Privacy Harm
Privacy harm refers to the negative consequences a person can suffer when information about them is misused or exposed. Scholars typically divide it into two kinds: a subjective harm, which is the discomfort or unease of feeling watched or exposed, and an objective harm, which occurs when a person's information is actually used against them, such as through a denial of a job or a malicious attack. Defining privacy harm precisely is one of the most difficult and contested problems in privacy law, particularly because harms may be intangible and hard to measure.
Privacy harm is a contested concept in privacy scholarship and law describing the injuries that flow from the collection, use, or disclosure of personal information. In the influential framework advanced by M. Ryan Calo (2011), it is generally divided into an objective category, defined as the unanticipated or coerced use of information concerning a person against that person, producing negative external consequences, and a subjective category, associated with the perception or apprehension of unwanted observation. Practitioners should note the recognized distinction between tangible and intangible harms, a boundary that remains central to how courts assess standing and injury in privacy litigation; as noted in judicial commentary, alleged harm from access, disclosure, or inaccuracy of personal information is often difficult to establish. This entry describes an academic and litigation concept rather than a defined term within the GDPR text, and its treatment varies across jurisdictions and evolving case law, so readers should verify how any given legal framework or court characterizes actionable harm.
Why it matters
Privacy harm sits at the center of one of the most difficult and contested problems in privacy law: establishing when a person has actually suffered an injury from the collection, use, or disclosure of their personal information. This matters because remedies, standing to sue, and regulatory intervention often depend on whether a recognizable harm can be demonstrated. As judicial commentary has noted, alleged harm arising from the access, disclosure, or inaccuracy of personal information is frequently difficult to establish, which means the way a legal framework or court characterizes harm can be decisive to the outcome of a claim.
The distinction between tangible and intangible harms is generally regarded as central to how courts assess injury in privacy litigation. Objective harms, such as a person's information being used against them through the denial of a job or a malicious attack, tend to be more readily recognized because they produce measurable external consequences. Subjective harms, associated with the perception or apprehension of unwanted observation, are harder to quantify and may not always satisfy the threshold that a given jurisdiction sets for actionable injury. This boundary between the measurable and the intangible is where much of the contest in privacy law plays out.
Because privacy harm is an academic and litigation concept rather than a defined term within the GDPR text, its treatment varies across jurisdictions and continues to evolve through case law. Practitioners should be cautious about assuming that a harm recognized in one forum will be treated the same way in another, and should verify how the relevant legal framework or court characterizes actionable harm in the specific context at hand.
Who it's relevant to
Inside Privacy Harm
Common questions
Answers to the questions practitioners most commonly ask about Privacy Harm.