Research Article
BibTex RIS Cite

The Administrative Fines Regime of the General Data Protection Regulation and Its Impact

Year 2021, Volume: 3 Issue: 1, 1 - 16, 23.06.2021

Abstract

The GDPR provides a modernised and comprehensive personal data protection regime backed by strong enforcement measures. Aiming to ensure effective protection of personal data in the European Union, the GDPR allows the national data protection authorities to impose massive administrative fines along with other corrective powers for infringements of data protection rules. While the possible maximum amount of fines implies that the EU legislator seeks for complete compliance with the Regulation, the principles and assessment criteria protect the balance and encourage the parties involved to adopt a pro-active approach and to cooperate. Therefore, the GDPR sanction regime aims at effectiveness, proportionality, and dissuasiveness. Its implementation so far demonstrates a gradual increase not only in the number of violations that have become subject to administrative fines but also in sky-high fines in specific cases. In the following years, it is expected that a high level of coherent, consistent, and effective application of the GDPR’s administrative fine regime throughout the EU will progressively be reached.

Supporting Institution

Trinity College Dublin, Jean Monnet Scholarship Programme

References

  • Charter of Fundamental Rights of the European Union [2012] OJ C 326.
  • Consolidated Version of the Treaty on the Functioning of the European Union [2012] OJ C 326.
  • Case C-41/90 Kalus Höfner and Fritz Elser v Macrotron GmbH [1991] ECR I-01979.
  • Murray A, Information Technology Law (4th edn, Oxford University Press 2019).
  • Pila J and Torremans P, European Intellectual Property Law (2nd edn, Oxford University Press 2019).
  • Albrecht J P, ‘How the GDPR Will Change the World’ [2016] 2(3) EDPLR.
  • Data Protection Commission, ‘Annual Report’ [2019].
  • EU Agency for Fundamental Rights, Access to data protection remedies in EU Member States [2013].
  • EU Agency for Fundamental Rights, Handbook on European data protection law [2018].
  • Maxwell W and Gateau C, ‘A point for setting administrative fines under the GDPR’ [2019] 16 RJSP.
  • McLaughlin S, ‘Ireland: A Brief Overview of the Implementation of the GDPR’ [2018] 4(2) EDPL.
  • Nemitz P, ‘Fines under the GDPR’ [2017] CPDP Conference Book.
  • Purtova N, ‘The law of everything. Broad concept of personal data and future of EU data protection law’ [2018] 10(1) LIT.
  • Baines J, ‘Covid-19 and ICO’s proposed fines for BA and Marriott’ (Mishcon de Reya, 16 March 2020) <www.mishcon.com>.
  • Bodewits J and Blok B, ‘Dutch DPA Issues Record Fine for Violating GDPR Data Subject Rights’ (Lexology, 7 July 2020)
  • Council of Europe Directorate General Human Rights and Rule of Law, ‘Data Protection Convention 108’ (20 January 2020)
  • DLA Piper, ‘GDPR data breach survey: January 2020’ (20 January 2020) 4 <www.dlapiper.com>.
  • European Commission, ‘Commission fines Google €1.49 billion for abusive practices in online advertising’ (20 March 2019).
  • European Data Protection Board, ‘Irish Data Protection Commission announces decision in Twitter inquiry’ (15 December 2020).
  • European Data Protection Board, ‘Marketing: The Italian SA Fines TIM EUR 27.8 Million’ (1 February 2020).
  • Hamburg DPA, ’35.3 million euros fine for data protection violations in the H&M service center’ (1 October 2020)
  • Horgan-Jones J, ‘Data commissioner starts investigations into Google and Tinder’ The Irish Times (4 February 2020)
  • Information Commissioner’s Office, ‘Intention to fine British Airways £183.39m under GDPR for data breach’ (08 July 2019).
  • International Association of Privacy Professionals, ‘GDPR One Year Anniversary – Infographic’ <iapp.org>.
  • Kobie N, ‘Germany says GDPR could collapse as Ireland dallies on big fines’ (Wired, 27 April 2020) <www.wired.co.uk>.
  • Lillington K, ‘Coronavirus: Contact tracing app raises privacy concerns’ The Irish Times (3 April 2020)
  • Monteiro A M, ‘First GDPR fine in Portugal issued against hospital for three violations’ (IAPP, 3 January 2019) <iapp.org>.
  • Ram A and Khan M, ‘France fines Google €50m in test for EU’s new data laws’ (Financial Times, 21 January 2019
  • Ritzer C and Filkina N, ‘German Court cuts multimillion GDPR fine by 90%’ (the Data Protection Report, 17 November 2020)
  • Taylor C, ‘Data Protection Commission disappointed at budget allocation’ The Irish Times (9 October 2019)
  • Tinnefeld C and Hanssen H, ‘German Court Drastically Reduces GDPR Fine’ (Lexology, 17 November 2020)
  • Vinocur N, ‘One country blocks the world on data privacy’ (Politico, 24 April 2019) <www.politico.eu>.
  • Vinocur N, ‘We have a huge problem: European regulator despairs over lack of enforcement’ (Politico, 27 December 2019)

Genel Veri Koruma Tüzüğü İdari Para Cezaları Rejimi ve Etkiliği

Year 2021, Volume: 3 Issue: 1, 1 - 16, 23.06.2021

Abstract

GVKT, güçlü yaptırım olanakları ile desteklenen modern ve kapsamlı bir kişisel verilerin korunması rejimi düzenlemektedir. Avrupa Birliği’nde kişisel verilerin etkili bir şekilde korunmasını sağlamayı amaçlayan GVKT, ulusal veri koruma kurullarına, diğer düzeltici önlemler alma yetkisinin yanı sıra veri koruma kurallarının ihlali halinde önemli miktarlarda idari para cezası uygulama yetkisi vermektedir. İdari para cezalarının olası maksimum miktarı, AB yasa koyucusunun Tüzüğe tam uyum sağlanmasını amaçladığına işaret ederken, idari para cezalarına ilişkin temel ilkeler ile değerlendirme kriterleri dengeyi sağlamakta ve ilgili tarafları proaktif bir yaklaşım benimseyerek iş birliği yapmaya teşvik etmektedir. Bu nedenle GDPR yaptırım rejimi etkililiği, orantılılığı ve caydırıcılığı sağlamayı amaçlamaktadır. Şimdiye kadarki uygulama, yalnızca idari para cezalarına konu olan ihlallerin sayısında değil, aynı zamanda belirli ihlaller halinde uygulanan yüksek para cezalarında da kademeli bir artış olduğunu göstermiştir. Önümüzdeki yıllarda aşamalı olarak, GVKT’nin idari para cezalarına ilişkin kurallarının AB genelinde daha uyumlu, istikrarlı ve etkili bir şekilde uygulanacağı beklenmektedir.

References

  • Charter of Fundamental Rights of the European Union [2012] OJ C 326.
  • Consolidated Version of the Treaty on the Functioning of the European Union [2012] OJ C 326.
  • Case C-41/90 Kalus Höfner and Fritz Elser v Macrotron GmbH [1991] ECR I-01979.
  • Murray A, Information Technology Law (4th edn, Oxford University Press 2019).
  • Pila J and Torremans P, European Intellectual Property Law (2nd edn, Oxford University Press 2019).
  • Albrecht J P, ‘How the GDPR Will Change the World’ [2016] 2(3) EDPLR.
  • Data Protection Commission, ‘Annual Report’ [2019].
  • EU Agency for Fundamental Rights, Access to data protection remedies in EU Member States [2013].
  • EU Agency for Fundamental Rights, Handbook on European data protection law [2018].
  • Maxwell W and Gateau C, ‘A point for setting administrative fines under the GDPR’ [2019] 16 RJSP.
  • McLaughlin S, ‘Ireland: A Brief Overview of the Implementation of the GDPR’ [2018] 4(2) EDPL.
  • Nemitz P, ‘Fines under the GDPR’ [2017] CPDP Conference Book.
  • Purtova N, ‘The law of everything. Broad concept of personal data and future of EU data protection law’ [2018] 10(1) LIT.
  • Baines J, ‘Covid-19 and ICO’s proposed fines for BA and Marriott’ (Mishcon de Reya, 16 March 2020) <www.mishcon.com>.
  • Bodewits J and Blok B, ‘Dutch DPA Issues Record Fine for Violating GDPR Data Subject Rights’ (Lexology, 7 July 2020)
  • Council of Europe Directorate General Human Rights and Rule of Law, ‘Data Protection Convention 108’ (20 January 2020)
  • DLA Piper, ‘GDPR data breach survey: January 2020’ (20 January 2020) 4 <www.dlapiper.com>.
  • European Commission, ‘Commission fines Google €1.49 billion for abusive practices in online advertising’ (20 March 2019).
  • European Data Protection Board, ‘Irish Data Protection Commission announces decision in Twitter inquiry’ (15 December 2020).
  • European Data Protection Board, ‘Marketing: The Italian SA Fines TIM EUR 27.8 Million’ (1 February 2020).
  • Hamburg DPA, ’35.3 million euros fine for data protection violations in the H&M service center’ (1 October 2020)
  • Horgan-Jones J, ‘Data commissioner starts investigations into Google and Tinder’ The Irish Times (4 February 2020)
  • Information Commissioner’s Office, ‘Intention to fine British Airways £183.39m under GDPR for data breach’ (08 July 2019).
  • International Association of Privacy Professionals, ‘GDPR One Year Anniversary – Infographic’ <iapp.org>.
  • Kobie N, ‘Germany says GDPR could collapse as Ireland dallies on big fines’ (Wired, 27 April 2020) <www.wired.co.uk>.
  • Lillington K, ‘Coronavirus: Contact tracing app raises privacy concerns’ The Irish Times (3 April 2020)
  • Monteiro A M, ‘First GDPR fine in Portugal issued against hospital for three violations’ (IAPP, 3 January 2019) <iapp.org>.
  • Ram A and Khan M, ‘France fines Google €50m in test for EU’s new data laws’ (Financial Times, 21 January 2019
  • Ritzer C and Filkina N, ‘German Court cuts multimillion GDPR fine by 90%’ (the Data Protection Report, 17 November 2020)
  • Taylor C, ‘Data Protection Commission disappointed at budget allocation’ The Irish Times (9 October 2019)
  • Tinnefeld C and Hanssen H, ‘German Court Drastically Reduces GDPR Fine’ (Lexology, 17 November 2020)
  • Vinocur N, ‘One country blocks the world on data privacy’ (Politico, 24 April 2019) <www.politico.eu>.
  • Vinocur N, ‘We have a huge problem: European regulator despairs over lack of enforcement’ (Politico, 27 December 2019)
There are 33 citations in total.

Details

Primary Language English
Subjects Law in Context
Journal Section Articles
Authors

İbrahim Barış Sayar 0000-0002-4290-6463

Publication Date June 23, 2021
Submission Date January 3, 2021
Acceptance Date June 7, 2021
Published in Issue Year 2021 Volume: 3 Issue: 1

Cite

APA Sayar, İ. B. (2021). The Administrative Fines Regime of the General Data Protection Regulation and Its Impact. Kişisel Verileri Koruma Dergisi, 3(1), 1-16.
AMA Sayar İB. The Administrative Fines Regime of the General Data Protection Regulation and Its Impact. Kişisel Verileri Koruma Dergisi. June 2021;3(1):1-16.
Chicago Sayar, İbrahim Barış. “The Administrative Fines Regime of the General Data Protection Regulation and Its Impact”. Kişisel Verileri Koruma Dergisi 3, no. 1 (June 2021): 1-16.
EndNote Sayar İB (June 1, 2021) The Administrative Fines Regime of the General Data Protection Regulation and Its Impact. Kişisel Verileri Koruma Dergisi 3 1 1–16.
IEEE İ. B. Sayar, “The Administrative Fines Regime of the General Data Protection Regulation and Its Impact”, Kişisel Verileri Koruma Dergisi, vol. 3, no. 1, pp. 1–16, 2021.
ISNAD Sayar, İbrahim Barış. “The Administrative Fines Regime of the General Data Protection Regulation and Its Impact”. Kişisel Verileri Koruma Dergisi 3/1 (June 2021), 1-16.
JAMA Sayar İB. The Administrative Fines Regime of the General Data Protection Regulation and Its Impact. Kişisel Verileri Koruma Dergisi. 2021;3:1–16.
MLA Sayar, İbrahim Barış. “The Administrative Fines Regime of the General Data Protection Regulation and Its Impact”. Kişisel Verileri Koruma Dergisi, vol. 3, no. 1, 2021, pp. 1-16.
Vancouver Sayar İB. The Administrative Fines Regime of the General Data Protection Regulation and Its Impact. Kişisel Verileri Koruma Dergisi. 2021;3(1):1-16.