Comparative Data Protection Remedies .
Comparative Data Protection Remedies
1. Introduction
Comparative Data Protection Remedies means the comparative study of the legal remedies available in different jurisdictions when personal data is unlawfully collected, processed, disclosed, altered, misused, lost, transferred, or otherwise handled in violation of data-protection law.
Data protection law is no longer concerned merely with secrecy. Modern remedies protect:
privacy;
informational autonomy;
dignity;
reputation;
confidentiality;
control over personal information;
protection against profiling;
protection against automated decisions;
protection against data breaches;
economic interests.
Different legal systems adopt different remedial models. The EU provides one of the strongest individual compensation and regulatory-enforcement frameworks through the GDPR. India combines constitutional privacy, statutory data protection and regulatory remedies, with the DPDP framework now being implemented in stages. The UK combines the UK GDPR/Data Protection Act framework with judicial and regulatory remedies. The United States relies much more heavily on sector-specific statutes, state privacy laws, torts and constitutional standing requirements.
2. Meaning of Data Protection Remedies
A data-protection remedy is a legal mechanism through which a person or regulator responds to unlawful personal-data processing.
Broadly, remedies fall into six categories:
Preventive remedies
Corrective remedies
Compensatory remedies
Regulatory remedies
Declaratory remedies
Criminal or punitive remedies
For example:
A company unlawfully processes a person's medical information.
Possible remedies may include:
stop processing → delete data → correct data → disclose information about processing → compensate the victim → impose regulatory penalty.
3. Why Data Protection Remedies Are Different from Ordinary Tort Remedies
Traditional tort law generally asks:
“What injury did the defendant cause?”
Data protection law can ask a broader question:
“Was personal information processed lawfully and consistently with the individual's statutory rights?”
Consequently, data protection systems can provide remedies before conventional physical or financial injury occurs.
However, jurisdictions differ substantially regarding whether a mere statutory violation is enough for compensation.
This distinction is particularly important when comparing the EU and United States.
4. Major Types of Data Protection Remedies
A. Compensation/Damages
The victim may seek monetary compensation for:
financial loss;
identity theft;
reputational damage;
emotional distress;
loss of control over personal data;
other legally recognized non-material harm.
The EU's GDPR Article 82 is particularly significant because it expressly provides a right to compensation for material and non-material damage caused by GDPR infringements.
B. Injunction
A court may order a controller or processor to:
stop processing;
stop disclosure;
remove information;
prevent further dissemination;
implement security measures.
C. Erasure/Deletion
A person may seek deletion of personal information where legal requirements for erasure are satisfied.
This is particularly associated with the GDPR's right to erasure.
D. Rectification
Incorrect personal information can be corrected.
This is particularly important for:
credit records;
employment records;
medical data;
government databases;
insurance records.
E. Access
A data subject may obtain information about:
whether data is being processed;
what data is held;
purposes of processing;
recipients;
relevant processing information.
F. Regulatory Penalties
Data-protection authorities may impose:
administrative fines;
compliance orders;
processing restrictions;
suspension orders;
corrective directions.
This is distinct from compensation paid directly to the victim.
5. Compensation vs Regulatory Penalty
This distinction is extremely important.
Compensation
Purpose:
To compensate the victim.
Regulatory fine
Purpose:
To punish/deter unlawful conduct and enforce regulatory compliance.
The CJEU has repeatedly emphasized that GDPR Article 82 compensation is compensatory rather than punitive, while administrative fines serve a different enforcement function. (Eur-Lex)
Therefore:
A company can potentially face both a regulatory fine and a private compensation claim arising from the same underlying conduct.
6. Comparative Models
| Jurisdiction | Principal Model | Main Remedies |
|---|---|---|
| EU | Rights + regulatory + compensation | Damages, erasure, rectification, injunctions, complaints, fines |
| India | Constitutional + statutory/regulatory | Board directions/penalties, statutory rights, constitutional remedies, other applicable civil remedies |
| UK | Regulatory + judicial | Compensation, injunctions, rectification, erasure, enforcement notices |
| USA | Sectoral + state + tort/constitutional | Statutory damages in some laws, actual damages, injunctions, regulatory penalties |
| Canada | Privacy + administrative/judicial | Complaints, orders, damages in appropriate cases |
| International | Human-rights/data-protection principles | Judicial, administrative and treaty-based remedies |
7. European Union Model
The EU's GDPR creates a particularly comprehensive remedial system.
Important provisions include:
Article 15
Right of access.
Article 16
Right to rectification.
Article 17
Right to erasure.
Article 18
Right to restriction of processing.
Article 20
Data portability.
Article 21
Right to object.
Article 22
Protection concerning certain automated individual decision-making.
Article 77
Right to lodge a complaint with a supervisory authority.
Article 79
Right to an effective judicial remedy.
Article 82
Right to compensation.
Article 83
Administrative fines.
This produces a multi-layered remedy system.
8. Case Law 1: Österreichische Post AG v. UI
C-300/21, CJEU, 4 May 2023
This is one of the most important modern data-protection compensation cases.
Facts
Österreichische Post processed personal information to predict political-party affinity. The claimant was incorrectly associated with a political party and claimed non-material harm.
Issue
Was mere infringement of the GDPR sufficient to obtain compensation?
Judgment
The CJEU held that mere infringement is not by itself sufficient for compensation under Article 82.
Three elements must be established:
GDPR infringement;
damage;
causal connection between infringement and damage.
However, the Court rejected a requirement that non-material damage must cross some additional minimum seriousness threshold. (DPcuria)
Principle
GDPR compensation requires actual material or non-material damage, but there is no separate de minimis seriousness threshold.
Importance
This case establishes the fundamental EU compensation test.
9. Case Law 2: Natsionalna agentsia za prihodite
C-340/21, CJEU, 14 December 2023
Facts
A cyberattack resulted in personal data being compromised from a Bulgarian public authority.
The claimant alleged fear that the information might be misused.
Issue
Can fear of future misuse of personal data amount to non-material damage?
Judgment
The CJEU recognized that the fear of possible misuse can constitute non-material damage, provided the claimant establishes that the fear is well founded in the circumstances.
The Court also rejected the idea that compensation for non-material damage must be subject to a predefined seriousness threshold. (Eur-Lex)
Importance
This case is especially important for:
data breaches;
cybersecurity;
identity theft;
loss of control;
psychological consequences.
Principle
A data breach can generate compensable non-material harm even before actual identity theft occurs, if the claimant establishes a sufficiently real and well-founded fear.
10. Case Law 3: SCHUFA Holding AG
CJEU, Case C-634/21, 7 December 2023
Subject
Automated credit scoring.
Facts
SCHUFA generated a probability score concerning an individual's ability to repay financial obligations.
Issue
Could automated scoring itself fall within GDPR restrictions on automated decision-making where third parties relied heavily upon the score?
Judgment
The CJEU treated the automated generation of such a probability value as falling within Article 22 where a third party strongly relies upon it to establish, implement or terminate a contractual relationship.
Importance
The case shows that data-protection remedies are not limited to traditional “data leaks.”
They also protect people from:
profiling;
automated decisions;
algorithmic scoring;
opaque data-based classifications.
This is particularly important for:
banking;
insurance;
employment;
housing;
digital platforms.
11. Case Law 4: Google Spain SL v. AEPD and Mario Costeja González
C-131/12, CJEU, 2014
Facts
Mario Costeja González complained that Google search results continued to display information about an old property-related matter.
Judgment
The CJEU recognized important circumstances in which an individual could request removal of search-engine results relating to personal information.
Principle
Search-engine operators can have data-protection responsibilities in relation to personal data appearing in search results.
Remedy
The case is foundational for the right to delisting/de-indexing, often described as an aspect of the “right to be forgotten.”
The judgment directly addressed the responsibility of search-engine operators and the rights of data subjects under European data-protection law. (Eur-Lex)
Significance
It demonstrates that the remedy is not necessarily limited to:
“Delete the original webpage.”
It can also concern:
How personal information is made accessible through search technology.
12. Case Law 5: Lloyd v. Google LLC
[2021] UKSC 50
Facts
Richard Lloyd brought representative proceedings against Google on behalf of a large group of individuals concerning Google's collection and use of browser information.
Issue
Could the claim proceed as a representative action and could compensation be awarded without showing individual damage?
Judgment
The UK Supreme Court rejected the proposed representative damages claim on the pleaded basis.
The Court's decision emphasized the need to establish individual damage rather than treating the mere infringement of data-protection rights as automatically generating damages for every person. (Supreme Court UK)
Importance
The case demonstrates the UK's more restrictive approach to mass data-protection damages compared with some expansive theories of collective compensation.
Principle
Large-scale data misuse does not automatically establish a uniform damages entitlement for every affected person.
13. Case Law 6: Vidal-Hall v. Google Inc.
[2015] EWCA Civ 311
Facts
Google allegedly tracked the claimants' internet browsing information through cookies without their knowledge and used the information for targeted advertising.
Issue
Could individuals claim compensation for distress caused by misuse of personal data without proving financial loss?
Judgment
The Court of Appeal allowed the claim to proceed on the basis that damages for distress could be available under the applicable data-protection regime without requiring pecuniary loss.
Importance
The case was highly significant for recognizing non-economic harm in data-protection litigation.
It demonstrates the legal significance of:
distress;
privacy intrusion;
loss of control;
personal autonomy.
14. Case Law 7: TransUnion LLC v. Ramirez
594 U.S. 413 (2021)
Facts
TransUnion maintained credit files containing misleading terrorist-related alerts for thousands of individuals.
Some reports were disseminated to third parties; others were not.
Issue
Did every statutory violation automatically create Article III standing to claim damages?
Judgment
The US Supreme Court held that plaintiffs seeking damages in federal court must establish concrete injury.
Those whose misleading information was disseminated suffered a concrete reputational injury. But individuals whose information was merely retained internally, without dissemination, did not necessarily satisfy Article III's injury requirement. (Justia Law)
Principle
A statutory privacy/data violation does not automatically create federal standing for damages; concrete harm matters.
Comparative significance
This contrasts sharply with the EU approach, where Article 82 jurisprudence recognizes certain non-material harms, including well-founded fear in appropriate circumstances.
15. Case Law 8: Spokeo, Inc. v. Robins
578 U.S. 330 (2016)
Facts
Spokeo allegedly displayed inaccurate personal information about Robins.
Issue
Was violation of a statutory right automatically enough to establish Article III standing?
Judgment
The Supreme Court required the alleged injury to be concrete, not merely abstract.
Importance
Spokeo became a major foundation for later US data-privacy standing cases, including TransUnion.
Principle
A procedural or statutory violation does not necessarily equal a constitutionally cognizable injury.
This creates a significant difference between US constitutional standing doctrine and European data-protection compensation.
16. Case Law 9: Justice K.S. Puttaswamy v. Union of India
(2017) 10 SCC 1 — India
Judgment
The Supreme Court unanimously recognized privacy as a fundamental right under the Indian Constitution.
The Court linked privacy to:
dignity;
autonomy;
liberty;
personal choice;
informational privacy.
The constitutional test for privacy restrictions includes legality, legitimate state aim and proportionality. (Sci API)
Data-protection significance
Puttaswamy provides the constitutional foundation for Indian data-protection law.
It means that personal-data governance is not merely a commercial regulatory matter.
It can implicate:
Article 21 + dignity + autonomy + informational privacy.
17. Case Law 10: Justice K.S. Puttaswamy (Aadhaar) v. Union of India
(2019) 1 SCC 1
The Aadhaar litigation examined large-scale collection and use of biometric and demographic information.
Principle
The Court scrutinized:
proportionality;
purpose;
data collection;
authentication;
informational privacy;
constitutional safeguards.
Importance
It illustrates the Indian constitutional approach to large-scale data systems.
The case demonstrates that:
State collection of personal data must be connected to lawful purposes and constitutional safeguards.
18. Indian Data Protection Remedial Framework
India's Digital Personal Data Protection Act, 2023 created a dedicated statutory framework.
The final DPDP Rules, 2025 were notified in November 2025, and the Act's commencement is staggered rather than all provisions becoming operative simultaneously. The official government commencement notification specifies different dates for different provisions. (DPDP Act 2023)
The framework provides for:
Data Principals;
Data Fiduciaries;
Data Processors;
consent mechanisms;
certain legitimate uses;
access-related rights;
correction;
erasure;
grievance redress;
data-security obligations;
Data Protection Board;
financial penalties.
Important comparative point
The Indian model is more regulatory/administrative than the GDPR's Article 82 compensation model.
Therefore, one should not simply say:
“India's DPDP Act is the same as GDPR.”
It is not.
The remedial architecture is materially different.
19. DPDP Remedies in India
Broadly, the Indian framework emphasizes:
A. Grievance redress
The Data Principal can raise grievances through the prescribed mechanism.
B. Regulatory intervention
The Data Protection Board can exercise statutory functions.
C. Penalties
The Act provides substantial financial penalties for specified non-compliance.
D. Correction and erasure
Subject to the statutory framework and exceptions.
E. Constitutional remedies
Where state action implicates fundamental rights, constitutional remedies may remain relevant.
F. Other applicable civil remedies
Depending on the facts, other laws may provide remedies for:
breach of confidence;
negligence;
consumer harm;
defamation;
contractual breach;
constitutional injury.
Thus:
Data protection liability in India cannot be understood solely by reading the DPDP Act; it must be considered alongside constitutional privacy and other applicable laws.
20. Comparative India–EU Difference
| Issue | India | EU |
|---|---|---|
| Constitutional privacy | Strong | Charter-based |
| Comprehensive data statute | DPDP Act | GDPR |
| Individual compensation | More limited/indirect statutory structure | Express Article 82 right |
| Regulatory penalties | Yes | Yes |
| Erasure | Statutory framework | Strong GDPR right |
| Access | Statutory framework | Article 15 |
| Rectification | Yes | Article 16 |
| Automated decisions | Developing | Article 22 |
| Collective actions | Developing | Stronger procedural possibilities |
| Regulatory authority | Data Protection Board | National DPAs + EDPB |
| Non-material damage | Constitutional/civil routes may apply | Expressly recognized under Article 82 |
| Punitive damages under data law | Not central | Article 82 is compensatory, not punitive |
21. United States Model
The US does not have one comprehensive federal data-protection statute comparable to GDPR.
Instead, protection comes from:
HIPAA;
GLBA;
COPPA;
FCRA;
state comprehensive privacy statutes;
state data-breach laws;
FTC enforcement;
common-law privacy;
constitutional doctrines in specific contexts.
This creates a sectoral and decentralized model.
22. US Remedial Characteristics
Strengths
statutory damages under selected laws;
class actions;
FTC enforcement;
state attorney-general enforcement;
state privacy laws;
traditional tort remedies.
Weaknesses
fragmented legislation;
inconsistent standing requirements;
different state standards;
absence of a single comprehensive federal privacy code.
Spokeo and TransUnion show why standing is a central obstacle in federal privacy litigation.
23. UK Data Protection Remedies
The UK system combines:
UK GDPR;
Data Protection Act 2018;
Information Commissioner's Office enforcement;
civil claims;
judicial review where applicable;
injunctions;
compensation.
A person may potentially seek compensation for:
material damage;
non-material damage.
The UK has also developed important jurisprudence concerning:
distress;
misuse of private information;
representative proceedings;
damages for data breaches.
Vidal-Hall and Lloyd v Google demonstrate two sides of this system:
Vidal-Hall → individual non-economic harm can be legally significant.
Lloyd → mass damages require careful proof of individual entitlement.
24. Types of Damage in Data Protection Litigation
1. Material damage
Examples:
financial loss;
identity theft;
unauthorized transactions;
employment loss;
fraud-related costs.
2. Non-material damage
Examples:
distress;
anxiety;
reputational injury;
loss of control;
fear of misuse;
invasion of privacy.
3. Constitutional harm
Particularly important in jurisdictions such as India where privacy is a fundamental right.
4. Regulatory harm
This may result in penalties imposed against the organization rather than compensation paid to individuals.
25. Is Mere Data Breach Enough for Compensation?
The answer differs by jurisdiction.
EU
Not merely the infringement itself.
The claimant must establish:
infringement;
damage;
causal connection.
But there is no separate de minimis seriousness threshold for non-material damage. (Eur-Lex)
USA
A plaintiff generally needs constitutionally cognizable concrete injury to establish federal standing for damages.
TransUnion strongly illustrates this requirement. (Justia Law)
India
The answer depends on the particular statutory, constitutional and civil-law route invoked. The DPDP framework should not be equated automatically with GDPR Article 82.
26. Data Breach Remedies
A major modern category is cybersecurity breach.
Suppose a company loses:
Aadhaar-related information;
bank details;
passwords;
medical records;
biometric data.
Potential remedies include:
Preventive
security directions;
injunctions;
processing restrictions.
Corrective
notification;
correction;
deletion;
restoration.
Compensatory
financial loss;
distress;
identity-theft consequences.
Regulatory
administrative penalties;
enforcement orders.
Collective
representative or class proceedings where permitted.
27. Right to Be Forgotten
The right to be forgotten generally involves the ability, in appropriate circumstances, to require deletion or removal of personal information.
It is not absolute.
Countervailing interests may include:
freedom of expression;
freedom of information;
public interest;
journalism;
historical research;
legal obligations.
Google Spain remains foundational to the European development of this principle. (Eur-Lex)
28. Data Protection and Freedom of Expression
A sophisticated remedial system must balance:
privacy
against
freedom of expression and information.
For example, an individual may request removal of information from a search engine, but the information may concern:
political corruption;
public office;
serious crime;
public health;
matters of public interest.
Therefore, data protection remedies are generally subject to balancing rather than being absolute.
29. Automated Decision-Making
Modern data-protection remedies increasingly concern AI and automated systems.
Examples:
automated credit decisions;
AI recruitment;
insurance profiling;
facial recognition;
predictive policing.
The SCHUFA judgment demonstrates the importance of Article 22 where automated scoring substantially determines an individual's economic position.
Thus, modern data protection is evolving from:
“Keep my information secret.”
to:
“Do not use my information to make unjustified decisions about me.”
30. Collective Data Protection Remedies
Large-scale data violations create a problem:
One company may harm millions of individuals simultaneously.
Individual litigation may therefore be economically inefficient.
Collective mechanisms can include:
class actions;
representative actions;
consumer actions;
representative complaints;
public-interest litigation;
regulatory investigations.
However, the availability and procedural requirements differ substantially.
Lloyd v Google demonstrates that representative litigation is not automatically available simply because a large number of people experienced similar data processing. (Supreme Court UK)
31. Data Protection and Cross-Border Processing
Modern companies frequently process data across several jurisdictions.
For example:
Indian user → US platform → European cloud provider → Singapore processor
This creates questions concerning:
applicable law;
jurisdiction;
international transfers;
regulator competence;
enforcement;
evidence;
compensation;
conflicting national laws.
The GDPR's territorial reach and international-transfer framework are particularly important in this context.
32. Comparative Remedies Matrix
| Remedy | EU | India | UK | USA |
|---|---|---|---|---|
| Access | Strong | Yes | Strong | Sector-specific |
| Rectification | Strong | Yes | Strong | Sector-specific |
| Erasure | Strong | Yes, subject to framework | Strong | Variable |
| Restriction | Strong | Developing framework | Strong | Variable |
| Compensation | Express GDPR Article 82 | More fragmented | Yes | Statute/tort dependent |
| Regulatory fine | Yes | Yes | Yes | Yes |
| Injunction | Yes | Available through applicable law/courts | Yes | Yes |
| Class/collective relief | Available under mechanisms | Developing | Limited/representative | Strong in some areas |
| Constitutional privacy | Charter | Article 21 | Human-rights framework | Context-specific |
| Automated decision safeguards | Strong | Developing | UK GDPR | Sectoral/state |
33. Important Comparative Principles
Principle 1 — Compensation is not the only remedy
A person may need:
deletion rather than money.
For example, an individual whose sensitive medical information is being unlawfully published may primarily need an injunction.
Principle 2 — Regulation and compensation are complementary
A fine paid to the government does not necessarily compensate the individual.
Therefore:
Regulatory enforcement ≠ private compensation.
Principle 3 — Non-material harm matters
Privacy harm can occur without direct financial loss.
Examples:
anxiety;
embarrassment;
loss of control;
fear of identity theft;
reputational injury.
The CJEU's GDPR jurisprudence strongly recognizes this category. (Eur-Lex)
Principle 4 — Mere statutory violation may not always be enough
The EU requires infringement + damage + causation under Article 82.
The US additionally imposes constitutional standing requirements for federal damages litigation.
Principle 5 — Effective remedies must be proportionate
Remedies should:
stop unlawful processing;
compensate genuine harm;
deter serious misconduct where the legal system permits;
avoid unjust enrichment.
Under GDPR Article 82, damages remain compensatory rather than punitive. (Eur-Lex)
34. Major Challenges
1. Proving causation
It can be difficult to show that a particular data breach caused a particular loss.
2. Quantifying emotional harm
Privacy and anxiety are difficult to value monetarily.
3. Mass data breaches
Millions of people may be affected differently.
4. Cross-border enforcement
The defendant and data may be located in several countries.
5. Algorithmic profiling
The individual may not know that an automated decision has been made.
6. Data aggregation
Harmless pieces of data can become sensitive when combined.
7. Data retention
Old data can continue producing new harms.
8. AI-generated inferences
AI can infer information that the individual never directly provided.
9. Regulatory fragmentation
Different jurisdictions may impose conflicting requirements.
10. Collective-action barriers
Individual damages may be too small to justify litigation.
35. Comparative Evaluation
EU Model
Strongest feature: comprehensive individual rights plus regulatory enforcement and Article 82 compensation.
Weakness: compliance and litigation can be complex.
Indian Model
Strongest feature: constitutional privacy protection combined with the DPDP statutory framework.
Weakness: the remedial architecture is not a direct copy of GDPR-style individual compensation.
UK Model
Strongest feature: combination of regulatory enforcement and judicial remedies.
Weakness: representative damages litigation faces significant procedural constraints.
US Model
Strongest feature: powerful sector-specific statutes, class actions and private litigation.
Weakness: fragmentation and constitutional standing barriers.
36. Ten Important Cases at a Glance
| Case | Jurisdiction | Key Contribution |
|---|---|---|
| K.S. Puttaswamy v Union of India | India | Fundamental right to privacy |
| Puttaswamy (Aadhaar) | India | Proportionality in large-scale data processing |
| Österreichische Post | EU | Infringement + damage + causation |
| Natsionalna agentsia za prihodite | EU | Fear of misuse can constitute non-material damage |
| SCHUFA | EU | Automated credit scoring and Article 22 |
| Google Spain | EU | Delisting/right to be forgotten |
| Lloyd v Google | UK | Limits on representative data-damages claims |
| Vidal-Hall v Google | UK | Distress without pecuniary loss |
| Spokeo v Robins | USA | Concrete injury requirement |
| TransUnion v Ramirez | USA | Concrete harm required for federal damages standing |
37. Emerging Issue: Data Protection and AI
AI makes data-protection remedies more complicated because AI systems may:
collect personal information;
infer sensitive characteristics;
create profiles;
retain prompts;
generate personal information;
make automated decisions;
reproduce training data;
combine datasets.
Therefore, future data-protection remedies will increasingly concern:
data collection + inference + profiling + automated decision-making + AI accountability.
The SCHUFA jurisprudence is particularly relevant because it shows that the legal significance of data processing may arise from the decision-making consequences of a data-derived score, not merely from disclosure of the underlying data.
38. Exam-Oriented Definition
Comparative Data Protection Remedies means the comparative study of judicial, administrative, statutory, regulatory and collective remedies available in different jurisdictions to protect individuals against unlawful collection, processing, disclosure, retention, profiling, automated decision-making or other misuse of personal data, including compensation, injunctions, rectification, erasure, restriction, regulatory penalties and constitutional remedies.
39. Conclusion
Comparative data-protection law demonstrates that effective privacy protection requires more than simply prohibiting unlawful data processing. A complete system must provide mechanisms to:
prevent → detect → correct → stop → compensate → deter
The EU provides the most developed rights-based remedial structure, particularly through GDPR Articles 79 and 82. The CJEU has clarified that Article 82 requires infringement, damage and causation, while refusing to impose a separate minimum seriousness threshold for non-material damage. (Eur-Lex)
The UK combines regulatory and judicial remedies, with Vidal-Hall demonstrating the importance of non-economic privacy harm and Lloyd v Google illustrating the limits of large-scale representative damages claims. (UK Law Reference)
The United States follows a more fragmented approach, where Spokeo and TransUnion make the requirement of concrete injury particularly important for federal damages litigation. (Legal Information Institute)
India approaches data protection through the constitutional right to privacy recognized in K.S. Puttaswamy, supplemented by the Digital Personal Data Protection Act, 2023 and the 2025 Rules. The DPDP framework is being brought into force in stages, so its statutory remedies should be distinguished from the broader constitutional and civil remedies that may apply in particular circumstances. (Sci API)
The central comparative principle is:
A meaningful data-protection regime must give the individual not merely a right to privacy, but an effective remedy when that right is violated.

comments