Article 83: General conditions for imposing administrative fines
Praxikon tracks Article 83 (General conditions for imposing administrative fines) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 83 govern?
Article 83 determines when and how a supervisory authority can impose an administrative fine. Every fine must be effective, proportionate and dissuasive in the individual case (paragraph 1) and can come in addition to, or instead of, the other measures in Article 58(2) (paragraph 2). Paragraph 2 also lists the factors that count when deciding whether to fine and how much, such as the nature, gravity and duration of the infringement, intent or negligence, mitigation of damage, cooperation with the supervisory authority, previous infringements and how the authority learned of the infringement. Paragraphs 4 and 5 divide the GDPR obligations into two categories, each with its own maximum: up to 10 million euro or 2 percent of worldwide annual turnover for, among others, the obligations in Articles 25 to 39, and up to 20 million euro or 4 percent for, among others, the basic principles, data subject rights and transfers, whichever is higher; paragraph 3 caps the total fine for several linked infringements at the maximum for the gravest one. The article exists to strengthen and harmonise enforcement across the EU, with procedural safeguards for whoever receives a fine (paragraph 8 and recitals 148 and 150).
Key term: Effective, proportionate and dissuasive: the three requirements every fine must meet, so that it works, fits the infringement and deters others from doing the same
Directly affects:supervisory authoritycontrollerprocessormember stateCommission
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
The factors in paragraph 2 partly determine whether you are fined and how much: whether you mitigated the damage to data subjects (point (c)), which technical and organisational measures you had implemented under Articles 25 and 32 (point (d)), whether you cooperated with the supervisory authority (point (f)), whether you notified the infringement yourself (point (h)), and whether you adhere to an approved code of conduct under Article 40 or certification under Article 42 (point (j)). If you infringe several provisions with the same or linked processing operations, the total fine does not exceed the maximum for the gravest infringement (paragraph 3).
Processor
You too can be fined directly: paragraph 4(a) expressly names the processor's obligations, for example those in Articles 25 to 39, and paragraph 5(c) covers the transfer rules in Articles 44 to 49, which also apply to processors. The same factors in paragraph 2 count for you, such as your degree of responsibility and your cooperation with the supervisory authority.
Data Protection Officer
You help the organisation demonstrate the factors in paragraph 2: documented measures under Articles 25 and 32, a working procedure for notifying infringements, and follow-up of earlier measures ordered by the supervisory authority on the same subject (point (i)). You point out that a fine can come in addition to, or instead of, the measures in Article 58(2) (paragraph 2).
Compliance checklist
Related recitals
In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead o...
(149)Member States should be able to lay down the rules on criminal penalties for infringements of this Regulation, including for infringements of national rules adopted pursuant to and within the limits o...
(150)In order to strengthen and harmonise administrative penalties for infringements of this Regulation, each supervisory authority should have the power to impose administrative fines. This Regulation sho...
(151)The legal systems of Denmark and Estonia do not allow for administrative fines as set out in this Regulation. The rules on administrative fines may be applied in such a manner that in Denmark the fine...
(152)Where this Regulation does not harmonise administrative penalties or where necessary in other cases, for example in cases of serious infringements of this Regulation, Member States should implement a ...
Cross-references
Frequently asked questions
Connections
What connects to Article 83 GDPR
Themes where this returns
The counterpart in the other law
Case law
- Council of State upholds 6,000 euro DPA fine for recruitment firm
2024-05-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
2023-12-05 · final, Hof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft Berlin
- Land Hessen: the supervisory authority need not always fine where the organisation already remedied the breach
2024-09-26 · final, Hof van Justitie van de EU (Eerste kamer), TR tegen Land Hessen
- Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
2025-09-24 · final, Raad van State, Afdeling bestuursrechtspraak
Guidelines
- Consultation on the Dutch DPA's enforcement policy (April 2026)
2026-04-13 · under consultation, Autoriteit Persoonsgegevens
Enforcement and fines
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
Legislation in motion
- Amendment to the Dutch GDPR Implementation Act: DPA must publish GDPR sanctions from 1 September 2026
2026-09-01 · in force, Wetgever (Tweede Kamer) en Autoriteit Persoonsgegevens