GDPR Article 82 Damages Claims: Recent Case Law for Online Shops
AI generated
§
2026
Data Protection · GDPR Article 82 · Damages · Online Retail Law
GDPR Article 82 Damages Claims
what online shops should know now

A data protection breach in an online shop can give affected customers a right to damages under Article 82 of the General Data Protection Regulation, and this now applies to small and medium shops as well, not only to large corporations. We explain in plain language what this means and what to do now.

9 min read For shop owners, not legal advice Relevant for every shop with customer data

1. What is Article 82 GDPR and what is it about?

The GDPR, the General Data Protection Regulation, is the EU-wide rule governing how personal data may be processed. For an online shop this means: your customers' name, delivery address, order history and payment data are personal data, and you as the shop owner are the one who decides how that data is processed. That is precisely why the GDPR places obligations on you as the so-called "controller", and precisely why Article 82 of the GDPR can become relevant as soon as something goes wrong in that processing.

Article 82 GDPR gives every person who has suffered damage because of a GDPR violation their own right to claim damages against the controller. What matters here is that two kinds of damage count: material damage, meaning a financial disadvantage such as money lost through misuse of stolen payment data, and non-material damage. Non-material, sometimes also called immaterial or moral damage, means a harm that cannot be expressed in monetary terms, such as distress, fear of data misuse, or the feeling of having lost control over one's own data. Both kinds of damage can form the basis of a claim under Article 82 GDPR.

The term "controller" sounds abstract and legalistic at first, but in practice it usually means, very concretely, you yourself as the shop owner, not your web agency, not your hosting provider. Whoever decides on the purpose and means of data processing, that is, who determines which customer data is stored for which purpose, bears responsibility under the GDPR. This role cannot simply be outsourced by contract, even if the technical implementation and server operation are handed over to service providers. Processing itself, meaning every collection, storage, disclosure or deletion of customer data, therefore remains your legal responsibility, even when a provider runs the technology behind it.

2. Since when does it apply, and when does it become acute?

The GDPR has been in force EU-wide since 25 May 2018, and Article 82 with its right to damages was part of it from the start. What has changed since then is not the wording of the law but the practice: the actual wave of litigation around Article 82 has only intensified noticeably in recent years, driven substantially by rulings of the European Court of Justice, known as the ECJ. The ECJ is the European Union's highest court for questions of EU law, and its interpretation of the GDPR is binding on courts in all member states.

A particularly important clarification is one the ECJ has made repeatedly, among others in a widely noted case against the Austrian Post: a mere violation of the GDPR alone does not automatically trigger a right to damages. An actual damage must exist, and that damage must be demonstrated by the claiming party. At the same time, the ECJ has deliberately set the bar low for what counts as damage: even brief distress, the fear of data misuse, or a perceived loss of control over one's own data can already be sufficient. The ECJ specifically does not require any particular threshold of seriousness, of the kind one might expect from other areas of damages law.

For shop owners the topic becomes acute above all because, alongside the case law, the ways in which affected people can actually enforce their claims have also changed. Specialized legal service providers and so-called legal-tech platforms now actively gather affected individuals after a data breach becomes known and bundle their claims together. What used to be barely worth the effort of an individual lawsuit for a single affected person becomes economically attractive through this bundling, both for the affected individuals and for the providers of such platforms.

In the everyday practice of online shops, such claims typically arise from certain recurring triggers. These include data breaches and leaks, for example a hacked customer database, an incorrectly configured data export, or order data accidentally made publicly accessible. Equally common are unsolicited marketing emails sent without valid consent, the disclosure of customer data to third parties or tracking services without valid consent, for instance through tracking pixels or analytics tools, and late or incomplete responses to access requests under Article 15 GDPR. Knowing these typical triggers lets you focus precisely where most claims actually originate in practice.

3. Who is affected, does this apply to small shops too?

Yes, explicitly to small shops as well. Article 82 GDPR does not distinguish by company size, turnover, or number of employees. Practically every online shop that processes personal customer data, meaning it stores, processes, or discloses names, addresses, order history, or payment data, is affected. This applies to a one-person shop with a few hundred orders a year just as much as to a large online retailer with revenue in the millions. The widespread belief "we are too small to be sued" does not hold up in practice: small shops have already been confronted with damages claims after data breaches in the past, not only large corporations with well-known brand names.

The reason lies in the nature of the data itself, not in the size of the business. A small shop often stores the very same sensitive data categories as a large provider: full name, delivery address, payment method, sometimes even order history, from which conclusions about personal preferences or life circumstances can be drawn. If a data breach occurs, for example because a customer database is hacked, a data export is misconfigured, or order data is accidentally made publicly accessible, the affected customers are protected in their rights exactly as they would be with a large provider.

A real-world example from a small shop's everyday operations

A small online shop for natural cosmetics uses a contact form plugin that accidentally makes uploaded order confirmations for several customers publicly accessible through an insecure link. The mistake is only noticed when an affected customer stumbles upon the open file themselves and complains. Even though the shop only processes a few thousand orders a year and is not a well-known brand name, the resulting loss of control over one's own data is already enough, from the perspective of current case law, for affected customers to bring a claim under Article 82 GDPR.

4. What you specifically need to do

The most important building block is what the GDPR calls technical and organizational measures, or TOMs for short. These are concrete protective measures used to safeguard customer data against unauthorized access, loss, or misuse, such as access controls, encryption, or backup concepts. TOMs should not only be implemented but also documented in writing, so that in a real incident it can be proven that adequate protective measures were in place.

Concretely, this includes restricting access rights to customer data so that only the people who actually need it for their work have access, and encrypting stored as well as transmitted data. Equally important is a clean process for handling access requests under Article 15 GDPR. Article 15 gives every customer the right to find out what data a shop has stored about them, what it is used for, and to whom it may have been disclosed. Such requests generally must be answered in full within one month, and a late or incomplete response is itself already a possible violation that can give rise to a damages claim.

In addition, every shop needs a prepared notification process for data breaches. If a data breach occurs, it generally must be reported to the competent supervisory authority within 72 hours of becoming aware of it, a deadline known as the notification obligation. Anyone who has not prepared this process in advance loses valuable time in a real incident figuring out internally who needs to do what. All of this is rounded off by cleanly obtained cookie and tracking consents, an up-to-date privacy policy, and a record of processing activities, meaning an internal overview of which data is processed for which purpose and on which legal basis.

5. Checklist: securing data protection in your shop

  • Introduce, document, and regularly update technical and organizational measures (TOMs).
  • Restrict access rights to customer data so that only people who need it for their work have access.
  • Encrypt stored and transmitted customer data.
  • Establish a clear process for access requests under Article 15 GDPR, with a response within one month.
  • Prepare a notification process for data breaches, including reporting to the supervisory authority within 72 hours.
  • Obtain cookie and tracking consent cleanly, transparently, and in a way that can be proven.
  • Keep your privacy policy and record of processing activities up to date.

6. Fines and risks of non-compliance

A damages claim under Article 82 GDPR is independent of any regulatory fine proceedings. This means: even if the competent data protection supervisory authority sees no grounds for a fine, or such proceedings have not even been initiated, individual customers can still go to court themselves and demand damages. The two proceedings run legally separate from one another.

The size of the damages amounts that courts award per affected person has often been moderate in case law to date. The real economic risk arises, however, when many customers are affected at the same time, for example after a data leak involving thousands of affected people. In such cases the cumulative risk across all individual claims can add up considerably, even if the individual amount per person remains modest. This is exactly where the legal-tech platforms already mentioned come in, actively gathering many affected individuals and pursuing their claims in bundled form.

Beyond the direct financial risk, further, often underestimated consequences can follow: reputational damage once a data breach becomes publicly known, a noticeable amount of time and cost for your own legal defense, and, in repeat cases, a growing wave of lawsuits when a larger data breach becomes known and several customers join forces. Even a single claim can tie up considerable time, even if only a moderate amount is ultimately awarded, because preparing a legal defense costs resources regardless of the outcome.

Important to know

Damages claims under Article 82 GDPR can be brought independently of any regulatory fine, so the absence of fine proceedings does not automatically protect you. Individual amounts per affected person are often moderate, but with many affected people after a larger data breach, the overall risk can add up noticeably. Investing early in technical and organizational protective measures significantly lowers this risk, regardless of the size of your own shop.

7. Common misconceptions

A widespread misconception goes: "As long as the supervisory authority does not impose a fine, I am not at risk of a lawsuit either." This is wrong. Damages claims by individual customers under Article 82 GDPR are possible independently of regulatory fine proceedings, and a customer can sue without a fine ever having been on the table.

A second misconception is the assumption that a data leak alone is already enough for a claim. This is also not correct: the ECJ requires an actual damage that must be demonstrated by the affected person. However, as described, the bar for this is set very low, so that a loss of control over one's own data, or the mere fear of misuse, is often already sufficient.

A third misconception concerns company size: "Only big corporations get sued." This, too, does not match reality. Small shops have already been confronted with damages claims after data breaches in the past, because from the perspective of the affected customer it does not matter how large the company is that lost or mishandled their data.

8. What Mironsoft can take care of for you

We know that topics such as technical and organizational measures, access requests, and notification obligations can quickly feel overwhelming for shop owners without a technical or legal background. Mironsoft takes care of the practical side for you: we review how your shop system processes personal data, which cookie and tracking services are embedded, and whether the necessary consents are being obtained cleanly.

Beyond that, we support you in building and documenting technical and organizational measures, set up a process together with you so that access requests under Article 15 GDPR can be answered quickly and completely, and secure your server infrastructure so that typical entry points for data breaches are reduced from the outset.

The goal is that you, as a shop owner, do not have to grapple alone with GDPR wording or technical details of server configuration, but instead have a reliable partner who takes care of the technical implementation and alerts you in good time when action is needed, before a small detail turns into a serious risk. This way, data protection stays a manageable, plannable part of your shop's daily operations instead of a constant background worry.

Triggering event Reaction deadline Responsible body
Data breach Notification to the supervisory authority generally within 72 hours Competent data protection supervisory authority
Access request under Article 15 GDPR Response generally required within one month Shop owner as controller
Damages claim under Article 82 GDPR Standard limitation period under German civil law generally 3 years Competent civil court

9. Summary

Article 82 GDPR gives every person who has suffered material or non-material damage because of a data protection violation a right to damages against the responsible shop owner. The ECJ has clarified that a mere violation alone is not automatically enough, an actual damage must exist, though the bar for this is deliberately kept low.

Practically every shop that processes customer data is affected, regardless of its size. Implementing technical and organizational measures, answering access requests on time, and preparing a notification process for data breaches significantly lowers your own risk. This article provides a general overview and does not replace individual legal advice for your specific case.

GDPR Article 82 Damages Claims: The Essentials at a Glance

What it is about

Anyone who suffers material or non-material damage from a GDPR violation can claim damages from the shop owner.

Who is affected

Practically every shop with customer data, regardless of size or turnover, small shops are no exception.

Biggest risk

Lawsuits are possible independently of regulatory fines, and risk adds up quickly with many affected people.

What to do

Implement TOMs, answer access requests on time, prepare a notification process for data breaches.

10. FAQ: GDPR Article 82 Damages Claims

1What is Article 82 GDPR in simple terms?
A right to damages for anyone who has suffered material or non-material damage from a data protection violation, against the responsible shop owner.
2What does non-material damage mean?
A harm with no direct monetary value, such as distress, fear of misuse, or loss of control over one's own data.
3Is a data leak alone enough for a claim?
No, an actual damage must exist. The bar for this is low though, loss of control is often already enough.
4Is my small shop really at risk?
Yes, the rule does not distinguish by company size. Small shops have already been sued.
5What happens with an access request under Article 15?
The customer learns what data is stored and what it is used for. Response generally required within one month.
6How much time to report a data breach?
Generally 72 hours after becoming aware, reported to the competent supervisory authority.
7Do damages claims expire?
Yes, generally under the standard three-year limitation period, counted from knowledge of the damage and the liable party.
8What are legal-tech platforms?
Specialized legal service providers that gather affected people after data breaches and pursue claims in bundled form.
9Is a cookie banner alone enough?
No, TOMs, access request processes, and a notification process for data breaches are equally part of proper protection.
10What can Mironsoft specifically take care of?
Reviewing data processing, cookie and tracking review, support with TOMs, and building an access request process.

This article provides a general overview of Article 82 GDPR and does not replace individual legal advice for your specific case.