Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Unlawful processing can lead to a privacy regulator’s investigation, an order to stop or change how information is used, deletion or restriction of data, fines, compensation claims, and business or reputational harm. In some circumstances, a specific offence may also lead to criminal prosecution. None of these outcomes is automatic: the law that applies, the conduct, the data involved, the harm and the organization’s response all matter.

“Unlawful processing” is broader than hacking or a data breach. It can include collecting, using, sharing, retaining or profiling personal information without the required legal basis or safeguards. The consequences vary by jurisdiction; this guide focuses on the EU GDPR, UK GDPR and California’s CCPA/CPRA.

What counts as unlawful processing?

Processing means handling personal information, including collecting it, storing it, analyzing it, disclosing it or deleting it. Under the GDPR, an organization needs an applicable lawful basis for processing ordinary personal data. Consent is one option, but not the only one: depending on the circumstances, processing may instead be necessary for a contract, a legal obligation, vital interests, a public task or legitimate interests. The GDPR’s full text sets out those bases and other obligations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Having a lawful basis does not excuse other failures. Processing may still be unlawful or non-compliant if an organization:

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • uses information for a purpose incompatible with the one it explained when collecting it;
  • fails to give required information about what it collects, why, who receives it or how long it is kept;
  • collects more information than it needs or retains it longer than justified;
  • uses inaccurate information without correcting it where required;
  • discloses, sells or transfers information without the necessary legal basis, safeguards or consumer choice;
  • ignores a valid access, correction, deletion, objection, restriction, portability or opt-out request; or
  • fails to protect the information adequately.

Sensitive information—such as health, biometric, genetic, racial or ethnic, religious, political, trade-union or sexuality-related data—has additional protections under the GDPR. Criminal-offence data is also subject to special rules in the UK framework. A person’s information being publicly available does not automatically make it unrestricted for collection, profiling or resale. Nor does removing names necessarily make data anonymous if people can still be identified or singled out.

Consent is not a universal requirement, and it is not a universal cure. Consent may be invalid if it was not informed, freely given and easy to withdraw, or if the organization continues after withdrawal. Conversely, processing may be lawful on another basis even when the person did not consent.

Possible consequences

A regulator or court can respond in different ways, depending on its powers and the circumstances. Outcomes may include advice or no formal action, a warning or reprimand, an investigation or audit, an order to change practices, a restriction or ban on processing, a fine, or a claim for compensation. Organizations may also face contract disputes, customer losses, remediation costs and reputational damage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Outcome Who may impose or seek it? What it can mean
Warning or reprimand Privacy regulator Formal notice of a compliance failure and a requirement to address it.
Corrective order Regulator or court, depending on the law Correction, restriction, deletion or cessation of a particular use of data.
Fine Regulator A financial penalty set under the relevant law, based on the case.
Compensation Court or settlement Payment for qualifying damage caused by the infringement.
Criminal penalty Prosecutor and criminal court Possible only where a specific offence applies and its elements are met.
Contractual or business consequences Customers, partners or affected individuals Contract termination, indemnity claims, lost business or remediation obligations.

A fine is not automatic, and a breach does not automatically entitle every affected person to damages. Regulators commonly consider how serious and long-lasting the conduct was, whether it was intentional or negligent, how many people were affected, the sensitivity of the data, any benefit gained, past conduct, cooperation and steps taken to limit harm. Concealment, repeated conduct, ignoring complaints, or processing children’s or other sensitive information may make a case more serious. Cooperation and prompt remediation may matter, but do not erase an infringement.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Can a company be ordered to stop or delete the data?

Yes. A regulator can require an organization to correct its practices, restrict processing or, in some cases, stop processing altogether. Under the EU GDPR, corrective powers include temporary or definitive limitations, including a ban. Such an order can disrupt a marketing campaign, profiling activity, data transfer or product feature until the organization can lawfully operate it.

Deletion may be required when information is unlawfully processed, no longer needed or covered by an applicable erasure right. But deletion is not automatic in every case. Legal retention duties, legal claims, public-interest functions and other exceptions may justify keeping some information; restriction or correction may be more appropriate. Deleting data also does not necessarily undo earlier misuse, remove copies held by recipients, resolve harm already caused or eliminate the need to preserve evidence.

How the law differs by jurisdiction

European Union and EEA: GDPR

EU GDPR regulators can issue warnings, reprimands, corrective orders, restrictions and fines. For the relevant higher-tier infringements, the maximum administrative fine is €20 million or 4% of the organization’s total worldwide annual turnover for the preceding financial year, whichever is higher. That is a legal ceiling, not a standard or automatic penalty; the applicable tier and the facts determine the outcome. The European Commission’s enforcement overview and the European Data Protection Board’s fines page explain the available sanctions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An individual may seek compensation under the GDPR for material or non-material damage caused by an infringement. The infringement alone does not guarantee an award: the person generally needs to establish damage and a causal link, with the claim decided under applicable court procedures and law. Member States may also provide for criminal penalties in certain cases.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

United Kingdom: UK GDPR and Data Protection Act 2018

The Information Commissioner’s Office (ICO) can use tools including warnings, reprimands, information or assessment notices, enforcement notices and monetary penalty notices. Its guidance explains that compensation claims are pursued through the courts, not awarded by the ICO; a person who suffers damage or distress because of a relevant breach may be able to claim.

The Data Protection Act 2018 also contains criminal offences, including offences involving unlawfully obtaining or disclosing personal information in qualifying circumstances. A routine compliance mistake does not by itself mean someone will be prosecuted or imprisoned. Criminal liability depends on the specific offence and evidence. See the Data Protection Act 2018 and ICO guidance on enforcing data-protection rights.

UK data-protection rules have been affected by the Data (Use and Access) Act 2025, which received Royal Assent on June 19, 2025. The detail and commencement of relevant provisions can matter, so check current legislation and ICO guidance for a live dispute or compliance decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

United States: California and other state laws

The United States does not have one general privacy law that supplies the same remedies nationwide. Rights and enforcement can depend on state law, the kind of information and sector-specific rules covering, for example, health, finance, children, communications or employment.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

California’s CCPA/CPRA is a useful example of why “you can sue” needs qualification. Consumers generally do not have a private lawsuit for every CCPA violation. The private right of action is principally limited to specified data breaches involving certain nonencrypted and nonredacted personal information and statutory conditions. In qualifying cases, the California Attorney General says statutory damages may be up to $750 per incident, subject to the law’s limits and requirements. The California Attorney General and California Privacy Protection Agency enforce other CCPA violations. See the California Attorney General’s CCPA page.

Unlawful processing is not the same as a data breach

A data breach is a security incident involving personal information; unlawful processing is a broader question about whether handling that information complies with privacy law. The concepts can overlap, but neither automatically proves the other.

  • A breach without unlawful collection: An organization may have collected and used data lawfully but suffer an unauthorized access incident because its security was inadequate. Breach-notification duties may apply.
  • Unlawful use without a breach: A company may track people without proper notice, retain data too long or use information for an incompatible purpose without anyone hacking its systems.
  • Both at once: A vendor’s security failure may expose information that the organization also collected or shared unlawfully.

Regulatory action may be possible even if no individual can prove compensable loss. A private compensation claim, by contrast, depends on the requirements of the applicable law, including damage and causation where required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who may be responsible: organization, employee or vendor?

The organization that determines why and how personal data is handled is generally the controller under GDPR terminology. A processor handles data for a controller on its instructions. Labels in a contract are relevant but do not necessarily settle the roles; look at who actually decided the purposes and essential means of processing.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Using a vendor does not automatically remove the controller’s responsibilities. UK ICO guidance says controllers must select and oversee processors and can face corrective action, fines or compensation claims when a processor is involved. A processor may also face direct regulatory scrutiny or claims in appropriate circumstances. Contracts can allocate duties, remediation costs and indemnities, and a controller may seek contribution if a vendor caused or contributed to a loss, but a contract cannot simply transfer every legal obligation away from the controller.

An employee is not automatically personally liable merely because they work for an organization that breached privacy rules. Personal consequences become more plausible where someone misuses data, acts outside their authority, commits a specific criminal offence or breaches employment or professional rules. See the ICO’s controller and processor guidance.

What to do if you think your information was processed unlawfully

  1. Keep a record. Save privacy notices, emails, screenshots, account records, request responses and dates. Do not alter evidence or publish other people’s personal information while documenting the issue.
  2. Identify the organization and the jurisdiction. Check where it operates, where you are, what kind of information is involved and whether a sector-specific law may apply. The correct regulator and remedy depend on those details.
  3. Contact the organization. Ask what information it holds, why it was used, its legal basis, who received it and how long it will be retained. Depending on the situation and local law, you may also request access, correction, deletion, restriction, objection or an opt-out.
  4. Complain to the relevant regulator if needed. If the organization does not respond adequately, use the complaint route for the applicable privacy law. Keep the complaint, response and reference details.
  5. Assess whether you suffered harm. Record financial loss, identity theft, distress, discrimination or reputational consequences. Consider legal advice if the impact is substantial, a group is affected or you want to pursue compensation. Deadlines and proof requirements vary.
  6. Secure your accounts if exposure is possible. Change reused passwords, enable multifactor authentication and monitor relevant accounts for suspicious activity.

A regulator complaint and a compensation claim are different routes. A regulator may investigate or require changes even where a person has no damages claim; conversely, an individual claim is decided under the relevant law and court process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a business should do after discovering questionable processing

  1. Pause or restrict the activity where appropriate. Avoid continuing a questionable use while the facts and legal basis are assessed.
  2. Preserve records and logs. Keep evidence needed to understand what happened, who accessed or received data, and what decisions were made. Deletion should not destroy evidence or conflict with legal retention duties.
  3. Map the scope. Identify the data, people, purposes, systems, recipients, processors and time period involved.
  4. Get the right review. Involve the privacy lead or data-protection officer and, where warranted, privacy counsel. Distinguish a legal-basis or transparency problem from a security incident; both may be present.
  5. Assess notification duties separately. A processing violation does not automatically trigger a breach notice, and a security incident can trigger notification duties even when the original collection was lawful. Apply the relevant jurisdiction’s rules and deadlines.
  6. Remediate the cause. Correct notices, legal-basis records, consent flows, retention schedules, access controls, contracts or staff practices as appropriate. Review vendor roles and oversight.
  7. Document decisions and follow through. Record the facts, risk assessment, notices, corrective actions and reasons for decisions, then verify that changes work in practice.

Privacy-management software can help organize inventories, requests, vendor reviews and evidence, but it cannot determine by itself whether a particular activity is lawful in every jurisdiction. It is a governance aid, not a substitute for accountable decisions, legal analysis or security controls.

Legal frameworks and regulator guidance can change. This overview reflects the laws and sources cited as of September 2026; it is general information, not legal advice.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.