Search
Contact
09.05.2023 | KPMG Law Insights

ECJ on Data Protection: No Materiality Threshold for Damages

A breach of the General Data Protection Regulation (GDPR) alone is not sufficient to give rise to a claim for compensation for non-material damage. In the opinion of the ECJ, damage must actually have occurred to the person concerned. However, this damage need not exceed a “materiality threshold.”

In its judgment of May 4, 2023 (Case No.: C-300/21), the ECJ for the first time commented on a question that had been highly controversial, especially before German courts: the prerequisites for a claim for damages under Art. 82 GDPR .

The ECJ has clarified that a claim for damages under the GDPR is subject to three conditions:

  • a breach of provisions of the GDPR,
  • the occurrence of material or immaterial damage, and
  • the causality between the breach and the damage.

A mere violation of the GDPR is thus expressly not sufficient to establish a claim for damages, as the occurrence of a causal damage must be proven in each case.

No materiality threshold – even minor damage must be compensated for

However, this damage does not have to exceed a materiality threshold. The Court justifies this, among other things, by stating that the application of a corresponding de minimis limit would entail a significant risk of divergent case law and would thus run counter to the objective of maintaining a uniform level of data protection within the Member States, as set out in recital 10 of the GDPR.

The amount of damages is in principle subject to national law, provided that the principles of equivalence and effectiveness are observed. Financial compensation must fully compensate for the damage suffered as a result of the infringement. The claim does not have a punitive character.

The courts must decide at what point damage exists

The fact that plaintiffs must also prove concrete damage for a claim for damages is to be welcomed. However, it is not always clear at what point non-material damage is to be assumed. The determination of this remains the responsibility of the national courts. It remains to be seen whether the “subjective feeling of dissatisfaction” of the affected parties due to a GDPR violation, which is often cited in German case law, will be sufficient to establish that damages are compensable. The ECJ ruling does not provide any concrete answers to this question. Consequently, the presentation of a corresponding damage, which will be required by the courts in the future, will be decisive.

An increase in mass litigation must be expected

The clear denial of a materiality threshold tends to play into the hands of warning law firms and other service providers in the field of mass actions. In addition, German lawmakers are planning to implement the EU directive on collective actions this year. This means that consumer associations will also be able to sue directly for damages with the so-called remedial action for consumers. As a result, an increase in mass lawsuits related to GDPR violations is also to be expected. Affected companies are therefore likely to increasingly turn to legal tech products to fend off mass lawsuits.

Conclusion

Company executives should address the organizational and strategic challenges of mass litigation at an early stage. Again, better safe than sorry. The ECJ ruling has once again increased the financial risks associated with data privacy breaches. Companies should therefore continue to focus on establishing and expanding solid data protection management systems, including adequate handling of data subjects’ rights and data protection incidents, in order to prevent fines and claims for damages as far as possible.

Explore #more

16.04.2026 | KPMG Law Insights

Index clauses in commercial leases: BGH ruling opens up clawback risks for landlords

Value assurance provisions in the form of index clauses in standard commercial leases are not only subject to the restrictions of the Price Clause Act,…

16.04.2026 | In the media

Guest article in Beschaffung aktuell: Faster procurement for the Bundeswehr

With the Planning and Procurement Acceleration Act, the German government wants to make Bundeswehr procurement significantly faster. The temporary special law simplifies procurement procedures, allows…

09.04.2026 | Press releases

KPMG Law strengthens its insurance practice in Cologne with Dr. Julia Faenger

Since April 1, 2026, Dr. Julia Faenger, LL.M., has been strengthening the insurance law advice of KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) in Cologne as…

08.04.2026 | KPMG Law Insights

New Package Travel Directive 2026: Complaint management becomes mandatory

The EU is reforming the Package Travel Directive. The amendments were adopted by the European Parliament and Council in March 2026 and are expected to…

02.04.2026 | KPMG Law Insights

Building Modernization Act (GMG): What is now important for companies

The planned Building Modernization Act (GMG) is set to replace significant parts of the previous Building Energy Act (GEG). Companies in the real estate industry,…

01.04.2026 | In the media

Manager Magazin: KPMG Law in first place for legal advice

Every two years, Manager Magazin, together with the Wissenschaftliche Gesellschaft für Management und Beratung (WGMB), awards Germany’s best auditors with a “Best-in-Class” seal and evaluates

27.03.2026 | KPMG Law Insights

Special Infrastructure Fund and State Aid Law: Orientation for Funding Practice and Planning

The special fund “Infrastructure and Climate Neutrality” (SVIK) also entails considerable responsibility under state aid law for federal states, municipalities and recipients of funds. Anyone

23.03.2026 | Deal Notifications

KPMG Law, KPMG Law AT as well as KPMG in Germany and KPMG in Austria advise GOLDBECK GmbH on the acquisition of 50 percent of the shares in ZAUNERGROUP Holding GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and Buchberger Ettmayer Rechtsanwälte GmbH (KPMG Law AT) as well as KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG in Germany) and KPMG…

19.03.2026 | KPMG Law Insights

Business Judgement Rule in the use of AI: how governing bodies are liable for decisions

If an AI provides the basis for business decisions, the people responsible are liable, not the machine. This makes the use of artificial intelligence risky…

16.03.2026 | KPMG Law Insights

KPIs in the legal department: How legal becomes strategically effective through control, transparency and data analysis

Today, legal departments are facing a strategic turning point: they must reliably hedge risks, but at the same time enable speed, control costs and make…

Contact

Francois Heynike, LL.M. (Stellenbosch)

Partner
Head of Technology Law

THE SQUAIRE Am Flughafen
60549 Frankfurt am Main

Tel.: +49-69-951195770
fheynike@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll