CHAPTER VIIIREMEDIES, LIABILITY AND PENALTIES

Article 84Penalties

Official text

(1)Member States shall lay down the rules on other penalties applicable to infringements of this Regulation in particular for infringements which are not subject to administrative fines pursuant to Article 83, and shall take all measures necessary to ensure that they are implemented. Such penalties shall be effective, proportionate and dissuasive.

(2)Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.

Commentary

Article 84 is the GDPR’s bridge between the harmonised EU system of administrative fines and the national penalty systems of individual Member States. Article 83 gives supervisory authorities a common framework for imposing administrative fines, while Article 84 requires Member States to fill remaining enforcement gaps and, where appropriate, create additional civil, administrative, regulatory or criminal penalties.

In the simplest terms:

Article 83 tells supervisory authorities when and how GDPR administrative fines may be imposed. Article 84 tells Member States to ensure that other suitable penalties exist, particularly where Article 83 does not provide an administrative fine or where an additional national enforcement mechanism is needed.

Article 84 is short, but its operation is technically difficult because it raises questions about:

  • what counts as an “other penalty”;
  • which GDPR infringements require national penalties;
  • whether conduct already covered by Article 83 may also attract an Article 84 penalty;
  • when criminal sanctions are permitted;
  • whether profits may be confiscated;
  • how proportionality applies;
  • whether individuals, employees and companies may all be punished;
  • how to prevent double punishment;
  • what procedural safeguards are required;
  • why Member States must notify their laws to the European Commission.

The official text confirms that Member States must establish other penalties, especially for infringements outside Article 83, implement those penalties in practice and ensure that they are effective, proportionate and dissuasive.


1. The structural purpose of Article 84

The GDPR is a regulation and is therefore directly applicable throughout the European Union. However, it does not completely harmonise every form of sanction.

Article 83 creates a detailed administrative-fine regime, but it does not answer every enforcement question. For example, national law may need to address:

  • deliberate unlawful acquisition of personal data;
  • sale of confidential information by an employee;
  • obstruction of inspections;
  • destruction of evidence;
  • impersonation to obtain personal data;
  • breach of statutory secrecy;
  • misuse of national identification numbers;
  • serious violations of national employment-data rules;
  • fraudulent certification conduct;
  • conduct that also amounts to computer crime, fraud or professional misconduct.

Article 84 therefore obliges Member States to create a national penalty framework that complements the GDPR’s EU-level enforcement machinery. Recital 152 confirms that Member States may use administrative or criminal penalties where the GDPR has not harmonised the relevant sanction or where further penalties are necessary, particularly for serious infringements.

This does not mean that each Member State may redesign the GDPR’s substantive obligations. A Member State cannot decide that lawful basis, consent or access rights mean something entirely different nationally. It may, however, determine what additional national sanction follows from specified unlawful conduct, within the limits imposed by EU law.

Illustration

Assume that a hospital employee secretly copies patient records and sells them to an insurance intermediary. Several legal consequences may follow:

  1. The hospital may face an Article 83 administrative fine if its security, access-control or governance failures were negligent or intentional.
  2. The employee may face a national criminal offence concerning deliberate misuse or unlawful disclosure of personal data.
  3. The hospital and employee may face employment or professional consequences.
  4. Affected patients may claim compensation under Article 82.
  5. The supervisory authority may order deletion, access restrictions or other Article 58 corrective measures.

Article 84 ensures that national law can address personal wrongdoing and other harmful conduct that an Article 83 fine against the controller may not adequately capture.


2. Article 84 is addressed primarily to Member States

The wording begins:

“Member States shall lay down the rules…”

This means Article 84 is primarily a legislative obligation imposed on Member States. It is not, by itself, a fully defined criminal offence that can automatically be prosecuted against a controller, processor or employee.

A person must be able to identify the specific national law that:

  • defines the prohibited conduct;
  • identifies the persons who may be liable;
  • specifies the required mental element;
  • determines the penalty;
  • identifies the competent authority or court;
  • establishes the relevant procedure.

The Article provides the EU framework and standard, but national legislation supplies the actual offence and penalty.

Illustration

A prosecutor cannot simply charge a person with: “breach of Article 84 GDPR.” Article 84 itself does not specify:

  • the detailed prohibited act;
  • whether intention is required;
  • the maximum prison term;
  • the amount of a national fine;
  • defences;
  • limitation periods. The charge must be based on a sufficiently clear national provision adopted consistently with Article 84. This distinction also reflects the principle of legality. Penalties, especially criminal penalties, must be prescribed clearly and foreseeably by law. A person must be able to understand, with appropriate advice where necessary, what conduct is punishable and what consequences can follow.

3. “Shall lay down the rules” creates a positive obligation

Article 84 does not merely permit Member States to consider penalties. It says they shall establish the relevant rules.

The mandatory character has two dimensions.

First, Member States must create an adequate legal framework. Second, they must take the measures necessary to ensure the penalties are actually implemented. A penalty that exists only in legislation but is never capable of being investigated or imposed may not satisfy Article 84.

The obligation is related to the broader EU principle of sincere cooperation. Where EU law requires national enforcement, Member States must provide sanctions that make the EU rule practically effective. Commentary on Article 84 accordingly treats the provision as requiring national systems to reinforce GDPR enforcement rather than simply reproducing the Regulation’s wording.

Illustration

A Member State creates a criminal offence for deliberate sale of medical data but:

  • gives no authority power to investigate;
  • sets an impossible evidential standard;
  • limits prosecution to a body that does not exist;
  • provides a limitation period of only a few days. Although a penalty formally exists, it may not be genuinely implementable. The Member State may have failed to meet the effectiveness requirement. By contrast, a complete system would normally identify:
  • investigative authority;
  • prosecuting authority;
  • competent court;
  • procedural safeguards;
  • available sanctions;
  • enforcement mechanisms;
  • appeal rights.

4. Meaning of “other penalties”

The word “other” distinguishes Article 84 penalties from Article 83 administrative fines.

The concept is broad. Depending on national law, it may include:

  • criminal fines;
  • imprisonment;
  • administrative penalties outside the Article 83 model;
  • confiscation of profits;
  • professional disciplinary sanctions;
  • disqualification;
  • restrictions on carrying out specified activities;
  • judicial orders with a punitive character;
  • penalties for obstruction or evidence destruction;
  • sanctions linked to misuse of official powers.

Not every adverse legal consequence is necessarily a “penalty.”

For example:

  • Article 82 compensation primarily repairs individual damage.
  • An Article 58 erasure order corrects unlawful processing.
  • An injunction stops continuing conduct.
  • Withdrawal of certification may be corrective or regulatory.
  • A contractual damages payment enforces a private agreement.

A penalty usually has a punitive or deterrent function. It expresses public condemnation and imposes a burden because prohibited conduct occurred.

[!example] Illustration A company unlawfully possesses customer data. An order requiring deletion is corrective because it removes the unlawful situation. A monetary penalty imposed because the company deliberately acquired and exploited the data is punitive. Both measures may be used together because they perform different functions. The distinction matters for procedural rights and ne bis in idem. A genuinely punitive national sanction may need to be coordinated with an Article 83 fine directed at the same person for the same facts.

5. “In particular” means Article 84 is not confined to gaps in Article 83

Article 84 requires other penalties:

“in particular for infringements which are not subject to administrative fines pursuant to Article 83.”

The words“in particular” indicate emphasis, not an absolute limitation.

The principal task is to ensure that infringements not covered by Article 83 do not become sanction-free. But Article 84 does not say that Member States are forbidden from attaching another type of penalty to conduct that may also fall under Article 83.

Recital 149 expressly contemplates national criminal penalties for infringements of the GDPR and national rules adopted within its framework. It also warns that criminal and administrative penalties must not breach ne bis in idem. That warning would be largely unnecessary if Article 83 and Article 84 could never overlap.

The better interpretation is:

Article 84 must cover enforcement gaps, but it may also support additional national penalties for serious conduct already capable of attracting an Article 83 fine, provided that legality, proportionality, procedural fairness and the prohibition against double punishment are respected.

Illustration

A data broker deliberately obtains national identification records through bribery and sells them. The company’s processing may violate:

  • Article 5;
  • Article 6;
  • Article 32;
  • national secrecy law. The controller may face an Article 83 fine. The individuals who bribed officials or stole the records may also face national criminal prosecution. The Article 83 fine and criminal proceedings are not automatically incompatible. The authorities must analyse:
  • who is being punished;
  • for which conduct;
  • under which legal interest;
  • whether the facts are the same;
  • whether each proceeding is criminal in substance;
  • whether duplication is lawful and proportionate.

6. Infringements not subject to Article 83 fines

Article 83 contains a broad list of fineable GDPR obligations, but it does not expressly place every GDPR provision into one of its fine tiers.

Potential Article 84 subjects may include:

  • conduct outside the express Article 83 catalogues;
  • violations of national rules supplementing the GDPR;
  • personal misuse by employees or officials;
  • offences concerning unlawful acquisition rather than organisational controllership;
  • intentional disclosure of secret data;
  • obstruction not fully captured by Article 83;
  • conduct by persons who are neither controllers nor processors for the relevant act.

Illustration

An employee has legitimate access to a tax database for official work. The employee searches for a neighbour’s financial information out of curiosity and sends it to friends. Depending on the factual role analysis:

  • the public authority may remain controller for authorised processing;
  • the employee’s wholly personal misuse may fall outside authorised organisational activity;
  • national criminal or disciplinary law may punish abuse of official access;
  • Article 84 helps ensure that the individual misuse is not left without an effective sanction. This does not mean that Article 84 should be used to bypass Article 83 whenever the supervisory authority prefers a harsher result. The two regimes must be coordinated coherently.

7. Criminal penalties

Recital 149 explicitly permits Member States to establish criminal penalties for GDPR infringements and for infringements of national rules adopted within the GDPR’s limits.

Criminal penalties may be appropriate for conduct involving:

  • deliberate data theft;
  • sale of confidential databases;
  • intentional disclosure for profit;
  • blackmail using personal data;
  • deliberate re-identification;
  • unlawful surveillance for malicious purposes;
  • destruction or falsification of evidence;
  • abuse of public-office access;
  • obstruction of lawful inspections;
  • organised traffic in personal data.

Criminal law should ordinarily remain focused on sufficiently blameworthy conduct. Accidental and low-level organisational failures are generally more naturally addressed through:

  • corrective measures;
  • reprimands;
  • Article 83 fines;
  • civil liability;
  • professional discipline.

Illustration

A receptionist accidentally gives an appointment sheet to the wrong patient and immediately reports the incident. Treating that mistake as a serious criminal offence would likely be disproportionate. Contrast an employee who systematically exports thousands of patient records and sells them to fraudsters. Criminal punishment may be justified because the conduct is:

  • deliberate;
  • exploitative;
  • harmful;
  • difficult to address through organisational fines alone.

7.1 Criminal liability of individuals and organisations

National law may determine whether criminal responsibility attaches to:

  • natural persons;
  • directors;
  • employees;
  • public officials;
  • companies;
  • associations;
  • both the organisation and the responsible individuals.

Article 84 does not harmonise corporate criminal liability. Some legal systems permit criminal prosecution of corporate entities, while others rely on administrative or quasi-criminal liability.

The national model must nevertheless produce enforcement that is effective, proportionate and dissuasive.


8. Deprivation of profits

Recital 149 expressly states that national criminal penalties may allow deprivation of profits obtained through GDPR infringements.

Confiscation serves a simple principle:

A person should not retain the economic benefit of unlawful exploitation of personal data.

Illustration

A company unlawfully sells customer-location profiles and earns €10 million. An ordinary fine may punish the conduct. Confiscation may separately remove the €10 million benefit. The distinction is important:

  • a fine imposes a punitive financial burden;
  • confiscation removes unlawful gain;
  • compensation repairs harm suffered by individuals. These measures may coexist if the overall enforcement system remains lawful and proportionate.

8.1 Direct and indirect profits

National law may distinguish:

  • direct sales revenue;
  • advertising income generated from unlawful profiles;
  • business costs avoided;
  • property acquired through the proceeds;
  • indirect competitive advantage.

Article 84 itself does not provide a calculation formula. The national law must define the relevant confiscation mechanism with sufficient clarity.

8.2 Avoiding duplication

If financial benefit has already:

  • increased an Article 83 fine under Article 83(2)(k);
  • been confiscated under criminal law;
  • been repaid through another mechanism.

authorities must ensure that the combined financial burden remains proportionate and does not unlawfully punish the same element repeatedly.


9. Administrative penalties under national law

Recital 152 leaves the nature of additional penalties to Member State law and expressly recognises both criminal and administrative arrangements.

A national administrative penalty may address matters such as:

  • violation of national video-surveillance rules;
  • improper handling of national identification numbers;
  • failure to comply with sector-specific registration duties;
  • breach of national secrecy obligations;
  • unauthorised access to protected registries;
  • non-compliance with obligations created under Chapter IX.

These national penalties must not conflict with the harmonised Article 83 framework.

Illustration

A Member State cannot label a second, identical turnover-based fine as an “Article 84 penalty” merely to evade Article 83’s:

  • maximums;
  • factors;
  • fault requirement;
  • safeguards;
  • linked-infringement rules. The substance of the measure matters more than its domestic label. If a national sanction performs essentially the same punitive function as an Article 83 fine for the same conduct, EU-law safeguards concerning legality, proportionality and double punishment become central.

10. Professional and disciplinary sanctions

Some GDPR infringements arise within regulated professions or public employment.

Possible disciplinary consequences may include:

  • warning;
  • suspension;
  • loss of professional authorisation;
  • dismissal;
  • restriction of access privileges;
  • professional disqualification.

Illustration

A doctor intentionally searches the medical files of celebrities without a treatment-related purpose. Possible consequences include:

  • action against the hospital as controller;
  • disciplinary proceedings against the doctor;
  • professional regulatory action;
  • criminal prosecution under national secrecy law;
  • patient compensation claims. Whether a disciplinary measure qualifies as an Article 84 “penalty” depends on its legal basis and purpose. A measure genuinely designed to protect professional standards may coexist with GDPR enforcement, but the combined effect must remain proportionate. Professional rules also cannot reduce GDPR protection. A professional body cannot treat deliberate misuse of patient data as an insignificant internal matter where national law requires stronger enforcement.

11. Effective penalties

An effective penalty must contribute meaningfully to enforcement.

A penalty may be ineffective where:

  • the maximum is trivial;
  • prosecution is practically impossible;
  • no authority has jurisdiction;
  • limitation periods are unrealistically short;
  • penalties are never enforced;
  • evidential rules make conviction impossible;
  • unlawful profit greatly exceeds the penalty.

Illustration

National law sets a maximum fine of €50 for deliberate sale of a national health database. That amount would probably be absorbed as a routine cost and would not protect GDPR rights meaningfully. Effectiveness also concerns implementation. Article 84 expressly requires Member States to take all necessary measures to ensure the penalties are implemented. A well-written criminal offence is insufficient where:

  • police lack powers;
  • prosecutors lack jurisdiction;
  • courts cannot impose the sanction;
  • no cooperation exists with supervisory authorities. The national system should work in practice, not merely on paper.

12. Dissuasive penalties

A penalty is dissuasive when it discourages both:

  • the offender from repeating the conduct;
  • others from committing comparable infringements.

The penalty must be significant in relation to:

  • seriousness;
  • financial benefit;
  • offender’s resources;
  • likelihood of detection;
  • nature of the conduct;
  • risk of repetition.

Illustration

An employee earns €100,000 by selling a database. A €500 penalty is unlikely to deter repetition. A suitable penalty might include:

  • a meaningful fine;
  • confiscation of proceeds;
  • professional disqualification;
  • imprisonment in a particularly serious case. Dissuasiveness does not justify exemplary punishment without legal limits. The penalty must remain proportionate.

13. Proportionate penalties

Proportionality requires a reasonable relationship between the offence and the sanction.

Relevant considerations may include:

  • intention;
  • negligence;
  • duration;
  • number affected;
  • data sensitivity;
  • actual harm;
  • financial benefit;
  • offender’s role;
  • mitigation;
  • cooperation;
  • previous offences;
  • personal financial position;
  • vulnerability of affected people.

Illustration

Two persons unlawfully access one medical file. Person A accesses it accidentally through a system defect, closes it immediately and reports the incident. Person B searches for it deliberately, downloads it and threatens to publish it. Applying the same penalty to both would ignore proportionality.

13.1 Proportionality for natural persons

A penalty appropriate for a multinational company may be ruinous for an ordinary employee.

National courts may consider:

  • income;
  • assets;
  • family obligations;
  • level of responsibility;
  • profit obtained;
  • culpability.

But economic weakness does not automatically erase liability for deliberate and harmful conduct.

13.2 Proportionality of cumulative measures

The proportionality assessment should consider the combined burden of:

  • Article 83 fine;
  • Article 84 penalty;
  • confiscation;
  • professional sanction;
  • corrective orders;
  • criminal penalty.

Each measure may serve a different purpose, but their total effect must not become excessive.


14. Relationship between Article 82 compensation and Article 84 penalties

Article 82 and Article 84 perform different functions.

Article 82 provides compensation to a person who proves:

  • infringement;
  • damage;
  • causation.

Article 84 concerns public penalties imposed because unlawful conduct occurred.

Illustration

An employee sells a customer database. Affected customers may receive Article 82 compensation for:

  • financial loss;
  • distress;
  • identity fraud;
  • reputational harm. The employee may separately face an Article 84 criminal penalty. Compensation does not punish the offender, and the penalty is not paid to the affected individuals as compensation. A court may take payments and other consequences into account where national law and proportionality require, but the existence of compensation does not automatically prevent a public penalty.

15. Relationship with Article 83 administrative fines

Article 83 and Article 84 should be regarded as complementary but carefully coordinated.

Article 83 primarily addresses infringements by controllers, processors, certification bodies and monitoring bodies through a harmonised administrative-fine system.

Article 84 permits Member States to address:

  • remaining infringements;
  • personal misconduct;
  • serious intentional offences;
  • national supplementary obligations;
  • conduct requiring criminal or other sanctions.

The same event may trigger both regimes, but overlapping sanctions create risks.

Illustration

A telecommunications company unlawfully profiles customers and an executive deliberately conceals the system from the authority. The company may face an Article 83 fine for unlawful processing. The executive may face an Article 84 offence for:

  • deliberate concealment;
  • evidence falsification;
  • unlawful personal-data exploitation. if national law clearly provides for it. This may not involve punishing the same person twice. The company and executive are different legal subjects, though national corporate-liability rules may complicate the analysis.

16. The principle of ne bis in idem

The phrase means that a person should not be tried or punished twice for the same offence.

Article 50 of the Charter protects this principle. Recital 149 expressly requires Member States to ensure that criminal and administrative penalties do not violate it.

The analysis usually involves several questions:

  1. Are both proceedings or sanctions criminal in nature?
  2. Are they directed at the same person?
  3. Do they concern the same material facts?
  4. Has one proceeding reached a final outcome?
  5. If duplication exists, is it permitted under a lawful, necessary and proportionate coordinated system?

Eurojust’s overview identifies the principal elements as the criminal nature of the proceeding, identity of the offender, identity of the facts and finality of the earlier decision. It also discusses the transnational operation of the rule.


16.1 Criminal nature is determined substantively

A sanction may be called “administrative” under national law but still be criminal in substance for Charter purposes.

Relevant considerations may include:

  • legal classification;
  • nature of the offence;
  • punitive and deterrent purpose;
  • seriousness of the sanction.

A major Article 83 fine may therefore engage protections associated with criminal sanctions in the broader human-rights sense.

16.2 Same person

A sanction against Company A and criminal proceedings against its employee are not automatically proceedings against the same person.

However, where two sanctions target the same legal entity or the same natural person, the issue becomes more direct.

16.3 Same facts

Authorities should focus on concrete factual conduct, not merely legal labels.

Illustration

One proceeding describes conduct as:

  • unlawful data processing. Another describes the same acts as:
  • deliberate commercial sale of confidential records. Different labels do not necessarily mean different facts.

16.4 Final decision

The prohibition ordinarily becomes especially relevant once the first proceeding has ended in a final acquittal, conviction or punitive decision.

16.5 Closely coordinated dual proceedings

CJEU case law permits some duplication where the two proceedings form a sufficiently coordinated and proportionate whole, pursue complementary purposes, are foreseeable, and do not impose an excessive burden. More recent discussion of the Court’s jurisprudence emphasises the need for clear rules, close coordination, timely conduct and proportionate overall penalties.

Illustration

A data theft may lead to:

  • an Article 83 proceeding against the controller for systemic security failures;
  • a criminal proceeding against an employee for deliberate theft and sale. The proceedings address different persons and different aspects. If both proceedings target the same individual for exactly the same conduct, much closer ne bis in idem scrutiny is required.

17. Cross-border double punishment

Personal-data offences frequently cross borders.

Illustration

A person in Member State A steals data from a controller in Member State B and sells them to buyers in Member State C. Authorities in several states may seek prosecution. The transnational dimension raises questions under:

  • Article 50 of the Charter;
  • Schengen rules;
  • national jurisdiction;
  • mutual recognition;
  • judicial cooperation;
  • final decisions in another Member State. Eurojust’s CJEU case-law overview specifically treats the territorial and transnational dimensions of ne bis in idem, including identity of the offender and facts across Member States. Member States should therefore coordinate through:
  • prosecutorial cooperation;
  • information exchange;
  • Eurojust where appropriate;
  • recognition of final decisions;
  • allocation of the best-placed jurisdiction. Article 84 should not become a mechanism for serial punishment of the same person across Europe.

18. Procedural safeguards

Article 84 does not repeat Article 83(8), but Article 84 penalties remain subject to:

  • the Charter;
  • EU general principles;
  • national constitutional law;
  • applicable criminal or administrative procedure;
  • effective judicial protection.

Safeguards may include:

  • legality;
  • presumption of innocence;
  • notice of allegations;
  • right to remain silent where applicable;
  • legal assistance;
  • access to evidence;
  • right to challenge evidence;
  • impartial tribunal;
  • reasoned decision;
  • appeal;
  • protection against retroactivity;
  • proportionate limitation periods.

Illustration

A Member State creates a criminal offence worded as: “Any inappropriate handling of data is punishable.” This may be too vague because it does not allow a person to determine:

  • what conduct is prohibited;
  • which mental element is required;
  • which data are covered;
  • what “inappropriate” means. A valid criminal rule should define the offence with sufficient clarity.

19. Intent and negligence under national penalties

Article 84 does not itself prescribe one uniform mental element.

National law may distinguish:

  • intentional offences;
  • reckless conduct;
  • gross negligence;
  • ordinary negligence;
  • strict regulatory offences.

However, serious punitive sanctions normally require a suitably culpable mental element consistent with national and EU fundamental-rights standards.

Illustration

A criminal offence for deliberate sale of health data may require proof that the person:

  • knew the data were personal;
  • knew access or disclosure was unauthorised;
  • intended disclosure or profit. A separate regulatory offence might punish negligent failure to secure evidence during an inspection. The mental element should match the seriousness and stigma of the sanction. Strict criminal liability for minor accidental conduct would raise serious proportionality and due-process concerns.

20. Liability of employees

One important function of Article 84 is the ability to address individuals whose conduct may not be adequately captured by an organisational Article 83 fine.

Possible employee misconduct includes:

  • browsing records without work-related need;
  • selling customer details;
  • copying databases before resignation;
  • disclosing data for revenge;
  • using official records for private purposes;
  • sharing passwords deliberately;
  • re-identifying pseudonymised data.

Illustration

A call-centre employee searches an ex-partner’s account and gives the address to another person. The employer’s liability depends on:

  • access controls;
  • monitoring;
  • training;
  • foreseeability;
  • response. The employee may separately face a national Article 84 offence for intentional misuse. National law should distinguish personal misuse from ordinary mistakes and systemic failures.

21. Liability of directors and managers

Article 84 may permit national law to impose liability on directors or managers who:

  • order unlawful processing;
  • knowingly conceal breaches;
  • obstruct authorities;
  • falsify compliance records;
  • continue processing after prohibition;
  • deliberately fail to implement required controls.

But a director should not be punished merely because of job title.

National law should identify the basis of personal responsibility, such as:

  • direct participation;
  • authorisation;
  • deliberate omission despite a legal duty;
  • knowing concealment;
  • gross supervisory failure.

[!example] Illustration A DPO warns the board that a proposed data sale is unlawful. A director orders it to proceed and instructs employees to exclude the sale from records of processing. Personal liability may be justified if national law clearly covers that conduct.

22. National rules under Chapter IX

Chapter IX permits Member States to adopt more specific rules in areas such as:

  • freedom of expression;
  • public documents;
  • national identification numbers;
  • employment;
  • archiving and research;
  • secrecy obligations;
  • churches and religious associations.

Article 84 may provide penalties for breach of those national specifications.

Illustration

National law restricts use of a national identification number to specified legal purposes. A company sells identification-number databases for advertising. That conduct may violate:

  • the GDPR;
  • the national Article 87 framework;
  • a national Article 84 penalty provision. The national rule must remain within the GDPR’s permitted scope. Article 84 cannot save a national penalty based on a substantive rule that itself contradicts EU law.

23. Freedom of expression and other fundamental rights

National penalties must respect other Charter rights, including:

  • freedom of expression;
  • freedom of information;
  • freedom to conduct a business;
  • property;
  • fair trial;
  • legality.

Illustration

A journalist publishes personal information as part of a legitimate investigation into public corruption. A broadly worded national criminal offence for “disclosure of personal data without consent” could improperly criminalise journalism without considering:

  • Article 85;
  • public interest;
  • freedom of expression;
  • journalistic exemptions. Member States must design Article 84 laws that protect personal data while respecting legitimate expression and information rights. Similarly, a penalty against scientific research must account for lawful research safeguards and applicable national rules.

24. Article 84 does not create complete harmonisation

Article 83 substantially harmonises administrative fines. Article 84 deliberately leaves Member States a wider margin regarding other penalties.

As a result, the same deliberate misuse may carry different consequences in different Member States, such as:

  • different maximum terms of imprisonment;
  • different criminal-fine levels;
  • different confiscation rules;
  • different professional sanctions;
  • different limitation periods.

This variation is permitted, but not unlimited. Every national system must remain:

  • effective;
  • proportionate;
  • dissuasive;
  • consistent with the Charter;
  • consistent with the GDPR;
  • procedurally fair.

The Article has therefore been described as leaving Member States discretion over the type and nature of penalties while imposing EU-law boundaries on that discretion.


25. Paragraph 2: Notification to the European Commission

Each Member State had to notify the Commission of its Article 84 laws by 25 May 2018 and must notify subsequent amendments without delay.

This is not a requirement to notify individual criminal prosecutions or penalty decisions. It concerns the legal provisions adopted by the Member State.

The Commission maintains a public collection of Member State notifications under the GDPR, including notifications under Article 84(2), Article 83(9), and other national opening clauses.


25.1 Purpose of notification

Notification enables the Commission to:

  • understand national penalty systems;
  • assess whether Member States implemented Article 84;
  • compare national approaches;
  • identify enforcement gaps;
  • monitor compliance with EU law;
  • consider infringement proceedings;
  • support transparency and legal certainty.

Illustration

A Member State removes its principal criminal offence concerning deliberate personal-data sale. The amendment affects its Article 84 framework and should be notified without delay. The Commission can then assess whether adequate penalties remain.

25.2 Notification is not approval

A Member State does not obtain automatic confirmation that its penalty law is valid merely by notifying it.

The Commission may later conclude that the law is:

  • ineffective;
  • disproportionate;
  • discriminatory;
  • inconsistent with the GDPR;
  • incompatible with the Charter.

National courts may also review the law, and the CJEU may interpret the relevant EU requirements through Article 267 TFEU.

25.3 Outdated or incomplete notification

Failure to notify does not necessarily make every national penalty automatically unenforceable. The legal consequence depends on EU law and the nature of the obligation.

However, non-notification may prevent effective Commission oversight and may support a finding that the Member State failed to fulfil its EU obligations.


26. Relationship with Article 83(9)

Article 83(9) concerns Member States whose legal systems do not permit supervisory authorities to impose administrative fines directly. In such states:

  • the supervisory authority may initiate the process;
  • a national court may impose the fine;
  • the result must have equivalent effect.

Article 84 concerns other national penalties.

The two provisions should not be confused.

[!example] Illustration A court-imposed fine that replaces the ordinary Article 83 administrative-fine mechanism remains substantively an Article 83 fine, even if national law calls the proceedings criminal or misdemeanour proceedings. A separate offence punishing deliberate sale of personal data is an Article 84 penalty. Recital 151 originally described adapted arrangements in Denmark and Estonia, subject to the requirement that the penalties remain effective, proportionate and dissuasive. The Commission’s notification register separately identifies national notifications concerning Articles 83(9) and 84(2).

27. A complete practical illustration

Assume that a European hotel group maintains guest passport data.

An employee discovers that the database contains:

  • passport numbers;
  • addresses;
  • payment information;
  • travel dates;
  • VIP notes.

The employee copies 100,000 records and sells them to a fraud network.

Management later discovers the incident but destroys logs to avoid regulatory attention.

Hotel group

The supervisory authority investigates whether the hotel group violated:

  • Article 5;
  • Article 6;
  • Article 25;
  • Article 32;
  • Article 33.

If intentional or negligent organisational failures are established, an Article 83 fine may be imposed.

The authority may also order:

  • deletion;
  • access-control changes;
  • breach notification;
  • security audit;
  • restriction of processing.

Employee

National Article 84 law may punish:

  • deliberate copying;
  • unlawful disclosure;
  • sale for profit;
  • breach of confidentiality.

Possible penalties may include:

  • criminal fine;
  • imprisonment;
  • confiscation;
  • professional consequences.

Managers

Managers who intentionally destroyed logs may face separate offences relating to:

  • obstruction;
  • evidence destruction;
  • concealment.

Fraudsters

They may face national offences concerning:

  • fraud;
  • identity theft;
  • handling unlawfully obtained data;
  • cybercrime.

Guests

Affected guests may claim compensation under Article 82 if they prove:

  • material loss;
  • identity fraud;
  • distress;
  • loss of control;
  • causation.

Coordination

Authorities must assess:

  • whether the same person is being punished twice;
  • which facts each sanction covers;
  • whether proceedings are properly coordinated;
  • whether the total burden is proportionate;
  • whether unlawful profits have already been confiscated.

This example shows why Article 84 is necessary. Article 83 alone may sanction the controller, but it does not necessarily address the personal criminal conduct of employees, managers or outsiders.


28. Corrections and qualifications to the supplied commentary

Several points in the supplied commentary require refinement.

28.1 Article 84 is not limited strictly to infringements excluded from Article 83

The words “in particular” and Recital 149 indicate that national penalties may also apply to serious conduct that overlaps with Article 83, subject to safeguards against double punishment.

28.2 “Other penalties” are not necessarily only civil or criminal

They may include administrative, professional, disciplinary or confiscatory measures, depending on their national legal basis and function.

28.3 Compensation under Article 82 should not normally be described as an Article 84 penalty

Compensation is primarily reparative. Article 84 concerns public punitive or deterrent consequences.

28.4 National discretion is not unlimited

Member State laws must respect:

  • effectiveness;
  • proportionality;
  • deterrence;
  • legal certainty;
  • non-retroactivity;
  • due process;
  • Charter rights;
  • the harmonised Article 83 structure.

28.5 Overlap does not automatically mean unlawful double punishment

A detailed ne bis in idem analysis is required, including identity of the person, facts, criminal nature and finality.

28.6 An Article 83 fine and imprisonment may not be imposed casually for the same conduct

Where both are criminal in substance and directed against the same person for the same facts, close coordination and proportionality are essential.

28.7 Public authorities may also be relevant

Article 84 is not textually confined to private-sector controllers. National law may create offences for officials who abuse access to public databases.

28.8 Notification does not amount to Commission approval

It is a transparency and oversight mechanism, not a certificate that the national law complies with EU law.

28.9 National laws and examples can change

Current national exposure must always be checked in the Member State’s latest notified and enacted legislation rather than inferred from a general GDPR commentary. The Commission’s notification register is a useful starting point.


Conclusion

Article 84 ensures that the GDPR’s enforcement system has no avoidable gaps. Article 83 creates a harmonised framework for administrative fines against controllers, processors and specified regulatory bodies. Article 84 requires Member States to supplement that framework with other penalties, particularly where conduct is not covered adequately by Article 83. Those penalties may include:

  • criminal fines;
  • imprisonment;
  • confiscation of unlawful profits;
  • additional administrative penalties;
  • professional discipline;
  • disqualification;
  • sanctions for deliberate access, misuse, disclosure or obstruction. Member States have flexibility in designing the system, but the end result is governed by three binding requirements:
  • effective, meaning capable of enforcing the GDPR in practice;
  • proportionate, meaning appropriately matched to the conduct and offender;
  • dissuasive, meaning sufficiently significant to discourage repetition. The key technical difficulty is overlap. One incident may generate:
  • an Article 83 fine;
  • an Article 84 criminal offence;
  • an Article 82 compensation claim;
  • Article 58 corrective measures;
  • professional discipline;
  • confiscation.

These consequences do not automatically exclude one another because they serve different functions. But punitive duplication must respect:

  • ne bis in idem;
  • legality;
  • due process;
  • proportionality;
  • effective judicial protection.

Paragraph 2 supports EU oversight by requiring Member States to notify their national penalty rules and later amendments to the European Commission. The Commission’s public notification collection shows how Member States have used the GDPR’s national opening clauses and helps controllers, individuals and regulators identify applicable domestic rules.

The simplest final summary is:

Article 83 fines the organisation where its GDPR conduct is intentional or negligent. Article 84 allows national law to address additional wrongdoing, including serious personal misconduct such as deliberately stealing, selling, concealing or misusing personal data. Member States may choose different legal tools, but those tools must genuinely work, must be fair, and must not punish the same person twice unlawfully for the same offence.