Short Reads

Countdown 1 day until GDPR : Will administrative fines for violation of the GDPR increase compared to the fines imposed by current national regimes?

Stibbe - Will administrative fines for violation of the GDPR increase

Countdown 1 day until GDPR : Will administrative fines for violation of the GDPR increase compared to the fines imposed by current national regimes?

24.05.2018 EU law

Only 1 more day to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Will administrative fines for violation of the GDPR increase compared to the fines imposed by current national regimes?

The maximum level of administrative fines will effectively increase compared to the fines imposed by current national regimes. The GDPR sets two categories of administrative fines.

Some violations, including violations concerning aspects such as privacy by design and privacy by default, records processing activities, security, personal data breach notifications, data protection impact assessments, the ​designation of a data protection officer etc., are subject to administrative fines up to EUR 10 million or up to 2% of the total worldwide annual turnover of the preceding financial year of the undertaking, whichever is higher.

Other violations, including violations concerning the basic principles for lawful processing, the conditions for valid consent, data subjects’ rights, transfers of data outside the EU, etc., are subject to administrative fines up to EUR 20 million or up to 4% of the total worldwide annual turnover of the preceding financial year of the undertaking.

Nevertheless, the GDPR puts forward as a key principle that each supervisory authority must ensure that the administrative fines in each case must be effective, proportionate, and dissuasive with respect to the violation. When deciding whether to impose an administrative fine and on the amount thereof, regard should be given to the specific circumstances of the violation, including the nature, gravity, and duration of the infringement, the intentional or negligent character, the degree of responsibility, any previous infringements, the financial benefits gained, etc.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

07.12.2018 BE law
GDPR-roundtable on practical questions encountered during implementation

Roundtable - After the success of the roundtable sessions we held before the GDPR took effect (in May this year), our TMT team is enthusiastic about the session of 7 December, focusing on the lessons we have learned from working on multiple GDPR-matters in the past year. We will tackle some practical questions that we have encountered and that are not or cannot be readily answered by the new regulation.

Read more

07.12.2018 BE law
Virtual Currency Regulation Law Review

Articles - The first edition of the Virtual Currency Regulation Law Review is intended to provide a practical, business-focused analysis of recent legal and regulatory changes and developments, and of their effects, and to look forward at expected trends in the area of virtual currencies on a country-by-country basis.

Read more

Our website uses cookies: third party analytics cookies to best adapt our website to your needs & cookies to enable social media functionalities. For more information on the use of cookies, please check our Privacy and Cookie Policy. Please note that you can change your cookie opt-ins at any time via your browser settings.

Privacy – en cookieverklaring