What Changed
Over the past year, case law has provided compliance teams with much-needed clarity on privacy expectations. Courts in the UK and EU have ruled on what constitutes a reasonable expectation of privacy, how to prove non-material damage under Article 82 GDPR, and when a controller's security measures satisfy Articles 24 and 32. If you've been operating in the ambiguous space of "it depends," these decisions offer clearer guidelines.
The trend is clear: judges are protecting privacy in arrests and investigations but not in public, performative settings. They will award damages for fear of data misuse if that fear is justified. The burden of proof is on controllers to show their security measures were appropriate for the risk.
Key Findings
Privacy expectations now cover arrests, not just charges. In WFZ v BBC, the High Court ruled that a high-profile individual arrested but not charged had a reasonable expectation of privacy in the arrest. This builds on the Supreme Court's ZXC precedent, indicating courts may limit the publication of arrest information until charges are filed. Your incident response protocols should reflect this broader scope of protected information.
Fear of data misuse can be non-material damage if justified. The CJEU's ruling in VB v. Natsionalna agentsia za prihodite clarified that individuals affected by a data breach don't need to show actual harm. The fear of potential misuse, like blackmail or assault, can qualify as compensable non-material damage under Article 82 if the fear is reasonable. This impacts how you assess exposure after a breach: the potential severity of misuse is as important as whether it occurred.
A data breach doesn't automatically mean security measures failed. The same Bulgarian Revenue Agency case established that cyber attacks don't automatically indicate a breach of Articles 24 or 32. The CJEU noted that GDPR aims to "mitigate" risks, not eliminate them. National courts must assess your measures against the risks you faced. However, you must prove your measures were appropriate.
Context, not just location, determines privacy expectations. In Stoute v News Group Newspapers, a couple arriving at a celebrity-frequented beach restaurant by jet ski had no reasonable expectation of privacy in photographs taken there. The Court of Appeal focused on the "performative" nature of their arrival. If your legitimate interests assessments rely on "public place" as a bright line, this case shows courts will consider behavior and context, not just geography.
Historic privacy claims may not be barred by limitation periods. In Baroness Lawrence v Associated Newspapers, the High Court found claimants alleging unlawful information gathering had a real prospect of defeating limitation defenses. This matters if you're assessing legacy risk from past processing activities: the six-year clock may not have started when you think it did.
What This Means for Your Team
Your data protection impact assessments should include well-founded fear as a damage category. When evaluating risks under Article 35, consider not just the likelihood of misuse but the reasonableness of data subjects fearing misuse based on the data types involved. Medical records, financial data, and information that could enable blackmail or identity theft carry higher exposure.
Your breach notification templates should address this explicitly. When drafting the Article 34 communication to affected individuals, explain why their fear would not be well-founded or acknowledge the risk and describe your mitigation steps. Vague reassurances won't hold up if a supervisory authority reviews your response.
Your security documentation must be specific to the processing activity. Generic statements that you "implement appropriate measures" won't satisfy the burden of proof the CJEU placed on controllers. For each high-risk processing activity, document the specific threats you identified, the measures you chose, and why those measures are appropriate. If you suffer a breach, you'll need to show this analysis to demonstrate compliance with Articles 24 and 32.
Action Items by Priority
Immediate: Update your incident response playbook. Add a step to evaluate whether affected individuals could reasonably fear misuse of the exposed data. If yes, your Article 34 communication must address that fear with specific information about what you're doing to reduce the risk. This is about demonstrating you've assessed the actual impact.
This quarter: Document your security measures by processing activity. For any processing that requires a data protection impact assessment, create a record showing the risks you identified and why your chosen measures are appropriate. Don't wait until after a breach to build this justification. The CJEU made clear you bear the burden of proof.
This quarter: Review your legitimate interests assessments for any processing that relies on "public information" or "public places." If your legitimate interests assessment assumes information is fair game because it's observable in public, the Stoute case shows that's not enough. Courts will look at whether the individual's behavior was performative or whether they had a reasonable expectation of privacy despite the location.
Next review cycle: Audit your legacy processing activities for limitation risk. If you're relying on the six-year limitation period to dismiss potential claims from historic processing, the Baroness Lawrence case suggests that defense may not be as solid as you thought. Identify your highest-risk legacy activities and evaluate whether section 32 could extend the limitation period.
Ongoing: Train your data protection officer and legal team on the WFZ arrest-privacy precedent. If you process information about investigations, arrests, or allegations, your transparency obligations and disclosure decisions need to account for this expanded protection. The line isn't at charges anymore; it's at arrest.



