Civil Law And Behavioral Advertising Privacy Harm Claims In Europe .
Civil Law and Behavioral Advertising Privacy Harm Claims in Europe
1. Introduction
Behavioral advertising privacy harm arises when an online platform, advertising network, data broker, publisher, app developer, or other business collects and analyses information about an individual in order to predict interests, behaviour, characteristics or purchasing decisions and then uses that information for targeted advertising.
Typical data may include:
browsing history;
search history;
location;
device identifiers;
cookies;
advertising IDs;
purchase history;
app activity;
social-media activity;
inferred interests;
behavioural profiles;
sensitive or special-category information;
data obtained from third parties.
The resulting civil dispute may involve:
data collection → profiling → targeting → privacy interference → economic/non-material harm → compensation.
European law does not have one standalone cause of action called “behavioral advertising privacy harm.” Claims are principally built around the GDPR, the ePrivacy framework, consumer law, contract law, tort/delict principles, and, in some circumstances, competition law.
The CJEU's recent Meta Platforms (C-252/21) judgment is especially important because it directly connected large-platform behavioural advertising, personal-data processing, consent, legitimate interests and competition law. (curia)
2. What Is Behavioral Advertising?
Behavioral advertising differs from ordinary contextual advertising.
Contextual advertising
A website about cars displays advertisements for cars.
The advertisement is selected mainly because of the content of the page.
Behavioral advertising
A platform observes that a person:
searches for cars;
visits car websites;
watches automobile videos;
searches for financing;
visits dealerships;
and creates an advertising profile predicting:
“This person is likely to purchase a vehicle.”
Advertisements are then selected based on the individual's behaviour or inferred characteristics.
The privacy problem is that the system may involve persistent monitoring and profiling across services.
3. Principal European Legal Framework
A. GDPR
The GDPR provides the central civil-law framework.
Important provisions include:
Article 5 — principles of processing;
Article 6 — lawful bases;
Article 7 — consent;
Article 9 — special-category data;
Articles 12–14 — transparency/information;
Article 15 — access;
Article 17 — erasure;
Article 18 — restriction;
Article 21 — objection;
Article 22 — automated decision-making;
Article 24 — controller responsibility;
Articles 26–28 — controller/processor relationships;
Article 32 — security;
Article 35 — DPIA;
Article 79 — judicial remedies;
Article 82 — compensation.
Article 82 is particularly important because it provides a civil compensation mechanism for material and non-material damage resulting from GDPR infringement.
4. Lawful Basis for Behavioral Advertising
A company cannot simply say:
“The user agreed to our terms, therefore we can track everything.”
The controller must identify an appropriate legal basis.
Possible legal bases include:
consent;
legitimate interests;
contract, where genuinely necessary;
other Article 6 grounds where applicable.
The EDPB has specifically emphasised that targeted advertising is not automatically necessary for performing a contract merely because advertising supports the platform's business model. (European Data Protection Board)
5. Consent
For consent to be valid under the GDPR, it must generally be:
freely given;
specific;
informed;
unambiguous;
withdrawable.
Therefore:
“Accept all cookies”
combined with:
“Reject”
hidden behind several screens can generate legal questions concerning whether the user's choice was genuinely free and informed.
The EDPB's 2024 Opinion 08/2024 specifically addressed “consent or pay” models for behavioural advertising and stated that large platforms generally need to provide users with a real choice; merely requiring users either to consent to behavioural advertising or pay may not ordinarily satisfy the GDPR's requirements for freely given consent. (European Data Protection Board)
6. Case 1 — Meta Platforms and Others
Case C-252/21, CJEU, 4 July 2023
This is the most important modern CJEU authority for behavioral-advertising privacy disputes.
The case concerned Meta's processing of so-called “off-Facebook” data, including information obtained from other websites and applications.
The German competition authority had treated certain data-processing practices as relevant to competition-law concerns.
The CJEU addressed the relationship between:
GDPR;
consent;
legitimate interests;
special-category data;
contractual necessity;
competition law;
dominant platforms.
The Court held, among other things, that a dominant platform cannot automatically treat all extensive personal-data processing as necessary for performing its social-network contract.
The case is particularly significant because it recognises that data-protection compliance and competition law can interact. (curia)
Civil-law significance
A behavioral-advertising claim may therefore involve more than a simple privacy-policy dispute.
Potential issues include:
unlawful profiling;
invalid consent;
excessive data combination;
processing of third-party data;
lack of transparency;
unfair contractual practices;
abuse of a dominant position.
Principle
A platform's commercial dependence on targeted advertising does not by itself make extensive behavioural-data processing contractually necessary.
7. Case 2 — Meta Platforms Ireland (Represented Action)
Case C-757/22, CJEU, 11 July 2024
This case concerned a consumer association's representative action relating to Meta's processing practices.
The CJEU examined issues concerning collective/representative enforcement of GDPR rights and the ability of consumer organisations to bring proceedings concerning unlawful processing.
The judgment is important because privacy harms from behavioral advertising can affect millions of users simultaneously.
Significance
Instead of:
1 user → 1 lawsuit
European law can permit certain representative or collective enforcement mechanisms.
This is particularly significant where the alleged practice is:
systematic;
platform-wide;
repeated;
difficult for an individual user to litigate economically.
The CJEU's 2024 judgment is now an important authority for the relationship between GDPR enforcement and representative actions. (Curia)
Principle
Large-scale data-processing practices can be challenged through collective or representative mechanisms where the applicable procedural requirements are satisfied.
8. Case 3 — Wirtschaftsakademie Schleswig-Holstein
Case C-210/16, CJEU, 5 June 2018
Wirtschaftsakademie concerned a Facebook fan page and the responsibility of the page administrator for processing personal data through Facebook's platform.
The CJEU held that the administrator and Facebook could be regarded as joint controllers in relation to relevant processing.
Importance for behavioral advertising
This is highly relevant to advertising ecosystems involving:
Publisher → advertising platform → analytics provider → data broker
A company cannot necessarily escape responsibility by saying:
“The advertising platform collected the data, not us.”
Where parties jointly determine relevant purposes or means, joint-controller principles may apply.
Principle
Responsibility can be distributed across an advertising ecosystem rather than resting exclusively with the platform operating the advertising technology.
9. Case 4 — Fashion ID GmbH & Co. KG
Case C-40/17, CJEU, 29 July 2019
Fashion ID concerned a website embedding Facebook's “Like” button.
The embedded technology could transmit visitors' personal data to Facebook.
The CJEU held that the website operator could be a joint controller for the collection and transmission of personal data, even though it did not control every subsequent processing operation.
Behavioral advertising relevance
The same reasoning is important for:
tracking pixels;
social-media plug-ins;
advertising SDKs;
analytics tools;
retargeting technologies;
embedded advertising scripts.
Principle
A website operator can have GDPR responsibility for the part of an advertising-data operation in which it participates, even if another company performs later processing.
10. Case 5 — Planet49
Case C-673/17, CJEU, 1 October 2019
Planet49 concerned cookies and the requirements for valid consent.
The CJEU addressed whether a pre-ticked checkbox could constitute valid consent for cookies.
The Court concluded that consent cannot simply be inferred from a pre-selected box; the user must actively indicate agreement.
Importance
Cookies are a fundamental component of behavioral advertising.
They can enable:
user recognition;
cross-site tracking;
advertising profiles;
retargeting;
measurement of advertising behaviour.
Therefore Planet49 is one of the most important European authorities for advertising-tracking consent.
Principle
Silence, inactivity or a pre-ticked box does not satisfy the GDPR/ePrivacy consent requirements where affirmative consent is required.
11. Case 6 — Orange România
Case C-61/19, CJEU, 11 November 2020
Orange România concerned consent to personal-data processing and whether consent could genuinely be considered freely given where contractual documentation created uncertainty about what the consumer was agreeing to.
The CJEU emphasised that consent must involve a freely given, specific, informed and unambiguous indication of the individual's wishes.
Behavioral advertising application
Suppose a platform presents:
“By using this service, you agree to all data processing, advertising, analytics and partner sharing.”
The question becomes whether the user has genuinely given separate and informed consent.
Principle
Consent must reflect a genuine affirmative decision rather than being buried inside general contractual conditions.
The CJEU's subsequent case law continues to rely on Orange România when assessing consent and transparency. (Curia)
12. Case 7 — Österreichische Post
Case C-300/21, CJEU, 4 May 2023
This is one of the most important cases for privacy damages.
The CJEU considered Article 82 GDPR and clarified that:
GDPR infringement alone
does not automatically establish a right to compensation.
There must be:
an infringement;
damage;
causal connection between the infringement and the damage.
However, the CJEU also held that EU law does not impose a minimum seriousness threshold for non-material damage.
Behavioral advertising application
A user might claim:
“The platform illegally created an advertising profile about me.”
The court must then distinguish:
unlawful processing
from
compensable harm caused by that processing.
Potential non-material harm could include, depending on the evidence and applicable law:
loss of control over personal data;
distress;
reputational consequences;
privacy intrusion;
fear concerning misuse of personal information.
But the claimant must still establish actual damage and causation under Article 82.
Principle
GDPR violation and compensable privacy damage are related but legally distinct questions.
13. Case 8 — UI v Österreichische Post
Case C-300/21, CJEU, 4 May 2023
This is the same leading Article 82 authority often referred to as Österreichische Post.
Its significance is especially important in behavioral-advertising claims because privacy litigation frequently involves non-material damage rather than conventional economic loss.
For example:
“I did not lose money, but I was subjected to unlawful profiling.”
The claim is not automatically successful merely because the processing was unlawful.
The claimant must demonstrate the legally relevant damage and causal connection.
14. Case 9 — Google Spain
Case C-131/12, CJEU, 13 May 2014
Google Spain concerned the right to request removal of search results relating to an individual.
Although it was not an advertising case, it is foundational for understanding European privacy rights in relation to online information.
The CJEU recognised important rights concerning:
personal data;
online dissemination;
individual privacy;
data subjects' rights;
balancing privacy against other interests.
Behavioral advertising relevance
The case supports the broader principle that online processing can have significant consequences for personal autonomy and privacy.
A behavioral profile can similarly influence what information, advertisements and commercial opportunities an individual encounters.
Principle
Online personal-data processing can create legally significant interference with individual privacy and autonomy.
15. Case 10 — Breyer v Germany
Case C-582/14, CJEU, 19 October 2016
Breyer concerned dynamic IP addresses and whether they can constitute personal data.
The CJEU adopted an interpretation under which an IP address may constitute personal data where the controller has legally available means that could reasonably be used to identify the person.
Advertising relevance
Online advertising frequently depends on:
IP addresses;
device identifiers;
browser identifiers;
cookies;
advertising IDs.
Thus, Breyer is important for determining whether technical identifiers fall within personal-data protection.
Principle
Technical online identifiers can constitute personal data where identification is reasonably possible under the applicable circumstances.
16. Case 11 — Österreichische Post / Identity of Data Recipients
Case C-154/21, CJEU
This line of CJEU case law concerns the right of data subjects to obtain information concerning the recipients of their personal data.
Behavioral advertising significance
Suppose a user asks:
“Who received my advertising profile?”
The answer may require identifying relevant recipients or categories of recipients depending on the applicable circumstances.
This is important because behavioral advertising frequently involves multiple actors:
Platform → ad exchange → demand-side platform → advertiser → analytics provider → data broker.
Transparency becomes difficult when individuals cannot determine where their data went.
17. Joint Controller Problem
Behavioral advertising commonly involves an ecosystem rather than a single company.
Example:
User
↓
Website
↓
Tracking pixel
↓
Advertising platform
↓
Data broker
↓
Advertiser
↓
Analytics provider
The cases Wirtschaftsakademie and Fashion ID show why controller status must be examined functionally.
A company cannot necessarily avoid GDPR responsibility simply by outsourcing technical processing.
18. Data Brokerage
A particularly sensitive area is the purchase and sale of behavioral information.
For example:
Data broker purchases information about 10 million users and creates commercial profiles.
Potential data points:
age;
location;
interests;
shopping history;
political interests;
health-related inferences;
financial interests.
The legal problems can include:
lawful basis;
transparency;
source of data;
purpose limitation;
data minimisation;
accuracy;
profiling;
special-category data;
retention;
onward transfers.
19. Sensitive Inferences
Behavioral advertising becomes more legally sensitive where algorithms infer information relating to:
health;
religion;
political opinions;
sexual orientation;
ethnicity;
biometric characteristics.
Even if the user never directly supplied the sensitive information, an advertising system may infer it from behaviour.
This can raise questions under Article 9 GDPR concerning special-category data.
20. Profiling
GDPR Article 4(4) defines profiling broadly around automated processing used to evaluate or predict aspects concerning an individual.
Behavioral advertising is therefore closely connected with:
profiling → prediction → segmentation → targeted advertising.
Examples:
“likely luxury purchaser”;
“likely to need medical products”;
“financially vulnerable”;
“frequent traveller”;
“likely teenager”;
“high-value customer.”
The more intrusive the profile, the more significant the questions of transparency, fairness and lawful basis can become.
21. Automated Decision-Making
Not every targeted advertisement is automatically an Article 22 decision.
This distinction is important.
Ordinary targeted advertising
Algorithm chooses which advertisement to display.
Significant automated decision
Algorithm decides whether a person receives a loan, insurance, employment opportunity or other legally/significantly consequential treatment.
Article 22 concerns certain decisions based solely on automated processing that produce legal effects or similarly significant effects.
Therefore:
Behavioral advertising ≠ automatically Article 22 decision-making.
But profiling can become relevant to Article 22 if the advertising system is linked to a decision producing the requisite significant effect.
22. Consent-or-Pay Models
Modern European privacy litigation increasingly involves:
“Consent to personalised advertising or pay for an ad-free service.”
The EDPB's 2024 Opinion 08/2024 is particularly important.
It states that large platforms should provide a real choice, and that merely offering:
behavioural advertising consent OR payment
will in many cases not be enough to establish freely given consent. (European Data Protection Board)
The EDPB also emphasises that consent does not remove the obligation to comply with:
fairness;
purpose limitation;
data minimisation;
necessity;
proportionality;
accountability.
(European Data Protection Board)
23. Legitimate Interests
A company may attempt to rely on legitimate interests rather than consent.
This requires a balancing analysis.
Generally, the controller must consider:
legitimate interest;
necessity of processing;
balancing against the individual's rights and freedoms.
For behavioral advertising, questions include:
How much data is collected?
Is cross-service tracking involved?
Is profiling extensive?
Is the individual reasonably expecting it?
Are sensitive characteristics involved?
Can less intrusive advertising achieve the same objective?
The Meta C-252/21 judgment is especially important for the limits of relying on contractual necessity and for the relationship between data processing and a platform's economic model. (curia)
24. Privacy Harm Without Financial Loss
One of the most important civil-law questions is:
Can a person suffer legally relevant harm even without losing money?
Yes, potentially.
GDPR Article 82 expressly covers material and non-material damage, subject to its requirements.
Examples of potential non-material harm may include:
distress;
loss of control;
privacy intrusion;
anxiety concerning misuse;
reputational consequences.
But Österreichische Post makes clear that an infringement alone is not enough; damage and causation must still be established.
25. Economic Privacy Harm
Behavioral advertising can also generate economic loss.
Examples:
discriminatory pricing;
differential offers;
exclusion from commercial opportunities;
manipulation of purchasing behaviour;
incorrect consumer categorisation;
exploitation of vulnerability.
Suppose an algorithm incorrectly labels a person:
“High-risk consumer.”
The platform then provides worse commercial terms.
The claimant may potentially have:
GDPR claims;
consumer-law claims;
discrimination claims;
contractual claims;
tort/delict claims.
The applicable cause of action depends upon the particular facts.
26. Manipulative Advertising
Privacy and consumer law can overlap when profiling is used to exploit behavioural vulnerabilities.
Examples:
targeting individuals during periods of vulnerability;
repeated advertisements designed to exploit compulsive behaviour;
using sensitive inferred information;
dark patterns encouraging consent;
making rejection substantially harder than acceptance.
This is particularly relevant under broader EU digital and consumer-protection legislation.
27. Dark Patterns
A website may present:
Accept
Large button.
Reject
Small hidden link.
Settings
Several screens.
Advertising partners
Hundreds of boxes.
This may raise questions about whether consent was:
informed;
freely given;
specific;
unambiguous.
Planet49 and Orange România are important authorities for the consent analysis. (Curia)
28. Evidence in Behavioral-Advertising Litigation
Evidence can include:
cookie logs;
consent-management-platform records;
privacy notices;
advertising profiles;
data-processing agreements;
tracking pixels;
SDK configurations;
server logs;
advertising IDs;
data-broker contracts;
algorithmic classifications;
records of data sharing;
internal policy documents.
A central issue may be:
What data did the company actually use to construct the individual's advertising profile?
29. Data Subject Access
Article 15 GDPR can become particularly important.
The individual may seek information concerning:
categories of personal data;
purposes;
recipients;
sources;
processing operations;
profiling information where applicable.
This can help establish the factual basis of a subsequent civil claim.
30. Controller vs Processor
A platform may argue:
“We were only a processor.”
But Wirtschaftsakademie and Fashion ID demonstrate that the legal classification depends upon actual participation in determining purposes and means.
Thus:
Contractual label ≠ automatically decisive GDPR classification.
31. Advertising Agency Liability
Suppose:
Advertiser → advertising agency → ad-tech company → data broker
A privacy claim may need to determine:
who collected the data;
who decided the advertising purpose;
who determined targeting criteria;
who controlled the data;
who merely processed data on instructions.
This determines potential:
controller liability;
joint-controller liability;
processor obligations.
32. Data Accuracy
Behavioral profiles can be wrong.
Example:
Platform incorrectly concludes that User A is interested in gambling.
The system repeatedly targets gambling advertisements.
Possible issues include:
inaccurate personal data;
unlawful inference;
failure to correct data;
unfair profiling;
privacy harm.
The GDPR's accuracy principle can therefore become central.
33. Cross-Device Tracking
A platform may connect:
mobile phone;
laptop;
tablet;
smart TV;
browser;
app.
The result is a unified behavioral profile.
The privacy issue is not necessarily each individual data point but the aggregation and inference created by combining them.
34. Cross-Website Tracking
A user visits:
Website A;
Website B;
Website C.
A tracking technology connects all three activities.
This can generate:
single website data → cross-site profile → targeted advertising.
The Planet49 and Fashion ID cases are particularly useful in analysing the legal foundations of tracking technologies and third-party data transmission.
35. Remedies
Possible remedies include:
1. Compensation
Under GDPR Article 82.
2. Erasure
Article 17 where applicable.
3. Restriction
Article 18.
4. Objection
Article 21, particularly important for certain direct-marketing processing.
5. Access
Article 15.
6. Injunction
National procedural law may provide mechanisms to stop unlawful processing.
7. Collective/representative action
Where the applicable procedural and statutory requirements are satisfied.
The Meta Platforms Ireland C-757/22 judgment is particularly relevant to representative enforcement. (Curia)
36. Causation
A privacy claimant should distinguish:
Processing
“My data was processed.”
Infringement
“The processing violated GDPR.”
Damage
“I suffered legally compensable harm.”
Causation
“The infringement caused that harm.”
This four-stage analysis prevents the assumption that every unlawful processing incident automatically creates a damages award.
Österreichische Post is the leading CJEU authority for this distinction.
37. Hypothetical Example
Facts
A social-media platform tracks User A across:
social media;
shopping websites;
mobile applications.
The platform creates a profile:
“Likely interested in weight-loss products.”
The profile is shared with 100 advertising partners.
User A never knowingly consented to this cross-platform profiling.
The user later discovers the profile and claims privacy harm.
Legal questions
Was the information personal data?
Was profiling taking place?
What was the lawful basis?
Was consent valid?
Was cross-platform combination lawful?
Were third-party recipients adequately disclosed?
Were special-category data or sensitive inferences involved?
Were the platform and partners controllers or processors?
Did the user suffer material or non-material damage?
Was that damage caused by the infringement?
Relevant authorities include:
Meta Platforms, C-252/21
Wirtschaftsakademie, C-210/16
Fashion ID, C-40/17
Planet49, C-673/17
Orange România, C-61/19
Österreichische Post, C-300/21.
38. Case-Law Summary Table
| Case | Main principle | Behavioral-advertising relevance |
|---|---|---|
| Meta Platforms, C-252/21 | Data processing, consent, legitimate interests and platform power | Direct/very strong |
| Meta Platforms Ireland, C-757/22 | Representative GDPR enforcement | Direct/strong |
| Wirtschaftsakademie, C-210/16 | Joint controllership | Directly relevant |
| Fashion ID, C-40/17 | Website/platform joint responsibility | Directly relevant |
| Planet49, C-673/17 | Active cookie consent | Directly relevant |
| Orange România, C-61/19 | Freely given/informed consent | Directly relevant |
| Österreichische Post, C-300/21 | GDPR damage and causation | Directly relevant to damages |
| Breyer, C-582/14 | IP addresses as personal data | Technical tracking |
| Google Spain, C-131/12 | Online privacy/data-subject rights | General privacy authority |
| Österreichische Post, C-154/21 | Recipient transparency | Advertising data-sharing |
39. Direct vs Analogical Authorities
The distinction is important.
Directly relevant to behavioral advertising
Meta Platforms, C-252/21
Wirtschaftsakademie, C-210/16
Fashion ID, C-40/17
Planet49, C-673/17
Directly relevant to GDPR consent
Orange România, C-61/19
Directly relevant to compensation
Österreichische Post, C-300/21
General privacy/data authorities
Breyer
Google Spain
Österreichische Post recipient case
Therefore, it would be inaccurate to describe every privacy case as a direct behavioral-advertising judgment.
40. Legal Test for Behavioral Advertising Privacy Claims
A useful examination formula is:
Step 1 — Identify the data
What information was collected?
Step 2 — Identify the processing
Was there:
tracking;
profiling;
targeting;
data combination;
sharing?
Step 3 — Identify the controller
Who determined the purpose and means?
Step 4 — Identify the legal basis
Consent? Legitimate interest? Another Article 6 basis?
Step 5 — Test consent
Was it:
free;
informed;
specific;
unambiguous?
Step 6 — Test transparency
Did the individual understand:
what was collected;
why;
by whom;
with whom it was shared?
Step 7 — Examine profiling
Were behavioural or sensitive characteristics inferred?
Step 8 — Examine third parties
Was information transferred to:
advertisers;
data brokers;
ad exchanges;
analytics companies?
Step 9 — Establish infringement
Which GDPR/ePrivacy obligation was breached?
Step 10 — Establish damage
Material or non-material?
Step 11 — Establish causation
Did the infringement cause the damage?
Step 12 — Determine remedy
Compensation, erasure, objection, restriction, injunction or collective/representative relief.
41. Conclusion
Behavioral advertising privacy harm claims in Europe are principally governed by the GDPR, supported by ePrivacy, consumer-protection, contract, tort/delict and, in some circumstances, competition law.
The most important authorities are:
Meta Platforms, C-252/21 — behavioural advertising, personal-data processing, consent and legitimate interests;
Wirtschaftsakademie, C-210/16 — joint controllership;
Fashion ID, C-40/17 — responsibility for data collection through embedded technologies;
Planet49, C-673/17 — consent and cookies;
Orange România, C-61/19 — freely given and informed consent;
Österreichische Post, C-300/21 — compensation, damage and causation;
Meta Platforms Ireland, C-757/22 — representative enforcement.
The central civil-law principle is:
Unlawful behavioral tracking does not automatically equal a damages award; the claimant must connect the unlawful processing to legally compensable damage and causation.
At the same time, the European framework increasingly treats control over personal data, meaningful consent, transparency and protection against intrusive profiling as substantive legal interests rather than merely technical compliance matters. The EDPB's 2024 position on “consent or pay” reinforces the requirement for a genuine choice in behavioural-advertising models. (European Data Protection Board)
Exam Keywords
Behavioral advertising — targeted advertising — GDPR — ePrivacy — profiling — cookies — tracking pixels — advertising ID — personal data — off-platform data — consent — freely given consent — informed consent — legitimate interests — purpose limitation — data minimisation — transparency — joint controller — data broker — ad-tech — cross-site tracking — cross-device tracking — special-category data — Article 22 — Article 82 — material damage — non-material damage — causation — privacy harm — collective action — representative action — dark patterns — consent or pay — data subject rights — erasure — objection — accountability.

comments