As a rule, a person seeking compensation must prove the harm they have suffered. The Court of Cassation has now confirmed that the same logic governs breaches of the GDPR.
In this case, an employer ran phishing simulation exercises, sending staff harmless fake scam emails to test whether they would spot the threat ; employees had been told about the campaigns. One employee deliberately « failed” the last six tests, clicking the trap links each time and typing insults in place of his login details. To identify the author of the insults, the employer accessed the data he had entered – held by its service provider – without his consent to that processing. Dismissed on disciplinary grounds, he argued that this breach had « necessarily” caused him harm.
The Court of Cassation quashed the ruling in his favour. Under Article 82 of the GDPR, a mere breach does not, in itself, give a right to compensation : it was for the lower court to assess whether the employee had shown that the breach caused him material or moral harm, in line with the case law of the Court of Justice of the European Union, for which the concept of harm is autonomous. The Court sent the case back for that assessment, leaving open a further argument raised by the Advocate General – that where an employee brings about the very interference he complains of, his own conduct may break the causal link and defeat the claim.
The ruling favours employers but should be handled with care. Examined instead through the right to privacy (Article 9 of the Civil Code), the same interference may still give rise to entitlement to compensation on the mere finding of a breach, so the classification chosen can decide the outcome. In addition, the absence of individual harm does not erase the breach : the administrative penalties available to the data protection authority (CNIL), which do not depend on any individual loss, remain in play.
Cass. soc., 24 June 2026, no. 24-22.792