Laws · GDPR ·art-83-par-2-pnt-b EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
the intentional or negligent character of the infringement;
How it connects
Cited by
- DeFine is a calculator for GDPR fines based on method of the EDPB
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Private individual: Insufficient legal basis for data processing
- UODO fines accounting firm €2,760 for email breach security failures
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
All 37
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- DSB (Austria) - 2026-0.016.479
- UODO (Poland) - DKE.561.4.2026
- Garante per la protezione dei dati personali (Italy) - 487/2026
- NAIH (Hungary) - NAIH-11443-3/2026
- AEPD fines El Español for publishing video of minor assailant without anonymization
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Garante fines Lusha Systems Inc. over unauthorized B2B contact database
- UODO (Poland) - DKN.5131.5.2025
- DSB (Austria) - 2025-1.049.138
- NAIH (Hungary) - NAIH-450-7-2026
- NAIH (Hungary) - NAIH-4462-5-2026
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- Garante per la protezione dei dati personali (Italy) - 10269624
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- Garante per la protezione dei dati personali (Italy) - 551/2026
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste
- Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights
- Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- CNIL fines EXTIA for failing to properly handle job applicant erasure requests
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer
- UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR