GDPR administrative fines — Art. 83 two-tier framework and statutory maximums
The General Data Protection Regulation establishes a two-tier administrative fine framework that empowers each supervisory authority to impose fines up to €20 million or 4 % of total worldwide annual turnover (whichever is higher) for the most serious infringements, and up to €10 million or 2 % of turnover for a defined set of less serious violations. The fine regime is set out in Article 83 GDPR, which mandates that every fine must be "effective, proportionate and dissuasive" in each individual case (Art. 83(1)).
Two-tier structure
Article 83(4)–(6) GDPR categorizes infringements by substantive gravity. The lower tier (Art. 83(4)) — €10 million or 2 % of turnover — applies to infringements of controller and processor obligations (Arts. 8, 11, 25–39, 42, 43), processor obligations under Art. 28, certification-body obligations under Arts. 42 and 43, and monitoring-body obligations under Art. 41. The higher tier (Art. 83(5)) — €20 million or 4 % of turnover — covers violations of the basic processing principles (Art. 5), lawful bases for processing (Art. 6), special-category data safeguards (Art. 9), data-subject rights (Arts. 12–22), and international-transfer rules (Arts. 44–49). Infringement of a supervisory-authority order under Art. 58(2) also triggers the higher tier (Art. 83(6)).
Turnover calculation and the "undertaking" concept
The Court of Justice of the European Union held in Deutsche Wohnen (C-807/21, 5 December 2023) and ILVA (C-383/23, 13 February 2025) that the statutory maximum is calculated on the basis of the total worldwide annual turnover of the "undertaking" within the meaning of EU competition law (Arts. 101 and 102 TFEU), not the turnover of the legal entity that is the controller. An undertaking comprises any entity engaged in economic activity, irrespective of legal form, and may include a parent company and its subsidiaries acting as a single economic unit. The Court ruled that only a fine which takes into account the actual or material economic capacity of the addressee can satisfy the Art. 83(1) requirement that the fine be effective, proportionate, and dissuasive.
Fault requirement
The CJEU confirmed in Deutsche Wohnen and Nacionalinis visuomenės sveikatos centras (C-683/21, 5 December 2023) that a supervisory authority may impose an administrative fine under Art. 83 only where the controller or processor intentionally or negligently committed the infringement. Although fault is not listed among the threshold conditions in Art. 83(4)–(6), it appears as a mandatory consideration in Art. 83(2)(b) when deciding on the amount of the fine, and the Court held that the structure and purpose of GDPR preclude strict liability.
Corrective powers under Art. 58(2)
Article 58(2) GDPR grants supervisory authorities a menu of corrective powers, including warnings, reprimands, orders to bring processing into compliance, temporary or definitive bans on processing, suspension of data flows to third countries, and the power to impose an administrative fine "in addition to, or instead of" the other measures listed (Art. 58(2)(i)). Article 83(2) mirrors this language: administrative fines "shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of" the other Art. 58(2) measures. A fine is therefore one corrective tool among several, and the supervisory authority retains discretion to combine a fine with an order to cease processing or a compliance deadline.
Art. 83(2) factors
When deciding on the amount of the fine, the supervisory authority must give due regard to a non-exhaustive list of factors set out in Art. 83(2): the nature, gravity, and duration of the infringement; the intentional or negligent character; action taken to mitigate damage; degree of responsibility (technical and organizational measures implemented); previous infringements; degree of cooperation with the supervisory authority; categories of personal data affected; how the authority became aware of the infringement; compliance with prior orders; approved codes of conduct or certification mechanisms; and any other aggravating or mitigating circumstances. The European Data Protection Board's Guidelines 04/2022 on the calculation of administrative fines under the GDPR (adopted 24 May 2023) provide a harmonized five-step methodology: (1) identify sanctionable conduct and infringements; (2) determine a starting point based on the categorization under Art. 83(4)–(6), the seriousness of the infringement, and the turnover of the undertaking; (3) adjust for aggravating or mitigating factors; (4) verify legal maximums; (5) confirm the final amount meets the requirements of effectiveness, dissuasiveness, and proportionality.
Member-State discretion and public authorities
Article 83(7) permits each Member State to decide whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. Article 83(8) allows Member States to lay down the rules on whether and how courts may impose fines under GDPR, and Art. 83(9) confirms that Member States may provide for national rules specifying when a fine may be imposed for infringements not already subject to fines under Art. 83(4)–(6). These provisions are the sole openings for national divergence in the fine regime; the Court has held that Member States may not add substantive conditions — such as requiring prior attribution of the infringement to an identified natural person — beyond those set out in GDPR itself.
Source: Regulation (EU) 2016/679 (GDPR), Articles 58, 83 Source: CJEU, Deutsche Wohnen, C-807/21, EU:C:2023:950 Source: CJEU, ILVA, C-383/23, EU:C:2025:84 Source: CJEU, Nacionalinis visuomenės sveikatos centras, C-683/21, EU:C:2023:949 Source: EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR, Version 2.1
Supervisory authority investigative powers — Art. 58(1) GDPR toolkit for audits, document access, and on-site inspections
Article 58(1) GDPR equips each supervisory authority with a comprehensive set of investigative powers to examine whether a controller or processor is complying with the Regulation. These powers result directly from GDPR and do not require implementation by national law, though Member State procedural law governs the exercise of certain powers—notably access to premises under Art. 58(1)(f). The investigative toolkit is the foundation of enforcement: before a supervisory authority can impose a fine or order corrective action under Art. 58(2), it must first gather the evidence, and Art. 58(1) specifies the means by which it does so.
Six investigative powers under Art. 58(1)
Article 58(1) lists six distinct powers:
(a) Information orders. The supervisory authority may order the controller, the processor, and—where applicable—the controller's or processor's representative to provide any information the authority requires for the performance of its tasks. This power is not limited to documents already in existence; it extends to answers to specific questions and explanations of processing operations. The authority may specify the form (written, electronic, oral testimony) and deadline for the response.
(b) Data protection audits. The supervisory authority may carry out investigations in the form of data protection audits. An audit is a structured review of processing activities, technical and organisational measures, documentation (Records of Processing Activities under Art. 30, Data Protection Impact Assessments under Art. 35), security safeguards, and compliance with data-subject-rights requests. Audits may be triggered by a complaint, a data-breach notification, the authority's own monitoring activity, or coordination with other supervisory authorities under Art. 62 (joint operations).
(c) Review of certifications. The supervisory authority may carry out a review of certifications issued pursuant to Art. 42(7) GDPR. This power allows the authority to verify that a controller or processor holding a GDPR certification (such as a European Data Protection Seal) continues to meet the certification criteria and to investigate complaints alleging that a certified entity is not in compliance.
(d) Notification of alleged infringement. The supervisory authority may notify the controller or processor of an alleged infringement of GDPR. This is a procedural step that formally opens an investigation and triggers the controller's or processor's obligation to cooperate under Art. 31 GDPR. The notification typically specifies the provision(s) allegedly infringed and invites the controller or processor to submit observations.
(e) Access to personal data and information. The supervisory authority may obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks. "Information" includes processing documentation, contracts with processors and sub-processors, records of consent, logs of data-subject-rights requests, breach records, internal policies, training materials, and correspondence with data subjects. The authority may request access in situ or require the controller or processor to transmit copies. Refusal to provide access is itself an infringement: Art. 83(5)(e) GDPR subjects failure to provide access or cooperation under Art. 31 to an administrative fine of up to €20 million or 4 % of total worldwide annual turnover, whichever is higher.
(f) Access to premises and processing equipment. The supervisory authority may obtain access to any premises of the controller and the processor, including to any data processing equipment and means, in accordance with Union or Member State procedural law. This power enables on-site inspections of offices, data centres, servers, workstations, and mobile devices. Because access to premises may engage constitutional protections (inviolability of the home, rights of defence), Member State procedural law typically requires that the inspection be authorised by a court order or conducted with the consent of the controller or processor when the premises are constitutionally protected. The European Data Protection Board's internal document on supervisory-authority duties (EDPB Document 02/2021) confirms that national procedural rules apply to the exercise of this power, subject to the principles of equivalence and effectiveness—national law must not make it excessively difficult or impossible to exercise the rights conferred by GDPR.
Cooperation obligation and consequences of non-compliance
Article 31 GDPR requires the controller, the processor, and—where applicable—the representative to cooperate with the supervisory authority upon request. This obligation applies throughout the exercise of Art. 58(1) investigative powers. Failure to cooperate—such as refusing to answer questions, withholding documents, obstructing an audit, or denying access to premises—is an infringement punishable under Art. 83(5)(e) with a fine of up to €20 million or 4 % of total worldwide annual turnover. In December 2021 the Polish supervisory authority fined Pactum Poland Sp. z o.o. for lack of cooperation after the company accepted one information request but failed to reply and refused to accept three subsequent requests, demonstrating unwillingness to cooperate under Art. 31 and Art. 58(1)(e).
Procedural safeguards and judicial review
Article 58(4) GDPR provides that the exercise of the powers conferred on the supervisory authority pursuant to Art. 58 shall be subject to appropriate safeguards, including effective judicial remedy and due process, set out in Union and Member State law in accordance with the Charter of Fundamental Rights. These safeguards include the right to be heard, the right to access the file, the principle that administrative decisions must be reasoned, and the right to an effective judicial remedy under Art. 78 GDPR. The Court of Justice of the European Union has held that these safeguards do not permit a Member State to add substantive conditions beyond those in GDPR—for example, a national rule requiring that an infringement be attributed to an identified natural person before an investigation may proceed would undermine the effectiveness of Art. 58(1).
Use in cross-border investigations and joint operations
When a supervisory authority is the lead supervisory authority for a cross-border processing case under Art. 56 GDPR, it exercises its Art. 58(1) investigative powers in coordination with concerned supervisory authorities under Art. 60. Article 62 GDPR authorises joint operations: supervisory authorities may conduct joint investigations and enforcement actions, and members or staff of the supervisory authority of one Member State may exercise investigative powers on the territory of another Member State under the direction and in the presence of members or staff of the host supervisory authority. The European Data Protection Board has established a Support Pool of Experts to facilitate the matching of specialised expertise (forensic IT analysis, cloud-architecture assessment, advertising-technology tracing) with operational needs during complex investigations.
Recital 129 and the objective of consistent enforcement
Recital 129 GDPR explains that supervisory authorities should have "the same tasks and effective powers, including powers of investigation, corrective powers and sanctions" in each Member State in order to ensure consistent monitoring and enforcement of GDPR throughout the Union. The recital emphasises that these powers include the power to bring infringements to the attention of judicial authorities and engage in legal proceedings, and that such powers should include the power to impose a temporary or definitive limitation, including a ban, on processing. The grant of investigative powers under Art. 58(1) is therefore not discretionary: each supervisory authority shall have all of the listed investigative powers, and the exercise of those powers is a core element of the supervisory authority's independence under Arts. 51–54 GDPR.
Source: Regulation (EU) 2016/679 (GDPR), Articles 31, 58, 83 Source: EDPB, Internal Document 02/2021 on SAs duties in relation to alleged GDPR infringements Source: Polish DPA enforcement notice, Pactum Poland Sp. z o.o., 1 December 2021
Private right to compensation — Art. 82 GDPR's three-prong test, no de minimis threshold, and compensatory-only function
Article 82 GDPR establishes a private right to compensation that runs parallel to the administrative enforcement regime under Arts. 58 and 83. Any person who has suffered material or non-material damage as a result of an infringement of GDPR has the right to receive compensation from the controller or processor for the damage suffered (Art. 82(1)). This private enforcement mechanism allows data subjects to bring civil claims directly in national courts, and the compensation regime has generated a substantial body of case law from the Court of Justice of the European Union clarifying the conditions for liability, the burden of proof, the scope of compensable damage, and the methodology for quantifying awards.
Three cumulative conditions for a right to compensation
The CJEU held in Österreichische Post (C-300/21, 4 May 2023) that Art. 82(1) establishes three cumulative conditions that a data subject must satisfy to obtain compensation: (1) an infringement of GDPR, (2) material or non-material damage actually suffered by the data subject, and (3) a causal link between the infringement and the damage. The Court emphasized that a mere infringement of GDPR is not, by itself, sufficient to confer a right to compensation—the data subject must demonstrate that he or she has actually suffered damage as a consequence of the infringement. This principle distinguishes the private compensation regime under Art. 82 from the administrative-fine regime under Art. 83 (which punishes the infringement itself) and from the judicial-remedy rights under Arts. 77 and 78 (which allow a data subject to complain to a supervisory authority or challenge a supervisory authority's decision in court regardless of whether damage has been suffered).
Concept of 'damage' — no de minimis threshold
Recital 146 GDPR provides that "the concept of damage should be broadly interpreted in the light of the case-law of the Court of Justice in a manner which fully reflects the objectives of this Regulation." The CJEU ruled in Österreichische Post (C-300/21, paragraph 51) that Art. 82 GDPR precludes a national rule or practice which makes compensation for non-material damage subject to the condition that the damage suffered by the data subject has reached a certain degree of seriousness—such as a "threshold of seriousness" or a "de minimis threshold." The Court held that imposing a materiality threshold would be contrary to the broad conception of damage chosen by the EU legislature and would undermine the effectiveness of the right to compensation. The ruling has been consistently reaffirmed in subsequent CJEU decisions, including Natsionalna agentsia za prihodite (C-340/21, 14 December 2023), ZQ v Medizinischer Dienst (C-667/21, 21 December 2023), GP v juris GmbH (C-741/21, 11 April 2024), and IP v Quirin Privatbank (C-655/23, 4 September 2025).
Non-material damage — fear of misuse, loss of control, and evidentiary burden
Non-material damage under Art. 82 includes a wide range of harms. Recital 85 GDPR identifies illustrative categories: "loss of control over personal data," "limitation of rights," "discrimination," "identity theft or fraud," "financial loss," "damage to reputation," and "loss of confidentiality of personal data protected by professional secrecy." The CJEU has confirmed that the fear experienced by a data subject with regard to a possible misuse of his or her personal data by third parties can, in itself, constitute non-material damage, provided that the fear is well-founded and the national court verifies that such fear can be deemed to exist in the specific circumstances of the case (Natsionalna agentsia za prihodite, C-340/21, paragraph 46). The Court also confirmed in GP v juris GmbH (C-741/21, paragraph 49) that loss of control over personal data as a result of a data breach constitutes non-material damage, provided the data subject can convincingly demonstrate that such loss of control occurred. However, a purely hypothetical risk of unspecified future harm where no third party has become aware of the personal data does not, by itself, constitute compensable damage (PS (Incorrect address), C-590/22, 20 June 2024, paragraph 35). The data subject bears the burden of proving the existence of damage and the causal link between the infringement and the damage; the CJEU has held that the data subject must show that the consequences of the infringement constitute damage that differs from the mere infringement of GDPR provisions.
Liability regime — fault-based with reversed burden of proof
Article 82 establishes a fault-based liability regime with a reversal of the burden of proof. The CJEU held in ZQ v Medizinischer Dienst (C-667/21, paragraph 38) and GP v juris GmbH (C-741/21, paragraph 41) that liability under Art. 82 requires the existence of a fault committed by the controller or processor, but the fault is presumed and the controller or processor bears the burden of proving that it is not in any way responsible for the event giving rise to the damage. This reversal is codified in Art. 82(3): "A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage." The CJEU has clarified that a controller cannot exempt itself from liability solely by proving that the damage resulted from unauthorized disclosure by a third party (such as a cyberattack) or from the misconduct of an employee or other person acting under the controller's authority (Art. 29 GDPR). To avoid liability, the controller must prove that it complied with all applicable GDPR obligations—including the obligations to implement appropriate technical and organizational measures under Arts. 24, 25, and 32—and that the damage was caused by an event entirely outside the controller's sphere of responsibility.
Quantification of damages — national law subject to effectiveness and equivalence
Article 82 GDPR does not contain any provision defining the rules for the assessment of the amount of damages. The CJEU held in Österreichische Post (C-300/21, paragraph 58) that national courts must apply the domestic rules of each Member State relating to the extent of financial compensation, provided that the principles of effectiveness and equivalence of EU law are complied with. The principle of effectiveness requires that national rules must not make it impossible or excessively difficult for a data subject to exercise the right to compensation. The principle of equivalence requires that claims under Art. 82 GDPR must not be treated less favorably than similar domestic claims. The CJEU emphasized in ZQ v Medizinischer Dienst (C-667/21, paragraph 45) and IP v Quirin Privatbank (C-655/23, paragraph 57) that Art. 82 has an exclusively compensatory function, not a punitive or deterrent function. Consequently, the degree of fault (intentional versus negligent) and the severity of the infringement are not relevant when determining the amount of damages, and the criteria laid down for administrative fines in Art. 83 GDPR do not apply to the calculation of compensation under Art. 82. Damages must ensure full and effective compensation for the harm actually suffered, but punitive damages and awards that exceed full compensation are prohibited. The CJEU confirmed in IP v Quirin Privatbank (C-655/23, paragraph 70) that compensation payable under Art. 82 cannot be awarded, in part or in full, in the form of a prohibitory injunction, since the right to compensation fulfills an exclusively compensatory function whereas the purpose of a prohibitory injunction is preventive.
Joint and several liability; processor's direct liability
Article 82(4) GDPR provides that where more than one controller or processor, or both a controller and a processor, are involved in the same processing and are responsible for any damage caused by processing, each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject. Article 82(5) permits a controller or processor who has paid full compensation to recover from other controllers or processors involved in the same processing the part of the compensation corresponding to their respective share of responsibility, in accordance with the conditions set out in Art. 82(4). This joint-and-several-liability regime ensures that a data subject can recover the full amount of damages from any one of the responsible parties and is not forced to pursue multiple defendants to piece together compensation.
Relationship with administrative enforcement
The private right to compensation under Art. 82 operates independently of the administrative enforcement powers conferred on supervisory authorities under Arts. 58 and 83. Recital 146 states that "the controller or processor should compensate any damage which a person may suffer as a result of processing that infringes this Regulation," and that "the concept of damage should be broadly interpreted." A supervisory authority's decision to impose (or not to impose) an administrative fine on a controller for a GDPR infringement does not affect the data subject's parallel right to bring a civil claim for compensation under Art. 82. The two regimes serve different purposes: administrative fines under Art. 83 are designed to be effective, proportionate, and dissuasive, and the fine amount is informed by the factors in Art. 83(2) (including the degree of fault and the seriousness of the infringement), whereas compensation under Art. 82 is purely compensatory and is measured by the actual damage suffered by the data subject.
Source: Regulation (EU) 2016/679 (GDPR), Article 82 Source: CJEU, Österreichische Post (Non-material damage in connection with the processing of personal data), C-300/21, EU:C:2023:370 Source: CJEU, Natsionalna agentsia za prihodite, C-340/21, EU:C:2023:986 Source: CJEU, ZQ v Medizinischer Dienst, C-667/21, EU:C:2023:1019 Source: CJEU, GP v juris GmbH, C-741/21, EU:C:2024:296 Source: CJEU, IP v Quirin Privatbank, C-655/23, EU:C:2025:655 Source: CJEU, PS (Incorrect address), C-590/22, EU:C:2024:536
Supervisory authority corrective powers — Art. 58(2) GDPR nine-measure enforcement toolkit and discretion framework
Article 58(2) GDPR grants each supervisory authority a comprehensive toolkit of nine distinct corrective powers that it may deploy to remedy GDPR infringements. These powers range from warnings and reprimands to binding orders that halt processing entirely, and they operate alongside—or as an alternative to—the administrative fines imposed under Article 83. The corrective-powers menu is the core enforcement mechanism of GDPR: every enforcement action by a supervisory authority uses one or more of these powers, and practitioners defending or negotiating enforcement must understand which measures the authority can and will impose.
The nine corrective powers under Art. 58(2) GDPR
Article 58(2) provides that each supervisory authority shall have all of the following corrective powers:
(a) Issue warnings. The supervisory authority may issue a warning to a controller or processor that intended processing operations are likely to infringe GDPR. A warning is prospective and precautionary—it addresses planned processing before it occurs. Warnings are non-binding but create a formal record that the authority has flagged the risk.
(b) Issue reprimands. The supervisory authority may issue a reprimand to a controller or processor where processing operations have infringed GDPR. A reprimand is retrospective and declaratory—it formally records that an infringement has occurred. Unlike a warning, a reprimand addresses completed conduct. Reprimands carry no monetary penalty and impose no future obligations beyond the declaration of non-compliance.
(c) Order compliance with data-subject-rights requests. The supervisory authority may order the controller or processor to comply with a data subject's requests to exercise rights under Chapter III (Arts. 12–22). This power is the enforcement backstop for data-subject rights: when a controller refuses or fails to respond to an access request (Art. 15), erasure request (Art. 17), or objection (Art. 21), the data subject may complain to the supervisory authority under Art. 77, and the authority may order the controller to comply.
(d) Order processing into compliance with GDPR. The supervisory authority may order the controller or processor to bring processing operations into compliance with GDPR, where appropriate in a specified manner and within a specified period. This is the general compliance order—it applies to any substantive GDPR obligation (lawful basis under Art. 6, transparency under Arts. 12–14, security under Art. 32, processor contracts under Art. 28, records of processing activities under Art. 30, data protection impact assessments under Art. 35, etc.). The authority specifies the violation, the corrective action required, and the deadline. Failure to comply with an order under Art. 58(2) is itself an infringement subject to a fine of up to €20 million or 4 % of total worldwide annual turnover under Art. 83(6).
(e) Order communication of a personal data breach to data subjects. The supervisory authority may order the controller or processor to communicate a personal data breach to the data subject in accordance with Art. 34 GDPR. This power applies when the controller has failed to notify data subjects of a breach that is likely to result in a high risk to their rights and freedoms.
(f) Impose temporary or definitive processing bans. The supervisory authority may impose a temporary or definitive limitation, including a ban, on processing. This is the most intrusive corrective power: the authority can order a controller to cease processing entirely, either for a defined period (temporary ban, to allow time for compliance) or permanently (definitive ban, when the processing cannot be brought into compliance). A processing ban may be total (all processing activities) or partial (specific processing operations, specific categories of data, or specific purposes). The CJEU held in Facebook Ireland and Schrems (C-311/18, 16 July 2020, paragraph 112) that the supervisory authority must determine which action is appropriate and necessary, taking into account all the circumstances of the specific case and executing its responsibility to ensure GDPR is fully enforced.
(g) Suspend data flows to third countries or international organizations. The supervisory authority may order the suspension of data flows to a recipient in a third country or to an international organization. This power enforces Chapter V (Arts. 44–49, international transfers). The authority may suspend transfers when it determines that the transfer mechanism (Standard Contractual Clauses, Binding Corporate Rules, adequacy decision, or derogation) does not provide adequate protection or has been breached.
(h) Withdraw or suspend certifications and order certification bodies to act. The supervisory authority may withdraw certification or order the certification body to withdraw certification issued pursuant to Arts. 42 and 43, or may order the certification body not to issue certification if the requirements for the certification are not or are no longer met. This power polices the GDPR certification regime: if a controller or processor holds a data-protection seal and the authority determines that the certified entity no longer meets the certification criteria, the authority may revoke the certification or order the certification body to do so.
(i) Impose an administrative fine pursuant to Art. 83. The supervisory authority may impose an administrative fine in addition to, or instead of, the other measures listed in Art. 58(2)(a)–(h), depending on the circumstances of each individual case. Fines are addressed separately in Art. 83 and in the guide section on administrative fines. The key structural point is that a fine is one corrective power among nine—Art. 83(2) mirrors the language of Art. 58(2), providing that fines "shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of" the other corrective measures. A supervisory authority may issue a reprimand without a fine, impose a compliance order with a deadline and reserve the right to fine if the deadline is missed, or combine a fine with a processing ban.
**Discretion, limits, and the duty to act: TR v Land Hessen (C-768/21)**
The CJEU ruled in TR v Land Hessen (C-768/21, 26 September 2024) that supervisory authorities possess discretion as to the manner in which they remedy an infringement, but this discretion is limited by the need to ensure consistent and high-level protection of personal data through strong enforcement. The Court held (paragraphs 37–38) that "the GDPR leaves the supervisory authority a discretion as to the manner in which it must remedy the shortcoming found, since Article 58(2) thereof confers on that authority the power to adopt various corrective measures," and that "the supervisory authority must determine which action is appropriate and necessary, and must do so taking into consideration all the circumstances of the specific case." However, the Court emphasized that this discretion is "limited by the need to ensure a consistent and high level of protection of personal data through strong enforcement of the rules, as is apparent from recitals 7 and 10 of the GDPR." The authority is not required to impose a fine in every case where an infringement is found, but it must react appropriately to remedy the infringement. The CJEU confirmed in SCHUFA Holding (C-26/22 and C-64/22, 7 December 2023, paragraph 57) that when a supervisory authority finds an infringement following investigation of a complaint, it is required to react appropriately to remedy the shortcoming, and each measure should be appropriate, necessary, and proportionate in view of ensuring compliance with GDPR.
Combining corrective measures and enforcement against processors
Article 58(2) applies to both controllers and processors. Processors are directly subject to corrective powers for violations of their own obligations under Arts. 28, 32, and 33 (processor contracts, security, breach notification to the controller). Supervisory authorities routinely combine multiple corrective powers in a single enforcement decision—for example, a reprimand for the infringement, an order under Art. 58(2)(d) to bring processing into compliance within a specified period, and an administrative fine under Art. 58(2)(i).
Recital 129 and uniform powers
Recital 129 GDPR provides that "in order to ensure consistent monitoring and enforcement of this Regulation throughout the Union, the supervisory authorities should have in each Member State the same tasks and effective powers, including powers of investigation, corrective powers and sanctions." The grant of corrective powers under Art. 58(2) is therefore mandatory and uniform—each supervisory authority shall have all nine corrective powers, and Member States may not restrict or dilute those powers through national law (except for the limited public-authority carve-out in Art. 83(7) and the Member State option to provide for court-imposed fines under Art. 83(9) where the national legal system does not allow administrative fines).
Source: Regulation (EU) 2016/679 (GDPR), Articles 58, 83 Source: CJEU, TR v Land Hessen (Obligation to act by the data protection authority), C-768/21, EU:C:2024:785 Source: CJEU, SCHUFA Holding (Discharge from remaining debts), C-26/22 and C-64/22, EU:C:2023:958 Source: CJEU, Facebook Ireland and Schrems, C-311/18, EU:C:2020:559
Judicial remedies — Arts. 77, 78, 79 GDPR three-track procedural rights (complaint to supervisory authority, judicial remedy against authority, judicial remedy against controller/processor)
GDPR establishes three distinct procedural rights: the right to lodge a complaint with a supervisory authority (Art. 77), the right to an effective judicial remedy against a supervisory authority (Art. 78), and the right to an effective judicial remedy against a controller or processor (Art. 79). These remedies operate in parallel to the private right to compensation under Art. 82 and form the core of the EU data protection enforcement regime. Practitioners must understand not only the text of these articles but also key CJEU rulings on how parallel proceedings and complaint handling are coordinated.
Article 77 — Right to lodge a complaint with a supervisory authority
Art. 77 allows any data subject to file a complaint, without proof of damage, with a supervisory authority in the Member State of residence, work, or alleged infringement. The authority must investigate "to the extent appropriate" (Art. 57(1)(f)), inform the complainant of progress and outcome, and provide a reasoned decision. The CJEU (C-132/21, 2023) confirms this remedy is independent of Art. 79 civil actions.
Article 78 — Judicial remedy against a supervisory authority
Art. 78(1) gives a right to challenge legally binding supervisory authority decisions. Art. 78(2) creates a right to judicial remedy if the authority does not inform the complainant on progress/outcome within 3 months. Judicial review is full and encompasses both procedural and substantive assessment (C-26/22 & C-64/22, 2023). This mechanism ensures the complainant is not left without recourse if the authority is inactive or rejected the complaint on formal grounds.
Article 79 — Judicial remedy against controller/processor
Art. 79 allows direct civil actions against a controller or processor for GDPR violations in national courts, either in the controller’s country or the complainant’s habitual residence. This action does not require exhaustion of administrative remedies or proof of damage. It is separate from Art. 82 compensation claims.
Recent CJEU development — Interplay and suspension of proceedings (C-414/24, 18 June 2026)
A recent judgment by the CJEU has materially clarified the operation of these rights: supervisory authorities generally must process Art. 77 complaints even where judicial proceedings have been initiated on the same matter (Art. 79), unless suspension is necessary for effective judicial protection or to avoid conflicting decisions. The authority cannot reject a complaint solely because a corresponding Article 79 lawsuit is pending—the two-track structure remains robust unless national procedural law and effectiveness of protection require suspension. The CJEU rejected automatic dismissal in this scenario, emphasizing that all tracks remain available and concurrent absent a clear conflict. (C-414/24, 18 June 2026)
Implications and practice
For data subjects, this means complaints and judicial claims may be pursued simultaneously or sequentially. Supervisory authorities should actively investigate complaints but may—under clear, justified circumstances—pause handling if there is a real risk of contradictory results from ongoing judicial review. For controllers, there is increased litigation coordination risk, as issues about the same underlying data processing may be litigated in parallel in administration and courts.
Source: Regulation (EU) 2016/679 (GDPR), Articles 77, 78, 79 Source: CJEU, SCHUFA Holding (Discharge from remaining debts), C-26/22 and C-64/22, EU:C:2023:958 Source: CJEU, Nemzeti Adatvédelmi és Információszabadság Hatóság, C-132/21, EU:C:2023:2 Source: CJEU, TR v Land Hessen, C-768/21, EU:C:2024:785 Source: CJEU, Datenschutzbehörde and Dr. G S v Bundesministerin für Justiz and D GmbH, C-414/24, EU:C:2026:625
Mutual assistance, joint operations, and EDPB consistency mechanism under Chapter VII GDPR
Chapter VII GDPR (Arts. 60–67) establishes mandatory procedures for cooperation and consistency between EU supervisory authorities where cross-border processing is involved. These articles set out when and how the Lead Supervisory Authority (LSA), Concerned Supervisory Authorities (CSAs), and the European Data Protection Board (EDPB) interact to ensure consistent enforcement across Member States.
One-stop-shop: Art. 60 GDPR The LSA—generally the authority of the Member State where the main establishment of the controller or processor is located (Art. 56)—must cooperate with all CSAs where cross-border processing occurs. A CSA is any supervisory authority concerned because (a) the data subjects in its Member State are substantially affected or likely to be affected by the processing, or (b) a complaint has been lodged with it (Art. 4(22)). The LSA and CSAs exchange information, seek consensus, and attempt joint resolution. Any CSA may submit a “relevant and reasoned objection” (RRO) to a draft decision. If the LSA does not follow the RRO or consensus fails, referral to the EDPB follows (Art. 60(4)–(6)).
Mutual assistance: Art. 61 GDPR Supervisory authorities must provide each other mutual assistance—sharing information and supporting enforcement—without undue delay, and at the latest within one month of request, with a stated reason required for any delay (Art. 61(8)).
Joint operations: Art. 62 GDPR Authorities may carry out joint operations, including investigations and enforcement measures, particularly where processing substantially affects data subjects in more than one Member State. The LSA or any CSA may invite other authorities to participate (Art. 62(1)).
Consistency mechanism: Arts. 63–65 GDPR Article 63 introduces a consistency mechanism to ensure uniform application of GDPR. Article 64 requires SAs to submit certain types of decisions to the EDPB for opinion. Article 65 empowers the EDPB to resolve disputes—such as unresolved RROs regarding draft decisions, identification of the LSA, or when an LSA does not request/comply with an EDPB opinion—by issuing a binding decision within one month (which may be extended for complex matters). These binding decisions impose obligations on all concerned SAs (Art. 65(2), (3)).
Effect These procedures make a single regulatory outcome binding across the EU for cross-border cases and prevent inconsistent enforcement. The system’s structure allows SAs to coordinate, object, and, when necessary, escalate to the EDPB for a binding, EU-wide resolution, as required by the GDPR text itself.
Source: Regulation (EU) 2016/679 (GDPR), Articles 4, 56, 60–67
Collective representation and nonprofit actions — Art. 80 GDPR's mandate/no-mandate dichotomy, national discretion, and practical effect
Article 80 GDPR introduces the concept of collective representation in EU data protection enforcement, allowing nonprofit bodies, organizations, or associations that satisfy certain criteria to lodge complaints and pursue remedies on behalf of data subjects. The intent is to facilitate the defense of data protection rights at scale, particularly where individual enforcement may be practically or economically challenging for data subjects.
1. Two forms of collective action (Art. 80(1) vs. 80(2))
- Article 80(1) GDPR gives every data subject the right to mandate a qualifying nonprofit to lodge a complaint with a supervisory authority, seek a judicial remedy against a controller or processor, or exercise the rights afforded by arts. 77–79 and 82 on their behalf. The nonprofit must be "properly constituted according to the law of a Member State, have statutory objectives which are in the public interest, and be active in the field of the protection of data subjects’ rights and freedoms.”
- Article 80(2) GDPR permits but does not require Member States to allow such organizations to exercise these rights independently—without the mandate of a data subject—when they consider that the rights of multiple individuals have been infringed as a result of processing. This “no mandate” power is at Member State discretion and has led to divergent implementation across the EU. Some Member States allow such representational actions only with a direct mandate (e.g., Germany), others allow limited no-mandate actions, and a few have enabled broader public-interest litigation.
2. Practical implementation and limitations
- Art. 80(1) is directly effective—any data subject anywhere in the Union may mandate a qualifying organization in their Member State.
- Art. 80(2) leaves room for national divergence. The CJEU in Schrems v Facebook Ireland (C-498/16, 25 January 2018) confirmed the validity of national restrictions on no-mandate actions, provided that Art. 80 rights are not rendered ineffective. Recital 142 GDPR also clarifies that the Regulation allows Member States to choose the modalities of collective action for the purposes of protecting data subjects’ rights.
- The European Commission’s recent proposal for a Directive on representative actions (Directive (EU) 2020/1828) aims to harmonize procedural collective redress further but does not supplant the GDPR regime.
3. Relationship to Arts. 77–79 and 82 remedies
- Nonprofits acting under Art. 80 may lodge complaints (Art. 77), seek judicial remedies against authorities (Art. 78), against controllers/processors (Art. 79), and pursue compensation claims (Art. 82), provided the data subject authorizes them (Art. 80(1)), or, where national law permits, independently (Art. 80(2)).
4. Strategic and compliance considerations
- Controllers facing mass claims or public-interest litigation should consult the specific implementation in each relevant Member State. The scope of nonprofit standing and permissible remedies varies, and pan-EU strategy requires attention to these divergences.
Source: Regulation (EU) 2016/679 (GDPR), Article 80 Source: CJEU, Schrems v Facebook Ireland, C-498/16, EU:C:2018:37
Criminal sanctions for GDPR violations — Art. 84 GDPR and Member State discretion
Article 84 GDPR addresses the possibility of criminal sanctions for certain data protection infringements, granting Member States discretion to lay down specific penalties—including criminal penalties—when such conduct is not already subject to administrative fines under the Regulation.
Article 84(1) provides that Member States must establish rules on "other penalties" for infringements of GDPR, particularly for violations that are not already covered by administrative fines under Article 83. These penalties must be "effective, proportionate and dissuasive." While GDPR itself sets out detailed administrative sanctions at the EU level, it does not harmonize criminal liability; instead, it explicitly allows each Member State to determine whether, and to what extent, GDPR violations trigger criminal consequences at national law.
The practical effect is that criminal exposure for GDPR breaches varies across Member States. Some, such as Germany and France, have specific offenses in their national data protection acts—e.g., unlawful collection or disclosure of personal data, failure to comply with an order from a supervisory authority, or obstructing an investigation. Others rely primarily on administrative mechanisms. Art. 84 does not require Member States to implement criminal law, but it creates space for national legislatures to do so, in line with their constitutional systems and legal traditions.
Notably, Article 84(2) mandates that each Member State must notify the European Commission of any new criminal penalties it establishes under this provision. The Article itself does not specify maximum penalties, specific acts qualifying as criminal, or procedural safeguards; these are matters for national law, subject to general EU law requirements (including the Charter of Fundamental Rights).
Practitioners should therefore consult local implementing legislation in each relevant Member State to determine the existence, scope, and enforcement history of criminal provisions adopted under Art. 84 GDPR. The risk profile for organizations and individuals—such as DPOs or executive officers—may differ substantially depending on national choices made under this provision.
Limitation periods for enforcement and compensation actions under GDPR — national law, CJEU guidance, and unresolved issues
GDPR does not establish a uniform statute of limitations for administrative enforcement, judicial remedies, or compensation actions. Articles 77–79 (remedies), Article 82 (compensation), and Article 83 (fines) are silent as to any limitation period. Instead, the applicable limitation period is determined by national law in each Member State, subject to EU-law principles of effectiveness and equivalence.
Recital 143 GDPR confirms this allocation: “Each supervisory authority should handle complaints lodged by a data subject … within a reasonable period.” There is no reference to a limitation period in the substantive articles of the Regulation. For compensation claims under Article 82, national law governs the statute of limitations, provided that it does not render the exercise of the right to compensation impossible or excessively difficult (the effectiveness principle) and does not treat GDPR claims less favourably than similar domestic actions (the equivalence principle).
CJEU: National limitation periods apply, but EU-law boundaries bind The Court of Justice of the European Union confirmed in Österreichische Post (C-300/21, 4 May 2023, para. 58) and ZQ v Medizinischer Dienst (C-667/21, 21 December 2023, para. 45) that the assessment and quantification of compensation—including limitation periods—are governed by national rules. Yet, these rules must respect the effectiveness and equivalence requirements. In practice, this means limitation periods ranging from one to five years, varying by Member State. Short limitation periods or those running from the date of infringement—rather than from when the data subject became aware—may be vulnerable to challenge if they systematically prevent GDPR claims.
For administrative enforcement (investigation and imposition of fines under Articles 58, 83), GDPR does not specify any limitation period, and in the absence of EU harmonization, national procedural law again fills the gap. Some Member States (e.g., Germany under § 31 OWiG) set different limitation periods for administrative offences, typically three years for regulatory fines, while others are more generous. Supervisory authorities must also comply with general EU-law requirements for reasonable handling times (Recital 143) and due process.
No EDPB harmonization: practitioners must consult national law Neither the European Data Protection Board nor the GDPR itself has issued harmonized guidelines or recommendations on limitation periods. Controllers and data subjects must therefore review the applicable statutes and case law for each Member State in which proceedings may be brought or enforcement may occur. Where a single data-processing event gives rise to actions in multiple Member States, divergent limitation periods may apply, leading to possible inconsistencies in outcomes.
Current uncertainty and strategic recommendations The lack of harmonized limitation periods is a source of material legal uncertainty, especially for cross-border processing and mass claims. In the absence of CJEU clarification on what constitutes a breach of the effectiveness/equivalence principles in this context, prudent practitioners should take a conservative approach and assume that the shortest plausible national period could apply. Internal compliance processes should ensure timely complaint handling, documentation, and retention to preserve evidence and procedural rights for both enforcement and compensation.
Source: Regulation (EU) 2016/679 (GDPR), Recital 143 Source: CJEU, Österreichische Post, C-300/21, para. 58 Source: CJEU, ZQ v Medizinischer Dienst, C-667/21, para. 45
Publication and transparency of enforcement actions — Art. 83(8) GDPR and EDPB guidance
The GDPR requires transparency in enforcement, establishing publication rules for certain corrective actions by supervisory authorities. The core statutory basis for publication is Article 83(8) GDPR, which provides: "The exercise by the supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law... The imposition of administrative fines shall, in each individual case, be made public by the supervisory authority, unless such publication would jeopardise the interests of data subjects." Thus, the default is publication of the fine—but there is a statutory carve-out: the supervisory authority must withhold or redact details where disclosure could put data subjects at risk. Neither Article 83(8) nor the remaining GDPR text requires or prohibits naming the controller in every published decision, but practice and case law across the EU tend toward full publication unless a demonstrable risk exists.
Recital 148 GDPR further clarifies the intent: penalties, and their publication, are meant to deter and enhance enforcement. However, the Recital endorses proportionality: "Where proportionate, measures including publication of information relating to such infringements should be taken." Practically, this means that authorities weigh the deterrent and transparency value against any residual privacy or security risk to individuals involved.
For other corrective powers (warnings, reprimands, bans, orders), GDPR does not mandate publication. Article 58(2) is silent on publication obligations for these measures, and no provision in the Regulation requires or prohibits disclosure of their imposition. As a result, Member State practice diverges and is shaped by national law, policy, and EDPB coordination; GDPR delegates this discretion. Controllers and processors should therefore verify the applicable local approach.
The European Data Protection Board's Guidelines 04/2022 on the calculation of administrative fines underscore that (p. 46–47): authorities must balance transparency and the right of the public to know about significant enforcement actions with potential impacts on data subjects, third parties, or integrity of ongoing investigations. The Guidelines explain that not all information must necessarily be disclosed and confirm that publication may be postponed or redacted where justified by legitimate competing interests.
The EDPB also maintains a public Consistency Register showing binding decisions in cross-border cases, increasing EU-level transparency, but the GDPR itself does not prescribe this register by law—its role is derived from the Board's responsibilities under Arts. 64–65.
Source: Regulation (EU) 2016/679 (GDPR), Article 83(8), Recital 148 Source: EDPB Guidelines 04/2022 on the calculation of administrative fines, pp. 46–47
EDPB binding and urgent binding decisions under Arts. 65–66 GDPR: escalation, majority, and binding effect (updated for 2026 CJEU ruling)
The General Data Protection Regulation entrusts the European Data Protection Board (EDPB) with a decisive adjudicatory role whenever supervisory authorities cannot reach consensus in cross-border cases. This dispute-resolution role is codified in Article 65 GDPR (binding decision) and Article 66 GDPR (urgent binding decision), which create an escalation and consistency mechanism for EU-wide enforcement.
When does Art. 65 trigger? Article 65(1) GDPR is triggered when the Lead Supervisory Authority (LSA) and one or more Concerned Supervisory Authorities (CSAs) disagree on a draft decision—typically after a CSA raises a "relevant and reasoned objection" under Article 60(4). If consensus cannot be reached, or if the LSA fails to adopt a position consistent with EDPB’s opinion, the case is referred to the EDPB. The EDPB must adopt a binding decision by a two-thirds majority within one month (extendable for complex matters), binding all supervisory authorities involved (Art. 65(2)–(3), (6)).
Legal effect — 2026 CJEU clarification The process and effect of EDPB binding decisions have recently been clarified by the Court of Justice of the European Union. In its judgment of 10 February 2026 (Case C-97/23 P, WhatsApp Ireland v EDPB), the CJEU held that Article 65 GDPR binding decisions produce direct legal effects vis-à-vis third parties. This means that the EDPB’s decision is no longer a purely internal matter between authorities—it is now reviewable directly before EU courts by affected parties, enhancing legal certainty and reviewability. This marks a shift from earlier practice where only the LSA’s final administrative decision was considered reviewable, not the EDPB’s decision itself. As of February 2026, controllers and processors can challenge EDPB binding decisions directly before the CJEU. The LSA remains obliged to adopt a conforming final decision (Art. 65(6)), but the EDPB’s determination is the operative act subject to judicial scrutiny.
Urgent binding decisions — Art. 66 GDPR Separately, Article 66(1) GDPR authorizes any supervisory authority to take provisional measures in urgent situations to protect data subjects’ rights, with immediate notification to the Commission, EDPB, and other authorities. The EDPB may then, by a two-thirds vote within two weeks, determine whether the urgency and measures are justified and issue an urgent binding decision (Art. 66(2)).
Strategic and practical effect For practitioners, dispute escalation to the EDPB under Articles 65–66 ensures a swift, uniform enforcement result that is binding on all authorities. Since the 2026 CJEU judgment, the EDPB’s binding decisions can now be challenged directly in EU courts, adding a new layer of immediate judicial oversight absent in prior years. In high-profile or high-stakes cross-border cases, this new direct review mechanism can be decisive for litigation and compliance strategies.
Source: GDPR, Articles 65 & 66 Source: CJEU, Case C-97/23 P, WhatsApp Ireland v EDPB (10 Feb 2026) Source: EDPB Register of consistency and of accountability tools
How to lodge a complaint and supervisory authority obligations — Art. 77 GDPR complaint handling and due process
Article 77 GDPR entitles any data subject to lodge a complaint with a supervisory authority if they believe the processing of their personal data infringes the Regulation. This core enforcement route does not require proof of harm or damage; belief alone suffices (Art. 77(1)). The right is exercisable regardless of other remedies and can be brought before an SA in the State of the complainant’s habitual residence, place of work, or where the alleged infringement occurred.
Procedural requirements for lodging a complaint The GDPR itself imposes no categorical requirements regarding the complaint format, substance, or language, and SAs may not impose disproportionate formalities that would undermine effectiveness (recital 141). National law and SA guidelines often set out forms or online portals, but GDPR’s effectiveness principle requires they remain accessible and not unduly burdensome. Complaints may be anonymous, although Member States may have identity rules for follow-up investigations. The CJEU (Case C-132/21, Nemzeti Adatvédelmi és Információszabadság Hatóság, 2023) clarified that admissibility cannot be made conditional on prior resolution attempts or other requirements not stated in the Regulation.
Upcoming harmonised procedure for cross-border complaints (effective April 2027) A new regulation, Regulation (EU) 2025/2518 on GDPR procedural rules, enters into force on 1 January 2026 and applies from 2 April 2027. This regulation harmonises complaint-handling procedures for cross-border GDPR cases. Key changes include:
- Explicit admissibility rules (defining what constitutes a valid complaint and required information)
- Unified procedural rights (the right to be heard, right to submit observations, right to receive information on the status and outcome of the complaint)
- Fixed investigation deadlines: For regular cases, supervisory authorities must conclude investigations within 15 months; for simpler cases, within 12 months from notification. The regulation also sets deadlines for cross-border cooperation and dispute resolution.
- Standardised cooperation procedures: Supervisory authorities must coordinate under harmonised rules for joint investigations and decision making.
These changes directly affect how Article 77 complaints—especially cross-border—are processed, adding procedural certainty, transparency, and timeliness compared to the current practice, which is governed by a patchwork of national rules. The substance of Article 77 GDPR is not replaced, but the procedural landscape will materially change beginning April 2027.
Obligations of the supervisory authority Under GDPR (Art. 57(1)(f)), the SA must handle complaints, investigate the subject matter as appropriate, and inform complainants of progress and outcome within a reasonable period. Under the new regulation (from April 2027), complaint handling, investigation, and information duties will be subject to EU-level deadlines and rights, particularly in cross-border cases. Failure to act within three months still allows complainants to seek judicial remedy under Art. 78(2). SAs retain discretion to dismiss manifestly unfounded or excessive complaints (Art. 12(5)), but reasons must be given and are subject to review.
Timelines and complainant due process Currently, there is no maximum statutory deadline to resolve a complaint, only the requirement to update complainants within a "reasonable period" (recital 143). The three-month period under Art. 78(2) is a threshold for judicial remedy, not a resolution deadline. From April 2027, the new harmonised rules will impose fixed deadlines for investigation and notification in cross-border cases. Throughout, complainants are entitled to be informed of progress, to receive reasoned decisions, and to appeal any binding decision or inaction.
Practical impact Controllers may be called to respond to SA inquiries at any stage after a complaint is filed. For cross-border cases, after April 2027, harmonised timelines and procedural rights will apply, reducing delays and inconsistencies that exist under national rules.
Source: Regulation (EU) 2016/679 (GDPR), Articles 12, 57, 77, 78, Recitals 141, 143 Source: CJEU, Nemzeti Adatvédelmi és Információszabadság Hatóság, C-132/21, EU:C:2023:2 Source: Regulation (EU) 2025/2518, laying down additional procedural rules in relation to the enforcement of Regulation (EU) 2016/679, OJ L, 2025 Source: Council Press Release, "Council adopts new EU law to speed up handling of cross-border GDPR complaints", 17 Nov 2025
Defense rights and due process in GDPR enforcement — Art. 58(4), Art. 78, and the Charter of Fundamental Rights
The General Data Protection Regulation requires that all enforcement proceedings respect the defense rights and due process guarantees of the parties subject to investigation or sanction (controllers and processors). This protection is codified in Article 58(4) GDPR: the exercise of corrective powers by supervisory authorities "shall be subject to appropriate safeguards, including effective judicial remedy and due process, set out in Union and Member State law". These core rights have been clarified and enforced in CJEU jurisprudence as well as by reference to Article 47 of the Charter of Fundamental Rights of the EU.
Minimum defense guarantees in enforcement Supervisory authorities must ensure the right to be heard (each party has an opportunity to comment on accusations and submit evidence), access to the administrative file, and receipt of a reasoned decision—before fines, bans, or corrective orders are imposed. The CJEU has held that the right to be heard applies at every stage, especially before any measure that adversely affects the controller (see C-277/11 MM v Minister for Justice, C-337/17 Xing v Finanzamt, and C-245/19 A v Veselības ministrija).
GDPR's Art. 78(1) ensures that every "natural or legal person" subject to a binding decision by a supervisory authority—including controllers and processors—has a right to an effective judicial remedy. Article 58(4) and Art. 78(1) are interpreted in light of Art. 47 of the Charter, which requires a fair trial and the possibility to challenge administrative measures before an impartial tribunal. The CJEU, in its SCHUFA Holding (C-26/22 and C-64/22) ruling (7 Dec 2023), confirmed that courts must conduct a "full judicial review" of a DPA’s decision—not only on form, but on the substance and proportionality of corrective measures or fines imposed.
National procedural law and uniform EU minimums While Member States retain some procedural autonomy (which remedies are available, deadlines, evidentiary standards), this leeway ends where national rules would make it excessively difficult or impossible to exercise the defense rights guaranteed by EU law—the "principle of effectiveness"—or treat GDPR defendants less favorably than comparable domestic defendants—the "principle of equivalence". The right to appeal, to reasoned decisions, and access to an independent and impartial court are uniformly binding across the EU.
Controllers or processors facing enforcement should receive timely and detailed notifications of allegations, access to evidence, and have an opportunity to rebut claims before sanctions are final. Any refusal, procedural shortcut, or withholding of reasoning may violate Arts. 47 Charter and 58(4), 78 GDPR.
Source: Regulation (EU) 2016/679 (GDPR), Arts. 58(4), 78 Source: Charter of Fundamental Rights of the European Union, Article 47 Source: CJEU, SCHUFA Holding (Discharge from remaining debts), C-26/22 and C-64/22, EU:C:2023:958
GDPR enforcement — repeated or prior infringements as aggravating circumstances under Art. 83(2)(e)
Repeated or prior infringements are a specified aggravating factor in GDPR fine calculation and essential for practitioners assessing multi-violation risk. Article 83(2)(e) GDPR directs supervisory authorities (SAs) to consider “any relevant previous infringements by the controller or processor” when deciding on fines.
The European Data Protection Board’s final Guidelines 04/2022 (adopted 24 May 2023) embed this rule in a five-step methodology. Step 3 (“Adjust for aggravating or mitigating factors”) explicitly includes prior infringements as an aggravating factor that can increase the fine amount. The Guidelines instruct SAs to integrate past breaches into their proportionality analysis—stating (para. 91): “Previous infringements of the GDPR… can serve as an aggravating circumstance. The nature, level of severity, and recurrence character of prior infringements will be taken into account in the adjustment of the basic amount upwards.”
For multi-instance or continuous conduct, Step 1 requires SAs to determine whether “one or more instances of sanctionable conduct… led to one or multiple infringements,” thus enabling escalation when repeated conduct is aggregated. The EDPB clarifies (para. 35) that persistent or continued non-compliance, even if technically classified as a single infringement, may increase the gravity assigned in the fine calculation.
The Guidelines do not impose a fixed formula or multiplier—supervisory authorities retain discretion to weigh prior violations contextually. The final amount must always remain within the statutory caps under Art. 83(4)–(6) and be effective, proportionate, and dissuasive, as required by Art. 83(1).
In practice, public enforcement decisions—such as recent Irish DPC cases against multinational tech firms—have confirmed that prior fines or corrective orders, if disregarded or followed by subsequent violations, have led to materially higher sanctions in later rounds, reflecting aggravation. National courts and SAs are converging toward an expectation that prior adverse enforcement history will be treated as a serious aggravating factor, even in the absence of explicit national implementing guidance.
Source: Regulation (EU) 2016/679 (GDPR), Article 83(2)(e) Source: EDPB Guidelines 04/2022 on the calculation of administrative fines, para. 35, 91