When a data breach lands on your desk, the incident response doesn't end with notification. You're now managing two parallel tracks: regulatory compliance and potential civil liability. Under Article 82 of GDPR, affected individuals can seek compensation for damages resulting from your organization's failure to protect their data. The CNIL can't award damages, but a judge can, and the evidentiary standard is exacting.
This playbook walks you through building a defensible position from the moment you detect a breach.
The Problem: Three Conditions, One Missing Link
Article 82 establishes a right to compensation, but claimants must prove three elements:
- A GDPR violation occurred
- They suffered real material or moral damage
- A causal link exists between the violation and the damage
The third condition is where most claims falter or succeed. It's not enough that a breach happened and someone feels anxious, they must demonstrate that your specific failure caused their specific harm. This means you need to document not just what went wrong, but what you did right, what controls were in place, and where the chain of causation breaks.
Your exposure isn't theoretical. French courts have clarified that moral damage doesn't require a minimum severity threshold, but it must be personally suffered and real. The mere fact of a GDPR violation isn't compensable on its own.
What You Need Before Starting
Before you can defend against or support a compensation claim, gather:
- Your data processing register: Current inventory of what personal data you hold, where it's stored, and under what legal basis for processing
- Security documentation: Technical and organizational measures implemented before the breach (encryption status, access controls, audit logs, staff training records)
- Breach timeline: Detection timestamp, containment actions, affected data categories, number of individuals impacted
- Notification records: What you told the CNIL, when you notified data subjects, and what mitigation you offered (credit monitoring, password resets)
- Incident response logs: Commands run, systems isolated, forensic evidence preserved
You'll also need to identify your legal venue. If the responsible controller is a private entity, claims go to the tribunal judiciaire. If a public administration is at fault, the tribunal administratif has jurisdiction, with different procedural rules including mandatory pre-litigation demand letters.
Step-by-Step Implementation
1. Preserve the Evidentiary Record
Within 24 hours of breach detection:
- Take forensic snapshots of affected systems before remediation
- Export access logs covering the 90 days preceding the breach
- Document every containment action with timestamps and responsible parties
- Preserve all internal communications (Slack threads, email chains, incident tickets)
Store these artifacts in a separate, access-controlled repository. You're building the foundation for demonstrating either compliance or good-faith effort.
2. Document Your Pre-Breach Security Posture
Compile evidence that you implemented appropriate technical and organizational measures before the breach:
- Data Protection Impact Assessments conducted for high-risk processing
- Penetration test reports and remediation tracking
- Staff training completion records (especially for anyone with access to the compromised data)
- Vendor security assessments if a subprocessor was involved
- Encryption implementation for data at rest and in transit
GDPR imposes a presumption of liability on controllers, but you can rebut this by proving you weren't responsible for the event causing the damage. This documentation is your exoneration path.
3. Map the Causation Chain
For each affected individual who files a claim, create a causation matrix:
- What specific data of theirs was exposed?
- What harm do they allege (financial loss, identity theft, reputational damage, anxiety)?
- What evidence do they provide linking your breach to their harm?
- What intervening factors exist (did they reuse passwords across sites? Did they ignore your mitigation offer)?
Consider a scenario where an individual claims anxiety after their email address was exposed in a breach. If you can show the exposed data was limited to email and account creation date, not payment details or sensitive categories, and that you immediately forced password resets and offered monitoring, the causal link weakens. The claimant must prove the breach caused their specific anxiety, not just that they feel anxious and a breach occurred.
4. Assess Your Liability Exposure
Review your breach against GDPR's security obligations:
- Did you implement Data Protection by Design and Data Protection by Default in the affected system?
- Was the data pseudonymized or encrypted?
- Did you conduct regular security testing?
- Were access controls role-appropriate?
If you failed to implement security measures "appropriate to the risk," you've met the first condition (GDPR violation). Document any gaps honestly, courts will discover them anyway, and your credibility matters for settlement negotiations.
5. Prepare Your Response Strategy
You have three options:
Settle directly: If liability is clear and damages are modest, direct settlement avoids litigation costs. Require a full release and confidentiality clause.
Defend in court: If you believe you met your security obligations or the causal link is weak, prepare for tribunal judiciaire proceedings. Engage counsel experienced in GDPR Article 82 claims.
Support a class action: If multiple individuals were harmed identically, an action de groupe (class action) may be more efficient. Since the April 2025 reform, a unified class action regime covers data protection claims. Authorized associations can represent affected individuals collectively.
Validation: How to Verify Your Position
Before committing to a defense strategy, stress-test your evidence:
- Can you prove security measures were implemented before the breach? If your documentation is post-hoc, it won't help.
- Can you quantify the exposed data's sensitivity? "Customer database" is too vague; "email addresses and account creation dates, no payment data" is defensible.
- Can you show prompt, effective mitigation? Delayed notification or inadequate remediation strengthens causation arguments.
- Do you have evidence breaking the causal chain? Third-party actions, claimant negligence, or lack of actual use of the exposed data all weaken causation.
Run this analysis with your legal team before the CNIL closes its investigation. Regulatory findings will be discoverable in civil proceedings.
Maintenance: Ongoing Tasks
After resolving immediate claims:
- Update your breach response plan with lessons learned, especially around evidence preservation
- Implement compensating controls for any security gaps identified during the incident
- Document all security improvements with before/after configurations and deployment dates
- Train your incident response team on evidence collection procedures that support both regulatory and civil defense
- Review your cyber insurance policy to confirm coverage for Article 82 claims and understand your insurer's evidence requirements
The CNIL can't award damages, but its investigation findings will influence judicial outcomes. Treat every breach as if it will end in court, because increasingly, it does.




