When people think about a privacy disaster, they usually picture hackers. A recent Danish Supreme Court judgment points somewhere less dramatic: a routine administrative request handled wrongly. The case raises a practical question about GDPR compensation for unauthorised data disclosure, and it shows how much damage a single clerical mistake can do.

What happened in the Danish municipality case

According to the report, a Danish municipality mistakenly disclosed sensitive health information and financial data about a resident to that resident's former spouse. The disclosure happened while the municipality was handling a routine file access request. No attacker, malware or stolen credentials were involved. A public body simply released information to someone who should not have received it.

The case went to Denmark's highest court. It examined whether the unauthorised disclosure of highly sensitive personal data should lead to compensation under the GDPR. The summary available to us does not set out the full reasoning, the final outcome or any amount awarded, so we will not speculate on those details. Readers who want the specifics should consult the full judgment or a legal analysis of it.

How the Supreme Court approached GDPR compensation

The legal backdrop is Article 82 of the GDPR. It states that any person who has suffered material or non-material damage as a result of an infringement of the regulation has the right to receive compensation from the controller or processor responsible. "Non-material" damage matters here. It covers harms such as distress or loss of control over personal information, not only measurable financial loss.

That is why cases like this one are closely watched. When data goes to the wrong person, there may be no stolen money or identity fraud to point to. The question for a court is how to treat the harm that follows from exposure itself, particularly when the recipient is someone with a personal history with the affected person. Courts across Europe have been working through where the line sits, and a ruling from a national supreme court adds a useful data point for how these claims are assessed.

Another point worth noting is that the controller in this case was a public authority. Public bodies hold large amounts of data about residents, often because residents have no real choice about sharing it. That makes careful handling a legal obligation rather than a courtesy.

Why sensitive health and financial data raises the stakes

The GDPR treats health data as a special category that gets stronger protection. Financial information is not formally in the same category, but it can be just as revealing. Together they can expose a person's medical conditions, income, debts and living circumstances.

In the context of a former spouse, the risk is easy to understand. Information about someone's health or finances can be used in disputes, or simply cause distress, once it lands in the hands of a person with whom the relationship has ended. A disclosure like this cannot be undone. Once the information has been seen, there is no way to retrieve it.

This is also why the incident differs from the breaches that usually dominate headlines. A hacker typically wants data in bulk. A misdirected disclosure involves one person's most personal details, delivered to exactly the wrong reader.

What individuals can and can't control about their data

It is worth being direct about the limits of personal security tools. A VPN encrypts your connection and hides your IP address from sites you visit. It does nothing to stop a municipality, hospital or court from sending your records to the wrong person. Once an institution holds your data, how it is handled depends on that institution's processes, training and checks.

The same applies to larger incidents. The Thomson Reuters C-Track breach affecting courts in 11 states is another example of data held by institutions ending up outside the control of the people it describes. Likewise, government data collection schemes such as Karnataka's proposed Aadhaar requirement for social media show how much personal information flows into official systems that individuals cannot audit.

What This Means For You

You cannot prevent every institutional mistake, but you do have rights that apply when one happens:

  • Right of access: You can ask an organisation what data it holds about you and how it is used.
  • Right to complain: If you believe your data was mishandled, you can lodge a complaint with your national data protection authority.
  • Right to compensation: Under Article 82, you can seek compensation for material or non-material damage caused by a GDPR infringement.

If you are in a dispute with a former partner, consider telling any authority you deal with, in writing, that your records should not be released to third parties without verification. That will not guarantee against error, but it creates a record and may prompt extra checks.

Key takeaways

  • Many of the most harmful privacy failures come from institutional error, not hacking.
  • A VPN cannot protect data that an organisation holds and mishandles.
  • GDPR compensation for unauthorised data disclosure can cover non-material harm, not only financial loss.
  • Know how to exercise your rights to access, complain and claim.

The Danish ruling is a reminder that data protection law exists for exactly these moments. Learn what the GDPR entitles you to, keep records if something goes wrong, and read about other cases of institutional data failures, such as the Thomson Reuters C-Track breach, to see how often the weak point is outside your control.