Laws · GDPR ·art-83-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.
How it connects
Cited by
- Record fine for Instagram following EDPB intervention
- GDPR Fines: A Graphic Calculation Guide – Part 1
- DeFine is a calculator for GDPR fines based on method of the EDPB
- Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO
- Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack
All 66
- Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Private individual: Insufficient legal basis for data processing
- EDPB Annual Report 2024
- Response to CCIA Europe concerning EDPB guidelines on calculation of fines
- Meta Platforms and Others v Bundeskartellamt
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin
- Garante per la protezione dei dati personali (Italy) - 10214411
- UODO fines accounting firm €2,760 for email breach security failures
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- DSB (Austria) - 2026-0.016.479
- UODO (Poland) - DKE.561.4.2026
- Garante per la protezione dei dati personali (Italy) - 487/2026
- APD/GBA (Belgium) - 159/2023
- Greek HDPA: Classroom video surveillance at school unlawful; oral notice insufficient
- Statement 2/2024 on the financial data access and payments package
- EDPB Annual Report 2022
- EDPB Annual Report 2021
- WhatsApp Ireland Ltd v European Data Protection Board
- Steiermärkische Bank und Sparkassen AG and Others v Österreichische Finanzmarktaufsichtsbehörde (FMA)
- Criminal proceedings against ILVA A/S
- TR v Land Hessen
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija
- WhatsApp Ireland Ltd v European Data Protection Board
- AEPD fines El Español for publishing video of minor assailant without anonymization
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Austrian court reviews postal service selling political affinity data of customers
- Garante fines Lusha Systems Inc. over unauthorized B2B contact database
- UODO (Poland) - DKN.5131.5.2025
- DSB (Austria) - 2025-1.049.138
- Garante per la protezione dei dati personali (Italy) - 476/2026
- AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber
- Garante per la protezione dei dati personali (Italy) - 10266250
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- Garante per la protezione dei dati personali (Italy) - 10269624
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car
- AEPD: Continuous workplace audio recording violates GDPR data minimisation principle
- Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on
- Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15
- AEPD (Spain) - ps-00256-2025
- Persónuvernd (Iceland) - 2025010364
- Garante per la protezione dei dati personali (Italy) - 551/2026
- Francesco Gagliardi: Non-compliance with general data processing principles
- Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR
- IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M
- Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at
Related across sources
C-768/21 TR v Land Hessen In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of… CJEU ·First Chamber Sep 26, 2024 Supervision Data Breaches Integrity and Confidentiality Principle
C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin C-807/21 (Deutsche Wohnen) CJEU Dec 5, 2023 Fines Public Authority Processors
C-383/23 Criminal proceedings against ILVA A/S The Court of Justice of the European Union ruled on a preliminary reference from the Danish High Court in criminal proceedings against ILVA A/S, addressing whether the GDPR… CJEU ·Fifth Chamber Feb 13, 2025 Fines Controllers Processors
Guidelines 04/2026 application of the power to impose administrative fines in relation to other corrective powers under the GDPR Guidelines ·EDPB Sep 17, 2026 Fines Authority Powers for Fundamental Rights Protection Supervision
Guidelines 04/2022 calculation of administrative fines under the GDPR Guidelines ·EDPB May 24, 2023 Fines Notified Body Reporting and Notification Obligations Supervision
C-741/21 GP v juris GmbH In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject… CJEU ·Third Chamber Apr 11, 2024 Liability Personal Data Integrity and Confidentiality Principle