Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 79 Right to an effective judicial remedy against a controller or processor


Summary What does Article 79 of the GDPR regulation say?

This article guarantees data subjects the right to seek an effective judicial remedy against a controller or processor when they believe their rights under the GDPR have been infringed.

It sits alongside, rather than replacing, other remedies available to data subjects — most notably the right to lodge a complaint with a supervisory authority under Article 77.

The article also establishes where such legal proceedings can be brought, giving data subjects a degree of flexibility in choosing their jurisdiction.

Important points:

  • Data subjects have the right to bring court proceedings against a controller or processor for non-compliance with the regulation, regardless of any other remedies available to them.
  • Proceedings can be brought either in the Member State where the controller or processor is established, or where the data subject habitually resides.
  • The option to litigate in the data subject's country of habitual residence does not apply where the controller or processor is a public authority acting in the exercise of its public powers.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.

    1. Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod