# Administrative Fines on Union Institutions, Bodies, Offices and Agencies — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/administrative-fines-union-institutions
> Sources are cited per item. Verify against the official texts before relying on them.

This specific provision addresses a distinct category of administrative fines applicable exclusively to Union institutions, bodies, offices and agencies, which differs from fines applicable to private actors and requires separate treatment to capture the unique institutional context and procedures.

## Overview

## Legal Framework
Article 100 of the AI Act establishes a specialized administrative fine regime applicable exclusively to Union institutions, bodies, offices, and agencies. Unlike the tiered percentage-of-turnover model applied to commercial entities, this provision imposes a fixed monetary cap on penalties—generally set at 1,500,000 EUR—recognizing the public mandate and non-profit structure of EU bodies. The European Data Protection Supervisor (EDPS) acts as the competent market surveillance authority for these entities. This framework ensures that EU bodies are held to the same substantive compliance standards as private actors but under a penalty structure suited to their institutional context.

## Key Developments
Enforcement under the AI Act is nascent, but existing data protection jurisprudence informs how the EDPS will exercise its fining powers. The CJEU ruling in *Rynes* established a broad interpretation of personal data, confirming that visual recordings fall within the regulatory scope when identification is possible. This expansive definition triggers strict compliance duties for EU institutions deploying AI systems involving biometric or visual data. Furthermore, national enforcement trends provide a proxy for EDPS severity assessments. The Danish DPA's actions against IDdesign (€13,450) and Taxa 4x35 (€160,000) demonstrate that violations of core principles, particularly data minimization, attract substantial penalties. The EDPS will likely apply similar proportionality metrics when assessing institutional failures under Article 100.

## Practical Guidance
- Ensure all AI systems processing visual or biometric data implement strict data minimization protocols, as established in *Rynes* and enforced in the Taxa 4x35 decision.
- Establish robust mechanisms for data subject access requests, aligning internal procedures with the standards articulated in EDPB Guidelines 01/2022 to mitigate enforcement risk.
- Implement certification mechanisms where feasible, as outlined in EDPB Guidelines 1/2018, to demonstrate proactive compliance and accountability under the AI Act.
- Conduct regular internal audits of AI systems to verify that processing activities remain within the institutional mandate and do not exceed the strict necessity threshold required by EU supervisory authorities.

## Legislation (full text of key provisions)

### Administrative fines on Union institutions, bodies, offices and agencies

*Source: AI Act, aiact-art-100-en, 2024-06-12 — https://overview.legal/posts/93564*

## Case law

### Deutsche Wohnen SE v Staatsanwaltschaft Berlin

*Source: CJEU, C-807/21, 2023-12-05 — https://overview.legal/posts/51487 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0807*

Fines can be imposed directly on legal persons without identifying responsible natural person.

### Österreichische Datenschutzbehörde v CRIF

*Source: CJEU, C-487/21, 2023-10-26 — https://overview.legal/posts/51486 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0487*

Right of access includes obtaining a copy in commonly used electronic form.

### UI v Österreichische Post AG

*Source: CJEU, C-300/21, 2023-05-04 — https://overview.legal/posts/51483 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0300*

Right to compensation under GDPR Article 82 requires proof of actual damage.

### Peter Nowak v Data Protection Commissioner

*Source: CJEU, C-434/16, 2017-12-20 — https://overview.legal/posts/51480 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0434&ref=51480*

Examination scripts constitute personal data of the candidate.

### Patrick Breyer v Bundesrepublik Deutschland

*Source: CJEU, C-582/14, 2016-10-19 — https://overview.legal/posts/51479 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0582&ref=51479*

Dynamic IP addresses can be personal data when holder can identify the person.

### RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”)

*Source: CJEU, 2014-12-11 — https://overview.legal/posts/6155 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013CJ0212&ref=6155*

Personal data: The image of a person recorded by a camera constitutes personal data because it makes it possible to identify the person concerned. (¶ 22)

## Guidance

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 03/2021 on the application of Article 65(1)(a) GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-651a-gdpr, 2023-05-24 — https://overview.legal/posts/38137 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032021-on-the-application-of-article-651a-gdpr_en*

The European Data Protection Board (EDPB) adopted Guidelines 03/2021 to clarify the dispute resolution mechanism under Article 65(1)(a) GDPR, which governs the EDPB's authority to issue binding decisions when a Lead Supervisory Authority receives relevant and reasoned objections from Concerned Supervisory Authorities that it does not follow. The Guidelines address the procedural framework, the threshold for "relevant and reasoned" objections, the scope of the EDPB's substantive competence, and applicable procedural safeguards including the right to be heard, access to the file, and available judicial remedies.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

### Guidelines 02/2022 on the application of Article 60 GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-60-gdpr, 2022-03-14 — https://overview.legal/posts/38066 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022022-on-the-application-of-article-60-gdpr_en*

With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the  enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it  through  the establishments ...

### Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-relevant-and-reasoned-objection-under-regulation-2016679, 2021-03-09 — https://overview.legal/posts/38061 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-092020-on-relevant-and-reasoned-objection-under-regulation-2016679_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria for a "relevant and reasoned objection" by supervisory authorities within the GDPR's cooperation mechanism under Article 65. The guidelines specify that an objection must be both "relevant" (directed at the substance of the draft decision) and "reasoned" (supported by substantive arguments regarding GDPR compliance or risks to fundamental rights and the free flow of personal data within the Union). No fine amounts are involved, as this document provides interpretive guidance rather than an enforcement decision.

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

## Enforcement decisions

### IDdesign A / S: Non-compliance with general data processing principles

*Source: Danish Data Protection Authority (Datatilsynet), 2021-02-12 — https://overview.legal/posts/46137 — original: https://www.enforcementtracker.com/ETid-22*

Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of personal data of approximately 385,000 customers for a longer period than necessary for the purposes for which they were processed. Additionally, the company had not established and documented deadlines for deletion of personal data in their new CRM system. The deadlines set for the old system were not deleted after the

### Taxa 4x35: Non-compliance with general data processing principles

*Source: Danish Data Protection Authority (Datatilsynet), 2019-01-01 — https://overview.legal/posts/46136 — original: https://www.enforcementtracker.com/ETid-21*

The Danish DPA reported the taxi company to the police and recommended a fine (of 1.2M DKK) for non-adherence to the data-minimization principle. While the company deleted the names of its passengers from all its records after two years, the deletion did not include the rest of the ride records (about 8,873,333 taxi trips). Hence, the company continued to hold onto individual's phone numbers. Please note: Since Danish law does not provide for administrative fines as in the GDPR (unless it is an

## Recent developments

### De CNIL stelt een boete van 60 miljoen euro voor aan een Frans bedrijf dat zich bezighoudt met advertentietechnologie, vanwege het niet naleven van de AVG (Algemene Verordening Gegevensbescherming).

*Source: Hunton Andrews Kurth, 2022-08-05 — https://overview.legal/posts/51840*

De voorgestelde boete volgt op klachten die de privacyorganisatie "Privacy International" heeft ingediend tegen Criteo. [...]
In het kader van de sanctieprocedure van de CNIL heeft Criteo het recht om te reageren op het rapport, zowel met betrekking tot de vermeende overtredingen als de voorgestelde sanctie.

### CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR

*Source: Hunton Andrews Kurth, 2022-08-05 — https://overview.legal/posts/6291 — original: https://www.huntonprivacyblog.com/2022/08/17/cnil-proposes-60-million-euros-fine-against-french-adtech-company-for-non-compliance-with-gdpr/#entry-12*

> The proposed fine follows complaints filed by privacy NGO ‘Privacy International’ against Criteo. […]
Under the CNIL’s sanction procedure, Criteo has the right to respond to the report, both with respect to the alleged infringements and the proposed sanction.

### GDPR Fines: A Graphic Calculation Guide – Part 1

*Source: MLL Legal, 2022-06-07 — https://overview.legal/posts/6303 — original: https://www.mll-news.com/gdpr-fines-a-graphic-calculation-guide-part-1/?lang=en#entry-15*

> European supervisory authorities’ varying practices of calculating GDPR administrative fines can be viewed, on the one hand, as inconsistent and in conflict with the principle of uniform interpretation and application of the GDPR in general and uniform sanction for GDPR infringements in particular, as enshrined in GDPR recital 10, 11 and 13.

### DeFine is a calculator for GDPR fines based on method of the EDPB

*Source: Kromann Reumert, 2022-02-01 — https://overview.legal/posts/6310 — original: https://www.khlaw.com/define#entry-14*

> DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, 12 May 2022, available online; it was subject to a public consultation until 27 June 2022).

## Related topics

- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/administrative-fines-union-institutions · 2026-08-22
