17 reader checks this week

Ireland’s Supreme Court Reframes GDPR Non-Material Damages

| By Legal News Team | Updated News
Ireland’s Supreme Court Reframes GDPR Non-Material Damages

The recent ruling by the Irish Supreme Court has set a significant precedent in the realm of data protection and privacy law, particularly concerning the General Data Protection Regulation (GDPR). This decision will likely influence how non-material damages are perceived and litigated in the context of privacy breaches. On 24 July 2025, the court delivered its judgment in the case of Dillon v Irish Life Assurance plc, a case pivotal for understanding the nuances of compensation claims related to privacy invasions.

Historically, the GDPR has been a robust framework for ensuring personal data protection across Europe. It emphasizes the rights of individuals in controlling their data and the responsibilities of organizations to uphold these rights. A critical aspect of GDPR is its recognition that harm from data breaches need not be purely financial. Article 82 of the GDPR stipulates that individuals can seek compensation for material as well as non-material damage, which includes emotional distress and reputational damage. This broadens the scope of potential claims, acknowledging the diverse impacts of data breaches.

Non-material damages refer to harm that does not directly translate into financial loss. This could encompass anxiety, distress, or reputational harm resulting from improper handling of personal information. The Court of Justice of the European Union (CJEU) has deliberated on what qualifies as non-material damage and the conditions under which claims can be made. In light of these discussions, the Dillon case is particularly noteworthy as it marks the first instance where the Irish Supreme Court has tackled this issue directly.

In examining whether claims for non-material damages under GDPR should be classified as personal injury claims, the Supreme Court in Dillon explored the procedural implications. The primary question was whether claimants needed to obtain authorization from the Injuries Resolution Board before initiating proceedings. This requirement had been a standard procedure for other personal injury claims, typically involving a formal assessment by the board, former known as the Personal Injuries Assessment Board (PIAB).

The Dillon case arose from a cyber incident where Irish Life Assurance plc mistakenly sent letters containing Dillon’s personal and financial details to a third party. Dillon claimed negligence and breach of statutory duty, seeking damages for emotional distress and inconvenience. Both the Circuit Court and the High Court initially deemed Dillon’s claims as seeking personal injury compensation, thus necessitating PIAB authorization.

The Supreme Court’s decision to overturn this requirement represents a crucial shift. According to the court, claims for general distress or anxiety that do not meet the legal threshold for psychiatric disorders do not require PIAB authorization. This distinction is essential because recognized psychiatric injuries continue to necessitate adherence to PIAB procedures, potentially involving greater compensation.

The implications of this ruling are multifaceted. For individuals, the elimination of the procedural barrier simplifies the process of pursuing claims for non-material damages under GDPR. It allows claimants to focus on clearly articulating the type of harm suffered and the legal basis for their claims without additional bureaucratic hurdles. However, the court also emphasized that compensation for non-material damages remains modest unless the claims reach the higher threshold of psychiatric injury.

For organizations, the decision provides reassurance that compensation for minor distress will remain limited. The requirement for PIAB authorization in cases involving significant psychiatric harm serves as a safeguard against inflated claims. This balance ensures that while individuals have a pathway to seek redress for privacy violations, organizations are not unduly burdened by claims for minor distress.

Overall, this landmark ruling underscores the evolving nature of data protection laws and the delicate balance between individual rights and organizational responsibilities. It highlights the importance of clarity in legal procedures and the need for organizations to maintain diligent data protection practices to avoid breaches that could lead to legal repercussions. As data continues to be a critical asset in the digital age, the implications of this decision will likely extend beyond Ireland, influencing broader interpretations of GDPR compliance and compensation frameworks across Europe. The case serves as a reminder of the dynamic interplay between evolving legal standards, technological advancements, and the ever-present need for robust privacy protections.

Free Claim Assessment

Find out if you have a valid claim — free, no obligation.

Start Free Assessment