EU Law Radar

Monitoring References to the Court of Justice of the European Union

Case C-273/25, Erser – is losing control of your data a harm in itself?

C-273/25pendingCURIA ↗EUR-Lex ↗

Thousands of German claims against Meta rest on the same short argument: my data ended up where it should not have been, and that is the harm. A court in Erfurt asks the Court of Justice whether the argument is complete.

Facts

S is suing Meta Platforms Ireland Limited before the Landgericht Erfurt for compensation under Article 82(1) of the GDPR. S’s personal data — at most a numerical user ID, name and gender, all of which S had already published online, together with a telephone number — were published on the internet by a third party, who had linked the number to the other data. The publisher was not Meta. The referring court asks whether it must award compensation to a claimant who has shown only that this happened, and whether the fact that the data other than the phone number were already public changes the answer. The notice does not say how the third party obtained the data; the pattern it describes — public profile fields joined to a phone number and published in bulk — is that of the scraping incidents that have produced a wave of litigation against Meta in the German courts. (Erser is a fictitious name assigned under the Court’s anonymisation practice; it does not correspond to any party.)

Questions Referred

1. Is Article 82(1) of Regulation (EU) 2016/679 (GDPR) to be interpreted as meaning that a national court must, in the event of an infringement of the GDPR, award compensation to a data subject who has merely demonstrated that a third party (and not the defendant data controller) has published the data subject’s personal data on the internet? In other words: does the mere loss of control, even for a short time, over one’s own data constitute non-material damage within the meaning of Article 82(1) of the GDPR?

2. If Question 1 is answered in the affirmative: to what extent does the answer differ, or does it make any difference, if the data published consist only of certain personal data (including, at most, numerical user ID, name and gender) that the data subject himself or herself had already published on the internet, together with the data subject’s telephone number, which a third party (who is not the defendant data controller) has linked to those personal data?

Comment

The Court has built the law of Article 82 in a series of judgments over three years, and the reference sits precisely in the gap they left. Article 82(1) gives compensation to “any person who has suffered material or non-material damage as a result of an infringement”. In Case C‑300/21, Österreichische Post (ECLI:EU:C:2023:370) the Court held that “the mere infringement of the provisions of that regulation is not sufficient to confer a right to compensation” — damage must be shown — but also that national law may not require the damage to reach “a certain degree of seriousness”. Then, in Case C‑340/21, Natsionalna agentsia za prihodite (ECLI:EU:C:2023:986), it held that “the fear experienced by a data subject with regard to a possible misuse of his or her personal data by third parties as a result of an infringement of that regulation is capable, in itself, of constituting ‘non-material damage’”. So infringement alone is not enough, fear is enough, and there is no threshold. The Erfurt court asks what lies between: is the loss of control itself — before any fear, distress or consequence is proved — a harm?

The question matters because of how mass claims are pleaded. If loss of control is damage, a claimant need only prove the infringement and the publication; every affected user has an identical claim and the litigation becomes arithmetic. If it is not, each claimant must show something personal — fear, anxiety, a concrete disadvantage — and the Court’s own ruling in Case C‑182/22, Scalable Capital (ECLI:EU:C:2024:531) that Article 82 “fulfils an exclusively compensatory function” and that minor damage may be met with “minimal compensation” starts to bite. Recital 85 of the GDPR lists “loss of control over their personal data” among the harms a breach may cause, which is the claimant’s strongest text; but a recital lists what may cause damage, not what damage is.

The second question is the more interesting one for the future of the argument, because it asks about data that were already public. If a user has chosen to publish name, gender and ID, what control was lost when a third party republished them? The referring court’s answer is built into the question: the harm, if any, is in the linking — a phone number attached to an identity the user had not attached it to. That reframes loss of control from a property-like notion (my data went somewhere) to an informational one (a new fact about me was created), and it is the version of the argument most likely to survive. Whichever way the Court goes, the answer will be read by every court in the Union handling a scraping or breach claim against a platform — which is to say, most of them.

Sources

OJ notice C/2025/3866 (EUR‑Lex) · Case file on CURIA · Regulation (EU) 2016/679