Publication date: October 05, 2026
The loss or corruption of data in a business is rarely “just” a technical problem. In practice it is a serious legal and financial crisis: production downtime, loss of trust among business partners and, in extreme cases, administrative fines running into millions. The scope of liability, however, depends above all on what kind of data has been lost or corrupted. The law treats the loss of source code or technical documentation quite differently from a leak of employee records or a customer database. The first step in assessing liability for a breach of the integrity or availability of data is therefore its unambiguous legal classification.
It is worth starting with the category that, in recent years, has come under particular legal protection as a result of stringent EU rules: personal data, the protection of which directly concerns the privacy and rights of natural persons. Personal data protection is governed by Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR). Under Article 4(1) GDPR, personal data means any information relating to an identified or identifiable natural person, i.e. a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name or a national identification number (in Poland, the PESEL number).
The rapid growth of the data-driven economy means that non-personal data is gaining ever greater economic and legal significance. Non-personal data is data that does not relate to an identified or identifiable natural person and therefore falls outside the scope of the GDPR. As the recitals of Regulation (EU) 2018/1807 of the European Parliament and of the Council on a framework for the free flow of non-personal data point out, information and communication technologies are no longer a separate sector but the foundation of all modern economic systems, with electronic data at their core. The statutory definition of non-personal data is contained in Article 3(1) of Regulation 2018/1807 and Article 2(4) of Regulation 2022/868 (the Data Governance Act): it is data other than personal data within the meaning of the GDPR. This category includes in particular:
Non-personal data includes both data that has never contained any information about natural persons (e.g. weather data or share prices) and data that was originally personal but has subsequently been effectively anonymised, i.e. to a degree that permanently prevents the identification of a natural person. It should be borne in mind that data which has merely been pseudonymised remains personal data (recital 26 GDPR). Non-personal data may be a key asset of a business, often worth more than its traditional tangible assets; in the case of artificial intelligence models, the quality, volume and diversity of the data directly determine the value and effectiveness of the model itself.
The fundamental distinction between personal and non-personal data is not merely a technical or definitional matter. It determines where the centre of gravity of legal protection lies:
The loss or corruption of non-personal data does not infringe the rights of any natural person within the meaning of the GDPR, but it may lead to serious financial losses, loss of competitive advantage, disruption of production processes or the permanent destruction of a resource that cannot be recreated at all, or only at disproportionate cost. This distinction translates into different bases of liability, because non-personal data is not subject to the sanctions provided for in the GDPR.
A separate issue is that of mixed data sets, i.e. data sets composed of both personal and non-personal data (e.g. the ERP and CRM systems of online shops). Under Article 2(2) of Regulation 2018/1807, where personal and non-personal data are inextricably linked, the GDPR applies to the whole data set. In other cases the GDPR applies only to the personal data part of the set, while non-personal data is governed primarily by the rules of contractual liability arising from the agreement and by the provisions of civil law.
| Criterion | Personal data | Non-personal data |
| Object of protection | Rights and freedoms of the natural person | Economic, organisational and technological interest |
| Main legal regime | GDPR | Civil law, contracts, sectoral regulation, cybersecurity law |
| Typical harm | Identity theft, distress, material or non-material damage | Downtime, loss of data value, wrong business decisions, contractual loss |
| Liable party | Controller, processor | IT provider, counterparty, management board, cloud service provider |
| Typical instruments | DPIA, breach notification, communication to the data subject | SLA, backup, RPO/RTO, disaster recovery, security audit, notification of the authority |
| Main practical problem | Exercise of the data subject’s rights | Recovery of the data and proof of economic loss |
To assess the consequences of the loss or corruption of personal data properly, three distinct concepts must be kept apart:
The occurrence of an incident does not automatically mean that the law has been infringed, and an infringement of the law does not in itself give rise to a right to compensation.
Under Article 4(12) GDPR, a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. Both the loss and the corruption of data therefore fall within the broad scope of this concept and may give rise to legal liability. A personal data breach may concern:
A breach may occur by accident or as a result of deliberate and unlawful action. The most common causes include:
A personal data breach occurs regardless of whether any adverse consequences actually materialise. A failure to respond appropriately and promptly, however, may result in adverse consequences for the data subject, such as physical harm, material or non-material damage, or identity theft or fraud (recital 85 GDPR).
Article 5(1)(f) GDPR sets out the principle of integrity and confidentiality: personal data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures. Article 5(2) GDPR introduces the principle of accountability, under which the controller must be able to demonstrate compliance with these principles.
The GDPR imposes on controllers a range of obligations relating to secure processing and to responding to breaches. These obligations are built on a risk-based approach: protective measures must be tailored to the risk that the processing poses to the rights and freedoms of natural persons. The requirements therefore differ from controller to controller depending on the specifics of the processing, and controllers must assess the associated risk themselves. The key obligations are:
Risk assessment consists in estimating the severity of the potential consequences of a breach and the likelihood of their occurrence, taking into account, among other things, the type of breach, the sensitivity of the data and the seriousness of the consequences for the data subjects.
An infringement of the GDPR is therefore conduct that fails to meet the above requirements. It is legal in nature, as opposed to the incident itself, which is a matter of fact. Failure to comply with the obligations listed in Articles 8, 11, 25 to 39, 42 and 43 GDPR is punishable under Article 83(4) GDPR by an administrative fine of up to EUR 10,000,000 or, in the case of an undertaking, up to 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher.
The Regulation also grants the data subject a number of rights, the exercise of which may become difficult or impossible once data has been lost or corrupted:
Infringement of the provisions governing data subjects’ rights (Articles 12 to 22 GDPR) and of the basic principles of processing (Articles 5 to 7 and 9 GDPR) is punishable under Article 83(5) GDPR by an administrative fine of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total worldwide annual turnover of the preceding financial year, whichever is higher.
Even where the GDPR has been infringed, the injured party does not automatically acquire a right to compensation. Under Article 82 GDPR, three conditions must be met cumulatively: an infringement of the Regulation, material or non-material damage, and a causal link between the two. The controller is liable; the processor is liable only where it has failed to comply with obligations specifically directed to processors or has acted outside or contrary to the lawful instructions of the controller (Article 82(2)). Exemption from liability is possible only on proof that the entity concerned is not in any way responsible for the event giving rise to the damage (Article 82(3)). Where more than one controller or processor is responsible for the damage, they are jointly and severally liable (Article 82(4)).
The case law of the CJEU and of the Polish courts on Article 82 GDPR has so far developed mainly in cases concerning the unauthorised disclosure of data to third parties; there are no decisions dealing directly with the loss or corruption of data. The principles developed by the Court are, however, general in nature and apply to all types of breach listed in Article 4(12) GDPR, and thus also to breaches of the integrity and availability of data. The most important of them are:
The CJEU has also pointed out that Article 82 GDPR covers only infringements of the Regulation itself. If the loss or corruption of data additionally involves an infringement of national law, including of personality rights, any extension of liability can be considered only on the basis of national provisions; in Poland, the injured party may then claim separate compensation for non-material harm under Articles 23 and 24 in conjunction with Article 448 of the Civil Code.
The basis for claims against external providers whose improper performance has contributed to the loss or corruption of data is Article 471 of the Polish Civil Code. This applies in particular to software vendors, cloud service operators, IT outsourcing companies and entities responsible for backup and disaster recovery. Under that provision, the debtor is obliged to remedy the damage resulting from non-performance or improper performance of an obligation, unless it proves that this is the consequence of circumstances for which it is not responsible.
In commercial practice the key instrument governing the scope of that liability is the agreement concluded with the IT service provider (e.g. a maintenance or implementation agreement) and, within it, the Service Level Agreement (SLA). It is in the SLA that the parties define the scope of the service, the required availability of systems, the permitted response time in the event of a failure and the consequences of non-compliance, including contractual penalties and grounds for termination. From the perspective of liability for data loss, two SLA parameters are of particular importance:
Both parameters form part of disaster recovery, i.e. the set of policies, procedures and tools designed to minimise the effects of unforeseen events such as cyberattacks, infrastructure failures or natural disasters. Disaster recovery comprises three layers:
In the case of cloud services, which consist in providing storage space, computing power or ready-made applications on infrastructure managed by the provider, liability for the loss or corruption of data rests as a rule with the operator that has taken control of the infrastructure. The customer should pay particular attention to data sovereignty clauses: providers subject to US law may be required to disclose data to law enforcement authorities under the CLOUD Act, even if the data is stored outside the territory of the United States.
A breach of the agreement with the provider gives rise to contractual liability. Where the agreement provides for a contractual penalty, improper performance obliges the provider to pay it. Where the breach has caused damage and no contractual penalty has been stipulated, or the right to claim damages exceeding the penalty has not been excluded, the customer may claim damages under Article 471 of the Civil Code. In the cases described here, improper performance will most often consist in exceeding the RTO or failing to meet other SLA parameters.
The parties may contractually modify the scope of the provider’s liability, in particular by:
In practice, customers often stipulate that the contractor is liable without limit for the most serious breaches of the agreement, which include precisely the loss of data, breach of confidentiality obligations and infringement of intellectual property rights. Force majeure may relieve the provider of liability, but this requires proof that the event was external, unforeseeable and unavoidable even with the use of all available means. In the case of known methods of cyberattack or foreseeable infrastructure failures, such a defence may be difficult to sustain, which is why the parties very often define in their agreements the catalogue of circumstances treated as force majeure.
The contractual liability regime described above applies to both personal and non-personal data, but its role differs fundamentally depending on the type of data. For personal data, liability under Article 471 of the Civil Code supplements the GDPR regime: the controller may bring recourse claims against a provider whose negligence contributed to a breach for which the controller has been held liable towards data subjects or the supervisory authority. For non-personal data, the agreement and the contractual liability arising from it are often the only available source of legal protection, given the absence of specific statutory rules dedicated to this type of data. This means that the SLA provisions, the precision of the RPO and RTO parameters, the scope of the liability clauses and the contractual penalties determine whether the provider will be held liable towards the customer.
Under Article 268a of the Polish Criminal Code, criminal liability is incurred by anyone who destroys, damages, deletes, alters or hinders access to computer data, or significantly disrupts or prevents the automatic processing, collection or transmission of such data. The offence is prosecuted on the motion of the injured party, meaning that the injured entity must file a request for prosecution. Criminal liability therefore extends, for example, to a person who deletes or corrupts data in a company’s computer system. The type of data (personal or non-personal) is irrelevant to the existence of the offence. Under Article 269 of the Criminal Code, where the data is of particular importance for national defence, transport safety, the functioning of government administration, another state authority or state institution, or local government, the offence carries a heavier penalty.
Liability of management board members may also arise under Article 293 of the Polish Commercial Companies Code (limited liability company) and Article 483 of that Code (joint-stock company) for damage caused to the company by an act or omission contrary to the law or the articles of association. Such damage may include an administrative fine imposed on the company as a result of a breach caused, for example, by a failure to implement appropriate safeguards or a data protection policy, or by a failure to carry out a DPIA, as well as the need to pay compensation to data subjects.
The loss or corruption of data in a business is a serious cybersecurity incident. In view of the reliance of the modern economy on data and the growth of digital threats, the EU legislator places great emphasis on protecting the availability and integrity of all of a company’s digital assets, attaching severe public-law liability to their loss. The legal framework is currently set by three key instruments: the DORA Regulation (dedicated to the financial sector), the NIS2 Directive and the Polish Act on the National Cybersecurity System (UKSC) implementing it. These rules impose stringent obligations on organisations in three main areas:
Failures in these areas resulting in the loss or corruption of data are no longer merely an operational problem. The amended UKSC provides for severe financial penalties for non-compliance, ranging from PLN 20,000 up to EUR 10,000,000.
The loss or corruption of data is never a legally neutral event. The scope and nature of liability, however, depend above all on the type of data affected by the incident and on whether the entity responsible for the data has complied with its obligations:
An appropriate response to the incident, including timely notification of the breach to the competent authorities, may significantly reduce the scope of that liability.