Civil Law And Behavioral Advertising Privacy Harm Claims In Europe .

Civil Law and Behavioral Advertising Privacy Harm Claims in Europe

1. Introduction

Behavioral advertising privacy harm arises when an online platform, advertising network, data broker, publisher, app developer, or other business collects and analyses information about an individual in order to predict interests, behaviour, characteristics or purchasing decisions and then uses that information for targeted advertising.

Typical data may include:

browsing history;

search history;

location;

device identifiers;

cookies;

advertising IDs;

purchase history;

app activity;

social-media activity;

inferred interests;

behavioural profiles;

sensitive or special-category information;

data obtained from third parties.

The resulting civil dispute may involve:

data collection → profiling → targeting → privacy interference → economic/non-material harm → compensation.

European law does not have one standalone cause of action called “behavioral advertising privacy harm.” Claims are principally built around the GDPR, the ePrivacy framework, consumer law, contract law, tort/delict principles, and, in some circumstances, competition law.

The CJEU's recent Meta Platforms (C-252/21) judgment is especially important because it directly connected large-platform behavioural advertising, personal-data processing, consent, legitimate interests and competition law. (curia)

2. What Is Behavioral Advertising?

Behavioral advertising differs from ordinary contextual advertising.

Contextual advertising

A website about cars displays advertisements for cars.

The advertisement is selected mainly because of the content of the page.

Behavioral advertising

A platform observes that a person:

searches for cars;

visits car websites;

watches automobile videos;

searches for financing;

visits dealerships;

and creates an advertising profile predicting:

“This person is likely to purchase a vehicle.”

Advertisements are then selected based on the individual's behaviour or inferred characteristics.

The privacy problem is that the system may involve persistent monitoring and profiling across services.

3. Principal European Legal Framework

A. GDPR

The GDPR provides the central civil-law framework.

Important provisions include:

Article 5 — principles of processing;

Article 6 — lawful bases;

Article 7 — consent;

Article 9 — special-category data;

Articles 12–14 — transparency/information;

Article 15 — access;

Article 17 — erasure;

Article 18 — restriction;

Article 21 — objection;

Article 22 — automated decision-making;

Article 24 — controller responsibility;

Articles 26–28 — controller/processor relationships;

Article 32 — security;

Article 35 — DPIA;

Article 79 — judicial remedies;

Article 82 — compensation.

Article 82 is particularly important because it provides a civil compensation mechanism for material and non-material damage resulting from GDPR infringement.

4. Lawful Basis for Behavioral Advertising

A company cannot simply say:

“The user agreed to our terms, therefore we can track everything.”

The controller must identify an appropriate legal basis.

Possible legal bases include:

consent;

legitimate interests;

contract, where genuinely necessary;

other Article 6 grounds where applicable.

The EDPB has specifically emphasised that targeted advertising is not automatically necessary for performing a contract merely because advertising supports the platform's business model. (European Data Protection Board)

5. Consent

For consent to be valid under the GDPR, it must generally be:

freely given;

specific;

informed;

unambiguous;

withdrawable.

Therefore:

“Accept all cookies”

combined with:

“Reject”

hidden behind several screens can generate legal questions concerning whether the user's choice was genuinely free and informed.

The EDPB's 2024 Opinion 08/2024 specifically addressed “consent or pay” models for behavioural advertising and stated that large platforms generally need to provide users with a real choice; merely requiring users either to consent to behavioural advertising or pay may not ordinarily satisfy the GDPR's requirements for freely given consent. (European Data Protection Board)

6. Case 1 — Meta Platforms and Others

Case C-252/21, CJEU, 4 July 2023

This is the most important modern CJEU authority for behavioral-advertising privacy disputes.

The case concerned Meta's processing of so-called “off-Facebook” data, including information obtained from other websites and applications.

The German competition authority had treated certain data-processing practices as relevant to competition-law concerns.

The CJEU addressed the relationship between:

GDPR;

consent;

legitimate interests;

special-category data;

contractual necessity;

competition law;

dominant platforms.

The Court held, among other things, that a dominant platform cannot automatically treat all extensive personal-data processing as necessary for performing its social-network contract.

The case is particularly significant because it recognises that data-protection compliance and competition law can interact. (curia)

Civil-law significance

A behavioral-advertising claim may therefore involve more than a simple privacy-policy dispute.

Potential issues include:

unlawful profiling;

invalid consent;

excessive data combination;

processing of third-party data;

lack of transparency;

unfair contractual practices;

abuse of a dominant position.

Principle

A platform's commercial dependence on targeted advertising does not by itself make extensive behavioural-data processing contractually necessary.

7. Case 2 — Meta Platforms Ireland (Represented Action)

Case C-757/22, CJEU, 11 July 2024

This case concerned a consumer association's representative action relating to Meta's processing practices.

The CJEU examined issues concerning collective/representative enforcement of GDPR rights and the ability of consumer organisations to bring proceedings concerning unlawful processing.

The judgment is important because privacy harms from behavioral advertising can affect millions of users simultaneously.

Significance

Instead of:

1 user → 1 lawsuit

European law can permit certain representative or collective enforcement mechanisms.

This is particularly significant where the alleged practice is:

systematic;

platform-wide;

repeated;

difficult for an individual user to litigate economically.

The CJEU's 2024 judgment is now an important authority for the relationship between GDPR enforcement and representative actions. (Curia)

Principle

Large-scale data-processing practices can be challenged through collective or representative mechanisms where the applicable procedural requirements are satisfied.

8. Case 3 — Wirtschaftsakademie Schleswig-Holstein

Case C-210/16, CJEU, 5 June 2018

Wirtschaftsakademie concerned a Facebook fan page and the responsibility of the page administrator for processing personal data through Facebook's platform.

The CJEU held that the administrator and Facebook could be regarded as joint controllers in relation to relevant processing.

Importance for behavioral advertising

This is highly relevant to advertising ecosystems involving:

Publisher → advertising platform → analytics provider → data broker

A company cannot necessarily escape responsibility by saying:

“The advertising platform collected the data, not us.”

Where parties jointly determine relevant purposes or means, joint-controller principles may apply.

Principle

Responsibility can be distributed across an advertising ecosystem rather than resting exclusively with the platform operating the advertising technology.

9. Case 4 — Fashion ID GmbH & Co. KG

Case C-40/17, CJEU, 29 July 2019

Fashion ID concerned a website embedding Facebook's “Like” button.

The embedded technology could transmit visitors' personal data to Facebook.

The CJEU held that the website operator could be a joint controller for the collection and transmission of personal data, even though it did not control every subsequent processing operation.

Behavioral advertising relevance

The same reasoning is important for:

tracking pixels;

social-media plug-ins;

advertising SDKs;

analytics tools;

retargeting technologies;

embedded advertising scripts.

Principle

A website operator can have GDPR responsibility for the part of an advertising-data operation in which it participates, even if another company performs later processing.

10. Case 5 — Planet49

Case C-673/17, CJEU, 1 October 2019

Planet49 concerned cookies and the requirements for valid consent.

The CJEU addressed whether a pre-ticked checkbox could constitute valid consent for cookies.

The Court concluded that consent cannot simply be inferred from a pre-selected box; the user must actively indicate agreement.

Importance

Cookies are a fundamental component of behavioral advertising.

They can enable:

user recognition;

cross-site tracking;

advertising profiles;

retargeting;

measurement of advertising behaviour.

Therefore Planet49 is one of the most important European authorities for advertising-tracking consent.

Principle

Silence, inactivity or a pre-ticked box does not satisfy the GDPR/ePrivacy consent requirements where affirmative consent is required.

11. Case 6 — Orange România

Case C-61/19, CJEU, 11 November 2020

Orange România concerned consent to personal-data processing and whether consent could genuinely be considered freely given where contractual documentation created uncertainty about what the consumer was agreeing to.

The CJEU emphasised that consent must involve a freely given, specific, informed and unambiguous indication of the individual's wishes.

Behavioral advertising application

Suppose a platform presents:

“By using this service, you agree to all data processing, advertising, analytics and partner sharing.”

The question becomes whether the user has genuinely given separate and informed consent.

Principle

Consent must reflect a genuine affirmative decision rather than being buried inside general contractual conditions.

The CJEU's subsequent case law continues to rely on Orange România when assessing consent and transparency. (Curia)

12. Case 7 — Österreichische Post

Case C-300/21, CJEU, 4 May 2023

This is one of the most important cases for privacy damages.

The CJEU considered Article 82 GDPR and clarified that:

GDPR infringement alone

does not automatically establish a right to compensation.

There must be:

an infringement;

damage;

causal connection between the infringement and the damage.

However, the CJEU also held that EU law does not impose a minimum seriousness threshold for non-material damage.

Behavioral advertising application

A user might claim:

“The platform illegally created an advertising profile about me.”

The court must then distinguish:

unlawful processing

from

compensable harm caused by that processing.

Potential non-material harm could include, depending on the evidence and applicable law:

loss of control over personal data;

distress;

reputational consequences;

privacy intrusion;

fear concerning misuse of personal information.

But the claimant must still establish actual damage and causation under Article 82.

Principle

GDPR violation and compensable privacy damage are related but legally distinct questions.

13. Case 8 — UI v Österreichische Post

Case C-300/21, CJEU, 4 May 2023

This is the same leading Article 82 authority often referred to as Österreichische Post.

Its significance is especially important in behavioral-advertising claims because privacy litigation frequently involves non-material damage rather than conventional economic loss.

For example:

“I did not lose money, but I was subjected to unlawful profiling.”

The claim is not automatically successful merely because the processing was unlawful.

The claimant must demonstrate the legally relevant damage and causal connection.

14. Case 9 — Google Spain

Case C-131/12, CJEU, 13 May 2014

Google Spain concerned the right to request removal of search results relating to an individual.

Although it was not an advertising case, it is foundational for understanding European privacy rights in relation to online information.

The CJEU recognised important rights concerning:

personal data;

online dissemination;

individual privacy;

data subjects' rights;

balancing privacy against other interests.

Behavioral advertising relevance

The case supports the broader principle that online processing can have significant consequences for personal autonomy and privacy.

A behavioral profile can similarly influence what information, advertisements and commercial opportunities an individual encounters.

Principle

Online personal-data processing can create legally significant interference with individual privacy and autonomy.

15. Case 10 — Breyer v Germany

Case C-582/14, CJEU, 19 October 2016

Breyer concerned dynamic IP addresses and whether they can constitute personal data.

The CJEU adopted an interpretation under which an IP address may constitute personal data where the controller has legally available means that could reasonably be used to identify the person.

Advertising relevance

Online advertising frequently depends on:

IP addresses;

device identifiers;

browser identifiers;

cookies;

advertising IDs.

Thus, Breyer is important for determining whether technical identifiers fall within personal-data protection.

Principle

Technical online identifiers can constitute personal data where identification is reasonably possible under the applicable circumstances.

16. Case 11 — Österreichische Post / Identity of Data Recipients

Case C-154/21, CJEU

This line of CJEU case law concerns the right of data subjects to obtain information concerning the recipients of their personal data.

Behavioral advertising significance

Suppose a user asks:

“Who received my advertising profile?”

The answer may require identifying relevant recipients or categories of recipients depending on the applicable circumstances.

This is important because behavioral advertising frequently involves multiple actors:

Platform → ad exchange → demand-side platform → advertiser → analytics provider → data broker.

Transparency becomes difficult when individuals cannot determine where their data went.

17. Joint Controller Problem

Behavioral advertising commonly involves an ecosystem rather than a single company.

Example:

User

↓

Website

↓

Tracking pixel

↓

Advertising platform

↓

Data broker

↓

Advertiser

↓

Analytics provider

The cases Wirtschaftsakademie and Fashion ID show why controller status must be examined functionally.

A company cannot necessarily avoid GDPR responsibility simply by outsourcing technical processing.

18. Data Brokerage

A particularly sensitive area is the purchase and sale of behavioral information.

For example:

Data broker purchases information about 10 million users and creates commercial profiles.

Potential data points:

age;

location;

interests;

shopping history;

political interests;

health-related inferences;

financial interests.

The legal problems can include:

lawful basis;

transparency;

source of data;

purpose limitation;

data minimisation;

accuracy;

profiling;

special-category data;

retention;

onward transfers.

19. Sensitive Inferences

Behavioral advertising becomes more legally sensitive where algorithms infer information relating to:

health;

religion;

political opinions;

sexual orientation;

ethnicity;

biometric characteristics.

Even if the user never directly supplied the sensitive information, an advertising system may infer it from behaviour.

This can raise questions under Article 9 GDPR concerning special-category data.

20. Profiling

GDPR Article 4(4) defines profiling broadly around automated processing used to evaluate or predict aspects concerning an individual.

Behavioral advertising is therefore closely connected with:

profiling → prediction → segmentation → targeted advertising.

Examples:

“likely luxury purchaser”;

“likely to need medical products”;

“financially vulnerable”;

“frequent traveller”;

“likely teenager”;

“high-value customer.”

The more intrusive the profile, the more significant the questions of transparency, fairness and lawful basis can become.

21. Automated Decision-Making

Not every targeted advertisement is automatically an Article 22 decision.

This distinction is important.

Ordinary targeted advertising

Algorithm chooses which advertisement to display.

Significant automated decision

Algorithm decides whether a person receives a loan, insurance, employment opportunity or other legally/significantly consequential treatment.

Article 22 concerns certain decisions based solely on automated processing that produce legal effects or similarly significant effects.

Therefore:

Behavioral advertising ≠ automatically Article 22 decision-making.

But profiling can become relevant to Article 22 if the advertising system is linked to a decision producing the requisite significant effect.

22. Consent-or-Pay Models

Modern European privacy litigation increasingly involves:

“Consent to personalised advertising or pay for an ad-free service.”

The EDPB's 2024 Opinion 08/2024 is particularly important.

It states that large platforms should provide a real choice, and that merely offering:

behavioural advertising consent OR payment

will in many cases not be enough to establish freely given consent. (European Data Protection Board)

The EDPB also emphasises that consent does not remove the obligation to comply with:

fairness;

purpose limitation;

data minimisation;

necessity;

proportionality;

accountability.

(European Data Protection Board)

23. Legitimate Interests

A company may attempt to rely on legitimate interests rather than consent.

This requires a balancing analysis.

Generally, the controller must consider:

legitimate interest;

necessity of processing;

balancing against the individual's rights and freedoms.

For behavioral advertising, questions include:

How much data is collected?

Is cross-service tracking involved?

Is profiling extensive?

Is the individual reasonably expecting it?

Are sensitive characteristics involved?

Can less intrusive advertising achieve the same objective?

The Meta C-252/21 judgment is especially important for the limits of relying on contractual necessity and for the relationship between data processing and a platform's economic model. (curia)

24. Privacy Harm Without Financial Loss

One of the most important civil-law questions is:

Can a person suffer legally relevant harm even without losing money?

Yes, potentially.

GDPR Article 82 expressly covers material and non-material damage, subject to its requirements.

Examples of potential non-material harm may include:

distress;

loss of control;

privacy intrusion;

anxiety concerning misuse;

reputational consequences.

But Österreichische Post makes clear that an infringement alone is not enough; damage and causation must still be established.

25. Economic Privacy Harm

Behavioral advertising can also generate economic loss.

Examples:

discriminatory pricing;

differential offers;

exclusion from commercial opportunities;

manipulation of purchasing behaviour;

incorrect consumer categorisation;

exploitation of vulnerability.

Suppose an algorithm incorrectly labels a person:

“High-risk consumer.”

The platform then provides worse commercial terms.

The claimant may potentially have:

GDPR claims;

consumer-law claims;

discrimination claims;

contractual claims;

tort/delict claims.

The applicable cause of action depends upon the particular facts.

26. Manipulative Advertising

Privacy and consumer law can overlap when profiling is used to exploit behavioural vulnerabilities.

Examples:

targeting individuals during periods of vulnerability;

repeated advertisements designed to exploit compulsive behaviour;

using sensitive inferred information;

dark patterns encouraging consent;

making rejection substantially harder than acceptance.

This is particularly relevant under broader EU digital and consumer-protection legislation.

27. Dark Patterns

A website may present:

Accept

Large button.

Reject

Small hidden link.

Settings

Several screens.

Advertising partners

Hundreds of boxes.

This may raise questions about whether consent was:

informed;

freely given;

specific;

unambiguous.

Planet49 and Orange România are important authorities for the consent analysis. (Curia)

28. Evidence in Behavioral-Advertising Litigation

Evidence can include:

cookie logs;

consent-management-platform records;

privacy notices;

advertising profiles;

data-processing agreements;

tracking pixels;

SDK configurations;

server logs;

advertising IDs;

data-broker contracts;

algorithmic classifications;

records of data sharing;

internal policy documents.

A central issue may be:

What data did the company actually use to construct the individual's advertising profile?

29. Data Subject Access

Article 15 GDPR can become particularly important.

The individual may seek information concerning:

categories of personal data;

purposes;

recipients;

sources;

processing operations;

profiling information where applicable.

This can help establish the factual basis of a subsequent civil claim.

30. Controller vs Processor

A platform may argue:

“We were only a processor.”

But Wirtschaftsakademie and Fashion ID demonstrate that the legal classification depends upon actual participation in determining purposes and means.

Thus:

Contractual label ≠ automatically decisive GDPR classification.

31. Advertising Agency Liability

Suppose:

Advertiser → advertising agency → ad-tech company → data broker

A privacy claim may need to determine:

who collected the data;

who decided the advertising purpose;

who determined targeting criteria;

who controlled the data;

who merely processed data on instructions.

This determines potential:

controller liability;

joint-controller liability;

processor obligations.

32. Data Accuracy

Behavioral profiles can be wrong.

Example:

Platform incorrectly concludes that User A is interested in gambling.

The system repeatedly targets gambling advertisements.

Possible issues include:

inaccurate personal data;

unlawful inference;

failure to correct data;

unfair profiling;

privacy harm.

The GDPR's accuracy principle can therefore become central.

33. Cross-Device Tracking

A platform may connect:

mobile phone;

laptop;

tablet;

smart TV;

browser;

app.

The result is a unified behavioral profile.

The privacy issue is not necessarily each individual data point but the aggregation and inference created by combining them.

34. Cross-Website Tracking

A user visits:

Website A;

Website B;

Website C.

A tracking technology connects all three activities.

This can generate:

single website data → cross-site profile → targeted advertising.

The Planet49 and Fashion ID cases are particularly useful in analysing the legal foundations of tracking technologies and third-party data transmission.

35. Remedies

Possible remedies include:

1. Compensation

Under GDPR Article 82.

2. Erasure

Article 17 where applicable.

3. Restriction

Article 18.

4. Objection

Article 21, particularly important for certain direct-marketing processing.

5. Access

Article 15.

6. Injunction

National procedural law may provide mechanisms to stop unlawful processing.

7. Collective/representative action

Where the applicable procedural and statutory requirements are satisfied.

The Meta Platforms Ireland C-757/22 judgment is particularly relevant to representative enforcement. (Curia)

36. Causation

A privacy claimant should distinguish:

Processing

“My data was processed.”

Infringement

“The processing violated GDPR.”

Damage

“I suffered legally compensable harm.”

Causation

“The infringement caused that harm.”

This four-stage analysis prevents the assumption that every unlawful processing incident automatically creates a damages award.

Österreichische Post is the leading CJEU authority for this distinction.

37. Hypothetical Example

Facts

A social-media platform tracks User A across:

social media;

shopping websites;

mobile applications.

The platform creates a profile:

“Likely interested in weight-loss products.”

The profile is shared with 100 advertising partners.

User A never knowingly consented to this cross-platform profiling.

The user later discovers the profile and claims privacy harm.

Legal questions

Was the information personal data?

Was profiling taking place?

What was the lawful basis?

Was consent valid?

Was cross-platform combination lawful?

Were third-party recipients adequately disclosed?

Were special-category data or sensitive inferences involved?

Were the platform and partners controllers or processors?

Did the user suffer material or non-material damage?

Was that damage caused by the infringement?

Relevant authorities include:

Meta Platforms, C-252/21

Wirtschaftsakademie, C-210/16

Fashion ID, C-40/17

Planet49, C-673/17

Orange România, C-61/19

Österreichische Post, C-300/21.

38. Case-Law Summary Table

CaseMain principleBehavioral-advertising relevance
Meta Platforms, C-252/21Data processing, consent, legitimate interests and platform powerDirect/very strong
Meta Platforms Ireland, C-757/22Representative GDPR enforcementDirect/strong
Wirtschaftsakademie, C-210/16Joint controllershipDirectly relevant
Fashion ID, C-40/17Website/platform joint responsibilityDirectly relevant
Planet49, C-673/17Active cookie consentDirectly relevant
Orange România, C-61/19Freely given/informed consentDirectly relevant
Österreichische Post, C-300/21GDPR damage and causationDirectly relevant to damages
Breyer, C-582/14IP addresses as personal dataTechnical tracking
Google Spain, C-131/12Online privacy/data-subject rightsGeneral privacy authority
Österreichische Post, C-154/21Recipient transparencyAdvertising data-sharing

39. Direct vs Analogical Authorities

The distinction is important.

Directly relevant to behavioral advertising

Meta Platforms, C-252/21

Wirtschaftsakademie, C-210/16

Fashion ID, C-40/17

Planet49, C-673/17

Directly relevant to GDPR consent

Orange România, C-61/19

Directly relevant to compensation

Österreichische Post, C-300/21

General privacy/data authorities

Breyer

Google Spain

Österreichische Post recipient case

Therefore, it would be inaccurate to describe every privacy case as a direct behavioral-advertising judgment.

40. Legal Test for Behavioral Advertising Privacy Claims

A useful examination formula is:

Step 1 — Identify the data

What information was collected?

Step 2 — Identify the processing

Was there:

tracking;

profiling;

targeting;

data combination;

sharing?

Step 3 — Identify the controller

Who determined the purpose and means?

Step 4 — Identify the legal basis

Consent? Legitimate interest? Another Article 6 basis?

Step 5 — Test consent

Was it:

free;

informed;

specific;

unambiguous?

Step 6 — Test transparency

Did the individual understand:

what was collected;

why;

by whom;

with whom it was shared?

Step 7 — Examine profiling

Were behavioural or sensitive characteristics inferred?

Step 8 — Examine third parties

Was information transferred to:

advertisers;

data brokers;

ad exchanges;

analytics companies?

Step 9 — Establish infringement

Which GDPR/ePrivacy obligation was breached?

Step 10 — Establish damage

Material or non-material?

Step 11 — Establish causation

Did the infringement cause the damage?

Step 12 — Determine remedy

Compensation, erasure, objection, restriction, injunction or collective/representative relief.

41. Conclusion

Behavioral advertising privacy harm claims in Europe are principally governed by the GDPR, supported by ePrivacy, consumer-protection, contract, tort/delict and, in some circumstances, competition law.

The most important authorities are:

Meta Platforms, C-252/21 — behavioural advertising, personal-data processing, consent and legitimate interests;

Wirtschaftsakademie, C-210/16 — joint controllership;

Fashion ID, C-40/17 — responsibility for data collection through embedded technologies;

Planet49, C-673/17 — consent and cookies;

Orange România, C-61/19 — freely given and informed consent;

Österreichische Post, C-300/21 — compensation, damage and causation;

Meta Platforms Ireland, C-757/22 — representative enforcement.

The central civil-law principle is:

Unlawful behavioral tracking does not automatically equal a damages award; the claimant must connect the unlawful processing to legally compensable damage and causation.

At the same time, the European framework increasingly treats control over personal data, meaningful consent, transparency and protection against intrusive profiling as substantive legal interests rather than merely technical compliance matters. The EDPB's 2024 position on “consent or pay” reinforces the requirement for a genuine choice in behavioural-advertising models. (European Data Protection Board)

Exam Keywords

Behavioral advertising — targeted advertising — GDPR — ePrivacy — profiling — cookies — tracking pixels — advertising ID — personal data — off-platform data — consent — freely given consent — informed consent — legitimate interests — purpose limitation — data minimisation — transparency — joint controller — data broker — ad-tech — cross-site tracking — cross-device tracking — special-category data — Article 22 — Article 82 — material damage — non-material damage — causation — privacy harm — collective action — representative action — dark patterns — consent or pay — data subject rights — erasure — objection — accountability.

LEAVE A COMMENT