Fines
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Administrative fines imposed for GDPR violations
Overview
24 sources · Aug 27, 2026Legal Framework
Administrative fines under the GDPR are governed primarily by Article 83, which sets out the general conditions for imposition, the criteria for determining amounts, and the maximum ceilings. Article 84 complements this by requiring Member States to establish "other penalties" for infringements not subject to administrative fines under Article 83. The European Data Protection Board's mandate under Article 70 includes issuing guidelines to encourage consistent application, and the Board has exercised this through its Guidelines 04/2022 on the calculation of administrative fines.
Article 83(1) establishes the tripartite standard that anchors every fine decision:
"Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive."
— GDPR Art. 83(1)
Article 83(2) enumerates the criteria supervisory authorities must weigh, including the nature, gravity and duration of the infringement, the intentional or negligent character, mitigating actions, the degree of responsibility, previous infringements, cooperation, the categories of data affected, and how the infringement came to light. The maximum fine ceilings differ by tier: up to €10 million or 2% of worldwide annual turnover under Article 83(4), and up to €20 million or 4% under Article 83(5) for the most serious infringements of basic processing principles and data subject rights.
Key Developments
The CJEU in UI v Österreichische Post AG clarified the relationship between fines, other penalties, and civil liability under Article 82. The Court drew a sharp distinction between compensation claims and the punitive regime:
"Articles 83 and 84 of the GDPR, which permit the imposition of administrative fines and other penalties, have essentially a punitive purpose and are not conditional on the existence of individual damage."
— UI v Österreichische Post AG ¶40
This confirms that supervisory authorities need not demonstrate individual harm to impose fines — the punitive and deterrent function operates independently.
In enforcement practice, the Spanish DPA in Caixabank referenced the Article 29 Working Party's WP253 guidelines, noting that recital 148 introduces the concept of "minor infringements" which may still fall under Articles 83(4) or 83(5) but, depending on the Article 83(2) criteria, may not warrant a fine at all. The EDPB's Guidelines 9/2022 on breach notification confirm that for failures to notify breaches under Articles 33 and 34, fines can reach the Article 83(4)(a) ceiling of €10 million or 2% of turnover.
Status of the Debate
This topic is actively contested in court. While the CJEU has confirmed the punitive independence of fines from individual damage in UI v Österreichische Post AG, the methodology for calculating fine amounts remains a live battleground. National supervisory authorities apply divergent approaches to the Article 83(2) criteria, and the EDPB's Guidelines 04/2022 attempt harmonisation but are not legally binding. Challenges to specific fine amounts are working their way through national courts, with parties disputing whether the correspondence between infringement seriousness and fine amount satisfies the proportionality requirement. A future CJEU reference on the calculation methodology — particularly on how turnover thresholds interact with gravity assessments — would resolve the central open question.
Practical Guidance
- Document mitigation efforts contemporaneously. Article 83(2)(c) requires authorities to consider actions taken to mitigate damage; maintaining a record of remedial measures implemented before and during investigation directly reduces fine exposure.
- Prioritise cooperation with the supervisory authority. Article 83(2)(f) treats cooperation as a mitigating factor — timely, substantive responses to information requests and proactive remediation can meaningfully reduce the imposed amount.
- Implement and evidence Article 25 and 32 measures. Article 83(2)(d) links the degree of responsibility to technical and organisational measures; demonstrable data protection by design and security documentation shifts the responsibility assessment in your favour.
- Track prior infringements and maintain a clean compliance record. Article 83(2)(e) allows authorities to consider previous infringements; recurring violations of the same provisions attract escalating penalties.
- Distinguish between fine tiers when assessing risk. Infringements of basic processing principles under Article 83(5) carry the highest ceiling (€20 million or 4% of turnover), while security and breach-notification failures under Article 83(4) are capped at €10 million or 2% — allocate compliance investment accordingly.
why this is here
Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.
This Article is the central provision in the GDPR governing the imposition and calculation of administrative fines, setting out the criteria, maximum amounts, and conditions for their application.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
The EDPB has devised the following methodology, consisting of five steps, for calculating administrative fines for infringements of the GDPR.
The entire document is about harmonising the methodology for calculating administrative fines under GDPR Article 83.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
it is possible that the objection challenges the elements relied upon to calculate the amount of the fine.
The document indicates that an objection may challenge the calculation of fines, but this is only a subordinate part of the broader objection procedure.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines
The document's entire purpose is to implement the EDPB's methodology for calculating administrative fines.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The EDPB has developed a methodology consisting of five steps for calculating administrative fines for breaches of the GDPR
The entire document is about the EDPB's methodology for calculating GDPR fines, making it a primary source for this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
proposing to impose a €60,000,000 fine against Criteo
The document is exactly about a proposed administrative fine under GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
imposed two fines against DOCTISSIMO
The document is centered on the fines imposed by the CNIL for GDPR and cookie law violations, making it a primary source for fines.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the Irish Data Protection Commissioner (the “DPC”) imposed a €405,000,000 fine on Instagram
The document's primary content is the announcement of a specific administrative fine imposed for GDPR violations.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the HDPA imposed on Clearview AI the largest fine it has ever imposed in its history of operation, amounting to 20 million euros
The document reports an administrative fine imposed for GDPR violations, directly relevant to fines.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
fined U.S.-based Argon Medical Devices 2.5 million kroner for failing to report a July 2021 data breach within the 72-hour deadline
The document is directly about a fine issued for a GDPR violation, making the fine the central subject.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
dispute resolution mechanism concerns draft decisions prepared by the Lead Data Protection Authority concerning private sector practices and may lead to fines amounting to hundreds of millions of euros
Fines are mentioned only as a potential outcome of the dispute resolution mechanism, not as the subject of the document.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 29 Guidance · all 39 Case Law · all 90 Enforcement · all 26 News