Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

GDPR Article 79 [1]:

> 1. Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.

> 2. Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. 2Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.

That sounds like a lawsuit to me.

[1] https://gdpr-info.eu/art-79-gdpr/



See article 78. There is an escalation path.


The way it is written makes it seem like 79 is independent of 77 and 78. You can pursue a claim through a supervisory authority (77) and if you are not happy with the result go to court (78), or you can go to court directly against the processor/controller (79), or maybe even do both.

79 specifically specifically says that pursuing a judicial remedy under it is without prejudice to any available administrative or non-judicial remedy, including the right to lodge an Article 77 complaint. If this was meant as something that has to come after not getting satisfaction from an Article 77 complaint it would make no sense to say it is without prejudice to the right to lodge an article 77 complaint since that would have already had to have been lodged before getting here.

This also fits with what I saw on assorted EU and international law firm blogs, back when they were all writing articles on what GDPR would mean.


:shrug: I’m not a GDPR lawyer and further most of it doesn’t have precedent yet so we aren’t sure how its going to fall out.

I did work on a GDPR compliance effort in an industry where it is big important (real time bidding ads) and our lawyers, while hedging, were not at all worried about random lawsuits. Their opinion was that we would easily be able to submit to the courts that the complaints needed to go through the authorities first.


I did see one legal firm blog that said they expected a lot of lawsuits from individuals, but most blogs and reports I saw seemed to think it there won't be a lot of them.

If there are any, they probably won't be a big deal for the defendants. An individual lawsuit is limited to compensation for the damages suffered. In most cases, that just won't be very much, and so probably won't be worth the time and effort to pursue.

Only supervisory authorities can can impose punitive measures such as fines based on revenue. Those are the only things likely to actually make a difference.

Also I get the impression that European regulators are more responsive than US regulators. Europeans report things to regulators first and expect them to be taken care of. Contrast that to Americans who are far more likely to view the regulators as ineffective and turn first to a lawsuit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: