Ruling
Land Hessen: the supervisory authority need not always fine where the organisation already remedied the breach
- Date
- Status
- final
- Body
- Hof van Justitie van de EU (Eerste kamer), TR tegen Land Hessen
- Reference
- C-768/21, ECLI:EU:C:2024:785
What it is about
Question: must a supervisory authority, after an established breach (a bank employee looked at customer data without reason), always take corrective action and impose a fine when a data subject asks for it? Ruling: no. The authority need not adopt a corrective measure or a fine where that is not appropriate, necessary or proportionate to remedy the shortcoming and ensure full compliance, for instance because the controller immediately took measures to prevent recurrence. Its discretion is limited by the need for a high and consistent level of protection.
What this means in practice
Fast and demonstrable self-correction after an incident pays off: it can prevent a fine. Have an incident procedure in which you remove the cause, prevent recurrence, document disciplinary or technical measures and substantiate the notification to the authority. Data subjects have no right to have the offender fined; they can have the authority's decision reviewed.
The GDPR articles concerned
Source: EUR-Lex, arrest C-768/21checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
Case law
- Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
2023-12-05 · final, Hof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft Berlin
- Reddit's summary proceedings against the DPA over a penalty order and legal privilege dismissed
2026-03-04 · status not established, Rechtbank Den Haag, voorzieningenrechter
- Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
2025-09-24 · final, Raad van State, Afdeling bestuursrechtspraak
- Council of State upholds 6,000 euro DPA fine for recruitment firm
2024-05-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
2024-03-26 · final, Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
- Schrems II: Privacy Shield invalid, transfers under standard clauses only with essentially equivalent protection
2020-07-16 · final, Hof van Justitie van de EU (Grote kamer), Data Protection Commissioner tegen Facebook Ireland Ltd en Maximillian Schrems
- Lindenapotheke: competitors may sue over GDPR breaches and pharmacy order data are health data
2024-10-04 · final, Hof van Justitie van de EU (Grote kamer), ND tegen DR (twee Duitse apothekers)
Guidelines
- Consultation on the Dutch DPA's enforcement policy (April 2026)
2026-04-13 · under consultation, Autoriteit Persoonsgegevens
- Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)
2019-11-27 · in force, Autoriteit Persoonsgegevens (AP)
Enforcement and fines
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Amendment to the Dutch GDPR Implementation Act: DPA must publish GDPR sanctions from 1 September 2026
2026-09-01 · in force, Wetgever (Tweede Kamer) en Autoriteit Persoonsgegevens
- Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie