Laws · GDPR ·art-83-par-4 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:
How it connects
Cited by
- DeFine is a calculator for GDPR fines based on method of the EDPB
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Response to CCIA Europe concerning EDPB guidelines on calculation of fines
- Deutsche Wohnen SE v Staatsanwaltschaft Berlin
- UODO fines accounting firm €2,760 for email breach security failures
All 24
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- Garante per la protezione dei dati personali (Italy) - 487/2026
- EDPB Annual Report 2022
- Opinion 02/2023 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to Article 41 GDPR
- EDPB Annual Report 2021
- Steiermärkische Bank und Sparkassen AG and Others v Österreichische Finanzmarktaufsichtsbehörde (FMA)
- Criminal proceedings against ILVA A/S
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Austrian court reviews postal service selling political affinity data of customers
- UODO (Poland) - DKN.5131.5.2025
- DSB (Austria) - 2025-1.049.138
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- AEPD sanctions Iberdrola Clientes for improper identity verification and unauthorized
- Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M