Skip to main content
Praxikon

Ruling

Land Hessen: the supervisory authority need not always fine where the organisation already remedied the breach

Date
Status
final
Body
Hof van Justitie van de EU (Eerste kamer), TR tegen Land Hessen
Reference
C-768/21, ECLI:EU:C:2024:785

What it is about

Question: must a supervisory authority, after an established breach (a bank employee looked at customer data without reason), always take corrective action and impose a fine when a data subject asks for it? Ruling: no. The authority need not adopt a corrective measure or a fine where that is not appropriate, necessary or proportionate to remedy the shortcoming and ensure full compliance, for instance because the controller immediately took measures to prevent recurrence. Its discretion is limited by the need for a high and consistent level of protection.

What this means in practice

Fast and demonstrable self-correction after an incident pays off: it can prevent a fine. Have an incident procedure in which you remove the cause, prevent recurrence, document disciplinary or technical measures and substantiate the notification to the authority. Data subjects have no right to have the offender fined; they can have the authority's decision reviewed.

The GDPR articles concerned

Source: EUR-Lex, arrest C-768/21checked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Themes where this returns

Case law

Guidelines

Enforcement and fines

Legislation in motion