# Fines — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/boetes
> Sources are cited per item. Verify against the official texts before relying on them.

Administrative fines imposed for GDPR violations

## Overview

## Legal Framework

Article 83 GDPR establishes the general conditions under which supervisory authorities may impose administrative fines for GDPR violations. The provision sets a two-tier maximum penalty structure. Under Article 83(4), violations of controller and processor obligations under Articles 8, 11, 25–39, 42, and 43 are subject to fines up to €10 million or, for undertakings, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. Article 83(5) elevates the ceiling to €20 million or 4% of worldwide annual turnover for violations of basic principles for processing (Articles 5, 6, 7, 9), data subject rights (Articles 12–22), transfers to third countries (Articles 44–49), and non-compliance with orders or processing restrictions imposed by supervisory authorities.

Article 83(2) requires authorities to consider the nature, gravity, and duration of the infringement, the number of data subjects affected, the level of damage suffered, the intentional or negligent character of the infringement, mitigating or aggravating factors, and the degree of cooperation with the authority. Article 83(3) provides that fines may be imposed in addition to, or instead of, corrective measures under Article 58(2). The AI Act (Article 100) and NIS2 (Article 34) replicate this administrative-fine model for their respective regulatory domains, applying similar turnover-based ceilings and criteria.

## Key Developments

The CJEU in *UI v Österreichische Post AG* clarified that Articles 83 and 84 GDPR serve a punitive purpose independent of individual damage claims under Article 82. Administrative fines and civil compensation are complementary instruments: fines encourage systemic compliance, while Article 82 actions reinforce operational protection and deter recurrence. This means a controller may face both regulatory fines and civil liability for the same infringement.

The CJEU in *Deutsche Wohnen SE v Staatsanwaltschaft Berlin* confirmed that the turnover-based ceilings apply specifically to "undertakings," drawing on EU competition law concepts to determine whether an entity qualifies. The Court emphasized that the maximum amounts under Article 83(4) and (5) represent hard caps, and authorities must individually calibrate fines below those ceilings based on the Article 83(2) criteria.

The EDPB's Guidelines 04/2022 on the calculation of administrative fines provide a structured methodology, directing supervisory authorities to follow a multi-step process: determine the starting point based on the legal basis and turnover, then adjust upward or downward based on aggravating and mitigating circumstances, and finally check against the statutory maximum. This methodology aims to harmonize divergent national approaches.

The Italian Garante's €850,000 fine against a network of agencies processing data on behalf of Acea Energia demonstrates that liability extends to processors and their sub-processors, and that the interconnected nature of data flows across corporate networks can aggregate exposure significantly.

## Practical Guidance

- **Map your processing activities to the correct fine tier.** Violations of transparency obligations and lawful basis requirements (Articles 5, 6, 12–22) carry the higher 4% ceiling under Article 83(5), while technical and organizational obligation breaches (Articles 25–39) fall under the 2% tier under Article 83(4). Prioritize remediation accordingly.

- **Calculate group-level turnover exposure.** The "undertaking" concept means fines are assessed against the consolidated worldwide annual turnover of the entire corporate group, not the individual subsidiary. Conduct group-wide risk assessments to understand maximum exposure.

- **Document mitigation efforts contemporaneously.** Article 83(2) explicitly rewards cooperation with the supervisory authority and corrective action taken. Maintain audit trails of remediation steps, DPIA outcomes, and internal investigations to demonstrate good faith during enforcement proceedings.

- **Prepare for concurrent civil and administrative exposure.** Following *UI v Österreichische Post AG*, a single infringement can trigger both regulatory fines and data subject compensation claims. Budget for both contingencies in incident response planning.

- **Monitor processor and sub-processor chains.** The Italian Garante enforcement illustrates that liability propagates through processing networks. Contractual indemnities, audit rights, and breach notification clauses with processors must align with your own regulatory exposure under Article 83.

## Legislation (full text of key provisions)

### General conditions for imposing administrative fines on essential and important entities

*Source: NIS2, nis2-art-34-en, 2022-12-14 — https://overview.legal/posts/96449*

### General conditions for imposing administrative fines

*Source: GDPR, gdpr-art-83-en, 2016-04-27 — https://overview.legal/posts/91378*

### Administrative fines on Union institutions, bodies, offices and agencies

*Source: AI Act, aiact-art-100-en, 2024-06-12 — https://overview.legal/posts/93564*

### Recital 168 — enforcement penalties and administrative fines

*Source: AI Act, aiact-rec-168-en, 2024-06-12 — https://overview.legal/posts/94018*

Compliance with this Regulation should be enforceable by means of the imposition of penalties and other enforcement measures. Member States should take all necessary measures to ensure that the provisions of this Regulation are implemented, including by laying down effective, proportionate and dissuasive penalties for their infringement, and to respect the ne bis in idem principle. In order to strengthen and harmonise administrative penalties for infringement of this Regulation, the upper limits for setting the administrative fines for certain specific infringements should be laid down. When assessing the amount of the fines, Member States should, in each individual case, take into account all relevant circumstances of the specific situation, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences and to the size of the provider, in particular if the provider is an SME, including a start-up. The European Data Protection Supervisor should have the power to impose fines on Union institutions, agencies and bodies falling within the scope of this Regulation.

### Recital 129 — competent authority power administrative fines

*Source: NIS2, nis2-rec-129-en, 2022-12-14 — https://overview.legal/posts/96786*

In order to ensure effective enforcement of the obligations laid down in this Directive, each competent authority should have the power to impose or request the imposition of administrative fines.

### Recital 150 — administrative fines for regulation infringements

*Source: GDPR, gdpr-rec-150-en, 2016-04-27 — https://overview.legal/posts/91815*

In order to strengthen and harmonise administrative penalties for infringements of this Regulation, each supervisory authority should have the power to impose administrative fines. This Regulation should indicate infringements and the upper limit and criteria for setting the related administrative fines, which should be determined by the competent supervisory authority in each individual case, taking into account all relevant circumstances of the specific situation, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences and the measures taken to ensure compliance with the obligations under this Regulation and to prevent or mitigate the consequences of the infringement. Where administrative fines are imposed on an undertaking, an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU for those purposes. Where administrative fines are imposed on persons that are not an undertaking, the supervisory authority should take account of the general level of income in the Member State as well as the economic situation of the person in considering the appropriate amount of the fine. The consistency mechanism may also be used to promote a consistent application of administrative fines. It should be for the Member States to determine whether and to which extent public authorities should be subject to administrative fines. Imposing an administrative fine or giving a warning does not affect the application of other powers of the supervisory authorities or of other penalties under this Regulation.

### Recital 148 — Penalties including administrative fines

*Source: GDPR, gdpr-rec-148-en, 2016-04-27 — https://overview.legal/posts/91811*

In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to this Regulation. In a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine. Due regard should however be given to the nature, gravity and duration of the infringement, the intentional character of the infringement, actions taken to mitigate the damage suffered, degree of responsibility or any relevant previous infringements, the manner in which the infringement became known to the supervisory authority, compliance with measures ordered against the controller or processor, adherence to a code of conduct and any other aggravating or mitigating factor. The imposition of penalties including administrative fines should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including effective judicial protection and due process.

### Recital 130 — administrative fine calculation rules

*Source: NIS2, nis2-rec-130-en, 2022-12-14 — https://overview.legal/posts/96788*

Where an administrative fine is imposed on an essential or important entity that is an undertaking, an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU for those purposes. Where an administrative fine is imposed on a person that is not an undertaking, the competent authority should take account of the general level of income in the Member State as well as the economic situation of the person when considering the appropriate amount of the fine. It should be for the Member States to determine whether and to what extent public authorities should be subject to administrative fines. Imposing an administrative fine does not affect the application of other powers of the competent authorities or of other penalties laid down in the national rules transposing this Directive.

### Recital 127 — minimum enforcement powers and proportionate penalties

*Source: NIS2, nis2-rec-127-en, 2022-12-14 — https://overview.legal/posts/96782*

In order to make enforcement effective, a minimum list of enforcement powers that can be exercised for breach of the cybersecurity risk-management measures and reporting obligations provided for in this Directive should be laid down, setting up a clear and consistent framework for such enforcement across the Union. Due regard should be given to the nature, gravity and duration of the infringement of this Directive, the material or non-material damage caused, whether the infringement was intentional or negligent, actions taken to prevent or mitigate the material or non-material damage, the degree of responsibility or any relevant previous infringements, the degree of cooperation with the competent authority and any other aggravating or mitigating factor. The enforcement measures, including administrative fines, should be proportionate and their imposition should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter of Fundamental Rights of the European Union (the ‘Charter’), including the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence.

### Recital 130 — cooperation between lead and local supervisory authorities

*Source: GDPR, gdpr-rec-130-en, 2016-04-27 — https://overview.legal/posts/91775*

Where the supervisory authority with which the complaint has been lodged is not the lead supervisory authority, the lead supervisory authority should closely cooperate with the supervisory authority with which the complaint has been lodged in accordance with the provisions on cooperation and consistency laid down in this Regulation. In such cases, the lead supervisory authority should, when taking measures intended to produce legal effects, including the imposition of administrative fines, take utmost account of the view of the supervisory authority with which the complaint has been lodged and which should remain competent to carry out any investigation on the territory of its own Member State in liaison with the competent supervisory authority.

## Case law

### Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di

*Source: Court of Justice of the European Union, C-654/23, 2025-11-13 — https://overview.legal/posts/132132 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0654*

The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian DPA (ANSPDCP) concerning the scope of "direct marketing" and the customer-relationship exception under Article 13 of the ePrivacy Directive (Directive 2002/58/EC) in relation to GDPR Article 6. The case addressed whether a daily newsletter sent to users who registered on an online platform to access additional content qualifies as a communication "for the purposes of direct marketing" and whether the platform registration constitutes obtaining contact details "in the context of the sale of a product or a service" under Article 13(2). The Court's ruling clarifies the interplay between the ePrivacy Directive's specific consent regime for unsolicited communications and the GDPR's general lawfulness requirements, with the underlying national proceedings involving an administrative penalty imposed by ANSPDCP for processing customers' personal data without consent.

### French Supreme Court upholds €8M CNIL fine against Apple for App Store ad tracking

*Source: Supreme Administrative Court, 2025-10-10 — https://overview.legal/posts/122852 — original: https://gdprhub.eu/index.php?title=CE_-_473833*

Facts — The DPA imposed an €8 million administrative fine on Apple (the controller) in 2022 (CNIL - SAN-2022-025). The DPA found that Apple used identifiers stored on users’ devices to enable personalized advertising in the App Store without first obtaining valid user consent, as required by Article 82 of the French Data Protection Act, which implements Article 5(3) of the ePrivacy Directive. Apple challenged the sanction before the Supreme Administrative Court (Conseil d’État), arguing that the DPA lacked jurisdiction, that the investigation violated Apple’s procedural rights, that the advertising-related processing did not fall within the scope of Article 82, and that the case should be referred to the Court of Justice of the EU. Apple also claimed that the fine was disproportionate. Holding — The court held that reading identifiers stored on user devices for the purpose of delivering personalised advertising constitutes access to information under Article 5(3) of the ePrivacy Directive, requiring the controller to obtain the user’s prior consent. It reasoned that since this operation was to implement personalized advertising it could not fall within the exemptions to the consent requirement. The court found that the national authority was competent because the controller’s establishment within the country contributed to the advertising operations in question. It did so by marketing devices pre-equipped with the App Store where personalized advertising appears and by providing Search Ads Specialists who helped monetize and optimize that advertising space. It also rejected the controller’s claim that the authority had violated its procedural rights, finding that the right to remain silent did not apply during CNIL investigations and that the authority had lawfully carried out the investigation providing sufficient opportunity for the controller to respond. Additionally, the court rejected Apple's request to reference the case to the Court of Justice of the EU stating that there wasn't any reasonable doubt Finally, it held that the €8 million fine was proportionate, noting the scale of the processing, the number of affected users, and the economic significance of the advertising activity.

### Judgment of the Court (Fifth Chamber) of 13 February 2025.#Criminal proceedings against ILVA A/S.#Request for a preliminary ruling from the Vestre Landsret.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 83(4) to (6) and (9) – Concept of an ‘undertaking’ – Parent company and subsidiary – Infringement of that regulation by a subsidiary – Calculation of the amount of the fine – Consideration of the total turnover of the group of which that sub

*Source: Court of Justice of the European Union, C-383/23, 2025-02-13 — https://overview.legal/posts/132149 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0383*

The Court of Justice of the European Union ruled on a preliminary reference from the Danish High Court in criminal proceedings against ILVA A/S, addressing whether the GDPR concept of "undertaking" under Article 83 permits calculating administrative fines based on the total worldwide annual turnover of a corporate group when a subsidiary commits the infringement. The Court held that "undertaking" must be interpreted consistently with EU competition law, meaning a subsidiary and its parent company may constitute a single undertaking where the parent exercises decisive influence over the subsidiary, and therefore the fine may be calculated based on the group's total consolidated turnover. No fine amount was specified in this ruling, as the Court's judgment clarifies the legal framework for fine calculation rather than imposing a specific penalty.

### BVwG - W258 2227269-1/39E

*Source: Federal Administrative Court, 2024-12-27 — https://overview.legal/posts/184564 — original: https://gdprhub.eu/index.php?title=BVwG_-_W258_2227269-1/39E*

Facts — On the 8 January 2019, the Austrian DPA (Datenschutzbehörde – DSB) launched an investigation into the actions of the Austrian postal service as it also had a business license for address publishing and direct marketing. Media reports had claimed that the postal service (the controller) sold data concerning the political affinities of data subjects to third parties. The controller ran a platform entitled “Adress Shop” on which it sold personal data to legal entities. The datasets included names and addresses but more importantly it included data subjects’ affinities to certain things such as an affinity to moving house, an affinity to organic products or how frequently a data subject receives packages. The purpose of the data processing was to sell this data to third parties who would use it for marketing purposes and therefore could avoid scattering losses. In order to create this database, the controller abused its position as postal service provider. In the postal service contract provided to data subjects the controller had included a notice stating that data subject are agreeing to their personal data being processed for marketing purposes. The contract however also included a box which could be ticked in order to refuse the data processing for marketing purposes. One of these affinities was concluded through an affinity score concerning the main political parties in Austria. For example, data subjects would be assessed with either a “very low”, “low”, “high” or “very high” affinity towards the SPÖ (the Socialist Party of Austria), the ÖVP (the Conservative Party of Austria) or any other major political party. The controller calculated this score through combing anonymous survey results, socio-demographic data (e.g., age or level of income and education) and voting results of particular region. On the 20 Febuary 2019, the DSB alleged that the controller had unlawfully processed sensitive data under Article 9 GDPR. The DSB found that the controller could not rely on a legal basis for the processing of this data and that the controller had sold the data to third parties. The DSB issued a fine of fine of €18,000,000 for the processing of sensitive data and other violations. The full details can be found here. On the 25 November 2019, the controller appealed the decision of the DSB to the Austrian Federal Administrative Court (Bundesverwaltungsgericht – BVwG) and alleged that the DSB had inadequately assessed the situation. On the 26 November, the BVwG annulled the decision of the DSB stating that the DSB had failed to name a natural person to whom the actions of the controller could be attributed to. Based on an Austrian provision, namely paragraph 45(1)(3) of the Administrative Penal Code (Verwaltungsstrafgesetz - VStG), in order to fine a legal person for a violation of the GDPR all necessary requirements for the penalization of a natural person must be fulfilled. This finding was however annulled by the Supreme Administrative Court (Verwaltungsgerichtshof – VwGH) on the 1 February 2024. The VwGH explained that although the BVwG correctly applied the national provision, the CJEU case C-807/21 Deutsche Wohnen showed that Article 58(2)(i) GDPR and Article 83 GDPR are excluded from national derogations. Therefore, the BVwG should not have applied the national provision. The case was therefore reverted back to the BVwG. Holding — The BVwG reassessed the case and partly upheld the DSB decision but made the following alterations. Article 9 GDPR data related to political affinities The BVwG confirmed that the controller had at no point in time obtained the consent of the data subject and therefore was processing data in violation of Article 9(1) GDPR since the 25 May 2018. The BVwG held that the controller's conduct had proved negligent. The BVwG noted that the controller had made efforts to apply the GDPR correctly but criticized for example that the DPO had to monitor all processing activities which did not prove an effective monitoring and controlling system as it would require too much time for just one person. The BVwG held that it was clearly unacceptable that the DPO thought that the data processed did not constitute personal data, especially when it was explicitly connected to an individual person. Further, The BVwG found that the controller never conducted an assessment on whether certain affinities could constitute sensitive data under Article 9 GDPR. The BVwG classified this as grossly negligent behaviour on the part of the controller. The BVwG concluded that the controller should have consulted an external expert around the uncertainties it had concerning the correct application of the GDPR. Affinity towards receiving packages In relation to the data processed to assess their affinity for receiving packages, the controller was in a privileged position to have access to the relevant data. However, it then further processed this data contrary to their legal mandate for creating projection models for marketing purposes in violation of Article 6(4) GDPR. The court also held that this violated the principles of fairness and transparency under Article 5(1)(a) GDPR. The BVwG highlighted that the controller knew that its positions as postal service provider and data broker is likely to cause issues, therefore its behaviour was classified as negligent. Affinity towards moving house Assessing whether data subjects were likely to move house differed to the assessment of an affinity towards receiving packages as there was a contractual relationship between the data subject and the controller due to contractual redirection orders. The BVwG assessed that the minimal information provided to data subjects on the processing for marketing purposes, proved to be just about enough as the personal data was made up of a calculation of averages which was then anonymized. The court found that this could be classified as processing which, based on the controllers description, could be expected from the notice included in the contract. In addition, data subjects could easily refuse the data processing. Data Protection Impact Assessment The controller had processed an extensive amount of sensitive data which requires a data protection impact assessment. The controller’s assessment that this data processing was of low risk was therefore faulty. The controller had therefore violated Article 35(3)(b) GDPR and Article 35(7) GDPR. The BVwG held that as the controller had negligently categorized its processing as not concerning any sensitive data, it consequently also proves to have acted negligently in assessing the risks under Article 35 GDPR. The BVwG rejected the controller’s argument that penalization under Article 35 GDPR would result in a double punishment for the same offence. It explained that the general obligations under the GDPR pursue a different aim to the provisions governing lawfulness of the processing. Further, the DPIA is to be conducted prior to processing. Records of processing The faulty and therefore inadequate DPIA resulted in a violation of Article 30(1)(c) GDPR, which requires the records of data processing to include the categories of data processed. The BVwG again assessed that the controller had acted negligently in relation to this aftereffect of its faulty categorization of the processed data. The controller had merely stated that the data would be processed for marketing purposes and this was held to have been inadequate as the controller processed data such as the political affinities. The BVwG held that the controller had failed to provide a full description of all the processed categories. Fine The BVwG reduced the fine to €16 million mainly based on the controller's low annual turnover. Further, the BVwG noted that the political data had only been sold to two political parties which resulted in a limited amount of data subjects being affected.

### Judgment of the Court (Eighth Chamber) of 4 October 2024.#A v Patērētāju tiesību aizsardzības centrs.#Request for a preliminary ruling from the Augstākā tiesa (Senāts).#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation and liability – Unlawful processing of data – Infringement of the right to protection of personal data – Concept of ‘damage’ – Compensation for non-material damage in the form of apologies – Whether

*Source: Court of Justice of the European Union, C-507/23, 2024-10-04 — https://overview.legal/posts/132162 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0507*

The Court of Justice of the European Union issued a preliminary ruling on a reference from the Latvian Supreme Court in Case C-507/23, involving an individual ("A") and the Patērētāju tiesību aizsardzības centrs (Consumer Rights Protection Centre, Latvia) regarding compensation for non-material damage allegedly suffered from unlawful processing of personal data under Article 82(1) GDPR. The Court addressed whether apologies can constitute compensation for non-material damage and whether the controller's attitude and motivation may be considered in assessing the form and level of compensation. No fine was imposed, as the ruling clarifies interpretive questions of EU law for the referring national court.

### Judgment of the Court (First Chamber) of 26 September 2024.#TR v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.#Case C-768/21.

*Source: Court of Justice of the European Union, C-768/21, 2024-09-26 — https://overview.legal/posts/132245 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0768*

In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of the Hessischer Beauftragte für Datenschutz und Informationsfreiheit (HBDI) for declining to exercise corrective powers against Sparkasse X following a personal data breach complaint. The Court clarified the limits of supervisory authorities' discretion under GDPR Articles 57(1) and 58(2), holding that while authorities retain discretion in selecting corrective measures, they are legally obliged to exercise those powers when an infringement is established, and complainants have a right to an effective remedy under Article 77 even where no enforcement action was taken. No fine was imposed in this proceeding, as the ruling addressed the supervisory authority's enforcement obligations rather than penalizing a controller.

### Judgment of the Court (Fourth Chamber) of 11 July 2024.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – First sentence of Article 12(1) – Transparency of information – Article 13(1)(c) and (e) – Obligation o

*Source: Court of Justice of the European Union, C-757/22, 2024-07-11 — https://overview.legal/posts/132250 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0757*

In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the context of proceedings between Meta Platforms Ireland Ltd and the Bundesverband der Verbraucherzentralen und Verbraucherverbände (Consumer Association). The core issue is whether a consumer protection association may bring a representative action under Article 80(2) GDPR without a mandate from specific data subjects and independently of an actual infringement of a data subject's rights, based on a controller's alleged violation of its transparency obligations under Articles 12(1) and 13(1)(c) and (e). The Court held that such an action is permissible, finding that an infringement of the controller's information obligations constitutes an "infringement of the rights of data subjects as a result of the processing" within the meaning of Article 80(2), and that Member States may allow representative actions without requiring a specific data subject's mandate or an actual infringement of individual rights.

### Judgment of the Court (Third Chamber) of 20 June 2024.#AT and BT v PS GbR and Others.#Request for a preliminary ruling from the Amtsgericht Wesel.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation for damage caused by data processing which infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Assessment of t

*Source: Court of Justice of the European Union, C-590/22, 2024-06-20 — https://overview.legal/posts/132253 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0590*

In Case C-590/22, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Amtsgericht Wesel (Germany) in proceedings between individuals AT and BT and tax consultancy PS GbR, concerning whether the claimants could receive compensation under Article 82(1) GDPR for non-material damage (fear and suffering) after their tax return was disclosed to third parties without consent. The Court held that the concept of non-material damage must be interpreted broadly and that compensation under Article 82 does not require the damage to reach a certain threshold of seriousness, nor can the criteria for administrative fines under Article 83 be applied to compensation claims, though the amount of compensation must correspond to the actual harm suffered.

### Judgment of the Court (Third Chamber) of 11 April 2024.#GP v juris GmbH.#Request for a preliminary ruling from the Landgericht Saarbrücken.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Impact of the seriousness of the damage suffered – Liability of the controlle

*Source: Court of Justice of the European Union, C-741/21, 2024-04-11 — https://overview.legal/posts/132262 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0741*

In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject GP and juris GmbH concerning GP's claim for compensation under Article 82 GDPR after the company processed his personal data for marketing purposes despite his objections. The Court held that "non-material damage" under Article 82(1) GDPR must be interpreted broadly and is not subject to a seriousness threshold, that a controller may be exempt from liability under Article 82(3) if it proves it was not in any way responsible for the infringement (including where a person acting under its authority under Article 29 was at fault), and that the criteria for administrative fines under Article 83 GDPR do not apply to the assessment of compensation amounts.

### Judgment of the Court (Third Chamber) of 25 January 2024.#BL v MediaMarktSaturn Hagen-Iserlohn GmbH.#Request for a preliminary ruling from the Amtsgericht Hagen.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by

*Source: Court of Justice of the European Union, C-687/21, 2024-01-25 — https://overview.legal/posts/132272 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0687*

In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht Hagen in proceedings between data subject BL and MediaMarktSaturn Hagen-Iserlohn GmbH concerning alleged non-material damage from personal data transmitted to an unauthorized third party due to employee error. The Court held that a controller's infringement of GDPR security obligations through employee error can give rise to a right to compensation under Article 82, that the severity of the infringement may be relevant to assessing both the appropriateness of protective measures and the existence of damage, and that the concept of non-material damage should be interpreted broadly without requiring a minimum threshold of severity. No fine was imposed, as the ruling addresses interpretation of GDPR provisions rather than administrative penalties.

### Judgment of the Court (Grand Chamber) of 5 December 2023.#Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija.#Request for a preliminary ruling from the Vilniaus apygardos administracinis teismas.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(2) and (7) – Concepts of ‘processing’ and ‘controller’ – Development of a mobile IT application – Article 26 – Joint control – Arti

*Source: Court of Justice of the European Union, C-683/21, 2023-12-05 — https://overview.legal/posts/132280 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0683*

The CJEU Grand Chamber issued a preliminary ruling in Case C-683/21, arising from a dispute between Lithuania's National Public Health Centre (NVSC) and the State Data Protection Inspectorate (VDAI) regarding a fine imposed for GDPR infringements related to a mobile IT application. The Court addressed the interpretation of key GDPR concepts including "processing," "controller," joint control under Article 26, and the conditions for imposing administrative fines under Article 83, particularly the requirement that infringements be intentional or negligent and the liability of controllers for processing carried out by processors. No specific fine amount was addressed in this portion of the judgment, as the ruling provides interpretive guidance to the referring Lithuanian court rather than resolving the underlying penalty.

### Deutsche Wohnen SE v Staatsanwaltschaft Berlin

*Source: CJEU, C-807/21, 2023-12-05 — https://overview.legal/posts/51487 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0807*

Fines can be imposed directly on legal persons without identifying responsible natural person.

## Guidance

### Response to CCIA Europe concerning EDPB guidelines on calculation of fines

*Source: EDPB, response-ccia-europe-concerning-edpb-guidelines-calculation-en, 2025-09-23 — https://overview.legal/posts/51176 — original: https://www.edpb.europa.eu/our-work-tools/our-documents/letters/response-ccia-europe-concerning-edpb-guidelines-calculation_en*

Anu Talus Chair of the European Data Protection Board Claudia Canelles Quaroni Privacy and Safety Lead, CCIA Europe Computer & Communications Industry Association (CCIA) Brussels, 17 September 2025 by e - mail only Subject: Response to your letter regarding a call for revision of the EDPB Guidelines on calculation of administrative fines Dear Ms. Canelles Quaroni , Thank you for your letter of 23 April, in which you provide your views regarding the possible effects of the rec ent CJEU judgment…

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

*Source: EDPB, edpb-guidelines-on-the-criteria-of-the-right-to-be-forgotten-in-the-search-engines-cases-under-th, 2020-07-07 — https://overview.legal/posts/38070 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-52019-on-the-criteria-of-the-right-to-be-forgotten-in-the-search_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria and grounds for exercising the right to erasure (right to be forgotten) specifically in the context of search engine cases under the GDPR. The document details the six grounds under Article 17(1) that allow data subjects to request delisting, alongside the relevant exceptions, such as the right to freedom of expression and information. As a guidance instrument, it does not impose administrative fines but instead aims to harmonize how search engine providers handle and balance delisting requests across the EU.

### EDPB Work Programme 2026-2027

*Source: EDPB, 2026-02-12 — https://overview.legal/posts/125689 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2026-2027_en*

EDPB Work Programme 2026–2027 Adopted on 11 February 2026 EDPB Work Programme 2026-2027 2 The European Data Protection Board The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: • Issuing opinions, guidelines, recommendations and best practices to promote a common understanding of the GDPR and the Law Enforcement Directive (LED); • Advising the European Commission on any…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### EDPB Work Programme 2024-2025

*Source: EDPB, edpb-work-programme-2024-2025-en, 2024-10-09 — https://overview.legal/posts/125711 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2024-2025_en*

The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: 1. In line with the Article 29 of the EDPB Rules of Procedure. This Work Programme is valid from 8 October 2024 until 31 December 2025 and supersedes, for the remaining part of 2024, the previous Work Programme 2023–2024. 2. https://www.edpb.europa.eu/system/files/2024-04/edpb_strategy_2024-2027_en.pdf EDPB Work Programme…

### Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority

*Source: EDPB, edpb-guidelines-for-identifying-a-controller-or-processors-lead-supervisory-authority, 2023-04-17 — https://overview.legal/posts/38046 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82022-on-identifying-a-controller-or-processors-lead-supervisory_en*

The European Data Protection Board (EDPB) adopted Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority, providing updated guidance on the criteria for determining main establishment and the one-stop-shop mechanism under the GDPR. The guidelines address key concepts including cross-border processing, the "substantially affects" threshold, and the steps controllers and processors must follow to identify their lead supervisory authority. This document serves as interpretive guidance with no fines or enforcement outcomes, replacing the prior WP244 guidelines endorsed by the EDPB in 2018.

### EDPB Work Programme 2023-2024

*Source: EDPB, edpb-work-programme-2023-2024-en, 2023-02-22 — https://overview.legal/posts/125868 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2023-2024_en*

EDPB Work Programme 2023/2024 Adopted on 14 February 2023 The European Data Protection Board The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: To issue opinions, guidelines, recommendations and best practices to promote a common understanding of the GDPR and the Law Enforcement Directive (LED); To advise the European Commission on any issue related to the protection of…

## Enforcement decisions

### AZOP (Croatia) - Decision 14-09-2023

*Source: AZOP (Croatia), 2023-09-01 — https://overview.legal/posts/122862 — original: https://gdprhub.eu/index.php?title=AZOP_(Croatia)_-_Decision_14-09-2023*

Facts — The two companies in question, as controllers, made use of cookies on their websites, but failed to inform data subjects visiting their web pages about the legal basis for installing cookies and collected a combined consent for all types of cookies. Information on how to withdraw one's consent was also missing on the cookie banners. Holding — The AZOP found three GDPR infringements by both controllers. First, the AZOP held that, failing to prove the existence of a legal basis for processing of personal data of the visitors of their websites through the use of cookies, the controllers acted contrary to Article 6(1) GDPR. In this, the controllers also failed to collect valid consents by the data subjects visiting their web pages. Namely, the controllers did not require separate consents for each type of cookie according to their functionality and in some cases there was no option to withdraw one's consent. This, according to the AZOP amounted to a violation of Article 7 GDPR. Further, the AZOP established that the controllers did not adequately inform the website visitors about the processing of personal data, i.e. about the use of cookies, the legal basis therefore and the period of storage of their personal data, thereby violating Article 13(1) GDPR and Article 13(2) GDPR. Accordingly, the AZOP decided to impose an administrative fine on each company in line with Article 83(2) GDPR, in the amounts of €20,000 and €30,000 respectively.

### IDdesign A / S: Non-compliance with general data processing principles

*Source: Danish Data Protection Authority (Datatilsynet), 2021-02-12 — https://overview.legal/posts/46137 — original: https://www.enforcementtracker.com/ETid-22*

Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of personal data of approximately 385,000 customers for a longer period than necessary for the purposes for which they were processed. Additionally, the company had not established and documented deadlines for deletion of personal data in their new CRM system. The deadlines set for the old system were not deleted after the

### NAIH fines online store HUF 2M for unclear and incomplete privacy notice

*Source: NAIH (Hungary), 2026-07-22 — https://overview.legal/posts/156361 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-11443-3/2026*

Facts — The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders. The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

### AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator

*Source: AEPD (Spain), 2026-07-13 — https://overview.legal/posts/109001 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202310345*

Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data subject) The duplicate SIM card was delivered to an impersonator after they passed the established protocols for verifying the applicant's identity. The controller appealed the decision by the Spanish DPA to impose a fine because they claimed that they had appropriate security measures. The controller claims that, by focusing on the result, the Spanish DPA is acting under strict liability. The mere fact that identity theft occurred does not equal a lack of due diligence on the part of the controller. The controller also requested a reduction of the fine on the basis of Article 83(5)(a) GDPR because there were no aggravating circumstances and no special categories of data were processed Holding — The Spanish DPA found a violation of Article 6(1) GDPR because issuing a duplicate SIM card and delivering it to a person other than the telephone line holder constitutes the processing of personal data within the meaning of Article 4(1) GDPR without a legal basis because the data subject did not give consent. The DPA ruled that the controller violated their duty of care because the security measures lacked the dilligence required. According to Article 5(2) GDPR (principle of proactive responsibility) the controller must demonstrate compliance to the GDPR. Proactive responsibility means that the measures are compliant to the GDPR under normal circumstances. The controller must also demonstrate that the measures are compliant with the GDPR and that they are effective in the specific context and purposes of processing (Article 24 en 25 GDPR). The controller had a higher standard of care because of a documented risk to SIM swap attacks and the high scale of processing. Recital 74 GDPR states that the controller’s must implement effective and appropriate measures that take into account the nature, scope and context, and purposes of processing. The card allows an impersonator to access additional data through which they can carry out actions with grave consequences. The controller did not demonstrate that their security measures sufficiently protected the data subject. Factual circumstances should have alerted DIGI to the fraud: the SIM card replacement was processed at a physical store in a different province from where the data subject resided. The Spanish DPA flagged that the controller did not ask the reason for issuing the card and they did not verify whether the old SIM card was functioning. Therefore the security measures were not appropriate to prevent'SIM swap attacks' that are prevalent in the telecom context. With regard to to the height of the fine, the Spanish DPA found that no new legal arguments were made that would lead to the reduction of the fine.

### VDAI (Lithuania) - 3R-1143

*Source: VDAI (Lithuania), 2026-06-19 — https://overview.legal/posts/53896 — original: https://gdprhub.eu/index.php?title=VDAI_(Lithuania)_-_3R-1143*

Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other personal data of patients (the data subjects). The first breach potentially concerned 63 data subjects, whereas the latter breach affected approximately 10,000 employees and 383,000 data subjects. The DPA initiated two separate investigations against the controllers in September 2024 and November 2025 respectively and later combined the cases. Holding — The DPA imposed a fine of €450,000 on the first controller it investigated as this company was also the legal successor of the other controller. It held that the controllers had failed to implement appropriate technical and organisational measures to ensure the security of processing and compliance with the principles of integrity and confidentiality. The controller had violated Articles 5(1)(f), 24(1), and 32(1)(b) GDPR. When assessing the GDPR infringements, the DPA took into account that the controllers processed sensitive categories of personal data. The DPA held the controllers lacked adequate security measures for protecting against unauthorised access to an IT system, such as access control and authentication. For instance, passwords used by employees did not reach a certain level of complexity, and multi-factor authentication was not used.

### UODO (Poland) - DKN.5131.34.2023

*Source: UODO (Poland), 2026-06-13 — https://overview.legal/posts/53104 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.34.2023*

Facts — An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained personal data of clients, their employees, and their children (the data subjects), including their names, dates of birth, salary information, and tax declarations. The controller notified the supervisory authority of a data breach in January 2021. The DPA initiated administrative proceedings regarding possible GDPR violations in December 2023. The controller argued that no personal data breach within the meaning of Article 4(12) GDPR had occurred as the unauthorised entity had only accessed and not obtained the personal data in question. Holding — The DPA held that the controller had violated Articles 5(1)(f) and 5(2), 24(1), 25(1), 32(1), and 32(2) GDPR and issued it a fine of € 2,760. First, it pointed out that mere unauthorised access to personal data processed via email constitutes a data breach under Article 4(12) GDPR. Second, the DPA held that the controller had failed to implement appropriate technical and organisational measures to ensure the security of this personal data – it had only taken measures to comply with the aforementioned provisions of the GDPR after the data breach had been notified to the DPA. The controller had not previously conducted a risk assessment. In addition, it had failed to regularly test, measure, and evaluate the effectiveness of the technical and organisational measures implemented. Finally, the DPA found that the processing posed a high risk to the rights and freedoms of data subjects: it affected a large number of individuals and concerned a broad scope of personal data. When determining the amount of the fine, the DPA took into account that there was a clear imbalance between the data subjects and the controller – the data subjects were required to provide personal data to the controller to fulfil obligations under labour law, social security law, and tax law and could not independently control the data. Consequently, the DPA considered the GDPR infringements to be of significant gravity.

### UODO (Poland) - DKN.5131.5.2025

*Source: UODO (Poland), 2026-05-25 — https://overview.legal/posts/184680 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.5.2025*

Facts — A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’) personal data to a specialised entity established for this purpose (the processor). In January 2023, a work laptop belonging to an employee of the processor was stolen from the trunk of a car parked in a parking garage. This resulted in a breach of confidentiality of the data subjects’ personal data, including names, addresses, ID numbers, and land registry numbers. The controller notified this data breach to the DPA later in January 2023. The DPA conducted an investigation and initiated administrative proceedings regarding the GDPR compliance of the processing operations carried out by the controller and the processor in March 2025. Holding — The DPA issued the controller a fine of PLN 21,000 (€4,900) and the processor a fine of PLN 12,500 (€2,900). First, the DPA held that the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of personal data processing – the controller had failed to demonstrate that it had conducted a thorough risk assessment in a manner that would have allowed for the selection of adequate security measures. These infringements resulted in the violations of the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR. Second, the DPA found that the controller had also violated Article 28(1) GDPR: it had failed to verify the adequacy of the technical and organisational measures implemented by the processor. Finally, the DPA came to the conclusion that the processor had infringed Articles 32(1) and 32(2) GDPR in conjunction with Articles 28(3)(c) and 28(3)(f) GDPR. The DPA held that the processor had failed to assist the controller in fulfilling its obligations and contributed to the controller’s GDPR violations. Unlike the controller, the processor had conducted a risk assessment covering the processing operations at issue; however, the processor had not implemented security measures to protect data stored on laptops used outside of its office premises, such as encryption.

### UODO (Poland) - DKE.561.4.2026

*Source: UODO (Poland), 2026-05-22 — https://overview.legal/posts/108997 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKE.561.4.2026*

Facts — The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending beyond the boundary of their property to include public roads and the data subjects’ properties. The DPA decided that the controller had unlawfully processed data subjects’ data. The DPA held that the controller had the obligation to erase the data, and prohibited the controller from future monitoring. The DPA later requested the controller to provide evidence of compliance with the decision, but did not receive a response from the controller. The DPA received a complaint from one of the data subjects, stating that the controller continued to violate the GDPR despite the DPA’s decision. The DPA found that the controller had reinstalled the cameras and continued to cover areas outside their property, even after the cameras were removed by police officers. Holding — The DPA found a violation of Article 5(2) GDPR, as the controller had failed to demonstrate compliance with the DPA’s decision. The DPA stated that the obligation to demonstrate compliance with the principle of lawfulness (Article 5(1)(a) GDPR) extended to complying with decisions from the DPA. The DPA reiterated that the controller processed data subjects’ personal data unlawfully through their surveillance camera. The DPA took into account the small size of the local community and the number of data subjects affected, and concluded that the controller’s continuous monitoring disrupted the community’s functioning by deeply interfering with data subjects’ lives. In addition, the DPA stated that the manner in which the controller used the surveillance footage suggested that the processing purpose was to harass data subjects. The DPA fined the controller PLN 26,711 (approximately €6,174).

## Recent developments

### Annual Report 2024 out now!

*Source: noyb - European Center for Digital Rights, 2025-07-31 — https://overview.legal/posts/53145 — original: https://noyb.eu/en/annual-report-2024-out-now*

Almost 7 years after the GDPR came into force, noyb remains to be one of the leading European forces pushing for the fundamental right to data protection for all users. To date, our legal work has resulted in administrative fines totalling €1.69 billion. Our achievements in 2024 prove once again that we can make an impact: In addition to filing 36 new complaints, we also obtained a number of new decisions from authorities and even a ruling from the European Court of Justice (CJEU). Annual Report

### GDPR Fines: A Graphic Calculation Guide – Part 1

*Source: MLL Legal, 2022-06-07 — https://overview.legal/posts/6303 — original: https://www.mll-news.com/gdpr-fines-a-graphic-calculation-guide-part-1/?lang=en#entry-15*

> European supervisory authorities’ varying practices of calculating GDPR administrative fines can be viewed, on the one hand, as inconsistent and in conflict with the principle of uniform interpretation and application of the GDPR in general and uniform sanction for GDPR infringements in particular, as enshrined in GDPR recital 10, 11 and 13.

### DeFine is a calculator for GDPR fines based on method of the EDPB

*Source: Kromann Reumert, 2022-02-01 — https://overview.legal/posts/6310 — original: https://www.khlaw.com/define#entry-14*

> DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, 12 May 2022, available online; it was subject to a public consultation until 27 June 2022).

### €50 million fine for Google confirmed by French Court

*Source: noyb - European Center for Digital Rights, 2020-06-19 — https://overview.legal/posts/53361 — original: https://noyb.eu/en/eu50-million-fine-google-confirmed-conseil-detat*

Forced Consent & Consent Bypass Background. Following a complaint by noyb and a similar complaint by the French NGO “La Quadrature du Net” the CNIL (the French Data Protection Authority) imposed a 50 million euro fine on Google over the company’s opaque privacy policy and lack of legal basis for personalized ads. This is so far the highest fine adopted by a DPA as a final decision. Nevertheless it is well below the maximum fine under GDPR of 4% of the global turnover of Google (this would be € 3

### BREAKING: CNIL fines Google € 50 Mio based on noyb complaint

*Source: noyb - European Center for Digital Rights, 2019-06-21 — https://overview.legal/posts/53381 — original: https://noyb.eu/en/breaking-cnil-fines-google-eu-50-mio-based-noyb-complaint*

Key Info The French data protection authority (CNIL) just has announced that it has imposed a record fine of € 50 million on Google for violating the GDPR today (Link) The penalty is based on two complaints by noyb.eu and the French NGO ‘La Quadrature du Net’ based on ‘forced consent’ on May 25, 2018 (More Information on the original complaints) Fine of € 50 million is the highest fine for privacy violations so far (the maximum fine under GDPR based on 4% of the turnover of Google would be € 3.7

## Literature

### Unveiling transparency in data protection enforcement across the EU: Assessing the level and quality of disclosure of GDPR fines by data protection authorities

*Source: European Law Journal, 2025-10-01 — https://overview.legal/posts/132503 — original: https://doi.org/10.1111/eulj.70008*

Abstract Despite the increasing recognition of data protection rights across the European Union (EU), evidence suggests they are often underenforced, thereby undermining the effectiveness of the General Data Protection Regulation (GDPR). This article shows that an often neglected aspect in GDPR enforcement is the variability in transparency exhibited by data protection authorities across EU Member States concerning the disclosure of fines. To bridge this research gap, we gathered data from 23 ou

### GDPR: A new challenge for personal data protection

*Source: Bankarstvo, 2017-01-01 — https://overview.legal/posts/132473 — original: https://doi.org/10.5937/bankarstvo1704166m*

stručni članak Erne Mraznica Raiffeisen banka ad Beograd erne.mraznica@raiffeisenbank.rs GDPR - NOVI IZAZOV ZAŠTITE PODATAKA O LIČNOSTI Rezime Dana 4. maja 2016. godine objavljena je Opšta Uredba o zaštiti podataka o ličnosti u Sl. glasniku EU, koja će se primenjivati od 25. maja 2018. godine. Cilj propisa je harmonizacija zaštite podataka o ličnosti na nivou EU, veći stepen kontrole za lica čiji se podaci obrađuju i unapređeno upravljanje savremenim rizicima iz ove oblasti. Banke, po prirodi svog poslovanja, spadaju među najveće rukovaoce podataka o ličnosti i u postupku usklađivanja sa obavezama utvrđenih Uredbom biće u prilici da izvrše punu analizu svog postojećeg regulatornog i infrastrukturnog okvira zaštite podataka o ličnosti. Istovremeno, pruža im se prilika da isprave eventualne nedostatke u postojećim procesima, odnosno da značajno povećaju svest organizacije o standardima zaštite podataka o ličnosti, posebno imajući u vidu zaprećene stroge sankcije za slučaj neusklađenosti. Ključne reči : GDPR, podatak o ličnosti, osnovni principi, prava lica, rukovalac, obrada podataka, transfer podataka, sankcije, usklađivanje JEL : F52, G14 doi: 10.5937/bankarstvo1704166M 166 Bankars

### Perlindungan Hukum Data Pribadi di Era Globalisasi Digital: Studi Perbandingan General Data Protection Regulation Uni Eropa dengan Undang-Undang Perlindungan Data Pribadi Indonesia

*Source: As-Syar i Jurnal Bimbingan & Konseling Keluarga, 2026-07-04 — https://overview.legal/posts/83517 — original: https://doi.org/10.47467/as.v8i3.12817*

Personal data protection has become an increasingly important legal issue due to the rapid development of digital technology and the growing volume of personal data processing activities. Indonesia has enacted Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) as the primary legal framework for personal data protection. However, several limitations remain within its substantive and institutional aspects, requiring further improvement. This study aims to analyze the substantive a

### Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection

*Source: International Journal of Social Sciences and Public Administration, 2025-01-23 — https://overview.legal/posts/132539 — original: https://doi.org/10.62051/ijsspa.v6n1.22*

In the digital age, data breaches have become a significant threat to consumer privacy, prompting the implementation of stringent data protection regulations worldwide. This paper evaluates the effectiveness of two prominent regulatory frameworks, the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, in safeguarding consumer data and responding to data breaches. Through a comparative analysis of their key provisio

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

## Tools

### GDPR Enforcement Tracker (fines and penalties database)

*Source: CMS, 2026-07-17 — https://overview.legal/posts/125626 — original: https://www.enforcementtracker.com/*

Continuously updated database by CMS of thousands of GDPR fines and penalties across all member states: authority, amount, date, sector, violated articles and a summary per decision, with filtering and statistics. The de-facto reference for fine benchmarking.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/boetes · 2026-08-22
