Laws · GDPR ·art-58-par-2 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Each supervisory authority shall have all of the following corrective powers:
How it connects
Cited by
- Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems
- Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 9/2022 on personal data breach notification under GDPR
- Guidelines 10/2020 on restrictions under Article 23 GDPR
All 155
- Guidelines 02/2022 on the application of Article 60 GDPR
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Guidelines 06/2022 on the practical implementation of amicable settlements
- Guidelines 07/2022 on certification as a tool for transfers
- Guidelines 03/2021 on the application of Article 65(1)(a) GDPR
- National Revenue Agency: Insufficient legal basis for data processing
- S.C. C&V Water Control S.A.: Insufficient cooperation with supervisory authority
- Xfera Moviles S.A.: Insufficient cooperation with supervisory authority
- POLAND DPA: Insufficient fulfilment of data breach notification obligations
- Nacionaliniam visuomenės sveikatos centrui (NVSC): Non-compliance with general data processing principles
- IT sprendimai sėkmei: Non-compliance with general data processing principles
- MALAGATROM, S.L.U.: Insufficient cooperation with supervisory authority
- DOOR2DOOR SPAIN, S.L.: Insufficient cooperation with supervisory authority
- Alfa Shipyard s.r.l.: Insufficient cooperation with supervisory authority
- Telemarketing company: Insufficient cooperation with supervisory authority
- SCOTCH CORNER BAR: Non-compliance with general data processing principles
- Private individual: Insufficient cooperation with supervisory authority
- EDITORIAL RIBADEO S.L.: Insufficient cooperation with supervisory authority
- Suomen Asiakastieto Oy: Insufficient cooperation with supervisory authority
- INMARAN ASESORES S.L.: Insufficient cooperation with supervisory authority
- SECURITAS DIREC ESPAÑA, S.A.: Insufficient cooperation with supervisory authority
- Private individual: Insufficient cooperation with supervisory authority
- SPAIN DPA: Insufficient cooperation with supervisory authority
- LATVIA DPA: Insufficient cooperation with supervisory authority
- TRC TRUCKS 2020, S.L.: Insufficient cooperation with supervisory authority
- PUNTO ROJO LIBROS, S.L.: Insufficient cooperation with supervisory authority
- Private individual: Insufficient cooperation with supervisory authority
- TRACTAMENT D'AIGUES TEIA, S.L.: Insufficient cooperation with supervisory authority
- Libra Internet Bank SA: Insufficient cooperation with supervisory authority
- ATLAS ENTERTAINMENT, S.L.: Insufficient cooperation with supervisory authority
- Municipality of Salento: Insufficient cooperation with supervisory authority
- 20 MINUTOS EDITORA, S.L.: Insufficient cooperation with supervisory authority
- Private individual: Insufficient cooperation with supervisory authority
- DENTAL REY-GAR, S.L.: Insufficient cooperation with supervisory authority
- Private individual: Insufficient cooperation with supervisory authority
- CLÍNICA PARÍS, S.L.: Insufficient cooperation with supervisory authority
- Website operator: Insufficient fulfilment of data subjects rights
- CONSULTORÍA PERITACIONES ALMERIENSES, S.L: Insufficient cooperation with supervisory authority
- Private individual: Insufficient cooperation with supervisory authority
- Private individual: Insufficient cooperation with supervisory authority
- RIVENDELL TECHNOLOGY, S.L.: Insufficient cooperation with supervisory authority
- KUR KLINIKUM, S.L.: Insufficient cooperation with supervisory authority
- HSSERVICE LIZCON SOLUTIONS, S.L.: Insufficient cooperation with supervisory authority
- CRIDOLMA BARCELONA S.L.: Insufficient cooperation with supervisory authority
- AUTOMOCIÓN 1972, S.L.: Insufficient cooperation with supervisory authority
- Freelancer: Insufficient cooperation with supervisory authority
- SHOPBAG GROUP ONLINE SRL: Insufficient cooperation with supervisory authority
- CUBILLO GALLEGO, S.L.: Insufficient cooperation with supervisory authority
- ARCONADA 1932, S.L.: Insufficient cooperation with supervisory authority
- TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with supervisory authority
- La Prima Srl: Insufficient legal basis for data processing
- Comune di Pazzano: Insufficient cooperation with supervisory authority
- ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN: Insufficient cooperation with supervisory authority
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”
- EDPB Annual Report 2024
- Data Protection Commissioner v Facebook Ireland and Maximillian Schrems
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin
- Media Company: Insufficient cooperation with supervisory authority
- AEPD (Spain) - EXP202306354 (PS/00312/2024)
- UODO fines accounting firm €2,760 for email breach security failures
- Housing Association: Insufficient cooperation with supervisory authority
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- AEPD (Spain) - PS-00020-2025
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- IMY (Sweden) - IMY-2024-2904
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- UODO (Poland) - DKE.561.4.2026
- AEPD fines DIGI Telecom for issuing duplicate SIM to impersonator without consent
- NAIH: School grades are personal data; failure to provide access in eKRÉTA system
- Garante per la protezione dei dati personali (Italy) - 10192784
- BVwG - W 108 2284491-1
- CNIL (France) - SAN-2020-013
- Austrian FAC: DPA rightly found loyalty program consent for profiling invalid under GDPR
- EDPB Article 97 GDPR application report: GDPR successful but improvements needed
- Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject
- EDPB Annual Report 2018
- Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)
- Court upholds €50,000 fine on Sociálna poisťovňa for sending sensitive data by ordinary
- Steiermärkische Bank und Sparkassen AG and Others v Österreichische Finanzmarktaufsichtsbehörde (FMA)
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Meta Platforms Ireland Ltd v European Data Protection Board
- Criminal proceedings against ILVA A/S
- Data Protection Commission v European Data Protection Board
- TR v Land Hessen
- Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság
- UF and AB v Land Hessen
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija
- UZ v Bundesrepublik Deutschland
- WhatsApp Ireland Ltd v European Data Protection Board
- EDPB - Binding Decision 1/2026
- DSB (Austria) - 2026-0.043.390
- HDPA (Greece) - 12/2026
- NAIH (Hungary) - NAIH-11443-3/2026
- AEPD (Spain) - PS-00140-2025
- HDPA (Greece) - 33/2020
- DSB (Austria) - 2025-0.950.759
- AEPD fines El Español for publishing video of minor assailant without anonymization
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Austrian court reviews postal service selling political affinity data of customers
- Garante fines Lusha Systems Inc. over unauthorized B2B contact database
- UODO (Poland) - DKN.5131.5.2025
- National court annuls DPA sanction against KFC Spain over website privacy information
- Finnish DPA: requesting address, ID number and strong authentication for access request
- NAIH (Hungary) - NAIH-450-7-2026
- Garante per la protezione dei dati personali (Italy) - 476/2026
- AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber
- NAIH (Hungary) - NAIH-4462-5-2026
- Garante per la protezione dei dati personali (Italy) - 10266250
- VG Berlin: DPA correctly found residential video surveillance for property protection
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- UODO reprimands mayor for disclosing data subject's data to company without legal basis
- Finnish DPA examines anti-doping organization's GDPR compliance over public suspension
- HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR
- Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded
- AEPD: Continuous workplace audio recording violates GDPR data minimisation principle
- Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on
- Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15
- Garante per la protezione dei dati personali (Italy) - 577/2026
- HDPA (Greece) - 15/2026
- AEPD (Spain) - ps-0035-2025
- AEPD (Spain) - ps-00256-2025
- Garante per la protezione dei dati personali (Italy) - 551/2026
- AEPD: Data subject entitled to identity of professionals who accessed medical records
- Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after
- VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Cyprus court upholds €5,000 DPA fine on Pancyprian Judo Federation for Article 31 GDPR
- Cyprus Court upholds DPA finding that Sigma TV unlawfully disclosed financial data
- Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor
- Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security
- Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights
- Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer
- Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools
- UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR
- IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M
- Private individual: Insufficient cooperation with supervisory authority
- AEPD (Spain) - ps-00287-2025
Related across sources
C-768/21 TR v Land Hessen In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of… CJEU ·First Chamber Sep 26, 2024 Supervision Data Breaches Integrity and Confidentiality Principle
C-46/23 Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory… CJEU ·Fifth Chamber Mar 14, 2024 Right to be Forgotten Personal Data Right to Restriction
Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems Schrems II CJEU Jul 16, 2020 Supervision Supervisory Authorities Personal Data
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin C-807/21 (Deutsche Wohnen) CJEU Dec 5, 2023 Fines Public Authority Processors
Guidelines 04/2026 application of the power to impose administrative fines in relation to other corrective powers under the GDPR Guidelines ·EDPB Sep 17, 2026 Fines Authority Powers for Fundamental Rights Protection Supervision