Table of Contents
Maximum Amount of Fines
The GDPR, depending on the type of specific violation, generally provides for two thresholds regarding the amount of administrative fines:

- up to 10,000,000 EUR, and in the case of an enterprise – up to 2% of its total annual worldwide turnover from the previous financial year, with the higher amount applying;
- up to 20,000,000 EUR, and in the case of an enterprise – up to 4% of its total annual worldwide turnover from the previous financial year, with the higher amount applying.
Additionally, in Poland, for entities in the public finance sector, research institutes, and the National Bank of Poland, there is an upper limit of 100,000 PLN for fines, and for state and local cultural institutions – up to 10,000 PLN.
As can be seen, fines are determined solely by indicating the upper limit of liability - this, in turn, is very high, which gives the authority an exceptionally wide range of options in determining the specific amount of the fine in each individual case.
Authority, or Who?
According to the GDPR, the monitoring and enforcement of the regulation (including the imposition of administrative fines for its violation) in each Member State is the responsibility of an independent public authority that protects the fundamental rights and freedoms of natural persons in relation to the processing of personal data. In the context of the Polish legal system, this is the President of the Polish Data Protection Authority. Anyone who believes that their personal data is being stored or processed unlawfully has the opportunity to report to the President of the Polish DPA, who, depending on the factual circumstances of the specific case, may impose an appropriately determined monetary fine on those responsible for the violations.
No Tariff – Fine Always Calculated Individually
How is the amount of the fine determined? The GDPR states that imposed fines should be effective, proportionate, and dissuasive, and when determining their amount in each individual case, attention must be paid to as many as 11 detailed criteria. The process of arriving at a specific amount is therefore very complicated, which is why the Guidelines of the Article 29 Working Party on the application and determination of administrative fines provide significant insights, as presented and discussed below.
Assessment Criteria, or What the Authority Will Consider
FREE
Reasons for Which the President of the Polish DPA Imposes Fines – 10 Most Important Decisions of the Polish DPA
Watch the webinarNature, Severity, and Duration of the Violation
By establishing two different maximum amounts for administrative fines in the regulation, it is indicated that violations of certain provisions of the regulation may be more serious than violations of other provisions. We also encounter the concept of “minor violations” (recital 148), which do not pose a serious threat to the rights of the individuals whose data are concerned. In such cases, according to the Guidelines, a monetary fine may – though not always – be replaced by a warning. The same possibility – of replacing a monetary fine with a warning – is created when the data controller is an individual, and the threatened monetary fine would constitute a disproportionate burden for them. However, it is always necessary to assess the number of individuals affected by the violation to determine whether it is a single incident or if it involves a more systematic violation or lack of appropriate procedures. The authority will also evaluate the duration of the violation, and in cases where the individual whose data is concerned has suffered damage, it will take into account the extent of that damage.
Intentional or Unintentional Nature of the Violation
Intentional violations are generally considered more serious than unintentional ones, and consequently, they are more frequently associated with the imposition of financial penalties. According to the Guidelines, an intentional violation may include, for example, unlawful processing of data clearly approved by senior management or altering personal data to create a misleading (positive) impression regarding the alleged achievement of certain goals. For obvious reasons, intentional violations of regulations are generally associated with increased liability.
Actions taken to minimize the harm suffered by data subjects
In straightforward terms, with respect to data controllers or data processors who have admitted to a violation and subsequently taken steps to remedy or mitigate the effects of the violations, we can expect some flexibility from the authority. Therefore, it is crucial (and beneficial) to demonstrate a responsible, proactive attitude upon discovering violations.
Degree of responsibility of the data controller or data processor considering technical and organizational measures
Violations can have various causes, and sometimes they cannot be avoided despite the implementation of numerous precautionary measures. For this reason, when assessing the situation, the authority will consider whether the data controller has implemented technical measures in accordance with the principle of data protection by design or the principle of data protection by default, whether organizational measures have been implemented to ensure the effectiveness of this principle at all levels of the organization, whether an appropriate level of security has been ensured, and whether appropriate data protection procedures are known and applied at the relevant management level within the organization. In other words, according to the Guidelines, the supervisory authority must ask itself to what extent the data controller has done everything that could be expected, given the nature, purposes, or scope of the data processing.
Any significant prior violations
Guided by the discussed criterion, the authority must assess how the entity in question has operated thus far, whether the same violation has occurred previously, and whether it was committed in the same manner. All these circumstances can significantly influence the authority's final decision.
Degree of cooperation with the supervisory authority to rectify the violation and mitigate its potential negative effects
Once again, the activity of the data controller or data processor will be subject to the assessment of the authority after a breach has occurred. This time, it will seek answers to the question of whether the entity responded in a specific manner to the requests of the supervisory authority during the investigation phase of this particular case.
Categories of personal data affected by the breach
This is an extremely important and broad criterion. In this part of its considerations, the authority should determine whether the breach concerns the processing of special categories of data, whether the data can be identified directly or indirectly, whether the processing involves data whose dissemination would immediately cause
harm or discomfort to the individual, whether the data is accessible directly without technical safeguards, or whether it is encrypted.
The manner in which the supervisory authority became aware of the breach, in particular,
whether and to what extent the data controller or data processor reported the breach
As indicated in the Guidelines, the supervisory authority may become aware of a breach as a result of proceedings, complaints, articles in the press, anonymous tips, or notifications from the data controller. According to the regulation, the data controller is obliged to notify the supervisory authority of a personal data breach. Merely fulfilling this obligation by the data controller cannot be interpreted as a mitigating factor. Conversely, a data controller who has demonstrated negligence by failing to fulfill the notification obligation may, according to the supervisory authority, deserve a more severe sanction. In other words, it is advisable to report breaches in order not to worsen one's situation.
Compliance with remedial measures previously applied by the authority
in the same case
DPIA and risk analysis.
How to do it?
Application of approved codes of conduct or approved certification mechanisms
According to the Guidelines, if the data controller or data processor has adhered to an approved code of conduct (created to clarify and facilitate the proper application of the GDPR), the supervisory authority may be convinced that the community applying the code, responsible for its management, will take appropriate actions against its member. Therefore, the supervisory authority may consider such measures to be sufficiently effective, proportionate, or deterrent in the given case, without the need to impose additional measures by the authority itself.
Any other aggravating or mitigating factors relevant to the circumstances of the case, such as financial benefits obtained directly or indirectly in connection with the violation or losses avoided
The authority will take into account all previously unmentioned circumstances that may be relevant to the case, including information about the financial benefits obtained as a result of the violation. The latter may be particularly significant for supervisory authorities, as such benefits cannot be compensated through non-monetary means. Consequently, the fact that the entity has gained benefits from the violation of the regulation may constitute a clear basis for the imposition of a monetary penalty.
A few words of summary
As can be seen, decisions regarding the amount of a specific penalty for violations of the GDPR are made after a very detailed analysis of the factual situation in each individual case. It is worth remembering that a proactive attitude of the entity that has experienced a violation is usually assessed in its favor and may positively influence the final amount of the penalty. For this reason, even in the face of indisputable violations, it is always worthwhile to attempt to assist oneself by cooperating with the authority, reporting violations, or taking actions aimed at minimizing the effects – all of this is also taken into account and can significantly affect the amount of the penalty or even the decision not to impose it.
Check what you remember - for the correct answer reward!
What should the monetary penalties imposed under the provisions of the GDPR be like:


