CHAPTER VIIIREMEDIES, LIABILITY AND PENALTIES

Article 83General conditions for imposing administrative fines

Official text

(1)Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.

(2)Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58 (2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:

(a)the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;

(b)the intentional or negligent character of the infringement;

(c)any action taken by the controller or processor to mitigate the damage suffered by data subjects;

(d)the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;

(e)any relevant previous infringements by the controller or processor;

(f)the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;

(g)the categories of personal data affected by the infringement;

(h)the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;

(i)where measures referred to in Article 58 (2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;

(j)adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and

(k)any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.

(3)If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.

(4)Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:

(a)the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43;

(b)the obligations of the certification body pursuant to Articles 42 and 43;

(c)the obligations of the monitoring body pursuant to Article 41 (4).

(5)Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:

(a)the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9;

(b)the data subjects’ rights pursuant to Articles 12 to 22;

(c)the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49;

(d)any obligations pursuant to Member State law adopted under Chapter IX;

(e)non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58 (2) or failure to provide access in violation of Article 58 (1).

(6)Non-compliance with an order by the supervisory authority as referred to in Article 58 (2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.

(7)Without prejudice to the corrective powers of supervisory authorities pursuant to Article 58 (2), each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.

(8)The exercise by the supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process.

(9)Where the legal system of the Member State does not provide for administrative fines, this Article may be applied in such a manner that the fine is initiated by the competent supervisory authority and imposed by competent national courts, while ensuring that those legal remedies are effective and have an equivalent effect to the administrative fines imposed by supervisory authorities. In any event, the fines imposed shall be effective, proportionate and dissuasive. Those Member States shall notify to the Commission the provisions of their laws which they adopt pursuant to this paragraph by 25 May 2018 and, without delay, any subsequent amendment law or amendment affecting them.

Commentary

Article 83 GDPR constitutes the principal provision governing the imposition of administrative fines under the Regulation. While Articles 55 to 67 establish the institutional and procedural architecture of supervisory enforcement, Article 83 addresses the substantive question that arises once an infringement has been identified:when may a supervisory authority impose a fine, how should it determine the amount, and what limits govern that fine?

The provision is deliberately structured to prevent administrative fines from becoming either automatic sanctions for every infringement or purely discretionary penalties imposed without a common methodology. Instead, Article 83 establishes a framework built around three ideas: effectiveness, proportionality and dissuasiveness. It then subjects the exercise of the fining power to a detailed list of aggravating and mitigating considerations, creates different statutory ceilings depending upon the nature of the infringement, regulates the treatment of multiple infringements, permits Member States to regulate fines against public authorities, and requires appropriate procedural safeguards.

Article 83 must therefore be read as more than a provision containing two monetary figures, €10 million/2% and €20 million/4%. Those figures are only the outer boundaries of the sanctioning power. The more important legal question is how an authority moves from an established infringement to an individualised, lawful and defensible amount.

The architecture can broadly be represented as:

Infringement → eligibility for fine → individual assessment → Article 83(2) factors → statutory maximum → effectiveness/proportionality/dissuasiveness → final amount.

The Court of Justice has significantly developed this architecture. In Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija, Case C-683/21, and Deutsche Wohnen SE v Staatsanwaltschaft Berlin, Case C-807/21, both decided on 5 December 2023, the Court clarified, among other things, that an administrative fine under Article 83 requires an intentional or negligent infringement and that, where the addressee is an undertaking belonging to a group, the relevant turnover for calculating the maximum may be that of the entire economic unit.

Article 83 is consequently the point at which the GDPR's substantive obligations are translated into economic consequences.


1. The opening principle: fines must be effective, proportionate and dissuasive

Article 83(1) begins by requiring each supervisory authority to ensure that administrative fines imposed under Article 83 are, in each individual case, effective, proportionate and dissuasive.

The words “in each individual case” are critical.

The GDPR does not prescribe a uniform tariff under which a particular infringement automatically attracts a predetermined fine. Nor does the existence of a high statutory maximum mean that the authority should ordinarily impose a fine approaching that maximum.

Instead, the fine must be calibrated to the circumstances of the particular infringement.

These three requirements perform different functions.

Effectiveness

A fine must be capable of achieving the regulatory purpose for which it is imposed. It must be sufficiently meaningful to induce compliance and to make the sanction practically consequential.

A nominal fine imposed on a very large undertaking for a serious, deliberate and prolonged infringement may fail to satisfy this requirement.

Proportionality

A fine must not exceed what is appropriate in light of the infringement and its circumstances.

Proportionality prevents the fining power from becoming punitive without justification. The authority must consider the seriousness of the conduct, the impact on data subjects and the other circumstances listed in Article 83(2).

Dissuasiveness

The sanction must create a sufficient incentive to comply with the GDPR in the future. Its function is not merely retrospective punishment; it also has a prospective compliance objective.

The CJEU has expressly recognised that administrative fines contribute to strengthening the protection of natural persons because their dissuasive effect encourages controllers and processors to comply with the GDPR.

Thus, Article 83(1) creates a three-part constraint:

Too low → potentially ineffective or insufficiently dissuasive.

Too high → potentially disproportionate.

Appropriately calibrated → effective, proportionate and dissuasive.



2. A fine is not automatically mandatory for every infringement

Article 83(2) does not establish an automatic rule that every infringement falling within Article 83(4), (5) or (6) must result in an administrative fine.

Instead, it provides that administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, the measures referred to in Article 58(2).

This is important because the GDPR gives supervisory authorities a broader enforcement toolbox.

Under Article 58(2), an authority may issue warnings, reprimands, orders to comply, orders to communicate a personal data breach, impose limitations or bans on processing, and exercise other corrective powers. A fine is therefore one component of the enforcement architecture rather than the sole response to non-compliance.

Recital 148 reinforces this approach by recognising circumstances in which an authority may refrain from imposing an administrative fine, particularly where an infringement is minor or where a fine would constitute a disproportionate burden for a natural person.

The consequence is that the first question under Article 83 is not simply:

“How much should the fine be?”

It is:

“Should a fine be imposed at all?”

Only after that question has been addressed does the calculation of the amount arise.



3. The requirement of individualised assessment

Article 83(2) repeatedly directs the supervisory authority to consider the circumstances “in each individual case.”

This prevents mechanical enforcement.

Two controllers may technically commit the same infringement but warrant materially different fines.

For example, assume Controller A and Controller B both violate Article 32 by failing to implement an appropriate security measure.

Controller A:

  • discovers the deficiency internally;
  • immediately begins remediation;
  • cooperates fully with the authority;
  • has no previous infringements;
  • affected a small number of data subjects; and
  • caused no demonstrable damage.

Controller B:

  • was repeatedly warned about the same deficiency;
  • ignored internal security reports;
  • continued the practice for several years;
  • refused to cooperate with the authority;
  • affected millions of individuals; and
  • exposed highly sensitive data.

The legal provision infringed may be identical, but the circumstances of the infringement are not.

Article 83 is designed to capture that distinction.



4. Article 83(2)(a): nature, gravity and duration

The first major factor requires the authority to consider the nature, gravity and duration of the infringement, taking into account the nature, scope or purpose of the processing, the number of data subjects affected and the level of damage suffered by them.

This is one of the most important provisions for determining seriousness.

The EDPB's Guidelines 04/2022 explain that these elements must be assessed in the concrete circumstances of the case and that the factors are frequently interconnected rather than operating in complete isolation. The EDPB refers to these elements, together with intentionality/negligence and the categories of data affected, as central to assessing the seriousness of an infringement.

Nature of the infringement

“Nature” concerns what kind of GDPR obligation has been violated and what the infringement means in the context of the regulatory framework.

An infringement of a fundamental requirement such as the existence of a lawful basis under Article 6 may be treated differently from a comparatively technical or administrative failure.

The EDPB has described lawfulness of processing as one of the fundamental pillars of data protection law and has treated processing without an appropriate legal basis as a serious violation of the data-protection right.

Gravity

Gravity concerns the seriousness of the actual infringement in its factual setting.

The question is not merely which GDPR provision was breached, but how seriously was it breached?

For example, an isolated and immediately corrected transparency defect affecting a small number of people may have considerably less gravity than systematic concealment of a processing operation affecting millions of individuals.

Duration

Duration considers how long the infringement existed.

An unlawful practice continuing for several years may be considerably more serious than an isolated error that was promptly corrected.

The duration factor is particularly important for compliance programmes because an organisation's continued failure to remediate a known problem may transform what began as an error into a sustained regulatory failure.



5. Number of data subjects and level of damage

Article 83(2)(a) expressly requires consideration of both the number of data subjects affected and thelevel of damage suffered by them.

These are related but distinct.

A processing operation may affect a very large number of individuals but cause relatively limited demonstrable harm to each individual.

Conversely, a processing operation affecting fewer people may create exceptionally serious consequences for those individuals.

Illustration

A marketing company unlawfully processes the email addresses of five million users. The scale is enormous, but assume the data consists only of ordinary email addresses and the immediate consequences are limited. A different company unlawfully discloses the medical records of 500 individuals. The number of affected individuals is dramatically smaller, but the nature and consequences of the processing may make the second infringement extremely serious. Article 83 therefore does not establish a crude rule that:more people = automatically higher fine. The number of data subjects must be assessed together with the nature, gravity, duration, scope and damage associated with the processing.



6. Article 83(2)(b): intentional or negligent character

Article 83(2)(b) requires consideration of whether the infringement was intentional or negligent.

This factor has acquired particular importance following the CJEU's judgments in Nacionalinis visuomenės sveikatos centras and Deutsche Wohnen.

The Court held that an administrative fine under Article 83 may be imposed only where the controller or processor has intentionally or negligently committed the relevant infringement. In other words, a purely strict-liability approach to Article 83 fines is not permissible.

This is a significant clarification because the text of Article 83 does not expressly state in paragraph 1 that fault is a precondition. The Court derived the requirement from the structure and purpose of Article 83(2), particularly the reference to intentional or negligent conduct.

The Court further held that Member States do not have discretion to establish a different substantive threshold permitting fines without fault. The substantive conditions governing Article 83 fines are governed by EU law.



7. Negligence does not require subjective knowledge of illegality

The CJEU's interpretation of negligence is particularly important.

A controller may be fined where it could not have been unaware of the infringing nature of its conduct, even if it did not know that its conduct actually infringed the GDPR.

This creates an important distinction.

There is a difference between:

knowing that conduct violates the GDPR

and

being unable reasonably to be unaware of the nature of the conduct that constitutes the infringement.

A company cannot necessarily avoid a fine by saying:

“We did not know that the GDPR prohibited this.”

If the organisation had sufficient circumstances indicating that its conduct required compliance analysis, and nevertheless proceeded negligently, Article 83 may still apply.

Illustration

A large technology company introduces a new profiling system involving extensive personal-data processing but does not conduct any meaningful legal or compliance assessment before deployment. If the system clearly falls within established GDPR requirements, the absence of subjective knowledge that the conduct was unlawful may not protect the organisation. The focus is therefore not simply on the mental state of an individual executive.



8. Corporate liability does not depend upon the knowledge of senior management

The CJEU further clarified in Nacionalinis visuomenės sveikatos centras and Deutsche Wohnen that, where the controller is a legal person, it is not necessary to establish that the infringement was committed by, or even known to, the management body of that legal person.

This prevents a corporate structure from being used as a shield.

A company cannot necessarily defend an Article 83 fine by arguing:

“The board did not know.”

The relevant question is whether the legal person, through its conduct and organisation, committed an intentional or negligent infringement.

This is especially important for large organisations where processing decisions are distributed among business units, compliance teams, product teams, engineers and contractors.



9. Article 83(2)(c): action taken to mitigate damage

The third factor concerns any action taken by the controller or processor to mitigate the damage suffered by data subjects.

This factor recognises the importance of post-infringement conduct.

Suppose a company discovers that personal data have been exposed.

One company immediately:

  • contains the incident;
  • secures the affected systems;
  • informs affected individuals where required;
  • resets credentials;
  • provides protective measures; and
  • cooperates with the supervisory authority.

Another company discovers the same incident but delays remediation, conceals the scope of the incident and leaves the vulnerability open.

The second company's conduct may justify a substantially different assessment.

Mitigation does not erase the original infringement. Rather, it can affect the appropriate level of sanction.

This distinction is important:

remediation ≠ absence of infringement.

But:

remediation may affect the amount of the fine.



10. Article 83(2)(d): degree of responsibility

Article 83(2)(d) requires consideration of the degree of responsibility of the controller or processor, taking into account technical and organisational measures implemented pursuant to Articles 25 and 32.

This connects Article 83 with the GDPR's accountability architecture.

A controller that has invested substantially in privacy governance, security controls, access management, testing, auditing and risk assessment may be treated differently from one that has ignored its obligations entirely.

However, compliance measures must be relevant to the infringement.

A company cannot rely on the existence of a general privacy programme if the particular processing activity was completely outside that programme.

Illustration

A company has a mature privacy management system but launches a new AI-powered profiling tool without conducting the necessary assessment of its processing risks. The existence of a sophisticated privacy programme may be relevant, but it does not automatically eliminate responsibility for the failure relating to the new processing activity. Article 83 therefore encouragessubstantive accountability, not compliance by paperwork.



11. Article 83(2)(e): previous infringements

The authority must consider any relevant previous infringements by the controller or processor.

This introduces an element of regulatory history into the assessment.

A first infringement and repeated non-compliance are not necessarily equivalent.

For example, if a company was previously sanctioned for inadequate security and subsequently commits a substantially similar security failure, the previous enforcement history may indicate that earlier regulatory intervention failed to produce sufficient compliance.

The factor is nevertheless framed in terms of relevant previous infringements.

The authority should therefore avoid treating every historical regulatory matter as equally probative.



12. Article 83(2)(f): degree of cooperation

Article 83(2)(f) requires consideration of the degree of cooperation with the supervisory authority in remedying the infringement and mitigating possible adverse effects.

This creates an incentive for constructive regulatory engagement.

Cooperation may include:

  • responding promptly to requests;
  • supplying relevant documents;
  • facilitating investigations;
  • explaining technical systems;
  • identifying affected data subjects;
  • assisting in remediation; and
  • implementing corrective measures.

Conversely, obstruction, delay or incomplete disclosure may aggravate the regulatory assessment.

The provision therefore makes cooperation economically relevant.

The organisation's conduct after the authority begins investigating can influence the final sanction.



13. Article 83(2)(g): categories of personal data

The authority must consider the categories of personal data affected by the infringement.

This provision reflects the GDPR's risk-sensitive structure.

Not all personal data carry the same potential consequences.

A violation involving publicly available business contact information may present a different level of risk from an infringement involving:

  • health data;
  • biometric data;
  • genetic data;
  • information concerning sex life or sexual orientation;
  • financial information; or
  • other particularly sensitive information.

The assessment must therefore consider what data were actually involved.

Again, the provision does not say that processing special categories automatically results in the maximum fine. The categories of data are one factor among several.



14. Article 83(2)(h): manner in which the infringement became known

The authority must consider the manner in which the infringement became known, in particular whether and, if so, to what extent the controller or processor notified the infringement.

This factor becomes particularly relevant in breach situations.

If an organisation promptly reports a personal-data breach as required under Article 33, provides accurate information and assists the authority, that conduct can form part of the overall assessment.

If the authority instead discovers the infringement independently after the controller failed to disclose it, the circumstances may be more serious.

The important point is that Article 83 looks not only at what happened, but also athow the organisation behaved once the problem existed.



15. Article 83(2)(i): compliance with previous measures

The authority must consider compliance with measures previously ordered against the controller or processor in relation to the same subject matter.

This is particularly significant where an organisation has already been subject to regulatory intervention.

If a supervisory authority previously ordered an organisation to remedy a particular compliance deficiency and the organisation subsequently fails to implement that order, the repeated failure may materially affect the fining assessment.

This gives corrective measures under Article 58(2) an additional dimension.

An order is not merely a standalone remedy.

Failure to comply with that order may itself become relevant to a subsequent sanctioning decision.



16. Article 83(2)(j): adherence to approved codes and certification mechanisms

Article 83(2)(j) requires consideration of adherence to approved codes of conduct under Article 40 or certification mechanisms under Article 42.

The provision recognises that voluntary accountability mechanisms can provide evidence relevant to compliance.

However, adherence to a code or certification mechanism does not create immunity from Article 83.

If a certified organisation nevertheless violates the GDPR, the certification cannot automatically prevent enforcement.

Rather, adherence is a factor in the overall assessment.

This distinction is particularly important because the GDPR does not intend certification to operate as a guarantee that no infringement can ever occur.



17. Article 83(2)(k): other aggravating or mitigating factors

The final factor permits consideration of any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained or losses avoided because of the infringement, directly or indirectly.

This is an intentionally open-ended provision.

It prevents the assessment from becoming artificially restricted to the preceding ten factors.

The reference to financial benefits is especially significant.

Suppose a company deliberately avoids investing €5 million in compliance infrastructure and gains a substantial competitive advantage as a result.

The mere fact that the organisation saved money by failing to comply may itself be relevant to determining a sufficiently dissuasive sanction.

The logic is straightforward:

Compliance should not become economically irrational.

If an organisation could profit from non-compliance and later pay only a nominal fine, the regulatory system would create the wrong incentive.



18. Article 83(3): multiple infringements

Article 83(3) addresses a situation in which a controller or processor, intentionally or negligently, infringes several provisions of the GDPR through thesame or linked processing operations.

In such circumstances, the total amount of the administrative fine must not exceed the amount specified for the gravest infringement.

This prevents the same underlying conduct from being multiplied into unlimited penalties merely because it violates several interconnected provisions.

Illustration

A controller launches one unlawful processing operation that simultaneously violates:

  • Article 6 because there is no lawful basis;
  • Article 13 because the required information is not provided; and
  • Article 22 because applicable safeguards concerning automated decision-making are not respected. If these infringements arise from the same or linked processing operations, Article 83(3) prevents the authority from treating each violation as an entirely independent route to a separate statutory maximum. The overall amount cannot exceed the maximum applicable to the gravest infringement.


19. “Same or linked processing operations” is crucial

Article 83(3) does not apply merely because several infringements were discovered during the same investigation.

The relevant question is whether the infringements arise from the same or linked processing operations.

This distinction matters.

Imagine that during an investigation into a company's security practices, the authority discovers an unrelated failure concerning its direct-marketing transparency.

The two matters may have been discovered during one investigation, but they may concern separate processing activities.

In that situation, Article 83(3)'s limitation may not apply.

The relevant enquiry is therefore:

same or linked processing?, not simply, same investigation?

Regulatory practice similarly distinguishes between multiple infringements arising from closely connected processing and unrelated conduct involving separate processing operations.



20. Article 83(3) does not mean that only one infringement exists

A subtle but important point is that Article 83(3) does not erase the underlying infringements.

There may still be several violations of the GDPR.

The provision regulates the aggregate amount of the fine.

Thus, an authority may identify several infringements arising from the same or linked processing operations, assess them individually for enforcement purposes, and nevertheless ensure that the combined monetary sanction does not exceed the statutory maximum applicable to the gravest infringement.

The provision is therefore a cap on aggregation, not a rule of substantive non-liability.



21. Article 83(4): the first level of maximum fines

Article 83(4) establishes the lower tier of administrative fines.

For the infringements listed there, the maximum is:

up to €10 million, or

in the case of an undertaking, up to 2% of its total worldwide annual turnover of the preceding financial year,

whichever is higher.

The lower tier covers, among other matters, specified obligations concerning controllers and processors, certification bodies and monitoring bodies.

The reference to “whichever is higher” is crucial.

It means that the authority does not simply choose the higher number as a discretionary penalty. The higher figure establishes the applicable statutory ceiling.

Example

If an undertaking has a preceding financial-year worldwide turnover of €100 million: 2% = €2 million. The statutory maximum is therefore €10 million, because €10 million is higher than €2 million. If the undertaking has a worldwide turnover of €1 billion: 2% = €20 million. The statutory maximum becomes €20 million because that exceeds €10 million. The turnover mechanism therefore prevents the maximum from becoming economically insignificant for very large enterprises.



22. Article 83(5) and (6): the higher level of maximum fines

Article 83(5) and (6) concern more serious categories of infringement and establish the higher ceiling:

up to €20 million, or

in the case of an undertaking, up to 4% of its total worldwide annual turnover of the preceding financial year,

whichever is higher.

The higher tier includes infringements of some of the GDPR's core substantive obligations, including key principles concerning processing, data subjects' rights, international transfers and certain obligations arising from national-law provisions adopted under the GDPR.

The structure is deliberate.

The GDPR effectively distinguishes between:

Article 83(4), €10 million / 2% tier

and

Articles 83(5), (6), €20 million / 4% tier.

The statutory architecture itself therefore signals that some obligations are considered sufficiently serious to attract a substantially higher potential sanction.



23. Turnover is not the fine

One of the most common misunderstandings of Article 83 is to treat 2% or 4% as an automatic fine.

It is not.

The percentage relates to the statutory maximum, and the EDPB's fining methodology uses turnover as one element in determining an appropriate starting point.

The EDPB's Guidelines 04/2022 make clear that the calculation of a fine is not a purely mathematical exercise and that the figures in the illustrative table are starting points rather than fixed amounts or “price tags”. The authority retains discretion within the applicable range, subject to effectiveness, proportionality and dissuasiveness.

Thus:

4% turnover ≠ automatic fine.

Rather:

4% turnover may establish the upper legal boundary where applicable.

The actual fine must still be individually determined.



24. The EDPB's five-step fining methodology

The EDPB adopted Guidelines 04/2022 on the calculation of administrative fines, with the final version 2.1 adopted on 24 May 2023.

The methodology provides a useful practical framework for understanding Article 83.

Broadly, the EDPB approach involves:

  1. identifying the processing operations and considering Article 83(3);
  2. establishing a starting point based on the infringement category, seriousness and turnover;
  3. considering aggravating and mitigating factors;
  4. ensuring that the relevant legal maximum is respected; and
  5. checking whether the resulting amount is effective, proportionate and dissuasive, with adjustment where necessary.

The EDPB expressly states that the numerical figures are starting points for further calculation rather than fixed amounts.

This is important because it demonstrates how Article 83 operates in practice.

The statutory provision establishes the legal framework; the EDPB methodology provides a more structured means of applying that framework consistently.



25. Step 1: identify the processing operations and Article 83(3)

The EDPB methodology begins by identifying the processing operations involved and determining whether Article 83(3) applies.

This is logically necessary.

Before calculating the amount of a fine, the authority must know what conduct it is sanctioning.

Otherwise, multiple legal violations could be counted inconsistently.

The authority therefore first identifies the processing operation or operations and determines whether the infringements are connected.

This prevents the fining process from becoming disconnected from the underlying conduct.



26. Step 2: seriousness and starting amount

The next stage involves establishing a starting point by considering:

  • the category of infringement under Article 83(4), (6);
  • the seriousness of the infringement; and
  • the turnover of the undertaking.

The seriousness assessment draws particularly on Article 83(2)(a), (b) and (g), nature, gravity and duration; intentional or negligent character; and categories of personal data.

The EDPB's illustrative table divides infringements into low, medium and high levels of seriousness and provides indicative starting ranges. It expressly cautions that these are not fixed amounts.

This is an important development in the practical interpretation of Article 83 because it introduces greater consistency into a provision that otherwise leaves substantial room for case-by-case assessment.



27. Step 3: aggravating and mitigating circumstances

Once the starting amount is identified, the authority considers the remaining circumstances under Article 83(2).

These may increase or decrease the amount.

For example:

Aggravating circumstances

  • deliberate conduct;
  • prolonged infringement;
  • large-scale impact;
  • repeated infringements;
  • failure to cooperate;
  • financial benefit from non-compliance;
  • failure to comply with earlier regulatory measures.

Mitigating circumstances

  • prompt remediation;
  • effective cooperation;
  • voluntary disclosure;
  • limited duration;
  • limited impact;
  • absence of relevant previous infringements;
  • effective measures taken to mitigate harm.

The important point is that these factors operate on the individualised amount, not on the statutory maximum itself.



28. Step 4: the statutory maximum remains an outer boundary

After the fine has been adjusted according to the circumstances, the authority must ensure that the amount does not exceed the applicable statutory maximum.

The EDPB's methodology explicitly treats the legal maximum as a constraint on the calculation.

This means that the authority has two separate exercises:

First: determine the amount justified by the circumstances.

Second: ensure that amount remains within the statutory ceiling.

The second exercise does not replace the first.

A €20 million maximum does not mean that the authority starts at €20 million and works downward.



29. Step 5: effectiveness, proportionality and dissuasiveness as a final check

The final stage returns to Article 83(1).

Even after all the factors have been assessed, the authority must ask whether the resulting amount is:

effective, proportionate and dissuasive.

The EDPB methodology expressly emphasises this final assessment.

This is significant because the three principles operate both as the opening statutory requirement and as a final constraint on the calculated amount.

The process can therefore be understood as:

Article 83(2) determines the relevant circumstances → the methodology produces a candidate amount → Article 83(1) tests the candidate amount.

This prevents the calculation methodology from becoming an automatic mathematical formula.



30. Article 83 and the economic reality of large undertakings

The turnover component serves an important regulatory function.

A fine that would be substantial for a small company could be commercially negligible for a multinational enterprise.

The percentage mechanism addresses this asymmetry.

For example, a €10 million fine could represent a severe economic consequence for a company with €50 million in annual worldwide turnover.

For a multinational undertaking generating €50 billion, the same €10 million might represent only 0.02% of turnover.

The 2%/4% mechanism allows the sanction to scale with the economic capacity of the undertaking.

This supports the dissuasive objective of Article 83(1).

But the CJEU has also clarified that turnover cannot be understood as an independent basis of liability. In Deutsche Wohnen, the Court addressed the calculation of fines where the addressee is part of a group of companies and held that the concept of an “undertaking” for Article 83 purposes is informed by EU competition-law principles.



31. The group-company principle

The CJEU's judgment in Deutsche Wohnen is particularly important for large corporate groups.

The Court held that where the addressee of the fine is part of a group of companies, the fine may be calculated by reference to the turnover of the economic unit constituted by that group, rather than merely the turnover of the individual legal entity receiving the fine.

The rationale is connected with the concept of an undertaking in EU law.

If the percentage ceiling were calculated only by reference to a relatively small subsidiary while the economic group possessed enormous resources and the subsidiary operated within that economic unit, the dissuasive function of the sanction could potentially be undermined.

The group principle therefore gives Article 83 greater practical force against economically integrated corporate structures.



32. Article 83(7): fines against public authorities

Article 83(7) creates an important national-law qualification.

Member States may lay down rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.

This means that the treatment of public authorities is not completely uniform across the Union.

The GDPR establishes the general framework, but it permits Member States to determine the availability and extent of fines against their own public authorities and bodies.

The provision therefore reflects the constitutional and administrative diversity of Member States.

A private undertaking and a public authority may consequently operate under different domestic rules concerning the imposition of administrative fines.



33. Article 83(8): procedural safeguards and due process

Article 83(8) states that the exercise of the supervisory authority's powers under Article 83 is subject to appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process.

This provision is essential because an administrative fine can be economically significant and legally consequential.

The authority must therefore exercise its fining power within a framework respecting procedural fairness.

The existence of an effective enforcement regime cannot justify abandoning the rights of the undertaking subject to the sanction.

The CJEU has emphasised this distinction: while the GDPR establishes substantive conditions for fines at EU level, Member States may regulate aspects of procedure where the GDPR does not itself provide detailed procedural rules, subject to the principles of equivalence and effectiveness.



34. Article 83(9): Member States and criminal penalties

Article 83(9) addresses the relationship between administrative fines and Member States in which fines are imposed through mechanisms that may have a criminal-law character.

The provision recognises that Member States may establish rules concerning penalties and must ensure that the resulting system does not undermine the effectiveness and uniform application of the GDPR.

This becomes especially relevant in Member States whose constitutional systems do not permit a supervisory authority itself to impose certain kinds of fines.

The CJEU has considered this issue in the context of the broader Article 83 framework and recognised that Member States retain procedural autonomy, while the substantive EU-law conditions for an Article 83 fine remain governed by the GDPR.



35. Article 83 is not Article 82

A useful distinction must be maintained between administrative fines under Article 83 andcompensation under Article 82.

Article 83 concerns a regulatory sanction imposed by a supervisory authority.

Article 82 concerns compensation for damage suffered as a result of processing infringing the GDPR.

The purposes are therefore different.

A fine is primarily regulatory and deterrent.

Compensation is restorative.

The CJEU confirmed in GP v juris GmbH, Case C-741/21, that the criteria used for calculating administrative fines under Article 83 are not applicable when assessing compensation under Article 82.

This distinction prevents the GDPR's enforcement mechanisms from being conceptually merged.

A data subject's entitlement to compensation does not depend upon whether the supervisory authority imposed a fine, and the amount of compensation is not calculated by applying Article 83's fining criteria.



36. Article 83 and corrective powers under Article 58

Article 83 also cannot be read independently of Article 58.

Article 58(2) allows supervisory authorities to impose administrative fines in addition to or instead of other corrective measures.

This means that a fine and an order to comply can coexist.

Illustration

A company unlawfully processes personal data. The authority may:

  • order the company to bring processing into compliance;
  • prohibit a particular processing activity; and
  • impose an administrative fine. The fine addresses the sanctioning and deterrent dimension, while the corrective order addresses the continuing compliance problem. Article 83 therefore forms part of a broader enforcement toolkit.


37. The difference between an infringement and the sanction

Another important analytical distinction is between:

establishing an infringement, and

determining the appropriate fine.

The existence of an infringement does not by itself determine its monetary value.

The authority must first establish what obligation was breached and whether the conditions for Article 83 liability are satisfied.

It must then assess the circumstances under Article 83(2).

Only thereafter can it determine the amount.

This distinction is particularly important after Nacionalinis visuomenės sveikatos centras and Deutsche Wohnen, because the CJEU confirmed that an Article 83 fine requires a wrongful infringement, intentional or negligent conduct by the controller or processor.



38. Responsibility for processors' conduct

Article 83 also operates in relation to processing carried out by processors.

In Nacionalinis visuomenės sveikatos centras, the CJEU held that a controller may be fined under Article 83 for unlawful processing carried out by a processor on its behalf.

But that responsibility is not unlimited.

Where the processor acts for its own purposes, or processes data in a manner incompatible with the framework or detailed arrangements determined by the controller, or in circumstances where it cannot reasonably be considered that the controller consented to that processing, the processor may itself be regarded as a controller for that processing under Article 28(10).

This is an important application of the controller-processor distinction.

The controller cannot escape responsibility merely because it outsourced processing.

But neither can the controller automatically be held responsible for every independent act of a processor that falls outside the processing framework it established.



39. Article 83 and accountability

The overall architecture of Article 83 reinforces the GDPR's accountability model.

The GDPR does not simply ask:

“Did a breach occur?”

It asks a broader set of questions:

  • What processing was undertaken?
  • Why was it undertaken?
  • How many people were affected?
  • What data were involved?
  • How serious was the infringement?
  • How long did it continue?
  • Was it intentional or negligent?
  • What responsibility did the controller bear?
  • What measures had been implemented?
  • Did the organisation cooperate?
  • Did it mitigate the consequences?
  • Had it previously infringed the GDPR?
  • Did it obtain a financial benefit?
  • Did it comply with previous regulatory measures?

The fining exercise therefore reconstructs the organisation's overall compliance behaviour.

That is why Article 83 is not simply a penalty provision. It is also a mechanism through which the GDPR evaluates the quality of organisational accountability.



40. A practical Article 83 assessment

Consider a hypothetical multinational platform that unlawfully processes users' behavioural data without an appropriate lawful basis.

The supervisory authority should not begin with:

“The company is large, therefore the fine should be 4% of turnover.”

Instead, the analysis should proceed sequentially.

Stage 1, Identify the infringement

Determine precisely what processing occurred and which GDPR obligation was infringed.

Stage 2, Establish Article 83 applicability

Determine whether the infringement falls within Article 83(4), (5) or (6), and establish the relevant fault requirement.

Stage 3, Apply Article 83(3)

Determine whether multiple infringements arise from the same or linked processing operations.

Stage 4, Assess seriousness

Consider nature, gravity, duration, scope, purpose, number of data subjects, damage and categories of data.

Stage 5, Examine conduct

Assess intentionality or negligence, responsibility, mitigation, cooperation and previous infringements.

Stage 6, Consider other circumstances

Examine previous orders, codes or certifications and financial benefits or other aggravating or mitigating circumstances.

Stage 7, Establish the appropriate amount

Use the relevant methodology to determine the starting point and adjust it.

Ensure that the amount remains within the applicable €10 million/2% or €20 million/4% ceiling.

Stage 9, Apply the Article 83(1) test

Ask whether the resulting amount is effective, proportionate and dissuasive.

Only after these stages should the authority arrive at the final fine.



41. The central tension in Article 83: deterrence versus proportionality

Article 83 contains an inherent tension.

A sanction must be sufficiently high to deter non-compliance, but it cannot become disproportionate.

This is particularly difficult in cases involving multinational companies.

A fine that is too low may be treated simply as a cost of doing business.

A fine that is too high may become disproportionate to the actual infringement.

The three-part test in Article 83(1) attempts to mediate this tension.

The EDPB's fining methodology reflects the same principle by stating that the calculation is not purely mathematical and that the final amount must still satisfy effectiveness, proportionality and dissuasiveness.



42. Article 83 and the principle of consistency

The requirement for effective, proportionate and dissuasive fines also serves a broader Union-level purpose.

If materially similar infringements produced radically different sanctioning outcomes without objective justification, the uniform application of the GDPR could be undermined.

The CJEU expressly linked the requirement for fault and the EU-wide harmonisation of Article 83 sanctions to the GDPR's objective of achieving an equivalent and homogeneous level of protection throughout the Union.

The EDPB Guidelines 04/2022 similarly seek to establish a more harmonised methodology for calculating fines across supervisory authorities.

Article 83 therefore has two levels of proportionality:

individual proportionality, the fine must fit the individual infringement;

Union-wide consistency, similar circumstances should not produce arbitrary disparities in enforcement.



43. Article 83 is a structured discretion, not unfettered discretion

Perhaps the most accurate way to understand Article 83 is as a system of structured regulatory discretion.

The supervisory authority has discretion:

  • whether to impose a fine, depending upon the circumstances;
  • what amount to impose;
  • how the Article 83(2) factors apply; and
  • how aggravating and mitigating circumstances affect the amount.

But that discretion is bounded by:

  • the requirement of an intentional or negligent infringement;
  • the factors listed in Article 83(2);
  • the aggregation rule in Article 83(3);
  • the statutory maximums in Article 83(4), (6);
  • national rules concerning public authorities under Article 83(7);
  • procedural safeguards under Article 83(8); and
  • the principles of effectiveness, proportionality and dissuasiveness under Article 83(1).

The authority therefore does not possess a blank cheque.



44. The deeper significance of Article 83

Article 83 represents the GDPR's transition from a largely compliance-oriented framework to a system in which privacy compliance has material economic consequences.

The provision changes the organisational calculation surrounding personal data.

Under a weak sanctioning regime, an organisation may rationally compare:

cost of compliance

against

expected cost of non-compliance.

Article 83 seeks to ensure that the second cannot become an attractive alternative.

The possibility of a fine linked to worldwide turnover is particularly significant for multinational enterprises because the economic consequence can extend far beyond the immediate financial value of the processing activity.

At the same time, the detailed factors in Article 83(2) prevent turnover from becoming the sole measure of culpability.

The system therefore combines:

economic capacity + seriousness of conduct + organisational responsibility + consequences for data subjects + post-infringement behaviour.



45. Conclusion

Article 83 GDPR is the central provision through which the Regulation converts data-protection obligations into an enforceable system of administrative sanctions. Its significance, however, lies not merely in the headline maximum fines of €10 million or 2% and€20 million or 4%. Those figures represent only the statutory ceilings. The actual exercise of the fining power requires an individualised assessment of the circumstances of the infringement.

The provision begins with the requirement that every fine be effective, proportionate and dissuasive. It then requires the supervisory authority to consider the nature, gravity and duration of the infringement; the scope and purpose of processing; the number of data subjects and level of damage; intentional or negligent conduct; mitigation; responsibility; previous infringements; cooperation; categories of data; the manner in which the infringement became known; compliance with previous measures; adherence to codes or certification mechanisms; and other aggravating or mitigating circumstances.

Article 83(3) then prevents excessive aggregation where several provisions are infringed through the same or linked processing operations, limiting the total fine to the statutory maximum applicable to the gravest infringement.

The CJEU's recent jurisprudence adds an especially important qualification. Following Nacionalinis visuomenės sveikatos centras and Deutsche Wohnen, an Article 83 administrative fine cannot be imposed merely because an objective infringement occurred. The controller or processor must have committed the infringement intentionally or negligently. At the same time, the Court made clear that this does not require proof that senior management personally knew that the conduct was unlawful.

The jurisprudence also confirms that the controller's responsibility may extend to unlawful processing carried out by a processor on its behalf, subject to the limits recognised by Article 28(10).

The EDPB's Guidelines 04/2022 complement this statutory framework by introducing a structured five-step methodology for calculating fines. Yet the EDPB expressly rejects the idea that the methodology is a mechanical formula: the numerical ranges are starting points, not fixed prices, and the final amount must still satisfy effectiveness, proportionality and dissuasiveness.

The architecture of Article 83 can therefore be reduced to a sequence:

  1. Was there an infringement?
  2. Was it intentionally or negligently committed?
  3. Does it fall within Article 83(4), (5) or (6)?

Are there multiple infringements arising from the same or linked processing operations?

  1. How serious was the infringement?
  2. What aggravating and mitigating circumstances exist?
  3. What is the appropriate starting amount?
  4. What is the applicable statutory maximum?
  5. Is the final amount effective, proportionate and dissuasive?

Only after this sequence is completed can the supervisory authority arrive at a legally defensible administrative fine.

The central proposition of Article 83 is therefore not that “GDPR violations attract heavy fines.”

It is more precise:

GDPR infringements falling within the fining provisions must be sanctioned through an individualised process in which fault, seriousness, impact, responsibility, conduct and economic circumstances are assessed against the requirements of effectiveness, proportionality and dissuasiveness, subject to the statutory ceilings established by the Regulation.

In that sense, Article 83 is simultaneously a sanctioning provision, a proportionality framework, an accountability mechanism and a harmonising instrument. It ensures that the economic consequences of violating data-protection law are sufficiently meaningful to deter non-compliance, while ensuring that the exercise of regulatory power remains tied to the circumstances of the particular case.