• Who We Are
  • Our Services
    • Outsourced DPO (Data Protection Officer) Services
    • Data Protection Advisory
    • Data Protection Training & Awareness Services
    • Onion Architecture
    • Helpline Service
  • Resources
    • Do I need a DPO (Data Protection Officer)?
    • Benefits of Outsourcing your DPO
    • Why you need GDPR Representation
  • Contact Us
DPO Placement & Consultancy Limited
  • Who We Are
  • Our Services
    • Outsourced DPO (Data Protection Officer) Services
    • Data Protection Advisory
    • Data Protection Training & Awareness Services
    • Onion Architecture
    • Helpline Service
  • Resources
    • Do I need a DPO (Data Protection Officer)?
    • Benefits of Outsourcing your DPO
    • Why you need GDPR Representation
  • Contact Us
DPO Placement & Consultancy Limited
Home / Blog / Blog / Privacy Wronged: Tort of Defamation or Violation of a Fundamental Right? A Cross-Jurisdictional Reckoning

Privacy Wronged: Tort of Defamation or Violation of a Fundamental Right? A Cross-Jurisdictional Reckoning

By admin-DPO inBlog

When personal data is exposed, misused, or a private fact is thrust into public view, the aggrieved party and their counsel faces a foundational strategic question: is this a defamation claim in tort, or is it a breach of a fundamental human right to privacy? The two routes are not mutually exclusive, but they carry different burdens of proof, remedies, and doctrinal ceilings. Getting the choice right, or knowing when to plead both, is increasingly a core competence for privacy practitioners across Africa, Europe, and the Americas.
The Doctrinal Divide
Defamation is fundamentally reputation-protective. It requires a false statement of fact, publication to a third party, and resulting harm to reputation. Truth is typically a complete defence. This creates an immediate problem for privacy harms: much of what damages a person through data exposure, including a leaked medical record, a disclosed relationship status, or a published address, is often true. A defamation claim collapses the moment the defendant proves accuracy, yet the privacy harm remains fully intact. The person has still been wronged; the tort simply has no answer for it.
Privacy as a human right, by contrast, is dignity-protective rather than reputation-protective. It does not ask whether the disclosed information was false. It asks whether the individual had a reasonable expectation of control over that information and whether that control was violated without lawful basis. This is the architecture underlying the EU’s GDPR, Nigeria’s Data Protection Act 2023, South Africa’s POPIA, and Kenya’s Data Protection Act 2019, all of which trace back to constitutional or quasi-constitutional guarantees of privacy rather than to reputational tort.
Where the Frameworks Diverge in Practice
In Nigeria, the 1999 Constitution guarantees privacy under Section 37, and the NDPA 2023 now gives data subjects direct statutory rights and access to the National Data Protection Commission, alongside civil remedies. A claimant can pursue an NDPC complaint or civil matter for a data breach without proving falsity; only that personal data was processed unlawfully. Defamation under Nigerian common law remains a separate, harder-to-win track, useful only where the harm is reputational and the statement is false.
South Africa offers perhaps the clearest dual-track model. The POPIA gives data subjects a statutory cause of action for unlawful processing, while the common-law actio iniuriae separately protects dignity and privacy as personality rights, hence distinguishing privacy from defamation, which protects reputation specifically. South African courts have long recognised informational privacy as independently actionable, so practitioners there rarely need to force a privacy harm into defamation’s shape.
The EU and UK have developed a hybrid tort of “misuse of private information,” carved directly out of privacy jurisprudence rather than defamation, precisely because defamation’s truth defence proved unworkable for image and data-based harms following cases distinguishing the two causes of action. The GDPR’s Article 82 right to compensation for material or non-material damage runs alongside this, giving claimants a statutory route entirely independent of reputational proof.
The United States remains the outlier. Absent a comprehensive federal privacy statute, litigants have historically leaned on state-law privacy torts (intrusion upon seclusion, public disclosure of private facts) and, where reputational falsity exists, defamation. The rise of state comprehensive privacy laws (California, Colorado, Virginia, and others) is now supplementing this patchwork with statutory rights, but private rights of action remain narrow, keeping tort-based reasoning more central than in Africa or Europe.
A Practitioner’s Framework
The strategic question should not be “which cause of action sounds stronger” but “what precisely was violated.” Three questions help:
Was the disclosed information false?
If yes, defamation is available and may offer higher reputational damages. If no, defamation is foreclosed and a rights-based or statutory data protection claim is the only viable route.
Is there a statutory data protection regulator with jurisdiction?
Where one exists (NDPC, an EU supervisory authority, South Africa’s Information Regulator), a regulatory complaint is often faster, cheaper, and carries investigatory power a civil claimant lacks.
What remedy does the client actually want?
Reputational vindication and damages point toward defamation, then cessation of processing, deletion, access, or systemic accountability points toward a data protection or constitutional privacy claim.
Conclusion
Privacy and reputation are related but distinct legal interests, and the global trend accelerated by comprehensive data protection statutes is toward treating informational privacy as a freestanding right rather than a subset of defamation. The most effective advocacy increasingly pleads both, in the alternative, while recognising that as data protection authorities mature across Africa, Europe, and beyond, the human-rights route is fast becoming the primary, not the fallback, vehicle for redress.

0
Like this post
917 Posts
admin-DPO
  • Flock tries to quell surveillance fears as questions pile up
    Previous PostFlock tries to quell surveillance fears as questions pile up

Related Posts

Getting the Legal Basis Right: Processing Employee Data Under the NDPA
Blog

Getting the Legal Basis Right: Processing Employee Data Under the NDPA

One Group, Many Entities: How to Manage Data Privacy as a DPO Across a Multi-Subsidiary African Organisation
Blog News

One Group, Many Entities: How to Manage Data Privacy as a DPO Across a Multi-Subsidiary African Organisation

Cross-Border Data Transfers Under the NDPA: What Nigerian DPOs Must Fix Now
Blog

Cross-Border Data Transfers Under the NDPA: What Nigerian DPOs Must Fix Now

Embedding Privacy by Design into Product Development
Blog

Embedding Privacy by Design into Product Development

Leave a Reply (Cancel reply)

Your email address will not be published. Required fields are marked *

*
*

Logo-03

28, Oka Akoko Street, Off Lagos Street Garki 2, Abuja.

+234 809 989 5658

contact@dpoplacement.com

Services

  • Outsourced DPO Services
  • Data Protection Advisory
  • Data Protection Training & Awareness Services
  • Helpline Service
  • Privacy Notice
  • Cookie Notice
  • Best Forex White Label Solutions

Subscribe to newsletter

© 2022 DPO Placement. Designed by ArtEkindle World

in
F.A.Q
Support Forum
Video Tutorials

Search panel can contain any widgets and shortcodes.

Call us: 0 800 255 22 55
Copy