{"id":2034,"date":"2019-04-05T12:03:06","date_gmt":"2019-04-05T12:03:06","guid":{"rendered":"https:\/\/seersco.com\/blogs\/?p=2034"},"modified":"2023-09-25T11:48:19","modified_gmt":"2023-09-25T11:48:19","slug":"guidelines-fines-under-the-gdpr","status":"publish","type":"post","link":"https:\/\/seersco.com\/blogs\/guidelines-fines-under-the-gdpr\/","title":{"rendered":"Guidelines For Fines Under The GDPR"},"content":{"rendered":"<p>The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) published a press release on 14 March 2019, updating its policy on calculating administrative fines. These guidelines are intended for the organisations to become aware of the updated structure of penalties.<\/p>\n<h2>BACKGROUND<\/h2>\n<p>The GDPR empowers each member state of the EU to impose administrative fines, the amount of which depends on every single case. Being a member state, The Dutch Data Protection Authority (AP) has the power to issue administrative fines for the violations of GPDR provisions.<br \/>\nArticle 83 of the <a href=\"https:\/\/seersco.com\/articles\/complete-gdpr-summary\/\"><strong>GDPR<\/strong><\/a> sets out the details for imposing fines on <a href=\"https:\/\/seersco.com\/blogs\/compliant-vs-non-compliant-cookie-banners\/\">non-compliant<\/a> organisations. The maximum limit is 20 million euros or 4% of annual global turnover. This big sum of money can pretty much wipe out the entire profits of a company hence eliminating the chances of regulatory arbitrage.<br \/>\nThe Dutch Data Protection Authority (AP), preparing to enforce the new rules, updated its penalties structure and published a press release on 14 March 2019. The newly updated policy provides insights on how the (AP) will use its administrative power.<\/p>\n<h3>OVERVIEW OF THE NEW GUIDELINES<\/h3>\n<p>Although the penalties described in GDPR are two-tiered, the AP divided the infringements into four categories. Each category has an upper and a lower limit, and a basic fine. The basic fine in each category will be 50% of the sum of the upper and lower limit. It is an average of the minimum and maximum fine in that category.<\/p>\n<h4 style=\"margin-top: 0px !important; padding-top: 0px !important;\">The AP will take into account the following factors while deciding the amount of fine:<\/h4>\n<ul>\n<li>The nature of the breach, how much risk is likely to be caused by the data breach?<\/li>\n<li>How many people are will affect as a result of the personal data breach?<\/li>\n<li>The amount of data compromised<\/li>\n<li>The types of data involved (e.g., sensitive vs non-sensitive data, children\u2019s data vs adults\u2019 data, or financial or non-financial information)<\/li>\n<li>How long has it been the breach? Generally, the more time spent, the more harm is likely to occur<\/li>\n<li>Whether it was a result of lack of security, organisational negligence, or a cyber-attack, and whether there is involvement or not.<\/li>\n<li>No matter it was a result of negligence or someone deliberately breach into the data records<\/li>\n<li>Whether or not the <a href=\"https:\/\/seersco.com\/articles\/articles\/data-controller-vs-data-processor\/\">data controller<\/a> has taken any action to minimise the damage to the victims. If the <a href=\"https:\/\/seersco.com\/articles\/articles\/data-controller-vs-data-processor\/\">data controller<\/a> stays careless despite knowing that a data breach occurred already, they are more likely to penalise.<\/li>\n<li>Whether there has been a previous data breach or not. A history of data breaches perks up the ears of regulatory authorities, implying negligence on the part of the <a href=\"https:\/\/seersco.com\/articles\/articles\/data-controller-vs-data-processor\/\">data controller<\/a> or some deliberate action involved, e.g. moral hazard or some mole in the organisation.<\/li>\n<li>Whether or not the <a href=\"https:\/\/seersco.com\/articles\/articles\/data-controller-vs-data-processor\/\">data controller<\/a> or processor gained any benefit from the breach<\/li>\n<li>Whether the organisation had adhered to any approved code of conduct (Article 40) or certification mechanism (Article 42)<\/li>\n<\/ul>\n<p>The maximum amount for the most severe violation of the GDPR is \u20ac1,000,000. However, this is not the final word. If this maximum amount of fine is inadequate in a particular scenario, the penalties can go even higher. If the infringements are repeating, the policy states that the Dutch DPA will increase the fines by 50%. However, the resulting amount will not exceed the threshold of \u20ac20,000,000.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GDPR | Seers Blog<\/p>\n","protected":false},"author":3,"featured_media":2036,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"rank_math_lock_modified_date":false,"footnotes":""},"categories":[20,1],"tags":[],"class_list":["post-2034","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-megamenufull","category-uncategorized","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","no-featured-image-padding"],"_links":{"self":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts\/2034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/comments?post=2034"}],"version-history":[{"count":0,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/posts\/2034\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/media\/2036"}],"wp:attachment":[{"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/media?parent=2034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/categories?post=2034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seersco.com\/blogs\/wp-json\/wp\/v2\/tags?post=2034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}