not in any way responsible for the event causing the damage. Consistent with the accountability principle, this typically demands demonstrable evidence rather than a stated assertion of compliance.

Best practices

Map, for each processing activity, whether your organisation acts as controller or processor under the EU or UK GDPR, since liability under Article 82 is allocated according to that role.
Maintain demonstrable, contemporaneous evidence of compliance and of lawful controller instructions, so that any claim to exemption from liability can be substantiated rather than merely asserted.
Review contracts with controllers, processors, and sub-processors to address allocation of responsibility and rights of recovery in light of potential joint and several liability.
Treat compensation exposure as distinct from regulatory fines in your risk assessments, recognising that a private compensation claim can arise independently of supervisory enforcement.
Where you operate across multiple jurisdictions, do not assume the GDPR compensation right applies elsewhere; confirm the specific remedies available under each applicable regime (for example CCPA/CPRA or HIPAA) separately.
Involve legal counsel when assessing non-material damage exposure, as the scope of recoverable distress or reputational harm is subject to evolving court interpretation.