Price list of fines, or how much will we actually pay for violating personal data protection principles?

14 May 2019

The consequences arising from the GDPR for acting contrary to regulations concerning the protection of personal data primarily include exorbitant financial penalties – reaching up to 20 million euros or 4% of the total annual worldwide turnover. However, European regulations only establish general frameworks for the threat, leaving the determination of the amount of penalties to national authorities.

In an effort to standardize the scale of sanctions applied, on February 19, 2019, the Dutch data protection authority (Dutch Autoriteit Persoonsgegevens) issued a regulation regarding administrative monetary penalties, commonly referred to as their “price list” or “tariff.” Based on the guidelines established by the Article 29 Working Party regarding the application and determination of administrative monetary penalties dated October 3, 2017, financial penalties serve as a fundamental tool for enforcing the newly introduced law by the relevant supervisory authorities.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
Furthermore, the act indicates the competence of the European Data Protection Board (EDPB) to shape the system for imposing financial penalties that are a consequence of violations of GDPR provisions.

Despite nearly a year having passed since the European regulation came into force, the EDPB has yet to establish any principles for calculating monetary penalties. Consequently, the supervisory authority in the Netherlands decided to issue its own general administrative provisions regarding the determination of the amount of these sanctions (regulation of the data protection authority on administrative monetary penalties 2019).

The Dutch are pioneers in this type of instruction; however, it is undeniable that supervisory authorities in other countries will draw from the price list presented to them—at least until further similar documents emerge. Therefore, it is worth outlining the rules that the Polish President of the Polish Data Protection Authority will likely follow when imposing additional financial penalties.

Key Categories

A critical element of the structure of the act issued by the Dutch authority is the categorization of individual provisions and their reference to specific monetary penalty rates. The provisions of the GDPR, as well as a number of national acts whose violation carries a fine, have been classified according to their maximum amount. Potential actions subject to fines have been divided into four categories, taking into account the severity of the violated norm. This is determined based on an objective assessment of the value of the provisions, their place in the legislative hierarchy, as well as the public goals and interests that the specific regulations serve. Each category has been assigned specific monetary penalty rates.

READ MORE: Managing Breaches
Article

Description



Category


General Data Protection Regulation

  

art. 8

Conditions for a child's consent in the case of information society services.II

art. 29

Processing on behalf of the data controller or data processor.I: if the violator is a natural person
II: if the violator is a legal person or part of a legal person

art. 30, subject to paragraph 3

Records of processing activities of personal dataII

art. 31

Cooperation with the supervisory authorityIII

art. 32

Security of processingII

art. 33, subject to paragraph 3

Notification of a personal data breach to the supervisory authorityIII

art. 37, paragraph 7

Designation of a Data Protection OfficerI

Fragment of Annex 1 to the regulation of the data protection authority regarding administrative monetary penalties

READ MORE: How much is this incident?

Only a million?

During the analysis of the tariff, particular attention is drawn to the disproportion between the maximum penalty rate adopted by the Dutch supervisory authority (1 million euros) and that provided for by the GDPR (20 million euros). Does this mean that the regulation in question prevents the imposition of a penalty higher than one million euros? Not at all – if justified by the circumstances, and if the maximum rate provided for by the regulation in a given situation is deemed inappropriate by the supervisory authority, it is permissible to impose sanctions exceeding the specified amount. In conclusion, it should be stated that the indicated rates are merely suggested values, not ultimately determining the shape of decisions issued by supervisory authorities.


Category I


Amount of possible fine
between € 0 and € 250,000


Basic fine: € 125,000


Category II


Possible fine amount
between € 150,000 and € 600,000


Basic fine: € 375,000


Category III


Possible fine amount
between € 350,000 and € 900,000


Basic fine: € 625,000

The amount of the basic fine for offenses for which the maximum penalty is € 900,000

Further Instructions

Regardless of the multipliers indicated in the form of tables, which constitute annexes to the regulation, the Dutch authority has also constructed general guidelines regarding the imposition of sanctions, describing their content in the act. According to the authority's guidelines, the amount of the imposed penalty should be proportional and sufficiently deterrent both for the perpetrator (specific prevention) and for potential perpetrators (general prevention). The Autoriteit Persoonsgegevens also emphasizes the admissibility of considering a range of factors related to the specific case when making a decision, which may influence the extent of the imposed sanctions. Any mitigating or aggravating circumstances, which are reflected in the penalty rate adopted by the competent authority, have been enumerated in the discussed regulation. Namely, when determining the amount of the monetary penalty, the imposing authority should take into account in each case:

  1. the nature, severity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question, as well as the number of affected individuals whose data are concerned, and the extent of the damage suffered by them;
  2. the intentional or unintentional nature of the infringement;
  3. measures taken by the data controller or data processor to mitigate the damage suffered by the individuals whose data are concerned;
  4. the extent of the responsibility of the data controller or data processor, taking into account the technical and organizational measures implemented in accordance with Article 25 and 32 of the GDPR;
  5. previous significant violations committed by the data controller or data processor;
  6. the degree of cooperation with the supervisory authority to remedy the violation and mitigate its potential negative effects;
  7. categories of personal data affected by the violation;
  8. the manner in which the supervisory authority became aware of the violation, in particular whether and to what extent the data controller or data processor reported the violation;
  9. compliance with the measures specified in Article 58(2) of the GDPR that were previously taken against the data controller or data processor in relation to the same matter;
  10. the application of approved codes of conduct, in accordance with Article 40 of the GDPR, or approved certification mechanisms, in accordance with Article 42 of the GDPR;
  11. any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained directly or indirectly in connection with the violation or losses avoided.

DPO role - it transfers well

Considering the mitigating or aggravating circumstances mentioned, the authority determines the amount of the fine by increasing the base amount (within permissible limits) or reducing it (to the prescribed minimum amount). Another accompanying assumption (or at least one that should accompany) the imposition of the aforementioned administrative fines is the principle of proportionality. This obliges the authority issuing the decision to take into account the financial circumstances of the offender when determining the amount of the fine.

In the case of establishing a negative financial situation of the fined entity, the authority may minimize the monetary penalty. In this context, the Dutch authority also refers to the provisions introducing the GDPR, which establish the requirement to consider the needs of small, medium, and micro-enterprises in the application of the regulations.

Dangerous Recidivism

A particular increase in the penalty may be applied in the case of a specific entity returning to committing violations, known as recidivism. The competent authority may then increase the penalty by as much as 50%, exceeding the established limits of the penalty applicable in a given situation. The application of the recidivism construct in proceedings related to personal data protection is undoubtedly an instrument that allows for the realization of the principles of prevention governing this process, both specific and general, although on the other hand – it is very unfavorable for the entities bearing the related consequences.

What next?

The regulation issued by the Dutch authorities will undoubtedly serve as a guideline for other European authorities when imposing further administrative fines. However, will other countries follow the lead of the Dutch data protection authority and create their own penalty schedules, or will they be satisfied with the already prepared document? Given the essence of the GDPR and its fundamental objectives, it seems that synchronizing national legal orders, also in terms of the decisions issued, would be a very reasonable solution, facilitating the application of the law not only for supervisory authorities but also for entities implementing it in their daily activities.

Meanwhile, local supervisory authorities are increasingly resorting to monetary penalties. Whether this trend will influence the unification of case law remains to be seen in the coming years, or perhaps even months.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.