Laws · GDPR ·art-83-par-2 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
How it connects
Cited by
- GDPR Fines: A Graphic Calculation Guide – Part 1
- DeFine is a calculator for GDPR fines based on method of the EDPB
- Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack
- Guidelines 02/2022 on the application of Article 60 GDPR
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
All 78
- IDdesign A / S: Non-compliance with general data processing principles
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Response to CCIA Europe concerning EDPB guidelines on calculation of fines
- Garante per la protezione dei dati personali (Italy) - 10214411
- UODO fines accounting firm €2,760 for email breach security failures
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- Garante per la protezione dei dati personali (Italy) - 385/2026
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- IMY (Sweden) - IMY-2024-2904
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- Perlindungan Hukum Data Pribadi di Era Globalisasi Digital: Studi Perbandingan General Data Protection Regulation Uni Eropa dengan Undang-Undang Perlindungan Data Pribadi Indonesia
- DSB (Austria) - 2026-0.016.479
- UODO (Poland) - DKE.561.4.2026
- Garante per la protezione dei dati personali (Italy) - 487/2026
- Garante per la protezione dei dati personali (Italy) - 471/2026
- CNIL (France) - SAN-2022-026
- AZOP (Croatia) - Decision 14-09-2023
- CNIL (France) - SAN-2020-013
- CNIL (France) - SAN-2021-023
- Statement 2/2024 on the financial data access and payments package
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- EDPB Annual Report 2022
- Court upholds €50,000 fine on Sociálna poisťovňa for sending sensitive data by ordinary
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Criminal proceedings against ILVA A/S
- TR v Land Hessen
- AT and BT v PS GbR and Others
- GP v juris GmbH
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija
- NAIH (Hungary) - NAIH-11443-3/2026
- AEPD fines El Español for publishing video of minor assailant without anonymization
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- HDPA (Greece) - 7/2026
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Austrian court reviews postal service selling political affinity data of customers
- Garante fines Lusha Systems Inc. over unauthorized B2B contact database
- UODO (Poland) - DKN.5131.5.2025
- DSB (Austria) - 2025-1.049.138
- National court annuls DPA sanction against KFC Spain over website privacy information
- NAIH (Hungary) - NAIH-450-7-2026
- Garante per la protezione dei dati personali (Italy) - 476/2026
- AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber
- NAIH (Hungary) - NAIH-4462-5-2026
- Garante per la protezione dei dati personali (Italy) - 10266250
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- UODO fines controller for refusing to cooperate and provide information in two data
- Garante per la protezione dei dati personali (Italy) - 10269624
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- AEPD: Continuous workplace audio recording violates GDPR data minimisation principle
- Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on
- Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15
- Garante per la protezione dei dati personali (Italy) - 551/2026
- Francesco Gagliardi: Non-compliance with general data processing principles
- Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after
- VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- AEPD sanctions Iberdrola Clientes for improper identity verification and unauthorized
- Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security
- Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights
- Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security
- Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- CJEU - C-458/25
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR
- IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M