Оn 14.12.2023. The CJEU ruled on the reference for a preliminary ruling of the Supreme Administrative Court of Bulgaria (SAC). It concerns the interpretation of Article 5(2), Articles 24 and 32 as well as Article 82(1) to (3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR). The reference is made in the context of a dispute between an individual and the National Revenue Agency Bulgaria (NRA) concerning compensation for the non-material damage which the individual claims to have suffered as a result of an alleged failure by that public authority to comply with its legal obligations as a personal data controller.
The CJEU has ruled that concerns about potential misuse of personal data arising from a breach of the GDPR can constitute non-material harm. It has been held that where a person seeks compensation on this ground, the national jurisdiction is obliged to examine whether the fears can be regarded as well-founded in the light of the circumstances of the particular case and of the data subject.
Moreover, the CJEU points out that the NRA cannot be exempted from liability just because it was victim of a hacking attack. It is underlined that the data leakage is not sufficient to consider that the measures applied by the NRA or any other controller are not appropriate within the meaning of the GDPR. It clarifies that the mere fact of a hacking attack neither exempts the controller from liability nor, on the contrary, necessarily means that the measures taken by it were inappropriate.

