Laws · GDPR ·art-83-par-5 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:
How it connects
Cited by
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Private individual: Insufficient legal basis for data processing
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- Tensa Art Design S.A: Insufficient cooperation with supervisory authority
- Garante per la protezione dei dati personali (Italy) - 10214411
All 57
- UODO fines accounting firm €2,760 for email breach security failures
- SC Hayat Dent SRL: Insufficient cooperation with supervisory authority
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- Coordinated Enforcement Action,
- VDAI fines medical company €450,000 for inadequate security measures in data breaches
- UODO (Poland) - DKN.5131.27.2023
- Perlindungan Hukum Data Pribadi di Era Globalisasi Digital: Studi Perbandingan General Data Protection Regulation Uni Eropa dengan Undang-Undang Perlindungan Data Pribadi Indonesia
- DSB (Austria) - 2026-0.016.479
- Garante per la protezione dei dati personali (Italy) - 487/2026
- Garante per la protezione dei dati personali (Italy) - 471/2026
- Garante per la protezione dei dati personali (Italy) - 10192784
- Belgian DPA: Roularta Media Group violated cookie consent rules
- AEPD (Spain) - EXP202103746
- CNIL (France) - SAN-2020-013
- EDPB Annual Report 2018
- NAIH (Hungary) - NAIH-11443-3/2026
- HDPA (Greece) - 33/2020
- AEPD fines El Español for publishing video of minor assailant without anonymization
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Austrian court reviews postal service selling political affinity data of customers
- DSB (Austria) - 2025-1.049.138
- NAIH (Hungary) - NAIH-450-7-2026
- Garante per la protezione dei dati personali (Italy) - 476/2026
- AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber
- NAIH (Hungary) - NAIH-4462-5-2026
- Garante per la protezione dei dati personali (Italy) - 10266250
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- Garante per la protezione dei dati personali (Italy) - 10269624
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car
- High Court examines DPA inquiry into Meta's refusal of raw data access and portability
- AEPD: Continuous workplace audio recording violates GDPR data minimisation principle
- Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on
- Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15
- Garante per la protezione dei dati personali (Italy) - 551/2026
- Francesco Gagliardi: Non-compliance with general data processing principles
- APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients
- Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights
- Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security
- Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary
- Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- CNIL fines EXTIA for failing to properly handle job applicant erasure requests
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer