Civil Law And Cross-Border Data Transfer Breach Litigation In Europe .

Civil Law and Cross-Border Data Transfer Breach Litigation in Europe

1. Introduction

Cross-border data transfer breach litigation arises when personal data is transferred from one country to another and the transfer, processing, security measures, or subsequent disclosure allegedly violates data-protection law.

Typical situations include:

an EU company transferring employee data to a non-EU parent company;

a cloud provider storing European customer data outside the EU;

an online platform transferring user data to servers in another country;

a bank sending customer information to an overseas group company;

an employer transferring HR data internationally;

a processor in a third country suffering a cyberattack;

a company using Standard Contractual Clauses (SCCs) for international transfers;

disclosure of transferred data to foreign government authorities;

onward transfer from one third country to another.

The central legal framework is the GDPR, especially Articles 44–49 concerning international transfers and Article 82 concerning compensation.

A major feature of European law is that a lawful transfer is not merely a question of whether paperwork exists. The controller must consider whether the transfer mechanism and the actual protection available in the destination country provide the level of protection required by EU law. This principle is central to Schrems I and Schrems II. (curia)

2. Meaning of Cross-Border Data Transfer

A transfer may be cross-border where personal data moves:

EU/EEA → third country

or through a chain such as:

EU controller → EU processor → US cloud provider → subcontractor in another country

Examples of personal data include:

names;

addresses;

identification numbers;

financial information;

health information;

employment records;

biometric data;

location data;

online identifiers;

customer profiles;

communications.

The fact that the data is transferred electronically does not make the transfer legally insignificant.

3. Parties That May Be Liable

Several parties may potentially be involved.

1. Controller

The organisation deciding why and how personal data is processed.

2. Processor

An entity processing personal data on behalf of the controller.

3. Sub-processor

A processor engaged by another processor.

4. Recipient

The organisation receiving the transferred information.

5. Data importer

The organisation receiving personal data outside the EU/EEA.

6. Group company

A foreign parent, subsidiary or affiliate receiving data.

The identity of the legally responsible party is critical to an Article 82 compensation claim.

4. Main European Legal Framework

A. GDPR Articles 44–49

These provisions regulate transfers of personal data to third countries and international organisations.

Broadly, transfers can rely upon mechanisms such as:

adequacy decisions;

appropriate safeguards;

Standard Contractual Clauses;

Binding Corporate Rules;

certain derogations in limited circumstances.

But a transfer mechanism does not operate in isolation from the actual circumstances of the transfer.

5. Adequacy Decisions

An adequacy decision means the European Commission has determined that a third country or specified framework provides an adequate level of protection.

Where an adequacy decision applies, transfers can generally take place without the controller having to rely upon Article 46 safeguards for that transfer.

However, the adequacy framework remains subject to European legal review.

The history of the EU-US transfer arrangements demonstrates the importance of this issue.

6. Standard Contractual Clauses

SCCs are contractual safeguards used for international transfers.

They allocate obligations between:

exporter;

importer;

controller;

processor;

sometimes third-party beneficiaries.

However, Schrems II established that SCCs do not automatically make every transfer lawful.

The parties must consider whether the law and practices of the destination country undermine the protection required by EU law. (curia)

7. Supplementary Measures

Where SCCs alone do not provide sufficient protection, organisations may need additional safeguards.

Possible measures include:

strong encryption;

pseudonymisation;

technical access restrictions;

strict key management;

minimisation;

contractual restrictions;

organisational safeguards.

The appropriate measures depend on the nature of the transfer and the risks involved.

8. Schrems I — The Foundational Case

Maximillian Schrems v Data Protection Commissioner

Case C-362/14

Court

Court of Justice of the European Union, Grand Chamber.

Background

Max Schrems challenged the transfer of his personal data by Facebook Ireland to the United States.

The dispute concerned the EU-US Safe Harbour framework.

Decision

The CJEU invalidated the European Commission's Safe Harbour adequacy decision.

It also confirmed that national supervisory authorities retain important powers to examine complaints concerning international transfers. (InfoCuria)

Principle

A third country must provide a level of protection essentially equivalent to that guaranteed within the EU legal order.

Civil-law importance

The case established the foundation for subsequent transfer disputes involving:

international cloud services;

multinational corporations;

social media;

outsourcing;

foreign government access;

employee-data transfers.

Classification: Direct and foundational authority.

9. Schrems II — The Most Important Transfer Authority

Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems

Case C-311/18

Court

CJEU, Grand Chamber.

Facts

The case again concerned transfers of personal data from Facebook Ireland to the United States.

The principal transfer mechanisms included:

adequacy decisions;

Standard Contractual Clauses.

Decision

The CJEU invalidated the EU-US Privacy Shield adequacy decision.

At the same time, it upheld the validity in principle of the Commission's Standard Contractual Clauses, subject to effective protection and assessment of the circumstances of the transfer. (curia)

Major principle

The exporter and recipient cannot treat SCCs as a purely formal contractual exercise.

They must consider:

the law of the destination country;

access by public authorities;

available legal remedies;

actual effectiveness of safeguards;

whether additional measures are necessary.

Civil-law significance

A defective international transfer can become the foundation for:

injunction proceedings;

regulatory proceedings;

suspension of transfers;

contractual disputes;

compensation claims.

Classification: Direct and foundational authority.

10. Article 82 GDPR: Civil Compensation

Article 82 creates a right to compensation where a person suffers material or non-material damage as a result of an infringement of the GDPR.

Three elements are particularly important:

1. GDPR infringement

There must be an infringement.

2. Damage

The claimant must establish material or non-material damage.

3. Causal connection

The damage must result from the infringement.

The CJEU has repeatedly treated these as cumulative requirements. (InfoCuria)

11. Case: Österreichische Post

UI v Österreichische Post AG

Case C-300/21

Facts

Österreichische Post processed personal information to determine individuals' political affinities.

The claimant argued that the processing caused distress and reputational harm.

CJEU ruling

The Court held that:

mere infringement of the GDPR does not automatically create a right to compensation;

actual material or non-material damage must exist;

however, non-material damage does not have to reach a particular minimum seriousness threshold. (InfoCuria)

Importance for transfer litigation

A claimant cannot simply argue:

“My data was transferred unlawfully, therefore I automatically receive damages.”

The claimant must establish the legally relevant damage and causal connection.

Classification: Direct Article 82 authority; closely applicable to transfer claims.

12. Case: Natsionalna agentsia za prihodite

VB v Natsionalna agentsia za prihodite

Case C-340/21

Facts

The Bulgarian National Revenue Agency suffered a cyberattack.

Personal data concerning millions of individuals was accessed and published.

Affected persons sought compensation, including for fear that their information might subsequently be misused.

CJEU ruling

The Court examined:

security obligations;

controller responsibility;

Article 32 GDPR;

Article 82 compensation;

non-material damage.

The Court recognized that fear of future misuse can constitute non-material damage where the circumstances establish actual damage rather than merely abstract concern. (InfoCuria)

Cross-border transfer relevance

The case is highly useful where:

EU personal data → foreign processor → security breach.

The claimant can potentially combine:

transfer violation + inadequate security + actual damage

in a civil claim.

Classification: Direct Article 82/security authority; closely applicable to cross-border transfers.

13. Case: Krankenversicherung Nordrhein

ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein

Case C-667/21

Court

CJEU.

Subject

Processing of health-related personal data and compensation under Article 82 GDPR.

Importance

The Court examined:

lawful processing;

special-category data;

Article 82 liability;

non-material damage;

the compensatory character of GDPR damages.

The decision confirms that Article 82 is fundamentally compensatory rather than punitive. (InfoCuria)

Transfer relevance

This is especially important where international transfers involve:

medical records;

insurance data;

employee health information;

genetic information;

other special-category data.

Classification: Direct GDPR damages authority; closely relevant to international transfers.

14. Case: MediaMarktSaturn

VB v MediaMarktSaturn

Case C-687/21

Facts

Personal data was accidentally provided to an unauthorized third party because of an employee error.

CJEU ruling

The Court explained that merely showing an employee accidentally handed information to an unauthorized person is not, by itself, enough to establish that the controller's technical and organisational measures were inappropriate.

The adequacy of the security measures must be assessed.

The Court also confirmed that Article 82 compensation is compensatory, not punitive. (InfoCuria)

Cross-border significance

The case is useful where an international transfer results from:

employee error;

incorrect recipient;

accidental disclosure;

inadequate organisational controls.

Classification: Direct GDPR security/liability authority.

15. Case: Gemeinde Ummendorf

VX and AT v Gemeinde Ummendorf

Case C-456/22

Facts

Personal data was published online without the required legal basis.

The claim concerned non-material damage.

Principle

The CJEU clarified that a mere GDPR infringement does not automatically create compensable damage.

However, actual loss of control over personal data can constitute non-material damage where the claimant demonstrates that such damage was actually suffered. (InfoCuria)

Transfer relevance

This principle can apply when transferred data is:

disclosed;

made accessible;

copied;

published;

exposed to unauthorized recipients.

Classification: Direct Article 82 authority.

16. Case: Scalable Capital

Scalable Capital

Joined Cases C-182/22 and C-189/22

Subject

GDPR compensation and loss of control over personal data.

Principle

The CJEU continued developing the rules concerning:

existence of damage;

non-material damage;

causal connection;

compensation.

Later CJEU case law expressly relies on this authority when explaining that Article 82 requires an infringement, actual damage and a causal link. (Curia)

Cross-border relevance

It is particularly useful in large-scale data incidents involving:

financial data;

customer databases;

international processors;

cloud platforms.

Classification: Direct GDPR damages authority.

17. Case: EDPS v SRB

European Data Protection Supervisor v Single Resolution Board

Case C-413/23 P

Judgment

4 September 2025.

Subject

The case concerned pseudonymised data transferred to Deloitte during proceedings concerning compensation for shareholders and creditors following the resolution of Banco Popular Español.

Principle

The CJEU examined when pseudonymised information remains personal data in the hands of a recipient and clarified the relationship between pseudonymisation and data-protection obligations. (InfoCuria)

Importance

This is particularly relevant to modern cross-border transfers involving:

financial institutions;

consultants;

auditors;

litigation experts;

regulators;

resolution authorities.

It demonstrates that changing identifiers or pseudonymising data does not automatically remove GDPR considerations.

Classification: Direct and recent European data-transfer/pseudonymisation authority.

18. Summary of the Major Cases

CaseMain principleRelevance
Schrems, C-362/14Safe Harbour invalid; supervisory control over transfersDirect
Schrems II, C-311/18Privacy Shield invalid; SCCs subject to effective protectionDirect
Österreichische Post, C-300/21Infringement alone does not establish compensationDirect Article 82
Natsionalna agentsia za prihodite, C-340/21Security breach, controller responsibility and non-material damageDirect/close
Krankenversicherung Nordrhein, C-667/21Compensation is compensatory; special-category dataDirect GDPR
MediaMarktSaturn, C-687/21Security measures and employee errorDirect GDPR
Gemeinde Ummendorf, C-456/22Loss of control and actual non-material damageDirect GDPR
Scalable Capital, C-182/22 & C-189/22Damage and causal link under Article 82Direct GDPR
EDPS v SRB, C-413/23 PPseudonymised data and personal-data conceptDirect/recent

19. Civil Liability for an Unlawful International Transfer

A typical claim can be analyzed through the following structure.

Step 1 — Personal data

Was the information personal data under the GDPR?

Step 2 — Controller/processor

Who determined the purpose and means of processing?

Step 3 — Transfer

Was the data transferred to a third country?

Step 4 — Transfer mechanism

Was the transfer based upon:

adequacy;

SCCs;

Binding Corporate Rules;

another Article 49 derogation?

Step 5 — Destination-country protection

Does the legal environment in the destination country undermine the required level of protection?

Step 6 — Supplementary measures

Were technical and organisational safeguards sufficient?

Step 7 — Breach

Did the controller or processor violate the GDPR?

Step 8 — Damage

Did the individual suffer material or non-material damage?

Step 9 — Causation

Was the damage caused by the GDPR infringement?

Step 10 — Remedy

What compensation, injunction or other relief is available?

20. Material Damage

Material damage may include demonstrable financial loss resulting from the breach.

Examples:

financial fraud;

identity-theft losses;

costs of restoring accounts;

unauthorized transactions;

expenses caused by the breach;

certain consequential financial losses.

The claimant must establish the connection between the unlawful processing/transfer and the loss.

21. Non-Material Damage

Non-material damage can include consequences such as:

anxiety;

fear of misuse;

reputational harm;

loss of control;

distress;

exposure of sensitive information.

But the CJEU has made an important distinction:

A GDPR infringement by itself is not automatically compensable damage.

Actual damage must be established. At the same time, European law does not impose a universal minimum seriousness threshold for non-material damage. (curia)

22. Fear of Future Misuse

This is particularly important in international transfers.

Suppose:

An EU company sends customer data to a foreign processor. The processor suffers a breach. The customer fears that criminals may use the information.

The claimant must establish legally relevant damage rather than relying solely upon a hypothetical possibility.

The CJEU has nevertheless recognized that genuine fear of future misuse can, depending on the facts, constitute non-material damage. (curia)

23. Security Obligations

Article 32 GDPR requires appropriate technical and organisational measures.

Possible measures include:

encryption;

access controls;

authentication;

pseudonymisation;

monitoring;

incident-response systems;

employee training;

data minimisation;

secure deletion.

The assessment is risk-based.

A company is not required to guarantee that a cyberattack can never happen.

24. Liability for Processor Conduct

A controller may engage a processor in another country.

Example:

German company → Irish controller → US cloud processor.

The controller cannot simply assume that the processor's foreign location eliminates its responsibility.

The contractual and GDPR relationship between:

controller;

processor;

sub-processor

must be examined.

25. Onward Transfers

An international transfer may involve several stages.

For example:

France → United States → India → Singapore.

The first transfer may satisfy one legal mechanism, but the subsequent transfer may require separate analysis.

This creates an important civil-litigation question:

At what stage did the GDPR protection become inadequate?

Evidence concerning the entire transfer chain may therefore become important.

26. Group Companies and Intra-Group Transfers

Multinational companies frequently transfer data between:

parent companies;

subsidiaries;

shared-service centres;

HR departments;

central IT systems.

Common examples include:

employee databases;

customer records;

compliance information;

fraud-prevention systems;

central CRM platforms.

Binding Corporate Rules may be relevant for certain intra-group transfers, but corporate ownership alone does not eliminate GDPR obligations.

27. Cloud Computing

Cloud arrangements are a major source of cross-border data-transfer issues.

A European company may not know precisely where data is processed at every stage.

Possible locations include:

EU data centres;

US data centres;

backup facilities;

disaster-recovery systems;

subcontractor facilities.

A civil claim may therefore require examination of:

data-location architecture;

processor contracts;

sub-processing;

encryption;

access rights;

government-access risks.

28. Government Access in the Destination Country

One of the most important issues following Schrems II is whether authorities in the destination country can access transferred information.

The legal analysis may concern:

surveillance legislation;

intelligence powers;

law-enforcement access;

judicial remedies;

proportionality;

independent oversight.

This is why an SCC cannot simply be treated as a piece of paperwork detached from the legal environment of the importing country. (curia)

29. Jurisdiction in Cross-Border Data Litigation

A claimant may potentially bring proceedings in different jurisdictions depending upon:

defendant's establishment;

controller's establishment;

processor's establishment;

place of the claimant;

place where damage occurred;

applicable GDPR jurisdictional rules.

This can create forum and procedural disputes before the substantive merits are even considered.

30. Supervisory Proceedings vs Civil Litigation

Two different legal routes should be distinguished.

Administrative route

A data-protection authority may:

investigate;

order compliance;

restrict processing;

prohibit transfers;

impose administrative fines.

Civil route

An individual may seek:

compensation;

judicial relief;

injunction;

declaration of rights.

These routes can coexist.

A regulatory finding may be highly relevant evidence, but the requirements for a private compensation claim must still be analyzed independently.

31. Compensation Is Not a Penalty

The CJEU has repeatedly emphasized that Article 82 compensation is compensatory rather than punitive.

Therefore, the amount should correspond to the damage actually suffered rather than function as a punishment merely because the infringement was particularly serious. (InfoCuria)

This is an important distinction from administrative fines under Article 83 GDPR.

32. Burden of Proof and Security Measures

Recent CJEU jurisprudence is particularly important concerning the controller's responsibility for security.

In the context of Article 82 claims, the Court has held that the controller bears an important burden concerning whether the security measures implemented were appropriate under Article 32. (Curia)

This can be highly significant in litigation following an international transfer or data breach.

33. Defences Available to Controllers

A controller may argue:

1. Lawful transfer mechanism

The transfer relied on a valid legal mechanism.

2. Adequate safeguards

Appropriate safeguards were implemented.

3. No GDPR infringement

The processing complied with the GDPR.

4. Appropriate security

The controller implemented appropriate technical and organisational measures.

5. No actual damage

The claimant has demonstrated only an infringement, not compensable damage.

6. No causal link

The alleged loss did not result from the transfer.

7. Third-party attack

The breach resulted from an external criminal act.

This defence does not automatically eliminate liability; the controller's own GDPR responsibilities must be assessed.

8. Hypothetical harm

The alleged future misuse is merely speculative.

9. Wrong defendant

Another entity was actually the controller or processor responsible for the relevant operation.

34. Remedies

Potential remedies include:

Compensation

For material or non-material damage.

Injunction

To prevent further unlawful transfers.

Suspension of transfer

Where continued processing is unlawful.

Erasure

Where GDPR requirements are satisfied.

Restriction

Temporary limitation of processing.

Correction

Where inaccurate information has been transferred.

Declaration

Judicial declaration concerning the legality of processing.

Regulatory measures

Separately, a supervisory authority may impose administrative measures.

35. Evidence in Cross-Border Transfer Litigation

Important evidence includes:

EvidenceLegal significance
SCCsTransfer mechanism
Adequacy decisionLegal basis
Data-transfer agreementContractual obligations
Data-flow mapWhere information travels
Processor agreementAllocation of responsibility
Sub-processor listFurther transfers
Encryption recordsSecurity
Access logsWho accessed data
Privacy noticesTransparency
DPIARisk assessment
Transfer Impact AssessmentDestination-country analysis
Incident reportNature of breach
Government-access recordsDestination-country risk
Expert evidenceTechnical security
Financial recordsMaterial damage

36. Practical Example

Facts

A French company collects European customer information.

It transfers the information to a US-based cloud provider.

The parties use SCCs.

The US processor suffers a cybersecurity incident and customer information becomes accessible to unauthorized persons.

Legal analysis

1. Controller:
French company.

2. Processor:
US cloud provider.

3. Transfer:
EU → third country.

4. Transfer mechanism:
SCCs.

5. Schrems II issue:
Were SCCs accompanied by adequate protection and, where necessary, supplementary measures?

6. Security issue:
Were appropriate technical and organisational measures used?

7. Damage:
Did customers actually suffer material or non-material damage?

8. Causation:
Did the damage result from the GDPR infringement?

9. Remedy:
Potential Article 82 compensation and/or other GDPR remedies.

This illustrates how transfer legality and breach liability are related but distinct questions.

37. Special Issues in Cross-Border Transfer Litigation

Modern cases increasingly involve:

AI training datasets;

international cloud infrastructure;

biometric databases;

genetic data;

financial information;

employee monitoring;

remote-work platforms;

multinational HR systems;

global cybersecurity operations;

international advertising platforms;

ad-tech;

data brokers;

pseudonymised datasets;

automated decision-making.

The 2025 EDPS v SRB judgment is particularly useful for understanding why pseudonymisation does not necessarily take information outside data-protection law. (InfoCuria)

38. Direct vs Closely Applicable Authorities

AuthorityClassification
Schrems, C-362/14Direct international-transfer case
Schrems II, C-311/18Direct international-transfer case
Natsionalna agentsia za prihodite, C-340/21Direct GDPR breach/security authority
Österreichische Post, C-300/21Direct compensation authority
Krankenversicherung Nordrhein, C-667/21Direct compensation/special-data authority
MediaMarktSaturn, C-687/21Direct security/liability authority
Gemeinde Ummendorf, C-456/22Direct Article 82 authority
Scalable Capital, C-182/22 & C-189/22Direct Article 82 authority
EDPS v SRB, C-413/23 PDirect/recent personal-data-transfer authority

39. Exam-Oriented Legal Test

For a problem concerning cross-border data transfer, follow this sequence:

1. Identify the personal data

↓

2. Identify controller and processor

↓

3. Identify the transfer and destination country

↓

4. Identify the Article 44–49 transfer mechanism

↓

5. Examine adequacy/SCC/BCR/derogation

↓

6. Assess destination-country legal risks

↓

7. Examine supplementary safeguards

↓

8. Examine security under Articles 5, 24 and 32

↓

9. Establish GDPR infringement

↓

10. Establish material/non-material damage

↓

11. Establish causal connection

↓

12. Determine Article 82 compensation

↓

13. Consider injunction, restriction or other remedies

↓

14. Determine cross-border jurisdiction and enforcement

40. Quick Revision Table

IssueKey rule
International transferGDPR Articles 44–49 apply
AdequacyDestination must provide required level of protection
SCCsContractual safeguards, not automatic immunity
Schrems ISafe Harbour invalidated
Schrems IIPrivacy Shield invalidated; SCCs upheld in principle subject to effective protection
SecurityAppropriate technical/organisational measures required
Article 82Compensation for material/non-material damage
Mere infringementNot automatically compensable
Non-material damageNo universal minimum seriousness threshold
CausationMust connect infringement and damage
CompensationCompensatory, not punitive
Fear of misuseMay constitute damage if genuine/actual rather than purely hypothetical
PseudonymisationDoes not automatically remove GDPR protection
EnforcementCivil compensation and regulatory proceedings are distinct

Conclusion

Cross-border data transfer breach litigation in Europe is a combination of GDPR substantive law, international-transfer rules and civil liability. The central issue is not simply whether data crossed a national border, but whether the transfer and subsequent processing maintained the level of protection required by EU law.

The two foundational transfer cases are Schrems (C-362/14) and Schrems II (C-311/18). The subsequent Article 82 cases—including Österreichische Post (C-300/21), Natsionalna agentsia za prihodite (C-340/21), Krankenversicherung Nordrhein (C-667/21), MediaMarktSaturn (C-687/21), Gemeinde Ummendorf (C-456/22) and Scalable Capital (C-182/22 and C-189/22)—develop the separate question of when an unlawful processing operation gives rise to compensable damage. (curia)

The basic civil-law formula is:

Unlawful transfer/processing + GDPR breach + actual damage + causal connection = potential civil compensation, subject to the applicable procedural, jurisdictional and remedial rules.

LEAVE A COMMENT