Skip to main content

Service · Defence

When claims arrive in series, so must your defence

A breach with many people affected does not produce one lawsuit: it produces hundreds, almost identical and with the same lawyer on the other side. Defending them one by one is the most expensive way to lose.

Claims after a breach do not arrive at random. They arrive in groups, with near-identical wording, gathered in bulk and filed in batches. Each one is small on its own; the problem is the whole, and above all the cumulative effect of the legal costs and of your team's time.

Post-Breach Claims Defence treats the wave for what it is: a single matter with many case numbers. One line of argument, one evidence file and a costs strategy designed for the whole, not for case number fourteen.

Who it is for

  • Companies that have already received the first claims or formal demand letters after an incident and can see them arriving in batches.
  • Anyone who has noticed that several filings come from the same law firm, with the same wording and the same request.
  • Anyone receiving a wave of erasure and access requests that signal the claim to follow.
  • Management teams that need to put a scale of exposure and a plan before the board, not a case-by-case response.

What it includes, exactly

  1. Analysis of the wave. Identification of the patterns: who is claiming, with what wording, what they ask for and what each filing actually proves.
  2. A single line of defence. A common set of arguments, resting on your diligence file, applied to every set of proceedings without contradicting itself.
  3. Standard defence pleadings. Model filings that can be adapted to each set of proceedings within hours, with the evidence bundle already assembled.
  4. Handling of erasure and access requests. An express reply, on time and with an inbound and outbound register, so that none of them turns into an additional claim.
  5. Costs strategy. A uniform criterion on when to concede, when to settle and when to litigate, decided with the whole picture in view.
  6. Tracking table. The status of each set of proceedings, the outcome and the accumulated cost, in a single document for the board.

Which rule it addresses

Rule C — Fault is presumed. Article 82.3 GDPR puts you in the position of having to prove your diligence in order to be exonerated, and SAP Madrid 273/2024 requires you to show that adequate measures were taken to prevent the infringement, including those relating to identity impersonation. The defence consists, literally, in putting that evidence in front of the judge. If the file does not exist, no strategy can replace it: that is why this service rests on the Demonstrable Diligence File.

Rule F — Erasure requests have a deadline and a form. They must be dealt with without undue delay and, in any event, within one month, with an express decision even where you hold no data on the applicant. But the Barcelona Provincial Court of Appeal also recalls something that works in your favour:

SAP Barcelona 307/2023 (Article 17 GDPR)
[...] the burden falls on the claimant to prove the sending and the receipt of the access request supposedly made... circumstances which are essential in order to find that the right was exercised. [translation]

In a wave of serial claims, that detail decides many sets of proceedings: a good part of the filings assert a right that they never prove they exercised. It is worth keeping in mind the other end of the same axis: processing that was lawful at the outset may become unlawful with the passage of time (SAP Alicante 33/2024), so keeping data longer than you should also generates claims.

Defending yourself one by one multiplies the cost and multiplies the contradictions. Defending yourself as a block does the opposite.

Deliverables

  • Exposure report: how many sets of proceedings, of what type and following what pattern.
  • Common defence arguments, anchored to your evidence file.
  • Standard defence pleadings and a documentary evidence bundle ready to be filed.
  • Response protocol for erasure and access requests, with an inbound and outbound register.
  • Written criteria on settlement and costs, approved with management.
  • Periodic tracking table for the board.

Indicative timescale

The line of defence and the standard pleadings are put together in two or three weeks from delivery of the documentation. Managing the proceedings then continues for as long as the wave lasts. If you already have demands with time running, they are dealt with immediately and in parallel.

If the first claim has not yet arrived, you are still in time to decide what you will defend yourself with: measure your position with the Breach Management Test and read what a court really looks at after a breach.

Post-Breach Claims Defence

Tell us how many filings you have received and what dates they bear. The first reading of the pattern is what determines the strategy for the whole block.

Talk to ILP Abogados
servicios/defensa-post-brecha
Post-Breach Claims Defence | ILP Abogados