Skip to Content (custom)

Clicks, Claims, and Collective Actions: Europe’s Digital Reckoning

  • Class Action and Mass Tort
  • 3 mins

Key Takeaway: Europe’s message to Big Tech is getting louder: platform design and use of personal data are equally as important as data protection. From data breaches to addictive design and platform power, the age of “click now, explain later” is coming to an end.

Europe’s latest collective actions show that Big Tech and digital businesses are being challenged not only for what they do with data, but also for how they retain it, protect it, keep user attention, and influence behaviour. From data breaches and medical privacy claims to Snapchat’s Snapstreaks and infinite scrolling, Europe's courts are becoming the latest battleground in the debate over digital accountability.

Examples range from Odido’s data breach fallout, Snapchat’s Snapstreak scrutiny, Steam’s €220 million competition challenge, the Dutch healthcare data leak, and Europe’s first social media addiction claim against Meta and TikTok. Together, they signal a broader shift in how consumers, regulators, and courts are holding digital businesses accountable.

Breaking Up Is Hard to Do, Especially for Your Data

After hackers gained access to systems containing the personal data of more than 6 million current and former Odido users, a Dutch consumer collective launched a mass claim alleging the breach resulted from shortcomings in Odido’s data protection practices.

The claim argues that Odido retained personal data for too long, failed to secure it adequately, and was not sufficiently transparent when the breach occurred.

The case centres on core General Data Protection Regulation (GDPR) principles: keep only the data you need, protect it properly, and act quickly when things go wrong. Claimants are seeking compensation, greater transparency about the breach, and stronger accountability for how companies handle client data.

While compensation figures of around €500 per person have been mentioned, any payout remains uncertain. Under Dutch law, a data breach does not automatically result in compensation, and whether affected individuals are entitled to damages will depend on the specific circumstances of the case.

Beyond any potential compensation, the case highlights a growing risk for organisations holding large volumes of personal data. Claimants allege that the breach was linked not only to inadequate security measures, but also to the retention of user data that was no longer necessary. Whether those allegations succeed remains to be seen, but the claim reflects increasing scrutiny of how long companies keep personal data and whether they can justify retaining it. As the Odido case suggests, personal data can outstay its welcome long after the client’s relationship has ended.

The Flame Emoji That Lit a Lawsuit

Snapchat built its reputation on disappearing photos, quirky filters, and keeping up with friends. Now, in the Netherlands, it faces a collective action asking whether some of that engagement was designed to be addictive.

In June 2026, Dutch consumer organisation Foundation for Market Information Research (SOMI) launched a mass claim against Snapchat, focusing on features like Snapstreaks, the flame emojis that reward users for maintaining daily contact. SOMI argues these design elements encourage frequent, sustained use rather than casual engagement.

The foundation also alleges that Snapchat collected extensive personal data to create advertising profiles, including minors until at least mid-2023. It is seeking compensation of up to €1000 for underage users and €750 for adults, while also calling for changes to the platform's practices.

At the same time, the European Commission is investigating Snapchat under the Digital Services Act (DSA), examining issues such as child protection, age verification, and the use of so-called “dark patterns” that may influence user behaviour.

Together, the lawsuit and regulatory scrutiny reflect a wider European trend which is a growing concern not just about how platforms use personal data, but how they compete for users’ attention. What was once celebrated as engagement is now increasingly being examined by courts and regulators.

When a Health Screening Becomes a Data Breach

A routine cervical cancer screening programme is now at the centre of one of the Netherlands' largest medical data breach claims.

The Women's Rights Collective (WRC) is preparing a mass action on behalf of hundreds of thousands of women whose personal and medical data was exposed following a cyberattack on laboratory clinical diagnostics. What initially appeared to affect around 485,000 women has since grown into a much larger issue, with at least 715,000 people now believed to have been impacted.

The fallout has been significant. The stolen data reportedly includes names, addresses, dates of birth, Burgerservicenummers (BSNs), and, in some cases, cervical screening information, exactly the kind of sensitive data nobody wants falling into the wrong hands.

Dutch regulators concluded that the laboratory had not adequately protected patient information, while many women have been left wondering how data shared for preventive healthcare ended up in the hands of hackers.

The case raises a broader question about privacy harm in the digital age: When highly sensitive medical information is exposed, is the injury limited to any subsequent misuse of the data, or does the loss of control over that information constitute harm in itself? That question is particularly important in healthcare, where patients routinely entrust organisations with deeply personal information on the understanding that it will remain confidential. For many affected women, the concern is not simply what hackers might do with the data in the future, but that information relating to their health was exposed at all.

Infinite Scroll Meets Finite Patience

For years, social media companies have competed for users’ attention. The longer they scroll, the more valuable they become. Now, that business model is being dragged into court. 

In Italy, Meta and TikTok are facing what has been described as Europe’s first collective action focused on protecting minors from potentially addictive platform design. The claim seeks stronger age-verification measures, greater transparency about risks, and changes to features such as recommendation algorithms and infinite scrolling. 

The case reflects a much broader trend. Across Europe, regulators and claimant groups are increasingly looking beyond privacy breaches and data collection practices. The new question is whether social media platforms are deliberately designed to keep users, particularly children, online for longer. 

Similar themes are already emerging elsewhere. Dutch actions against Snapchat have targeted allegedly addictive features such as Snapstreaks, while courts have begun scrutinising Meta's use of algorithmic feeds and so-called dark patterns.

Whether these claims succeed remains to be seen. But one thing is certain: Europe is no longer just asking how Big Tech uses people’s data. It’s starting to ask how Big Tech uses their attention. 

Learn more about Epiq Class Action and Mass Tort Services.

Phillipa Roudba 
Philippa Roubaud, EU Legal Operation and Administrative Support Specialist, Class Action Solutions, Netherlands
Philippa Roubaud brings over a decade of experience in translations, commercial and general law, debt recovery, and intellectual property consulting to her role at Epiq. She is a graduate of the Catholic University of Portugal and a member of the Portuguese Bar Association. Before joining the team, she specialised in multilingual and multilevel eDiscovery projects for international law firms in London.  

Philippa is currently based in the Netherlands, where she works closely with Dutch clients and has gained practical insight into the local legal landscape.

The contents of this article are intended to convey general information only and not to provide legal advice or opinions.

Subscribe to Future Blog Posts