Slide background

Guidelines 04/2022 - administrative fines under the GDPR

ID 16694 | | Visite: 291 | Documenti riservati Full PlusPermalink: https://www.certifico.com/id/16694

Guidelines EDPB 04 2022

Guidelines 04/2022 on the calculation of administrative fines under the GDPR

European Data Protection Board (EDPB) Version 1.0 Adopted on 12 May 2022

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory authorities use when calculating of the amount of the fine. These Guidelines complement the previously adopted Guidelines on the application and setting of administrative fines for the purpose of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine.

The calculation of the amount of the fine is at the discretion of the supervisory authority, subject to the rules provided for in the GDPR.

In that context, the GDPR requires that the amount of the fine shall in each individual case be effective, proportionate and dissuasive (Article 83 GDPR). Moreover, when setting the amount of the fine, supervisory authorities shall give due regard to a list of circumstances that refer to features of the infringement (its seriousness) or of the character of the perpetrator (Article 83 GDPR).

Lastly, the amount of the fine shall not exceed the maximum amounts provided for in Articles 83 and GDPR. The quantification of the amount of the fine is therefore based on a specific evaluation carried out in each case, within the parameters provided for by the GDPR.

Taking the abovementioned into account, the EDPB has devised the following methodology, consisting of five steps, for calculating administrative fines for infringements of the GDPR. Firstly, the processing operations in the case must be identified and the application of Article 83 GDPR needs to be evaluated (Chapter 3).

Second, the starting point for further calculation of the amount of the fine needs to be identified (Chapter 4).

This is done by evaluating the classification of the infringement in the GDPR, evaluating the seriousness of the infringement in light of the circumstances of the case, and evaluating the turnover of the undertaking. The third step is the evaluation of aggravating and mitigating circumstances related to past or present behaviour of the controller/processor and increasing or decreasing the fine accordingly (Chapter 5).

The fourth step is identifying the relevant legal maximums for the different infringements.

Increases applied in previous or next steps cannot exceed this maximum amount (Chapter 6).

Lastly, it needs to be analysed whether the calculated final amount meets the requirements of effectiveness, dissuasiveness and proportionality.

The fine can still be adjusted accordingly (Chapter 7), however without exceeding the relevant legal maximum.

Throughout all abovementioned steps, it must be borne in mind that the calculation of a fine is no mere mathematical exercise. Rather, the circumstances of the specific case are the determining factors leading to the final amount, which can – in all cases – vary between any minimum amount and the legal maximum. These Guidelines and its proposed methodology will remain under constant review of the EDPB.

...

Fonte: EU

Collegati

Descrizione Livello Dimensione Downloads
Allegato riservato Guidelines EDPB 04 2022.pdf
Version 1.0 Adopted on 12 May 2022
685 kB 0

Tags: Abbonati Full Plus Privacy

Articoli correlati

Più letti Full Plus

D PR  495 1992 Regolamento attuazione CdS
Giu 24, 2022 6199

DPR 16 dicembre 1992 n. 495

D.P.R. 16 dicembre 1992 n. 495 Regolamento di esecuzione e di attuazione del nuovo codice della strada. GU n. 303 del 28.12.1992 - SO n. 134 Allegati i testi consolidati (Riservati Abbonati Trasporto ADR): Aggiornato al 17.06.2019Aggiornato al 17.02.2019Aggiornato al 29.12.2018Aggiornato al… Leggi tutto
autorit  portuali
Gen 02, 2022 4230

Decreto Legislativo n. 169 del 4 agosto 2016

Decreto Legislativo n. 169 del 4 agosto 2016 / Autorità portuali ID 5310 | Update news 02.01.2022 Decreto Legislativo n. 169 del 4 agosto 2016 Riorganizzazione, razionalizzazione e semplificazione della disciplina concernente le Autorità portuali di cui alla legge 28 gennaio 1994, n. 84, in… Leggi tutto

Ultimi archiviati Full Plus

La normazione a supporto del PNRR
Ott 19, 2022 135

La normazione a supporto del PNRR

in News
La normazione a supporto del PNRR ID 17881 | 19.10.2022 / In allegato UNI e i suoi esperti del sistema Confindustria, in collaborazione con CROIL (Consulta Regionale degli Ordini degli Ingegneri della Lombardia), MIP (Graduate School of Business del Politecnico di Milano) e FEDERMANAGER, hanno… Leggi tutto
Circolare MIMS prot  n  29290 del 20 settembre 2022
Ott 05, 2022 211

Circolare MIMS prot. n. 29290 del 20 settembre 2022

Circolare MIMS prot. n. 29290 del 20 settembre 2022 ID 17766 | 05.10.2022 / In allegato Circolare Oggetto: Legge 5 agosto 2022, n. 108, recante “Conversione in legge, con modificazioni, del decreto-legge 16 giugno 2022, n. 68, recante disposizioni urgenti per la sicurezza e lo sviluppo delle… Leggi tutto
Vocabolario comune appalti pubblici
Ago 26, 2022 266

Regolamento (CE) n. 2195/2002

in News
Regolamento (CE) n. 2195/2002 / Vocabolario comune appalti pubblici Regolamento (CE) n. 2195/2002 del Parlamento europeo e del Consiglio del 5 novembre 2002 relativo al vocabolario comune per gli appalti pubblici (CPV) GU L 340/1 del 16.12.2002 __________ Articolo 1 1. È istituito un sistema di… Leggi tutto