Laws · GDPR ·art-83-par-2-pnt-a EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
How it connects
Cited by
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- UODO fines accounting firm €2,760 for email breach security failures
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Garante per la protezione dei dati personali (Italy) - 385/2026
All 40
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- DSB (Austria) - 2026-0.016.479
- UODO (Poland) - DKE.561.4.2026
- Garante per la protezione dei dati personali (Italy) - 487/2026
- Garante per la protezione dei dati personali (Italy) - 471/2026
- CNIL (France) - SAN-2022-026
- Statement 2/2024 on the financial data access and payments package
- NAIH (Hungary) - NAIH-11443-3/2026
- AEPD (Spain) - PS-00140-2025
- Garante per la protezione dei dati personali (Italy) - 483/2026
- UODO (Poland) - DKN.5131.5.2025
- DSB (Austria) - 2025-1.049.138
- NAIH (Hungary) - NAIH-450-7-2026
- NAIH (Hungary) - NAIH-4462-5-2026
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- Garante per la protezione dei dati personali (Italy) - 10269624
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on
- Garante per la protezione dei dati personali (Italy) - 551/2026
- APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights
- Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer
- UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR