KG LEGAL \ INFO
BLOG

Liability for Loss and Corruption of Data

Publication date: October 05, 2026

The loss or corruption of data in a business is rarely “just” a technical problem. In practice it is a serious legal and financial crisis: production downtime, loss of trust among business partners and, in extreme cases, administrative fines running into millions. The scope of liability, however, depends above all on what kind of data has been lost or corrupted. The law treats the loss of source code or technical documentation quite differently from a leak of employee records or a customer database. The first step in assessing liability for a breach of the integrity or availability of data is therefore its unambiguous legal classification.

Personal Data and Non-Personal Data

It is worth starting with the category that, in recent years, has come under particular legal protection as a result of stringent EU rules: personal data, the protection of which directly concerns the privacy and rights of natural persons. Personal data protection is governed by Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR). Under Article 4(1) GDPR, personal data means any information relating to an identified or identifiable natural person, i.e. a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name or a national identification number (in Poland, the PESEL number).

The rapid growth of the data-driven economy means that non-personal data is gaining ever greater economic and legal significance. Non-personal data is data that does not relate to an identified or identifiable natural person and therefore falls outside the scope of the GDPR. As the recitals of Regulation (EU) 2018/1807 of the European Parliament and of the Council on a framework for the free flow of non-personal data point out, information and communication technologies are no longer a separate sector but the foundation of all modern economic systems, with electronic data at their core. The statutory definition of non-personal data is contained in Article 3(1) of Regulation 2018/1807 and Article 2(4) of Regulation 2022/868 (the Data Governance Act): it is data other than personal data within the meaning of the GDPR. This category includes in particular:

  • technical, operational, industrial and telemetry data,
  • financial and production data,
  • source code and design documentation,
  • artificial intelligence models together with their training data,
  • data on the operation of IT systems.

Non-personal data includes both data that has never contained any information about natural persons (e.g. weather data or share prices) and data that was originally personal but has subsequently been effectively anonymised, i.e. to a degree that permanently prevents the identification of a natural person. It should be borne in mind that data which has merely been pseudonymised remains personal data (recital 26 GDPR). Non-personal data may be a key asset of a business, often worth more than its traditional tangible assets; in the case of artificial intelligence models, the quality, volume and diversity of the data directly determine the value and effectiveness of the model itself.

A Different Centre of Gravity of Protection

The fundamental distinction between personal and non-personal data is not merely a technical or definitional matter. It determines where the centre of gravity of legal protection lies:

  • for personal data, the central protected value is the rights and freedoms of natural persons, including the right to privacy and the right to informational self-determination; the GDPR regime is therefore constructed primarily from the perspective of the data subject as the weaker party in need of protection;
  • for non-personal data, the centre of gravity shifts dramatically: what matters is the economic interest of the business, its operational continuity, organisational security and the economic value of the data as such.

The loss or corruption of non-personal data does not infringe the rights of any natural person within the meaning of the GDPR, but it may lead to serious financial losses, loss of competitive advantage, disruption of production processes or the permanent destruction of a resource that cannot be recreated at all, or only at disproportionate cost. This distinction translates into different bases of liability, because non-personal data is not subject to the sanctions provided for in the GDPR.

Mixed Data Sets

A separate issue is that of mixed data sets, i.e. data sets composed of both personal and non-personal data (e.g. the ERP and CRM systems of online shops). Under Article 2(2) of Regulation 2018/1807, where personal and non-personal data are inextricably linked, the GDPR applies to the whole data set. In other cases the GDPR applies only to the personal data part of the set, while non-personal data is governed primarily by the rules of contractual liability arising from the agreement and by the provisions of civil law.

CriterionPersonal dataNon-personal data
Object of protectionRights and freedoms of the natural personEconomic, organisational and technological interest
Main legal regimeGDPRCivil law, contracts, sectoral regulation, cybersecurity law
Typical harmIdentity theft, distress, material or non-material damageDowntime, loss of data value, wrong business decisions, contractual loss
Liable partyController, processorIT provider, counterparty, management board, cloud service provider
Typical instrumentsDPIA, breach notification, communication to the data subjectSLA, backup, RPO/RTO, disaster recovery, security audit, notification of the authority
Main practical problemExercise of the data subject’s rightsRecovery of the data and proof of economic loss

Liability for Loss or Corruption of Personal Data

To assess the consequences of the loss or corruption of personal data properly, three distinct concepts must be kept apart:

  • a personal data breach (the security incident),
  • an infringement of the GDPR by the controller or processor,
  • damage suffered by the data subject.

The occurrence of an incident does not automatically mean that the law has been infringed, and an infringement of the law does not in itself give rise to a right to compensation.

Personal Data Breach

Under Article 4(12) GDPR, a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. Both the loss and the corruption of data therefore fall within the broad scope of this concept and may give rise to legal liability. A personal data breach may concern:

  • confidentiality – unauthorised disclosure of, or access to, the data;
  • integrity – unauthorised alteration of the data, i.e. any change made by an unauthorised person or an incorrect change made by an authorised person;
  • availability – unauthorised loss of data (a situation in which the data cannot be used, temporarily or permanently, although it can be recovered or recreated) or unauthorised destruction of data (the data is lost irretrievably because the controller has no means of recreating it).

A breach may occur by accident or as a result of deliberate and unlawful action. The most common causes include:

  • human error, e.g. a mistake, a lost storage device or a failure to recognise that a breach has occurred;
  • inadequate safeguards or procedures;
  • cybercrime, e.g. phishing (impersonating a trusted person in order to extract sensitive data) or ransomware (an attack that blocks access to a system or renders data unreadable, combined with a demand for payment to restore the original state);
  • physical or environmental factors, such as natural disasters and failures of technical infrastructure.

A personal data breach occurs regardless of whether any adverse consequences actually materialise. A failure to respond appropriately and promptly, however, may result in adverse consequences for the data subject, such as physical harm, material or non-material damage, or identity theft or fraud (recital 85 GDPR).

Infringement of the GDPR

Article 5(1)(f) GDPR sets out the principle of integrity and confidentiality: personal data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures. Article 5(2) GDPR introduces the principle of accountability, under which the controller must be able to demonstrate compliance with these principles.

The GDPR imposes on controllers a range of obligations relating to secure processing and to responding to breaches. These obligations are built on a risk-based approach: protective measures must be tailored to the risk that the processing poses to the rights and freedoms of natural persons. The requirements therefore differ from controller to controller depending on the specifics of the processing, and controllers must assess the associated risk themselves. The key obligations are:

  • Article 24(1) GDPR – the obligation to implement appropriate technical and organisational measures and to assess risk;
  • Article 25(1) GDPR – the obligation to take data protection into account already at the design stage of the processing and throughout the processing itself (privacy by design);
  • Article 32(1) GDPR – the obligation to implement measures ensuring a level of security appropriate to the risk, e.g. authentication procedures and appropriate infrastructure and safeguards;
  • Articles 33 and 34 GDPR – the obligation to notify a breach to the supervisory authority (as a rule within 72 hours) and, where the breach is likely to result in a high risk to the rights and freedoms of natural persons, also to communicate it to the data subject;
  • Article 35 GDPR – the obligation to carry out a formal data protection impact assessment (DPIA) where a type of processing is likely to result in a high risk (e.g. large-scale processing of special categories of data or of data relating to criminal convictions); this obligation is further specified by the list of processing operations published by the President of the Polish Personal Data Protection Office (PUODO).

Risk assessment consists in estimating the severity of the potential consequences of a breach and the likelihood of their occurrence, taking into account, among other things, the type of breach, the sensitivity of the data and the seriousness of the consequences for the data subjects.

An infringement of the GDPR is therefore conduct that fails to meet the above requirements. It is legal in nature, as opposed to the incident itself, which is a matter of fact. Failure to comply with the obligations listed in Articles 8, 11, 25 to 39, 42 and 43 GDPR is punishable under Article 83(4) GDPR by an administrative fine of up to EUR 10,000,000 or, in the case of an undertaking, up to 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher.

The Regulation also grants the data subject a number of rights, the exercise of which may become difficult or impossible once data has been lost or corrupted:

  • the right of access (Article 15 GDPR) – the right to obtain confirmation as to whether the controller is processing personal data and, if so, access to that data; after loss or corruption, the controller may be unable to give effect to this right, and if it fails to act on the request within one month (Article 12(3) and (4) GDPR), the data subject may lodge a complaint with the supervisory authority and seek a judicial remedy;
  • the right to rectification (Article 16 GDPR) – of particular importance where data has been corrupted; the difficulty may be that the controller does not know which data has been corrupted or to what state it should be restored, e.g. where the corruption has also affected the backup copies;
  • the right to erasure (Article 17 GDPR) – inter alia where the data is no longer necessary for the purposes for which it was collected, the data subject has withdrawn consent and there is no other legal basis, or the data has been processed unlawfully; where data has been lost (as opposed to destroyed) it still exists and can be restored, and a controller that cannot locate it will be unable to comply with an erasure request, which may in itself constitute an infringement of the GDPR;
  • the right to restriction of processing (Article 18(1)(a) GDPR) – where the data subject contests the accuracy of the data, which is precisely the case when data has been corrupted.

Infringement of the provisions governing data subjects’ rights (Articles 12 to 22 GDPR) and of the basic principles of processing (Articles 5 to 7 and 9 GDPR) is punishable under Article 83(5) GDPR by an administrative fine of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total worldwide annual turnover of the preceding financial year, whichever is higher.

Damage and Liability for Compensation

Even where the GDPR has been infringed, the injured party does not automatically acquire a right to compensation. Under Article 82 GDPR, three conditions must be met cumulatively: an infringement of the Regulation, material or non-material damage, and a causal link between the two. The controller is liable; the processor is liable only where it has failed to comply with obligations specifically directed to processors or has acted outside or contrary to the lawful instructions of the controller (Article 82(2)). Exemption from liability is possible only on proof that the entity concerned is not in any way responsible for the event giving rise to the damage (Article 82(3)). Where more than one controller or processor is responsible for the damage, they are jointly and severally liable (Article 82(4)).

The case law of the CJEU and of the Polish courts on Article 82 GDPR has so far developed mainly in cases concerning the unauthorised disclosure of data to third parties; there are no decisions dealing directly with the loss or corruption of data. The principles developed by the Court are, however, general in nature and apply to all types of breach listed in Article 4(12) GDPR, and thus also to breaches of the integrity and availability of data. The most important of them are:

  • C-300/21 (Österreichische Post) – a mere infringement is not sufficient for an award of compensation; the claimant must show damage (material or non-material) and a causal link; at the same time, there is no minimum threshold of seriousness of the damage;
  • C-687/21 (BL v MediaMarktSaturn Hagen-Iserlohn) – the mere fear or apprehension of possible misuse of data by third parties may constitute non-material damage, but the claimant must prove that it actually occurred; such apprehension does not constitute damage where there was no possibility of a third party becoming aware of the data, which is typically the case where data has been destroyed or lost without being disclosed; compensation is purely compensatory and not punitive in nature;
  • judgment of the Warsaw Court of Appeal of 22 June 2023, case no. I ACa 352/23 – the court confirmed that non-material damage within the meaning of Article 82 GDPR also covers distress and the risk of reputational harm.

The CJEU has also pointed out that Article 82 GDPR covers only infringements of the Regulation itself. If the loss or corruption of data additionally involves an infringement of national law, including of personality rights, any extension of liability can be considered only on the basis of national provisions; in Poland, the injured party may then claim separate compensation for non-material harm under Articles 23 and 24 in conjunction with Article 448 of the Civil Code.

Liability for Loss or Corruption of Non-Personal Data

Contractual Liability

The basis for claims against external providers whose improper performance has contributed to the loss or corruption of data is Article 471 of the Polish Civil Code. This applies in particular to software vendors, cloud service operators, IT outsourcing companies and entities responsible for backup and disaster recovery. Under that provision, the debtor is obliged to remedy the damage resulting from non-performance or improper performance of an obligation, unless it proves that this is the consequence of circumstances for which it is not responsible.

In commercial practice the key instrument governing the scope of that liability is the agreement concluded with the IT service provider (e.g. a maintenance or implementation agreement) and, within it, the Service Level Agreement (SLA). It is in the SLA that the parties define the scope of the service, the required availability of systems, the permitted response time in the event of a failure and the consequences of non-compliance, including contractual penalties and grounds for termination. From the perspective of liability for data loss, two SLA parameters are of particular importance:

  • Recovery Point Objective (RPO) – the acceptable amount of data an organisation can afford to lose in the event of an incident; this parameter determines the required frequency of backups;
  • Recovery Time Objective (RTO) – the maximum acceptable time for restoring operational processes after a disruption.

Both parameters form part of disaster recovery, i.e. the set of policies, procedures and tools designed to minimise the effects of unforeseen events such as cyberattacks, infrastructure failures or natural disasters. Disaster recovery comprises three layers:

  • prevention (backups, protective systems, maintenance),
  • detection (monitoring, security audits),
  • remediation (data restoration, activation of the business continuity plan).

In the case of cloud services, which consist in providing storage space, computing power or ready-made applications on infrastructure managed by the provider, liability for the loss or corruption of data rests as a rule with the operator that has taken control of the infrastructure. The customer should pay particular attention to data sovereignty clauses: providers subject to US law may be required to disclose data to law enforcement authorities under the CLOUD Act, even if the data is stored outside the territory of the United States.

Contractual Penalties, Limitation of Liability and Force Majeure

A breach of the agreement with the provider gives rise to contractual liability. Where the agreement provides for a contractual penalty, improper performance obliges the provider to pay it. Where the breach has caused damage and no contractual penalty has been stipulated, or the right to claim damages exceeding the penalty has not been excluded, the customer may claim damages under Article 471 of the Civil Code. In the cases described here, improper performance will most often consist in exceeding the RTO or failing to meet other SLA parameters.

The parties may contractually modify the scope of the provider’s liability, in particular by:

  • limiting liability to actual loss, excluding lost profits,
  • introducing a monetary cap on damages,
  • excluding the statutory warranty for defects.

In practice, customers often stipulate that the contractor is liable without limit for the most serious breaches of the agreement, which include precisely the loss of data, breach of confidentiality obligations and infringement of intellectual property rights. Force majeure may relieve the provider of liability, but this requires proof that the event was external, unforeseeable and unavoidable even with the use of all available means. In the case of known methods of cyberattack or foreseeable infrastructure failures, such a defence may be difficult to sustain, which is why the parties very often define in their agreements the catalogue of circumstances treated as force majeure.

The contractual liability regime described above applies to both personal and non-personal data, but its role differs fundamentally depending on the type of data. For personal data, liability under Article 471 of the Civil Code supplements the GDPR regime: the controller may bring recourse claims against a provider whose negligence contributed to a breach for which the controller has been held liable towards data subjects or the supervisory authority. For non-personal data, the agreement and the contractual liability arising from it are often the only available source of legal protection, given the absence of specific statutory rules dedicated to this type of data. This means that the SLA provisions, the precision of the RPO and RTO parameters, the scope of the liability clauses and the contractual penalties determine whether the provider will be held liable towards the customer.

Other Bases of Liability

Criminal Liability

Under Article 268a of the Polish Criminal Code, criminal liability is incurred by anyone who destroys, damages, deletes, alters or hinders access to computer data, or significantly disrupts or prevents the automatic processing, collection or transmission of such data. The offence is prosecuted on the motion of the injured party, meaning that the injured entity must file a request for prosecution. Criminal liability therefore extends, for example, to a person who deletes or corrupts data in a company’s computer system. The type of data (personal or non-personal) is irrelevant to the existence of the offence. Under Article 269 of the Criminal Code, where the data is of particular importance for national defence, transport safety, the functioning of government administration, another state authority or state institution, or local government, the offence carries a heavier penalty.

Liability of Members of Company Bodies

Liability of management board members may also arise under Article 293 of the Polish Commercial Companies Code (limited liability company) and Article 483 of that Code (joint-stock company) for damage caused to the company by an act or omission contrary to the law or the articles of association. Such damage may include an administrative fine imposed on the company as a result of a breach caused, for example, by a failure to implement appropriate safeguards or a data protection policy, or by a failure to carry out a DPIA, as well as the need to pay compensation to data subjects.

Loss or Corruption of Data as a Cybersecurity Incident

The loss or corruption of data in a business is a serious cybersecurity incident. In view of the reliance of the modern economy on data and the growth of digital threats, the EU legislator places great emphasis on protecting the availability and integrity of all of a company’s digital assets, attaching severe public-law liability to their loss. The legal framework is currently set by three key instruments: the DORA Regulation (dedicated to the financial sector), the NIS2 Directive and the Polish Act on the National Cybersecurity System (UKSC) implementing it. These rules impose stringent obligations on organisations in three main areas:

  • ICT risk management – entities covered by the rules are required to implement security management systems, continuously assess risk and monitor their systems for threats. Under Article 18(1)(d) DORA, data loss is one of the direct criteria for classifying an incident as major. Under both DORA and the UKSC, incidents must be reported to the competent authorities and, in the case of more serious incidents, also to clients.
  • Digital resilience and business continuity – organisations must have genuine mechanisms ensuring continuity of operations in a crisis, including backup procedures, emergency data restoration and recovery plans (for both personal and non-personal data) and systematic testing of protective systems.
  • Oversight of third-party providers – the rules (DORA in particular) significantly restrict cooperation with IT service providers that do not meet security standards. Agreements between financial entities and third-party providers must, among other things, guarantee the right to terminate where weaknesses in data protection are identified and must contain provisions on that protection.

Failures in these areas resulting in the loss or corruption of data are no longer merely an operational problem. The amended UKSC provides for severe financial penalties for non-compliance, ranging from PLN 20,000 up to EUR 10,000,000.

Conclusion

The loss or corruption of data is never a legally neutral event. The scope and nature of liability, however, depend above all on the type of data affected by the incident and on whether the entity responsible for the data has complied with its obligations:

  • personal data – administrative liability arises from an infringement of the GDPR, while liability for compensation depends on the existence of damage and a causal link;
  • non-personal data – the burden of protection rests on civil law and on the contract; the precision of the SLA provisions, the RPO and RTO parameters and the liability clauses determines whether the business can successfully pursue its claims, and in the absence of dedicated statutory rules the contract often remains the only instrument of protection;
  • regardless of the type of data – the loss or corruption of data may give rise, in parallel, to the criminal liability of the perpetrator, the liability of management board members towards the company and, for entities subject to sectoral regulation, public-law sanctions under DORA and the UKSC.

An appropriate response to the incident, including timely notification of the breach to the competent authorities, may significantly reduce the scope of that liability.

 

UP