Damages claims for breaches of GDPR are becoming more common – what applies?
Conditions for damages
Persons who consider themselves to have been affected by a breach of GDPR are entitled to claim compensation for the damage they have suffered from either the personal data controller or the personal data processor that participated in the processing. For example, it can concern situations where personal data has been shared illegally or there is no legal basis for the processing.
For liability for damages to be present, three criteria must be met:
Breach. A breach of GDPR (or where appropriate another applicable data protection legislation) must be established.
Actual damage. The individual must be able to demonstrate that s/he actually suffered damage, either material damage (i.e. pecuniary damage) or non-material damage (i.e. non-pecuniary damage, a type of compensation of violations to personal integrity). If a breach has taken place, but the individual has not suffered any harm, there is consequently no liability for damages.
There must be a causal connection between the breach of the data protection legislation and the damage suffered.
The Swedish Privacy Protection Authority (IMY) does not bring actions for damages against individuals. Individuals are instead directed to bring an action in court, which they are always entitled to do. It is therefore ultimately the court that determines whether damages are to be paid and what magnitude they are to be.
How large can the damages be?
The damages levels that apply according to Swedish case law are normally between SEK 3,000 - 5,000 in relation to non-pecuniary damage, but in a few individual cases have been at the levels of SEK 15,000 – 35,000. An individual is also entitled to compensation for material damages that s/he suffered due to the breach, e.g. if s/he is subject to identity theft or fraud, but this type of damages is very unusual.
Damages in foreign courts can be higher. For example, in several cases, German courts have set non-pecuniary damages at about 2,000 Euros.
So even though the level of damages in individual cases is low, the amounts can be major if a large number of persons are affected or if the breach leads to material damages.
Who pays the damages?
As set out above, in principle individuals are entitled to claim compensation either from the personal data controller or the personal data processor.
The point of departure is that it is personal data controllers that are liable for damages caused through infringements of the regulation. A personal data processor is only liable for damages that have arisen as a result of the processing if it has not fulfilled its obligations as personal data processor or acted outside of or contrary to the personal data controller's legal instructions
If several personal data controllers or personal data processors are involved in the same processing, for example, through an IT operation or a common database, the starting point is that the data subject has the right to claim compensation for the entire damages from any of these actors. These actors may then regulate the liability for damages between themselves through the right of recourse provided in GDPR. A condition for liability for damages is, however, that the actor from which damages are claimed is at least partially responsible for the incident that caused the damage.
These division of liabilities principles are often clarified, supplemented or modified between these actors if there is a personal data processing agreement or other agreement that regulates the liability for common processing of personal data. So always make sure to have an agreement that is adapted for the personal data processing in your operation and in your collaborations!

Do you want to know more? Contact:
Gabriel Miller
Senior Associate | AdvokatMikael Olsson
Senior Associate | AdvokatLisa Liljekvist
Senior Associate | AdvokatIda Karlsson
Specialist Counsel | AdvokatPontus Etéus
Senior Associate | AdvokatIda Hjorth
Associate | AdvokatCarousel items
-
Cases and transactions
6/30/2025
Lindahl advisor when Insig acquires residential portfolio in Nyköping
Insig AB has acquired four centrally located residential properties in Nyköping from Rikshem. Lindahl acted as legal advisor to Insig in the transaction. The agreed purchase price amounts to SEK 265 million, and completion is scheduled for 4 July...
-
News articles
6/27/2025
Johan Åberg appointed new Managing Partner at Lindahl in Stockholm
As of July 1, Advokatfirman Lindahl’s Stockholm office has a new Managing Partner. Johan Åberg succeeds Monica Lagercrantz, who has led the Stockholm office since January 2022.
-
Knowledge
6/27/2025
AB 04 and ABT 06 - Update on the BKK revision
After many years of work, the Construction Contracts Committee (BKK) is approaching the final phase of the comprehensive revision of the construction industry's standard contracts AB 04 and ABT 06. Here, Lindahl's experts review the latest status...
-
Portraits
6/23/2025
20 years at Lindahl: "It's a good grade, you develop all the time"
Johan Tollgerdt Ronnell has been part of Lindahl for almost 20 years. "It's a good mark, there have always been good and new career and development opportunities here."
-
Read more news and insights?