Non-pecuniary damages are not awarded automatically for breaches of data protection rules

In recent years, there has been a growing number of cases in which employees challenge employer measures not only in labour disputes, but also seek non-pecuniary damages by invoking violations of personality rights and data protection rules. In many instances, it is assumed that if an employer fails to comply with certain formal or procedural requirements in the course of data processing, this in itself gives rise to a claim for non-pecuniary damages. However, a case lasting more than eight years demonstrated precisely the opposite, and the judgment of the Curia (Hungary’s Supreme Court) provides particularly important guidance in this respect.

The case originated from the termination of a judge’s service relationship. The claimant was dismissed on grounds of medical unfitness, a decision he contested, pursuing litigation for years in order to have the legal consequences of unlawful termination applied and to obtain non-pecuniary damages for the alleged violation of his personality rights. The lengthy proceedings included several first- and second-instance judgments, a review by the Curia, and even a constitutional complaint. Although the Constitutional Court at one point annulled the courts’ decisions due to a lack of procedural safeguards, the repeated proceedings ultimately again concluded that the dismissal of the judge had been lawful.

The claim for non-pecuniary damages nevertheless persisted, as the claimant argued that his human dignity and reputation had been infringed and that his employer had unlawfully processed his health-related personal data. The courts, however, consistently examined whether these allegations amounted to an actual interference with the claimant’s private sphere that was capable of causing non-material harm.

In its final decision (Mfv.10049/2023/5), the Curia made it clear that although a data protection infringement had indeed occurred which did not fully comply with statutory requirements, this alone does not mean that a violation of personality rights has taken place. For non-pecuniary damages to be awarded, a mere technical error on the part of the data controller is insufficient. According to the Curia, such damages require that the infringement has interfered with the claimant’s private sphere in a real and demonstrable way, causing non-material harm. The claimant, however, failed to prove that the alleged data protection breach had any specific, tangible or adverse consequences for him.

It is also important to emphasise that, for the purposes of assessing the personality rights claim, a decisive factor was that the data processing – even if it involved certain formal shortcomings – took place within the framework of the service relationship and in connection with lawful employer measures. The courts therefore examined whether the employer’s conduct went beyond lawful operation or genuinely infringed the claimant’s private sphere. As no such evidence was found, the rejection of the claim for non-pecuniary damages was justified.

One of the key lessons of the decision is that a breach of data protection rules is not equivalent to a violation of personality rights, and non-pecuniary damages should not become a form of automatic “punitive tool”. The purpose of such damages is not to punish the infringing party, but to compensate the injured party for non-material harm suffered. Accordingly, the claimant must demonstrate that the contested data processing actually resulted in a concrete disadvantage – for example, that personal data was disclosed to unauthorised persons or made public in a way capable of damaging reputation or infringing privacy.

This case carries an important message for both employers and employees. Employers must of course continue to strive for full compliance with data protection rules, as this is a fundamental requirement of lawful operation and good practice. At the same time, a mere formal error does not automatically result in liability or an entitlement to non-pecuniary damages. Employees, for their part, should be aware that establishing a breach of rules alone is not sufficient: it must also be proven that the infringement led to a genuine violation of their personality rights. It should be noted that this case does not affect the powers of data protection authorities to impose administrative fines, which remain applicable independently.

Leave a Reply

Your email address will not be published. Required fields are marked *