Skip to main content
Category: Privacy Governance & Design

Privacy Harm

Simply put

Privacy harm refers to the negative consequences a person can suffer when information about them is misused or exposed. Scholars typically divide it into two kinds: a subjective harm, which is the discomfort or unease of feeling watched or exposed, and an objective harm, which occurs when a person's information is actually used against them, such as through a denial of a job or a malicious attack. Defining privacy harm precisely is one of the most difficult and contested problems in privacy law, particularly because harms may be intangible and hard to measure.

Formal definition

Privacy harm is a contested concept in privacy scholarship and law describing the injuries that flow from the collection, use, or disclosure of personal information. In the influential framework advanced by M. Ryan Calo (2011), it is generally divided into an objective category, defined as the unanticipated or coerced use of information concerning a person against that person, producing negative external consequences, and a subjective category, associated with the perception or apprehension of unwanted observation. Practitioners should note the recognized distinction between tangible and intangible harms, a boundary that remains central to how courts assess standing and injury in privacy litigation; as noted in judicial commentary, alleged harm from access, disclosure, or inaccuracy of personal information is often difficult to establish. This entry describes an academic and litigation concept rather than a defined term within the GDPR text, and its treatment varies across jurisdictions and evolving case law, so readers should verify how any given legal framework or court characterizes actionable harm.

Why it matters

Privacy harm sits at the center of one of the most difficult and contested problems in privacy law: establishing when a person has actually suffered an injury from the collection, use, or disclosure of their personal information. This matters because remedies, standing to sue, and regulatory intervention often depend on whether a recognizable harm can be demonstrated. As judicial commentary has noted, alleged harm arising from the access, disclosure, or inaccuracy of personal information is frequently difficult to establish, which means the way a legal framework or court characterizes harm can be decisive to the outcome of a claim.

The distinction between tangible and intangible harms is generally regarded as central to how courts assess injury in privacy litigation. Objective harms, such as a person's information being used against them through the denial of a job or a malicious attack, tend to be more readily recognized because they produce measurable external consequences. Subjective harms, associated with the perception or apprehension of unwanted observation, are harder to quantify and may not always satisfy the threshold that a given jurisdiction sets for actionable injury. This boundary between the measurable and the intangible is where much of the contest in privacy law plays out.

Because privacy harm is an academic and litigation concept rather than a defined term within the GDPR text, its treatment varies across jurisdictions and continues to evolve through case law. Practitioners should be cautious about assuming that a harm recognized in one forum will be treated the same way in another, and should verify how the relevant legal framework or court characterizes actionable harm in the specific context at hand.

Who it's relevant to

Privacy litigators and litigation counsel
Because standing and injury often turn on whether a recognizable harm can be shown, litigators need to understand the tangible/intangible distinction and the difficulty, noted in judicial commentary, of establishing harm arising from access, disclosure, or inaccuracy of personal information. How a court characterizes actionable harm varies across jurisdictions and evolving case law, so counsel should verify the applicable standard in the relevant forum.
Data protection officers and compliance leads
DPOs and compliance leads benefit from understanding privacy harm as a way to reason about the negative consequences of data misuse or exposure, distinguishing objective harms (information used against a person) from subjective ones (the apprehension of unwanted observation). It should be noted, however, that privacy harm is an academic and litigation concept rather than a defined term within the GDPR text, so it informs risk analysis rather than supplying a compliance definition.
Privacy scholars and policy researchers
The concept remains contested in privacy scholarship, with Calo's 2011 objective/subjective framework serving as an influential reference point. Researchers examining how harm is defined and measured, particularly where harms are intangible and difficult to quantify, engage directly with one of the most important unresolved problems in the field.
Engineers and product teams handling personal data
Teams designing systems that collect, use, or disclose personal information can use the objective/subjective distinction to anticipate how their processing might produce negative consequences for individuals, from external harms such as adverse decisions to the subjective unease of feeling watched. This supports harm-aware design, though it does not substitute for a formal legal assessment under the applicable framework.

Inside Privacy Harm

Material harm
Tangible, often quantifiable adverse effects on an individual, such as financial loss, identity theft, or fraud resulting from the processing or exposure of personal data. This category is generally the most readily evidenced in enforcement or litigation contexts.
Non-material harm
Intangible adverse effects, which may include distress, anxiety, reputational damage, loss of control over personal data, or discrimination. The GDPR recital framing recognises non-material damage as compensable, though the threshold and assessment of such harm has been the subject of case law and continues to develop.
Risk to rights and freedoms
A forward-looking concept used across the GDPR (for example in the context of impact assessments and breach notification) that focuses on the likelihood and severity of adverse effects on individuals, rather than only harm that has already materialised. Assessment is context and risk dependent.
Affected data subjects
Privacy harm concerns identified or identifiable natural persons whose personal data is processed. It generally does not extend to anonymous data, and the position on data of deceased persons or legal entities depends on national implementing law and can vary between member states.
Causal link to processing
For harm to be legally relevant, there typically needs to be a connection between a processing activity or infringement and the adverse effect experienced or risked by the individual. The strength of causation required can differ across regulators and courts.
Severity and likelihood dimensions
Privacy harm is commonly assessed along two axes: how serious the potential impact is and how probable it is to occur. These dimensions inform risk-based obligations such as impact assessments and decisions on breach notification.

Common questions

Answers to the questions practitioners most commonly ask about Privacy Harm.

Does privacy harm always require a demonstrable financial loss?
No. Privacy harm is not limited to material or financial loss. Non-material harm, such as distress, loss of control over personal data, reputational damage, or discrimination, is generally recognised under the GDPR framework, including in the context of Article 82 compensation. The precise threshold for compensable non-material harm has been the subject of judicial interpretation and continues to develop, so readers should verify the current position against case law and applicable national implementations.
Is a data breach the same thing as a privacy harm?
Not necessarily. A personal data breach is a security event involving accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Privacy harm refers to the adverse consequences that may result for individuals. A breach can occur without producing tangible harm to individuals, and conversely, harm can arise from lawful-seeming processing that does not involve any breach. The two concepts are related but distinct, and each should be assessed on its own terms.
How should we account for privacy harm when conducting a Data Protection Impact Assessment?
A DProtection Impact Assessment under Article 35 typically involves assessing risks to the rights and freedoms of natural persons, which includes potential privacy harms. In practice, this generally means identifying the range of possible harms (material and non-material), estimating their likelihood and severity, and considering measures to mitigate them. The characterisation of harm should be documented so that the risk analysis is traceable. The specific methodology can vary, and organisations should align their approach with current regulatory guidance.
How can privacy harm inform whether a personal data breach must be notified?
Breach notification obligations generally turn on the risk, or high risk, to the rights and freedoms of individuals, which involves assessing the potential harm that could result. In most cases, evaluating the type of data affected, the number of individuals, the ease of identification, and the potential consequences helps determine whether notification to a supervisory authority or communication to affected individuals is required. This is a context-dependent assessment, and organisations should document their reasoning and consult current guidance and applicable timelines rather than relying on fixed rules.
How does consideration of privacy harm feature in a legitimate interests assessment?
Where legitimate interests is relied on as an Article 6 basis, the balancing exercise typically weighs the interests pursued against the interests, rights, and freedoms of the data subject. Anticipating potential privacy harms is generally part of assessing the impact on individuals within that balance. The severity and likelihood of harm, together with the individuals' reasonable expectations and any safeguards, are usually relevant factors. This assessment is context-specific and should be recorded to support accountability.
How can an organisation document and evidence its assessment of privacy harm?
In practice, organisations typically record the categories of potential harm considered, the reasoning behind likelihood and severity estimates, and the mitigating measures adopted, often within records tied to the accountability principle, such as DPIA documentation or risk registers. Clear, dated records that show how harm was assessed and addressed generally support demonstrating compliance. The appropriate level of detail depends on the risk profile of the processing, and approaches may need to be revisited as guidance evolves.

Common misconceptions

Only financial loss counts as privacy harm.
Non-material harm such as distress, loss of control over personal data, or reputational damage can also be relevant. The recognition and threshold for such harm has been shaped by case law and continues to evolve, so practitioners should verify the current position against authoritative sources.
Harm must have already occurred before it is relevant.
Several GDPR obligations are risk-based and forward-looking, addressing the likelihood and severity of potential adverse effects on individuals' rights and freedoms rather than requiring harm to have already materialised.
If there is no demonstrable harm, there is no infringement.
An infringement of data protection obligations can exist independently of whether an individual suffers demonstrable harm. Harm is typically more relevant to compensation claims and risk assessment than to whether a rule was breached, though the interaction between infringement and harm is subject to ongoing legal interpretation.

Best practices

Assess potential harm along both severity and likelihood dimensions when carrying out risk-based obligations, and document the reasoning so it can be revisited as circumstances change.
Consider material and non-material harm together, avoiding an exclusive focus on quantifiable financial loss.
Identify the categories of affected data subjects and confirm that the data in scope relates to identifiable individuals, noting that anonymous data and, depending on national law, data of deceased persons or legal entities may fall outside GDPR protection.
Use qualified, context-specific language in harm assessments rather than treating any outcome as certain, since the evaluation is risk and fact dependent.
Monitor evolving case law and regulator guidance on non-material harm and causation, as thresholds can diverge between courts and member states.
Verify any specific legal thresholds, article references, or compensation standards against the current official text before relying on them in a compliance program.