
No Damages
following
Data breach.
No Damages
following
Data breach.
of
Is a listing on HaveIBeenPwned sufficient evidence of a data breach? Under what circumstances is a company actually liable for a successful cyberattack? What role does the burden of proof play in claims for damages following data breaches?
What’s it about?
A user of the software platform—which offers both a free trial and a paid subscription—sought damages from the provider after its systems were targeted by a cyberattack in 2020. Unknown third parties had gained access to some of the stored user data and published it on the dark web. The data was later uploaded to the research platform HaveIBeenPwned, where affected users can check whether their data has been compromised in a data breach.
The user stated that he had provided personal data during registration and sought compensation for non-pecuniary damages of at least 3,000 euros for the loss of control over his data, as well as an additional 2,000 euros due to what he considered to be insufficient information provided by the company. In addition, he sought a declaration of liability for future damages, an injunction, further information, and reimbursement of attorney’s fees. The company contested this, citing appropriate technical safeguards. It also argued that the attack was presumably attributable to the compromised login credentials of a single employee and was therefore due to human error beyond the company’s control.
Decision of the Traunstein Regional Court
The Traunstein Regional Court dismissed the lawsuit with Judgment of July 17, 2026 – Case No. 9 O 1560/24 dismissed.
First, the user was unable to prove that he was actually affected. He had claimed to have provided his full personal information, which the company disputed and substantiated with a negative credit report. In the court’s view, a mere match on HaveIBeenPwned was not sufficient as conclusive proof of specific harm, since the platform’s functionality and data basis could not be reliably verified in court. The user also failed to provide sufficient evidence regarding the alleged non-pecuniary damages. Although, according to current Supreme Court case law, even a brief loss of control could constitute compensable damages, this would require a concrete personal impairment. According to the court’s findings, the user’s descriptions consisted solely of standardized text blocks, the exact wording of which had been used in numerous similar cases. It is also noteworthy that the user had long since published his own data in a freely available press kit.
The plaintiff thus relinquished control over his personal data long before the incident at issue.
Furthermore, the court also ruled out any substantive violation of the General Data Protection Regulation. A successful hacker attack, in and of itself, does not prove that security measures were inadequate. The company had provided a substantiated account of the technical and organizational measures it had taken, whereas the user’s arguments on this point remained unsubstantiated. The court also found that the company’s obligation to provide information had been fulfilled by a prior letter from the company, and that the notification to the competent Irish supervisory authority had been made within the required time frame.
Conclusion
This ruling is one of a growing number of decisions that take a cautious approach to lawsuits filed in the wake of data breaches, particularly when the complaint is based on reused boilerplate text. Although the European Court of Justice and the Federal Court of Justice have recently lowered the substantive thresholds for non-pecuniary damages, the full burden of proof and presentation of facts remains with the plaintiff. In practice, the lowering of the substantive requirements is therefore often rendered meaningless if affected individuals cannot provide concrete evidence of their individual harm.
It remains to be seen how to address the structural lack of evidence faced by many affected individuals following major data breaches, and whether the evidentiary requirements still reflect the reality of mass data breaches.
We are happy to
advise you about
Data protection law!







