Recital 146
General Data Protection Regulation · UE 2016/679
| (146) | The controller or processor should compensate any damage which a person may suffer as a result of processing that infringes this Regulation. The controller or processor should be exempt from liability if it proves that it is not in any way responsible for the damage. The concept of damage should be broadly interpreted in the light of the case-law of the Court of Justice in a manner which fully reflects the objectives of this Regulation. This is without prejudice to any claims for damage deriving from the violation of other rules in Union or Member State law. Processing that infringes this Regulation also includes processing that infringes delegated and implementing acts adopted in accordance with this Regulation and Member State law specifying rules of this Regulation. Data subjects should receive full and effective compensation for the damage they have suffered. Where controllers or processors are involved in the same processing, each controller or processor should be held liable for the entire damage. However, where they are joined to the same judicial proceedings, in accordance with Member State law, compensation may be apportioned according to the responsibility of each controller or processor for the damage caused by the processing, provided that full and effective compensation of the data subject who suffered the damage is ensured. Any controller or processor which has paid full compensation may subsequently institute recourse proceedings against other controllers or processors involved in the same processing. |
In Luxembourg, Article 82 GDPR compensation claims are brought before the civil district court (tribunal d'arrondissement), and the law of 1 August 2018 organising the CNPD does not derogate from the joint and several liability principle of recital 146. Luxembourg case-law aligns with the CJEU and admits pure non-material damage, even without a gravity threshold. For financial sector actors, the CSSF may additionally impose cumulative administrative sanctions for data governance breaches, without absorbing GDPR civil liability.
Luxgap practice: we recommend documenting your evidence chain in French or Luxembourgish to facilitate its production before the district court, and subscribing to a cyber liability insurance that explicitly covers Article 82 condemnations and recourse costs against processors.