Skip to content
Topic Contested in court

Fines

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Administrative fines imposed for GDPR violations

205 linked items 12 Laws39 Case Law29 Guidance90 Enforcement26 News

Overview

24 sources · Aug 27, 2026

Legal Framework

Administrative fines under the GDPR are governed primarily by Article 83, which sets out the general conditions for imposition, the criteria for determining amounts, and the maximum ceilings. Article 84 complements this by requiring Member States to establish "other penalties" for infringements not subject to administrative fines under Article 83. The European Data Protection Board's mandate under Article 70 includes issuing guidelines to encourage consistent application, and the Board has exercised this through its Guidelines 04/2022 on the calculation of administrative fines.

Article 83(1) establishes the tripartite standard that anchors every fine decision:

"Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive."
— GDPR Art. 83(1)

Article 83(2) enumerates the criteria supervisory authorities must weigh, including the nature, gravity and duration of the infringement, the intentional or negligent character, mitigating actions, the degree of responsibility, previous infringements, cooperation, the categories of data affected, and how the infringement came to light. The maximum fine ceilings differ by tier: up to €10 million or 2% of worldwide annual turnover under Article 83(4), and up to €20 million or 4% under Article 83(5) for the most serious infringements of basic processing principles and data subject rights.

Key Developments

The CJEU in UI v Österreichische Post AG clarified the relationship between fines, other penalties, and civil liability under Article 82. The Court drew a sharp distinction between compensation claims and the punitive regime:

"Articles 83 and 84 of the GDPR, which permit the imposition of administrative fines and other penalties, have essentially a punitive purpose and are not conditional on the existence of individual damage."
— UI v Österreichische Post AG ¶40

This confirms that supervisory authorities need not demonstrate individual harm to impose fines — the punitive and deterrent function operates independently.

In enforcement practice, the Spanish DPA in Caixabank referenced the Article 29 Working Party's WP253 guidelines, noting that recital 148 introduces the concept of "minor infringements" which may still fall under Articles 83(4) or 83(5) but, depending on the Article 83(2) criteria, may not warrant a fine at all. The EDPB's Guidelines 9/2022 on breach notification confirm that for failures to notify breaches under Articles 33 and 34, fines can reach the Article 83(4)(a) ceiling of €10 million or 2% of turnover.

Status of the Debate

This topic is actively contested in court. While the CJEU has confirmed the punitive independence of fines from individual damage in UI v Österreichische Post AG, the methodology for calculating fine amounts remains a live battleground. National supervisory authorities apply divergent approaches to the Article 83(2) criteria, and the EDPB's Guidelines 04/2022 attempt harmonisation but are not legally binding. Challenges to specific fine amounts are working their way through national courts, with parties disputing whether the correspondence between infringement seriousness and fine amount satisfies the proportionality requirement. A future CJEU reference on the calculation methodology — particularly on how turnover thresholds interact with gravity assessments — would resolve the central open question.

Practical Guidance

  • Document mitigation efforts contemporaneously. Article 83(2)(c) requires authorities to consider actions taken to mitigate damage; maintaining a record of remedial measures implemented before and during investigation directly reduces fine exposure.
  • Prioritise cooperation with the supervisory authority. Article 83(2)(f) treats cooperation as a mitigating factor — timely, substantive responses to information requests and proactive remediation can meaningfully reduce the imposed amount.
  • Implement and evidence Article 25 and 32 measures. Article 83(2)(d) links the degree of responsibility to technical and organisational measures; demonstrable data protection by design and security documentation shifts the responsibility assessment in your favour.
  • Track prior infringements and maintain a clean compliance record. Article 83(2)(e) allows authorities to consider previous infringements; recurring violations of the same provisions attract escalating penalties.
  • Distinguish between fine tiers when assessing risk. Infringements of basic processing principles under Article 83(5) carry the highest ceiling (€20 million or 4% of turnover), while security and breach-notification failures under Article 83(4) are capped at €10 million or 2% — allocate compliance investment accordingly.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 83 General conditions for imposing administrative fines Laws GDPR Apr 2016 Administrative fine conditions and amounts
why this is here
Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.

This Article is the central provision in the GDPR governing the imposition and calculation of administrative fines, setting out the criteria, maximum amounts, and conditions for their application.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 04/2022 calculation of administrative fines under the GDPR Guidelines ·EDPB Guidance EDPB May 2023 fine calculation methodology
why this is here
The EDPB has devised the following methodology, consisting of five steps, for calculating administrative fines for infringements of the GDPR.

The entire document is about harmonising the methodology for calculating administrative fines under GDPR Article 83.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 09/2020 relevant and reasoned objection under Regulation 2016/679 Guidelines ·EDPB Guidance EDPB Mar 2021 Challenging fine calculation in objections
why this is here
it is possible that the objection challenges the elements relied upon to calculate the amount of the fine.

The document indicates that an objection may challenge the calculation of fines, but this is only a subordinate part of the broader objection procedure.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

DeFine is a calculator for GDPR fines based on method of the EDPB > DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the… News Kromann Reumert Feb 2022 calculation of administrative fines
why this is here
DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines

The document's entire purpose is to implement the EDPB's methodology for calculating administrative fines.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

GDPR Fines: A Graphic Calculation Guide – Part 1 > European supervisory authorities’ varying practices of calculating GDPR administrative fines can be viewed, on the one hand, as inconsistent and in conflict with the principle… News MLL Legal Jun 2022 Methodology for calculating fines
why this is here
The EDPB has developed a methodology consisting of five steps for calculating administrative fines for breaches of the GDPR

The entire document is about the EDPB's methodology for calculating GDPR fines, making it a primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Health data and use of cookies: DOCTISSIMO fined €380,000 Background information Following a complaint by the PRIVACY INTERNATIONAL association, the CNIL carried out four investigations into DOCTISSIMO. The doctissimo.fr website mainly… News CNIL May 2023 Imposition of fines
why this is here
imposed two fines against DOCTISSIMO

The document is centered on the fines imposed by the CNIL for GDPR and cookie law violations, making it a primary source for fines.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations > The fine is the result of an investigation that began in 2020 and focused on the company’s processing of children’s personal data. Based on press reports, the investigation… News Hunton Andrews Kurth Sep 2022 Imposition of GDPR fine
why this is here
the Irish Data Protection Commissioner (the “DPC”) imposed a €405,000,000 fine on Instagram

The document's primary content is the announcement of a specific administrative fine imposed for GDPR violations.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Greek SA fines Clearview AI for EUR 20M A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings News IAPP Oct 2022 Administrative fine of EUR 20 million
why this is here
the HDPA imposed on Clearview AI the largest fine it has ever imposed in its history of operation, amounting to 20 million euros

The document reports an administrative fine imposed for GDPR violations, directly relevant to fines.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Norway's DPA fines medical device company for breach notification violation > Norway's data protection authority, the Datatilsynet, fined U.S.-based Argon Medical Devices 2.5 million kroner for failing to report a July 2021 data breach within the 72-hour… News IAPP Mar 2023 Administrative fine imposed
why this is here
fined U.S.-based Argon Medical Devices 2.5 million kroner for failing to report a July 2021 data breach within the 72-hour deadline

The document is directly about a fine issued for a GDPR violation, making the fine the central subject.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

EDPB: Lack of resources puts enforcement of individuals’ data protection rights at risk News EDPB Sep 2022 fines in dispute resolution
why this is here
dispute resolution mechanism concerns draft decisions prepared by the Lead Data Protection Authority concerning private sector practices and may lead to fines amounting to hundreds of millions of euros

Fines are mentioned only as a potential outcome of the dispute resolution mechanism, not as the subject of the document.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 29 Guidance · all 39 Case Law · all 90 Enforcement · all 26 News