Fines / Penalties - General Data Protection Regulation (GDPR) (2024)

National authorities can or must assess fines for specific data protection violations in accordance with the General Data Protection Regulation. The fines are applied in addition to or instead of further remedies or corrective powers, such as the order to end a violation, an instruction to adjust the data processing to comply with the GDPR, as well as the power to impose a temporary or definitive limitation including a ban on data processing. For the provisions which relate to processors, he may be subject to sanctions directly and/or in conjunction with the controller.

The fines must be effective, proportionate and dissuasive for each individual case. For the decision of whether and what level of penalty can be assessed, the authorities have a statutory catalogue of criteria which it must consider for their decision. Among other things, intentional infringement, a failure to take measures to mitigate the damage which occurred, or lack of collaboration with authorities can increase the penalties. For especially severe violations, listed in Art. 83(5) GDPR, the fine framework can be up to 20 million euros, or in the case of an undertaking, up to 4 % of their total global turnover of the preceding fiscal year, whichever is higher. But even the catalogue of less severe violations in Art. 83(4) GDPR sets forth fines of up to 10 million euros, or, in the case of an undertaking, up to 2% of its entire global turnover of the preceding fiscal year, whichever is higher. Especially important here, is that the term “undertaking” is equivalent to that used in Art. 101 and 102 of the Treaty on the Functioning of the European Union (TFEU). According to case law of the European Court of Justice, “the concept of an undertaking encompasses every entity engaged in an economic activity, regardless of the legal status of the entity or the way in which it is financed”. An undertaking can therefore not only consist of one individual company in the sense of a legal person, but also out of several natural persons or corporate entities. Thus, a whole group can be treated as one undertaking and its total worldwide annual turnover can be used to calculate the fine for a GDPR infringement of one of its companies. In addition, each Member State shall lay down rules on other penalties for infringements of the Regulation which are not already covered by Art. 83. Those are most likely criminal penalties for certain violations of the GDPR or penalties for infringements of national rules which were adopted based on flexibility clauses of the GDPR. The national penalties must also be effective, proportionate and act as a deterrent.

A punishable situation in a company can be revealed through proactive inspection activities conducted by the data protection authorities, by an unsatisfied employee or by customers or potential customers who complain to the authorities, through the company making a self-denunciation, or by the press in general, especially through investigative journalism.

The Enforcement Tracker gives an overview of reported fines and penalties which data protection authorities within the EU have imposed so far.

External Links

Authorities

  • Article 29 Data Protection Working Party ► WP 253 – Guidelines on the application and setting of administrative fines (Link)
  • European Commission ► Enforcement and sanctions (Link)
  • Data Protection Authority Isle of Man ► Fines, penalties and sanctions (Link)
  • ► Handbook on European data protection law – Sanctions, page 247 (Link)

Expert contribution

  • Journal of Intellectual Property, Information Technology and Electronic Commerce Law ► Is Data Protection Law Growing Teeth? (Link)
  • IAPP ► Top 10 operational impacts of the GDPR: Part 10 – Consequences for GDPR Violations (Link)
  • A&L Goodbody ► The GDPR: A Guide for Businesses – Investigative, Corrective & Advisory Powers of Supervisory Authorities / Administrative fines, Page 31, 33 (Link)

Key IssuesTable of contents

Fines / Penalties - General Data Protection Regulation (GDPR) (2024)
Top Articles
19 Ways to Attract Customers to Your Coffee Shop
What is Holistic Home Design?
Radikale Landküche am Landgut Schönwalde
Couchtuner The Office
Bucks County Job Requisitions
A Complete Guide To Major Scales
Northern Whooping Crane Festival highlights conservation and collaboration in Fort Smith, N.W.T. | CBC News
Obituary (Binghamton Press & Sun-Bulletin): Tully Area Historical Society
Walgreens Alma School And Dynamite
Katie Boyle Dancer Biography
Missing 2023 Showtimes Near Lucas Cinemas Albertville
Cincinnati Bearcats roll to 66-13 win over Eastern Kentucky in season-opener
Seafood Bucket Cajun Style Seafood Restaurant in South Salt Lake - Restaurant menu and reviews
Skylar Vox Bra Size
How Many Cc's Is A 96 Cubic Inch Engine
Walthampatch
Nashville Predators Wiki
979-200-6466
Ou Class Nav
Niche Crime Rate
Is Grande Internet Down In My Area
G Switch Unblocked Tyrone
Labby Memorial Funeral Homes Leesville Obituaries
Drago Funeral Home & Cremation Services Obituaries
Craigslist Pet Phoenix
Ivegore Machete Mutolation
Canvasdiscount Black Friday Deals
Brbl Barber Shop
Wics News Springfield Il
Craigslist Illinois Springfield
Obituaries Milwaukee Journal Sentinel
Olivia Maeday
Airline Reception Meaning
Kimoriiii Fansly
Biografie - Geertjan Lassche
Cinema | Düsseldorfer Filmkunstkinos
Restored Republic
What is Software Defined Networking (SDN)? - GeeksforGeeks
How To Improve Your Pilates C-Curve
Frequently Asked Questions - Hy-Vee PERKS
Gr86 Forums
The Venus Flytrap: A Complete Care Guide
No Hard Feelings Showtimes Near Tilton Square Theatre
Eleceed Mangaowl
Jail View Sumter
Craigslist En Brownsville Texas
814-747-6702
Garland County Mugshots Today
Arcanis Secret Santa
N33.Ultipro
Enter The Gungeon Gunther
Lux Nails & Spa
Latest Posts
Article information

Author: Terence Hammes MD

Last Updated:

Views: 5986

Rating: 4.9 / 5 (69 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Terence Hammes MD

Birthday: 1992-04-11

Address: Suite 408 9446 Mercy Mews, West Roxie, CT 04904

Phone: +50312511349175

Job: Product Consulting Liaison

Hobby: Jogging, Motor sports, Nordic skating, Jigsaw puzzles, Bird watching, Nordic skating, Sculpting

Introduction: My name is Terence Hammes MD, I am a inexpensive, energetic, jolly, faithful, cheerful, proud, rich person who loves writing and wants to share my knowledge and understanding with you.