As per a report by the European Data Protection Board, national data protection authorities across the EU will now follow a five-step method, adopted on September 21, for deciding whether an infringement should draw an administrative fine: first checking that a fine is legally available, then identifying who is liable, assessing whether the breach was intentional or negligent, weighing aggravating and mitigating factors, and finally checking that any fine is effective, proportionate and genuinely deters repeat conduct. Minor infringements are meant to draw a reprimand rather than a fine under the framework, which includes 14 worked examples for regulators to follow.
The EDPB also finalised separate guidelines on how the Digital Services Act interacts with the GDPR, aimed at keeping the two regimes consistent where DSA obligations touch personal data handled by intermediary platforms. "The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed," said EDPB Deputy Chair Jelena Virant Burnik. The fining guidelines remain open for public comment until November 13.
Comments
0 commentsNo comments yet — be the first.