Civil Law And Dataset Provenance Verification Disputes In Europe .

Civil Law And Dataset Provenance Verification Disputes In Europe

1. Introduction

Dataset provenance means the ability to establish where data came from, who collected it, how it was verified, what transformations were applied, who subsequently used it, and whether the resulting dataset can legally and factually be trusted.

In European civil-law and EU law, disputes concerning dataset provenance usually arise through several overlapping legal fields:

GDPR and personal-data accuracy

Right to know the source of personal data

Right to rectification

Database rights and unlawful extraction

Copyright and text/data mining

Contractual warranties concerning datasets

AI-training dataset disputes

Evidence, audit trails and authenticity

Confidentiality and trade secrets

Compensation for inaccurate or unlawfully processed data

There is not yet a single European cause of action called “dataset provenance liability.” Instead, courts determine provenance-related disputes by applying existing rules on data protection, database rights, copyright, contract, evidence and civil liability.

The GDPR is particularly important because its principles include accuracy, transparency, accountability and traceability of processing, while Articles 14 and 15 expressly address the source of personal data. (European Data Protection Board)

2. Meaning of Dataset Provenance

A provenance dispute can concern:

A. Origin

Who originally created or collected the dataset?

B. Chain of custody

How did the data move from:

Original source → collector → processor → aggregator → database → AI/model → end user?

C. Verification

Was the information checked before being incorporated into the dataset?

D. Transformation

Was data:

cleaned,

translated,

labelled,

aggregated,

anonymised,

pseudonymised,

deduplicated,

enriched,

inferred,

synthetically generated?

E. Legal entitlement

Did the dataset owner have a lawful basis or contractual right to obtain and use the data?

F. Accuracy

Is the information factually correct for the purpose for which it is being used?

G. Traceability

Can an affected person or court identify the original source?

These questions become especially important when datasets are used for credit scoring, employment screening, medical research, automated decision-making or AI training.

3. Main European Legal Framework

3.1 GDPR Article 5 — Accuracy and Accountability

Article 5(1)(d) requires personal data to be accurate and, where necessary, kept up to date, with reasonable steps taken to rectify or erase inaccurate data.

Article 5(2) establishes the principle of accountability: the controller must be able to demonstrate compliance. (EUR-Lex)

Therefore, provenance is legally important because a controller may have difficulty demonstrating accuracy where it cannot establish:

where the information came from;

when it was obtained;

whether it was independently verified;

whether it was subsequently modified.

4. GDPR Article 14 — Right to Know the Source

Where personal data are not obtained directly from the data subject, Article 14 requires information concerning the source from which the data originated.

This makes source verification a direct legal issue.

The CJEU has emphasised that the source of data is important to the distinction between direct and indirect collection and to transparency toward the data subject. (EUR-Lex)

5. GDPR Article 15 — Access to Source Information

Article 15 gives a data subject a right to obtain available information about the source of personal data.

This can be crucial where someone says:

“This dataset contains incorrect information about me. I need to know where that information came from.”

The right, however, is not necessarily an unlimited right to discover every earlier person or document involved in the creation of the information.

That distinction is particularly important in provenance litigation.

6. GDPR Article 16 — Rectification

Where dataset information about an individual is inaccurate, Article 16 provides a right to rectification.

This is one of the most important remedies in provenance disputes because an incorrect upstream source can create a chain of downstream errors:

Incorrect source → incorrect database → incorrect profile → incorrect decision → financial/reputational damage.

7. Database Directive

The EU Database Directive 96/9/EC provides protection for qualifying databases through the sui generis database right.

Dataset provenance disputes can therefore concern:

extraction of data;

repeated extraction;

reuse;

substantial investment;

verification;

presentation;

systematic copying.

The CJEU has developed a substantial body of law in this field.

8. Case Law

Case 1 — British Horseracing Board Ltd v William Hill Organization Ltd

CJEU, Case C-203/02, 9 November 2004

Facts

The British Horseracing Board maintained a large database containing information relating to horse racing.

William Hill used racing information derived from that database for betting purposes.

The dispute concerned the scope of the database maker's sui generis right.

Principle

The CJEU distinguished between:

investment in creating data, and

investment in obtaining, verifying or presenting existing data.

Investment directed merely toward creating the materials contained in a database does not automatically constitute the investment protected by the sui generis right.

Provenance significance

This case demonstrates that a dataset owner must be able to explain what investment was actually made in obtaining and verifying the dataset.

Therefore:

Dataset ownership does not automatically establish an exclusive right over every underlying fact.

(InfoCuria)

9. Case 2 — Innoweb BV v Wegener ICT Media BV

CJEU, Case C-202/12, 19 December 2013

Facts

Wegener operated an online vehicle-advertising database.

Innoweb operated a dedicated metasearch engine that effectively searched and reused information from Wegener's database.

Holding

The CJEU examined whether systematic use of database contents through a dedicated metasearch engine constituted prohibited re-utilisation.

The Court recognised that repeated and systematic exploitation of database contents can interfere with the normal exploitation of the database.

Provenance significance

The case is important for modern datasets because provenance is not merely about the first collection of data.

It also concerns:

Who subsequently copied, aggregated or re-used the dataset?

A dataset may therefore have a provenance chain involving several successive databases.

(EUR-Lex)

10. Case 3 — Veronsaajien oikeudenvalvontayksikkö v A

CJEU, Case C-215/19, 2 July 2020

Significance

This case concerned the treatment of data-centre/server-related services under EU VAT law rather than a direct provenance claim.

It is useful by analogy because modern datasets are often maintained through complex technical infrastructure involving:

servers;

data storage;

processing;

hosting;

technical environments.

Provenance significance

It illustrates an important principle:

A dataset is not merely an abstract collection of information; its legal treatment can depend upon the technical and contractual environment in which it is collected, stored and processed.

This is an analogical authority, not a direct dataset-provenance judgment.

11. Case 4 — FF v Österreichische Datenschutzbehörde and CRIF GmbH

CJEU, Case C-487/21, 4 May 2023

This is one of the most important authorities for provenance-related data disputes.

Facts

The claimant requested access to personal data held by CRIF, including information contained in databases and documents.

The issue concerned the scope of the GDPR right of access.

Holding

The CJEU held that the right to obtain a copy of personal data can require a faithful and intelligible reproduction of the personal data.

Depending on circumstances, this may include extracts from documents or even entire documents/database extracts where necessary to allow the data subject effectively to exercise GDPR rights, while respecting the rights and freedoms of others. (EUR-Lex)

Provenance significance

This is highly relevant to dataset provenance.

A person challenging a dataset may need more than a general statement such as:

“We obtained this information from a third-party database.”

They may need sufficient underlying information to understand:

what information was processed;

how it appeared in the relevant record;

whether it was inaccurate;

whether rectification is necessary.

Principle

Access can be an evidentiary mechanism for investigating provenance.

12. Case 5 — Nowak v Data Protection Commissioner

CJEU, Case C-434/16, 20 December 2017

Facts

The case concerned examination-related information and whether information appearing in examination scripts could constitute personal data.

Principle

The CJEU adopted a broad understanding of personal data.

It also emphasised that whether information is accurate or complete must be assessed in light of the purpose for which the data were collected.

This principle was later expressly relied upon in the CJEU's 2025 accuracy jurisprudence. (EUR-Lex)

Provenance significance

Dataset accuracy is therefore not necessarily an abstract question of whether a statement is objectively true.

The relevant question may be:

Is the information accurate and complete for the purpose for which the dataset processes it?

This is highly important for:

AI datasets;

employment datasets;

credit databases;

medical datasets;

consumer profiles.

13. Case 6 — Google (De-referencing of allegedly inaccurate content)

CJEU, Case C-460/20, 8 December 2022

Issue

The case concerned allegedly inaccurate information appearing online and requests for removal/de-referencing.

Principle

The CJEU addressed the relationship between:

accuracy of information;

evidence of alleged inaccuracy;

freedom of expression;

protection of personal data.

A person seeking correction cannot simply assert that information is inaccurate without regard to evidentiary requirements.

The Court recognised the importance of relevant and sufficient evidence concerning alleged inaccuracies. This approach was subsequently cited in VP, Case C-247/23. (DPcuria)

Provenance significance

In a dataset dispute, the claimant may therefore need to establish:

Dataset entry → alleged error → evidence of error.

The provenance record can itself become evidence.

14. Case 7 — VP v Országos Idegenrendészeti Főigazgatóság

CJEU, Case C-247/23, 13 March 2025

This is a particularly important modern accuracy and verification authority.

Facts

Personal data concerning the claimant's gender identity had been recorded in a public register.

The claimant sought rectification.

Holding

The CJEU held that Article 16 GDPR requires a controller maintaining a public register to rectify inaccurate personal data.

The Court also stated that the person requesting rectification may be required to provide relevant and sufficient evidence reasonably required to establish inaccuracy.

But restrictions on the right must satisfy Article 23 GDPR. (EUR-Lex)

Provenance significance

The case demonstrates that dataset verification is a two-sided evidentiary process:

Controller: must maintain accurate information.

Data subject: may need to provide reasonable evidence showing that the information is inaccurate.

Important principle

A controller cannot use an excessively burdensome evidentiary requirement simply to make correction practically impossible.

15. Case 8 — CK v Dun & Bradstreet Austria GmbH

CJEU, Case C-203/22, 27 February 2025

This is particularly relevant to commercial datasets and automated profiling.

Facts

The dispute concerned automated creditworthiness scoring and information about how personal data were used to produce a particular result.

Holding

The CJEU interpreted Article 15(1)(h) GDPR as requiring meaningful information about the logic involved in automated decision-making.

The information must explain, in a concise, transparent and intelligible form, the procedure and principles actually applied to personal data to obtain a specific result such as a credit profile. (FRA)

The Court also addressed the relationship between access rights and:

third-party data;

trade secrets;

competing rights and interests.

Provenance significance

For AI and algorithmic datasets, provenance is not limited to:

“Where did the original data come from?”

It can also include:

“How did the data become part of the process that produced my profile?”

Thus, provenance can extend into the processing and transformation chain.

16. Case 9 — Digi Communications NV v Nemzeti Adatvédelmi és Információszabadság Hatóság

CJEU, Case C-77/21, 20 April 2023

Facts

Digi had copied personal data from one database into a test database for testing and troubleshooting.

The test database was retained for a lengthy period.

Holding

The CJEU examined purpose limitation and storage limitation.

It held that copying personal data into a testing database can be compatible with the original purpose in appropriate circumstances, but retaining such data longer than necessary for testing can breach the storage-limitation principle. (EUR-Lex)

Provenance significance

This is important because provenance includes the history of data movement.

A controller should be able to explain:

Original database → test database → purpose → retention period → deletion.

A failure to maintain that chain can create GDPR liability.

17. Case 10 — RS v TS (Waldfelber)

CJEU Case C-185/25 — Advocate General's Opinion, 18 June 2026

This case should currently be treated carefully because the material located is an Advocate General's Opinion, not a final CJEU judgment.

Issue

The case concerns Article 15(1)(g) GDPR and information about the source of personal data, including an opinion about an individual that was based on a discussion with another person.

The Advocate General considered the ordinary meaning of “source” and treated it primarily as the origin of the personal data, while warning against turning the right into an unlimited right to investigate every upstream source. (EUR-Lex)

Provenance significance

This is directly relevant to dataset provenance.

It suggests a potentially important distinction between:

Source of data

and

sources that influenced the source.

For example:

Database record → employee's report → third-party conversation → original event.

The Article 15 source right does not necessarily create an unlimited right to discover every person or document somewhere in that chain.

Because this remains an AG Opinion unless and until the Court rules, it should not be treated as binding CJEU precedent.

18. Dataset Provenance and AI Training

Modern European litigation increasingly connects dataset provenance with AI.

A typical dispute may allege:

Copyrighted works → scraped website → aggregated dataset → training dataset → AI model.

The legal questions can include:

Who collected the material?

Was it lawfully obtained?

Was it copied?

Was it transformed?

Was consent required?

Was copyright infringed?

Was a database right infringed?

Was personal data included?

Can the source be identified?

Can the claimant prove that its material entered the training dataset?

European database jurisprudence is therefore increasingly relevant to AI dataset litigation.

The CJEU's database cases establish that extraction and reutilisation must be analysed carefully, rather than simply assuming that any use of information constitutes infringement. (InfoCuria)

19. Dataset Provenance and Copyright

A provenance dispute may also concern the difference between:

Facts

Raw facts are generally treated differently from protected creative expression.

Database structure

The selection or arrangement of information may receive copyright protection where the relevant originality requirements are satisfied.

Database investment

A qualifying database may receive sui generis protection.

Source documents

The documents from which data were extracted may have separate copyright protection.

Therefore:

Data ownership ≠ database ownership ≠ copyright in source material.

This distinction is fundamental in dataset litigation.

20. Dataset Provenance and Contract Law

Many commercial datasets are supplied under contracts.

A dataset contract may contain warranties concerning:

accuracy;

completeness;

lawful collection;

licensing;

provenance;

absence of third-party claims;

regulatory compliance;

updating;

cybersecurity;

auditability.

A buyer may therefore bring a contractual claim where:

Seller represents that dataset is lawfully sourced → buyer discovers unlicensed or inaccurate data → dataset becomes unusable → buyer suffers economic loss.

Potential remedies include:

damages;

price reduction;

termination;

indemnification;

replacement dataset;

specific performance;

reimbursement of remediation costs.

The governing national contract law and choice-of-law rules will normally determine these remedies.

21. Dataset Provenance and Civil Liability

A civil claim can be expressed through the following chain:

Wrongful collection

↓

Defective provenance

↓

Unverified or unlawful data

↓

Inclusion in dataset

↓

Downstream use

↓

Damage

↓

Causation

↓

Civil liability

The claimant generally needs to connect the provenance defect to the legally recognised loss.

22. Important Evidentiary Issues

Dataset provenance disputes are highly evidence-intensive.

Courts may consider:

1. Metadata

timestamps;

file origins;

hashes;

creation dates;

modification history.

2. Audit logs

Who accessed or modified the data?

3. Data lineage

What systems processed the information?

4. Version control

Which version of the dataset was used?

5. Hash verification

Does the disputed dataset correspond to the alleged original?

6. Expert evidence

Technical experts may reconstruct:

source → transformation → output.

7. Contracts

Licences and data-supply agreements can establish lawful provenance.

8. Internal policies

Data-governance documentation may show whether verification procedures existed.

23. Burden of Proof

The burden varies according to the legal claim.

GDPR

The controller has significant accountability obligations and must demonstrate compliance with Article 5(1).

Rectification

The data subject may need to provide relevant and sufficient evidence showing that information is inaccurate, although requirements must remain reasonable. VP is important here. (EUR-Lex)

Database infringement

The claimant normally must establish the relevant database right and the defendant's extraction/re-utilisation.

Contract

The claimant normally needs to establish:

contractual obligation;

breach;

causation;

recoverable damage.

Copyright

The claimant generally must establish protected subject matter and the relevant infringing act.

24. Provenance Versus Accuracy

These concepts must not be confused.

IssueMeaning
ProvenanceWhere did the data come from?
AccuracyIs the data correct?
AuthenticityIs the dataset what it claims to be?
IntegrityHas it been altered improperly?
CompletenessIs relevant information missing?
LawfulnessWas collection/use legally permitted?
TraceabilityCan the data's lifecycle be reconstructed?
AccountabilityCan the controller demonstrate compliance?

A dataset can therefore have good provenance but inaccurate information, or accurate information but unlawful provenance.

25. Trade Secrets and Provenance

A company may argue:

“We cannot disclose our complete dataset-generation methodology because it is a trade secret.”

European data-protection law does not automatically allow such an argument to defeat data-subject rights.

In CK v Dun & Bradstreet, the CJEU required a balance between access rights and competing interests such as trade secrets and third-party rights. (FRA)

Therefore, courts may need to balance:

Transparency

against

Trade secrecy

and

Privacy of third parties.

26. Cross-Border Dataset Disputes

Dataset provenance litigation can involve several jurisdictions:

German company collects data in France → dataset stored in Ireland → processing in Netherlands → AI provider in another Member State → customer in Spain.

Questions can then arise concerning:

GDPR territorial scope;

lead supervisory authority;

Brussels I bis jurisdiction;

Rome I contractual law;

Rome II non-contractual liability;

intellectual-property jurisdiction;

database rights;

evidence gathering;

cross-border enforcement.

The GDPR's one-stop-shop system is particularly relevant for cross-border supervisory enforcement. The EDPB maintains a register of final one-stop-shop decisions designed to promote harmonised enforcement. (European Data Protection Board)

27. Civil Remedies

Depending upon the cause of action, possible remedies include:

A. Rectification

Correction of inaccurate dataset information.

B. Erasure

Removal of unlawfully processed information.

C. Restriction

Temporary limitation on processing.

D. Injunction

Stopping unlawful extraction or use.

E. Damages

Compensation for legally recognised material or non-material loss.

F. Contractual indemnity

Recovery under a data-supply agreement.

G. Database remedies

Protection against unlawful extraction/re-utilisation.

H. Copyright remedies

Depending upon applicable national and EU copyright law.

I. Disclosure

Orders requiring production of relevant provenance information or evidence.

28. Direct and Analogical Authorities

CaseJurisdictionMain relevance
British Horseracing Board v William Hill, C-203/02CJEUDatabase investment, obtaining and verification
Innoweb v Wegener, C-202/12CJEUExtraction and reutilisation
FF v CRIF, C-487/21CJEUAccess to database/document information
Nowak, C-434/16CJEUPersonal data and purpose-based accuracy
Google v CNIL/Google, C-460/20CJEUEvidence concerning inaccurate information
VP, C-247/23CJEUAccuracy and rectification
Digi, C-77/21CJEUData copying, purpose and retention
CK v Dun & Bradstreet, C-203/22CJEUAutomated profiling and meaningful information
RS v TS, C-185/25CJEU/AG OpinionSource of personal data; provenance
Veronsaajien oikeudenvalvontayksikkö, C-215/19CJEUTechnical data-centre environment; analogical only

29. Key Legal Principles

Principle 1 — Provenance is legally significant

Knowing the source of data can be necessary to assess its accuracy and legality.

Principle 2 — Accuracy is purpose-dependent

Information must be assessed in relation to the purpose for which it was collected and processed. Nowak and VP are important authorities. (EUR-Lex)

Principle 3 — Access can assist verification

Article 15 can provide information necessary for a person to investigate and challenge personal-data processing. FF v CRIF is particularly important. (EUR-Lex)

Principle 4 — Source disclosure is not unlimited

The right to know the source does not necessarily mean a right to discover every upstream contributor to a piece of information. This issue is especially visible in the pending RS v TS reference and the Advocate General's 2026 Opinion. (EUR-Lex)

Principle 5 — Database rights protect investment, not automatically facts

British Horseracing Board remains fundamental. (InfoCuria)

Principle 6 — Repeated extraction can itself be legally significant

Innoweb demonstrates the importance of systematic reuse. (EUR-Lex)

Principle 7 — Data copying creates a provenance trail

Digi shows that movement of personal data between databases can itself constitute relevant processing and must respect GDPR principles. (EUR-Lex)

Principle 8 — AI increases the importance of provenance

AI datasets can create multiple layers of:

collection → aggregation → transformation → training → output.

Determining which stage created the legal defect may be decisive.

30. Exam-Oriented Legal Test

For a dataset provenance dispute, use this sequence:

1. IDENTIFY DATA

What exactly is contained in the dataset?

2. IDENTIFY SOURCE

Who originally supplied or created it?

3. TRACE DATA

How did it reach the defendant?

4. VERIFY

Was the information checked?

5. CLASSIFY

Personal data? Copyright? Database contents? Trade secrets? Contractual information?

6. CHECK LAWfulness

Was collection and subsequent processing lawful?

7. CHECK ACCURACY

Is the information accurate for its purpose?

8. CHECK TRANSFORMATION

Was it copied, modified, aggregated or inferred?

9. ESTABLISH CAUSATION

Did the provenance defect cause the claimant's loss?

10. DETERMINE REMEDY

Rectification, erasure, injunction, damages, contractual compensation or database/copyright relief.

31. Conclusion

European law does not yet recognise a unified standalone tort of “dataset provenance failure.” Instead, provenance disputes are resolved through a combination of GDPR accuracy and transparency rules, database rights, copyright, contract, evidence and general civil liability.

The strongest legal pattern is:

SOURCE → COLLECTION → VERIFICATION → TRANSFORMATION → STORAGE → USE → ACCURACY → DAMAGE → REMEDY

The most directly useful authorities are British Horseracing Board, Innoweb, FF v CRIF, Nowak, Google (C-460/20), Digi, VP, and CK v Dun & Bradstreet. The 2026 RS v TS Advocate General's Opinion is especially interesting for the future development of the meaning of “source” under Article 15(1)(g), but it should not yet be treated as a final judgment. (EUR-Lex)

Ultra-Short Revision Keywords

Dataset Provenance – Source – Data Lineage – Traceability – Accuracy – Verification – Accountability – GDPR Art. 5 – Art. 14 Source – Art. 15 Access – Art. 16 Rectification – Database Directive – Extraction – Re-utilisation – Copyright – Trade Secrets – Metadata – Audit Trail – Chain of Custody – AI Training Data – Causation – Damages – Injunction – Cross-Border Processing.

LEAVE A COMMENT