Question of the month – how are fines under the GDPR calculated?

The EDPB has issued guidance on how fines under the GDPR are calculated. Whilst it may not be your first choice in terms of reading material, it does have some interesting things to say on how the behaviour of organisations faced with an enforcement action can better (or worsen!) their position and gives some insight into the workings behind the fines imposed. The EDPB notes that fines are within the discretion of the supervisory authority save to the extent the GDPR sets out rules in relation to them. The EDPB guidance pulls out the following five stages:

  1. Identify the processing operations and evaluate whether there is one or multiple infringements.
  2. Identify the starting point for further calculation of the fine, which involves:
    • Establishing the classification of the infringement (whether it falls within the lower or upper maximum fine).
    • Considering the seriousness of the infringement based on the specific circumstances, looking at the nature, gravity and duration of the infringement(s), taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected, and the level of damage suffered by them. Regard is also given to matters such as whether the infringement was negligent or intentional and the type of personal data involved.
    • Establishing the turnover of the entity (where the EDPB suggests adjustments to be made to the starting amount of the fine in reference to the annual turnover of the entity).
  3. Evaluate the aggravating and mitigating factors relating to the party’s past or present behaviour. The guidance notes that measures taken before a Data Protection Authority (DPA) is involved are more likely to be considered mitigating factors than those taken after. There will be a consideration of the degree to which the entity “did what it was supposed to do” in terms of compliance,   previous infringements, time frame and subject matter, co-operation with the DPA, the way the infringement came to light, adherence to codes of conduct/certification mechanisms and compliance with previous orders relating to the same subject matter as well as other factors. The guidance gives examples of how mitigating and aggravating factors may affect a fine.
  4. Identify the legal maximum for each infringement (this includes some guidance on the term “undertaking” and “turnover”).
  5. Consider whether the amount reached by this analysis meets the requirements of effectiveness, dissuasiveness (having a genuine deterrent effect on the addressee and the world at large) and proportionality (in relation to the severity of the infringement and to the size of the undertaking).

The annex to the guidance provides some useful worked illustrations.

The EDPB states that the calculation of fines is not a mere mathematical exercise but will depend very much on the circumstances of the case. The EDPB confirms in its guidance the need to act early, co-operate and learn from previous infringements in order to put yourself in a better position if faced with an enforcement action.

The full guidance can be found here.


Don't just take our word for it