Skip to main content
Praxikon

Article 83: General conditions for imposing administrative fines

Praxikon tracks Article 83 (General conditions for imposing administrative fines) under the GDPR, alongside the EU AI Act, citing the source for every statement.

Chapter VIIIIn force since 25-05-2018

What does Article 83 govern?

Article 83 determines when and how a supervisory authority can impose an administrative fine. Every fine must be effective, proportionate and dissuasive in the individual case (paragraph 1) and can come in addition to, or instead of, the other measures in Article 58(2) (paragraph 2). Paragraph 2 also lists the factors that count when deciding whether to fine and how much, such as the nature, gravity and duration of the infringement, intent or negligence, mitigation of damage, cooperation with the supervisory authority, previous infringements and how the authority learned of the infringement. Paragraphs 4 and 5 divide the GDPR obligations into two categories, each with its own maximum: up to 10 million euro or 2 percent of worldwide annual turnover for, among others, the obligations in Articles 25 to 39, and up to 20 million euro or 4 percent for, among others, the basic principles, data subject rights and transfers, whichever is higher; paragraph 3 caps the total fine for several linked infringements at the maximum for the gravest one. The article exists to strengthen and harmonise enforcement across the EU, with procedural safeguards for whoever receives a fine (paragraph 8 and recitals 148 and 150).

Key term: Effective, proportionate and dissuasive: the three requirements every fine must meet, so that it works, fits the infringement and deters others from doing the same

Directly affects:supervisory authoritycontrollerprocessormember stateCommission

Praxikon’s reading of the text and the recitals; the official text below prevails.

Official text

/
Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.
Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following: (a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them; (b) the intentional or negligent character of the infringement; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32; (e) any relevant previous infringements by the controller or processor; (f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement; (g) the categories of personal data affected by the infringement; (h) the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement; (i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures; (j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.
If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.
Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43; (b) the obligations of the certification body pursuant to Articles 42 and 43; (c) the obligations of the monitoring body pursuant to Article 41(4).
Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9; (b) the data subjects' rights pursuant to Articles 12 to 22; (c) the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49; (d) any obligations pursuant to Member State law adopted under Chapter IX; (e) non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2) or failure to provide access in violation of Article 58(1).
Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.
Without prejudice to the corrective powers of supervisory authorities pursuant to Article 58(2), each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.
The exercise by the supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process.
Where the legal system of the Member State does not provide for administrative fines, this Article may be applied in such a manner that the fine is initiated by the competent supervisory authority and imposed by competent national courts, while ensuring that those legal remedies are effective and have an equivalent effect to the administrative fines imposed by supervisory authorities. In any event, the fines imposed shall be effective, proportionate and dissuasive. Those Member States shall notify to the Commission the provisions of their laws which they adopt pursuant to this paragraph by 25 May 2018 and, without delay, any subsequent amendment law or amendment affecting them.

Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.

What does this mean for you?

Controller

The factors in paragraph 2 partly determine whether you are fined and how much: whether you mitigated the damage to data subjects (point (c)), which technical and organisational measures you had implemented under Articles 25 and 32 (point (d)), whether you cooperated with the supervisory authority (point (f)), whether you notified the infringement yourself (point (h)), and whether you adhere to an approved code of conduct under Article 40 or certification under Article 42 (point (j)). If you infringe several provisions with the same or linked processing operations, the total fine does not exceed the maximum for the gravest infringement (paragraph 3).

Processor

You too can be fined directly: paragraph 4(a) expressly names the processor's obligations, for example those in Articles 25 to 39, and paragraph 5(c) covers the transfer rules in Articles 44 to 49, which also apply to processors. The same factors in paragraph 2 count for you, such as your degree of responsibility and your cooperation with the supervisory authority.

Data Protection Officer

You help the organisation demonstrate the factors in paragraph 2: documented measures under Articles 25 and 32, a working procedure for notifying infringements, and follow-up of earlier measures ordered by the supervisory authority on the same subject (point (i)). You point out that a fine can come in addition to, or instead of, the measures in Article 58(2) (paragraph 2).

Compliance checklist

Related recitals

Cross-references

Frequently asked questions

Connections

What connects to Article 83 GDPR

Themes where this returns

The counterpart in the other law

Case law

Guidelines

Enforcement and fines

Legislation in motion