{"id":873,"date":"2016-04-15T22:44:50","date_gmt":"2016-04-15T20:44:50","guid":{"rendered":"https:\/\/planit.legal\/wp\/?p=873"},"modified":"2019-03-25T23:56:20","modified_gmt":"2019-03-25T22:56:20","slug":"fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2","status":"publish","type":"post","link":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/","title":{"rendered":"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2"},"content":{"rendered":"<p>The European Parliament has most recently adopted the <a href=\"https:\/\/planit.legal\/en\/gdpr\/\">General Data Protection Regulation (GDPR)<\/a>. Part of this new data protection framework are dramatically increased sanctions for violations of data protection law. When the GDPR enters into force, the blunt sword for enforcing data protection requirements will suddenly turn razor sharp. Companies must then be prepared for fines amounting to millions of Euros.<\/p>\n<h2>1. Data Protection Enforcement<\/h2>\n<p>Enforcing data protection law is and will in the first place be the data protection authorities\u2019 responsibility. Currently, <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0550\">Section 38 German Data Protection Act (BDSG)<\/a> establishes the respective competencies including information rights and the power to issue administrative orders and (administrative) fines in case of data protection violations. Respective powers of the data protection authorities are also provided for in <a href=\"https:\/\/planit.legal\/en\/gdpr#art-58\">Art. 58 GDPR<\/a> (see item 2.). Further, the courts may impose (criminal) penalties for severe infringements of data protection law (see item 3.) and affected data subjects may enforce their data protection rights individually including damages for data protection infringements (see item 4.).<\/p>\n<h2>2. Fines for Data Protection Violations<\/h2>\n<p>So far, fines amounting to millions of Euros are rarely seen in the data protection authorities\u2019 enforcement practice. Such spectacular cases were fines in the amount of EUR 1.46 million for 35 Lidl distribution companies, EUR 1.3 million against the Debeka Krankenversicherungsverein e.G. and EUR 1.12 million against the Deutsche Bahn AG.<\/p>\n<p>When the GDPR enters into force, such fines may be imposed more frequently. <a href=\"https:\/\/planit.legal\/en\/gdpr#art-83\">Art. 83<span id=\"qb\">(<\/span>4)-(6) GDPR<\/a> increases fines for data protection violations dramatically on a uniform European level. Art. 24 <a href=\"http:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=CELEX:31995L0046:en:HTML\">Data Protection Directive (DPD)<\/a> being the current basis for the rules of the member states on fines for data protection violations left the discretion for the permitted amount of fines to the member States. The consequence are strong discrepancies between the member states data protection laws. In Austria fines may amount to EUR 25,000, in France to EUR 150,000, in Spain to EUR 600,000 and in the United Kingdom to \u00a3 500,000.<\/p>\n<p>For Germany, <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0594\">Section 43<span id=\"qb\">(<\/span>3) BDSG<\/a> stipulates fines of up to EUR 50,000 for violations listed in <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0580\">Section 42<span id=\"qb\">(<\/span>1) BDSG<\/a> and fines of up to EUR 300,000 for violations listed in Section <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0594\">43<span id=\"qb\">(<\/span>2) BDSG<\/a>. Exceeding these limits, higher finds may be imposed to skim the profits gained from the data protection infringement. <a href=\"https:\/\/planit.legal\/en\/gdpr#art-83\">Art. 83<span id=\"qb\">(<\/span>4) GDPR<\/a> increases fines for named infringements up to EUR 10 million or 2% of a company\u2019s worldwide turnover, and <a href=\"https:\/\/planit.legal\/en\/gdpr#art-83\">Art. 83<span id=\"qb\">(<\/span>5) and (6) GDPR<\/a> provides for even higher fines of EUR 20 million or 4% of the worldwide turnover.<\/p>\n<p>In order to calculate the worldwide turnover, one must take into consideration the turnover of a company in the meaning of Art. 101 and 102 <a href=\"http:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:12012E\/TXT&amp;from=EN\">Treaty on the Functioning of the EU<\/a> (see <a href=\"https:\/\/planit.legal\/en\/gdpr\/recitals\/#150\">Recital 150 GDPR<\/a>). Accordingly, the turnover of the whole group of companies being affiliated with the data controller turns relevant. It is therefore well possible to even see fines for data protection violation in billions of Euros. The particular amount imposed will of course continue to be dependent on the individual circumstances and may also be far below such record breaking amounts. Criteria for setting the actual amount are stipulated by <a href=\"https:\/\/planit.legal\/en\/gdpr#art-83\">Art. 83<span id=\"qb\">(<\/span>2) GDPR<\/a> and include:<\/p>\n<ol>\n<li>the nature, gravity and duration of the infringement taking into account the nature, scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;<\/li>\n<li>the intentional or negligent character of the infringement;<\/li>\n<li>any action taken to mitigate the damage suffered by data subjects;<\/li>\n<li>the degree of responsibility taking into account technical and organisational measures implemented;<\/li>\n<li>any relevant previous infringements;<\/li>\n<li>the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;<\/li>\n<li>the categories of personal data affected by the infringement;<\/li>\n<li>the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the infringement was notified;<\/li>\n<li>in case measures have previously been ordered against the data controller or data processor concerned with regard to the same subject-matter, compliance with those measures;<\/li>\n<li>adherence to approved codes of conduct pursuant to <a href=\"https:\/\/planit.legal\/en\/gdpr#art-40\">Article 40 GDPR<\/a> or approved certification mechanisms pursuant to <a href=\"https:\/\/planit.legal\/en\/gdpr#art-42\">Article 42 GDPR<\/a>; and<\/li>\n<li>any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.<\/li>\n<\/ol>\n<p>As indicated by <a href=\"https:\/\/planit.legal\/en\/gdpr\/recitals\/#150\">Recital 150 GDPR<\/a>, ensuring a uniform application of fines requires the data protection authorities to use the consistency mechanism according to <a href=\"https:\/\/planit.legal\/en\/gdpr#art-63\">Article 63 GDPR<\/a>. At the same time, local circumstances such as wage level in the particular member state and economic state of the acting people are to be considered.<\/p>\n<p>For multiple violations, there may be multiple fines as a general rule. This rule is to be restricted, however, where a fine is imposed for the same or connected violations of data protection law, the total amount is limited to the fine for the most severe infringement. This creates a relevant limitation of liability in regard to fines for data protection violations.<\/p>\n<h2>3. Penalties for Data Protection Violations<\/h2>\n<p>There are no new criminal offences implemented by the GDPR. Rather <a href=\"https:\/\/planit.legal\/en\/gdpr#art-84\">Art. 84<span id=\"qb\">(<\/span>1) GDPR<\/a> and <a href=\"https:\/\/planit.legal\/en\/gdpr\/recitals\/#149\">Recital 149 GDPR<\/a> state that member states shall at their own discretion implement respective provisions under criminal law. This fully reflects the current framework under Art. 24 <a href=\"http:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=CELEX:31995L0046:en:HTML\">DPD<\/a>.<\/p>\n<p>Data protection criminal liability in Germany is currently governed by <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0627\">Section 44 BDSG<\/a> and the German States data protection acts. The latter shall not be subject of this article. <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0627\">Section 44 BDSG<\/a> refers to administrative offences stipulated in <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0594\">Section 43 BDSG<\/a> (see above item 2) and imposes criminal sanctions where these administrative offices are committed with the intent of gaining a commercial profit or causing damage to a third party.<\/p>\n<p>In light of this rather broad criminal liability it is to be assumed that infringements of data protection law rather often trigger data protection criminal offences as well. Should this be the case, at least the focus of criminal enforcement authorities is not directed at data protection crimes. As far as known to me, there has only been one data protection criminal case in the German criminal courts leading to criminal sanctions.<\/p>\n<p>Section <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0594\">43<span id=\"qb\">(<\/span>1) and (3) BDSG<\/a>, listing administrative offences will be replaced by <a href=\"https:\/\/planit.legal\/en\/gdpr#art-83\">Art. 83 GDPR<\/a>. The referral in <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0627\">Section 44 BDSG<\/a> will then not lead anywhere; accordingly, the German legislator would need to implement new provisions on data protection criminal law in order to keep German data protection criminal law in place.<\/p>\n<p>It must be assumed that the German legislator will implement provisions on data protection crimes. How this will be done technically, remains to be seen. A feasible approach would be to implement a provision in a similar manner as currently <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0627\">Section 44 BDSG<\/a> referring to administrative offences listed in <a href=\"https:\/\/planit.legal\/en\/gdpr#art-83\">Art. 83 GDPR<\/a> and linking criminal sanctions where additional requirements are fulfilled.<\/p>\n<h2>4. Damages for Data Protection Violations<\/h2>\n<p>Under <a href=\"https:\/\/planit.legal\/en\/gdpr#art-82\">Art. 82<span id=\"qb\">(<\/span>1) GDPR<\/a>, any person having suffered material or non-material damages by processing his or her personal data may claim compensation. This claim is in the first place directed against the data controller and insofar reflects the current situation under <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bdsg\/englisch_bdsg.html#p0172\">Section 7 BDSG<\/a> and Art. 23<span id=\"qb\">(<\/span>1) <a href=\"http:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=CELEX:31995L0046:en:HTML\">DPD<\/a> respectively. In addition, and insofar different from the current situation, there is also a direct claim against the involved data processor.<\/p>\n<p>As currently the case \u2013 also under the GDPR \u2013 the affected person must establish the infringement caused by the data protection violation and the resulting damage. Such damage may in deviation from the current framework also be non-material.<\/p>\n<p>To successfully claim damages from the data controller, it is required that the data controller is in breach with data protection obligations. To claim damages from the data processor, he has to be in violation of contractual obligations under the data processing agreement with the data controller or with data protection requirements particularly directed to him as data processor. However, there is the assumption that the data controller or data processors have violated their duties unless they prove the opposite. This may have massive effect as it significantly facilitates damage claims for data protection violations. Accordingly, an increase in the number of claims is to be expected.<\/p>\n<p><a href=\"https:\/\/planit.legal\/en\/gdpr#art-82\">Art. 82<span id=\"qb\">(<\/span>4) GDPR<\/a> stipulates the joint responsibility of data controller and data processor in the external relation to the affected data subjects. <a href=\"https:\/\/planit.legal\/en\/gdpr#art-82\">Article 82<span id=\"qb\">(<\/span>5) GDPR<\/a> then introduces the framework for internal compensation where either party is held liable and has compensated the data subject. These rules are in line with the principles of joint external responsibility under German civil law, namely Section <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bgb\/englisch_bgb.html#p1512\">421<\/a> and <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bgb\/englisch_bgb.html#p1535\">430 German Civil Code (BGB)<\/a>.<\/p>\n<p>In addition to any claims based on the data protection damage compensation framework under <a href=\"https:\/\/planit.legal\/en\/gdpr#art-82\">Art. 82 GDPR<\/a>, damage claims may also be based on other civil law actions such as tort under <a href=\"http:\/\/www.gesetze-im-internet.de\/englisch_bgb\/englisch_bgb.html#p3484\">Section 823<span id=\"qb\">(<\/span>2) BGB<\/a> in connection with an infringed provision under the GDPR.<\/p>\n<h2>5. Conclusion<\/h2>\n<p>Rules on data protection administrative offences and damage compensation further develop the European data protection framework without creating revolutionary new obligations. In the same way as under the current framework, data protection authorities will have the power to impose administrative fines. The amount, however, will change dramatically with an upper bound of EUR 20 million or even more. This must be considered in any company\u2019s compliance and risk-management strategy.<\/p>\n<p>Whether or not there will be material changes in data protection criminal law will now depend on the German legislator. While severe changes are unlikely, data protection criminal law is a dormant risk. It is better considered and approached in appropriate manner, as German criminal enforcement authorities may at any time draw their attention to this supposedly new field of criminal law enforcement.<\/p>\n<p>The law of data protection damage compensation under the GDPR brings new direct claims of data subjects against data processors and puts a burden of proof on the addressed data controllers and data processors. This must be addressed in the compliance framework as an increased number of claims is to be expected. The only line of defence \u2013 at least against unfounded claims &#8211; appears to be proper documentation of any data processing activities.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Other parts of this series:<\/p>\n<p>Part 1: EU Data Protection Regulation \u2013 New Series<\/p>\n<p><a href=\"https:\/\/planit.legal\/blog\/en\/principles-consent-and-statutory-justifications-gdpr-series-part-3\/\">Part 3: Principles, Consent and Statutory Justifications<\/a><\/p>\n<p><a href=\"https:\/\/planit.legal\/blog\/en\/commissioned-data-processing-and-international-data-transfer-gdpr-series-part-4\/\">Part 4: Commissioned Data Processing and International Data Transfer<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The European Parliament has most recently adopted the General Data Protection Regulation (GDPR). Part of this new data protection framework are dramatically increased sanctions for violations of data protection law. When the GDPR enters into force, the blunt sword for enforcing data protection requirements will suddenly turn razor sharp. Companies must then be prepared for [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":871,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[30,37],"tags":[],"class_list":["post-873","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-sanctions","category-general-data-protection-regulation"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2 - PLANIT\/\/LEGAL<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2 - PLANIT\/\/LEGAL\" \/>\n<meta property=\"og:description\" content=\"The European Parliament has most recently adopted the General Data Protection Regulation (GDPR). Part of this new data protection framework are dramatically increased sanctions for violations of data protection law. When the GDPR enters into force, the blunt sword for enforcing data protection requirements will suddenly turn razor sharp. Companies must then be prepared for [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/\" \/>\n<meta property=\"og:site_name\" content=\"PLANIT\/\/LEGAL\" \/>\n<meta property=\"article:published_time\" content=\"2016-04-15T20:44:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-03-25T22:56:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"384\" \/>\n\t<meta property=\"og:image:height\" content=\"288\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Dr. Bernd Schmidt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Dr. Bernd Schmidt\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/\"},\"author\":{\"name\":\"Dr. Bernd Schmidt\",\"@id\":\"https:\/\/legal-test.planit.legal\/#\/schema\/person\/616f088d80b0ac267989a17c228fb541\"},\"headline\":\"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2\",\"datePublished\":\"2016-04-15T20:44:50+00:00\",\"dateModified\":\"2019-03-25T22:56:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/\"},\"wordCount\":1668,\"commentCount\":0,\"image\":{\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg\",\"articleSection\":[\"Data Protection Sanctions\",\"General Data Protection Regulation\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/\",\"url\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/\",\"name\":\"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2 - PLANIT\/\/LEGAL\",\"isPartOf\":{\"@id\":\"https:\/\/legal-test.planit.legal\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg\",\"datePublished\":\"2016-04-15T20:44:50+00:00\",\"dateModified\":\"2019-03-25T22:56:20+00:00\",\"author\":{\"@id\":\"https:\/\/legal-test.planit.legal\/#\/schema\/person\/616f088d80b0ac267989a17c228fb541\"},\"breadcrumb\":{\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#primaryimage\",\"url\":\"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg\",\"contentUrl\":\"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg\",\"width\":384,\"height\":288},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\",\"item\":\"https:\/\/planit.legal\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data Protection Sanctions\",\"item\":\"https:\/\/planit.legal\/en\/category\/data-protection-sanctions\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/legal-test.planit.legal\/#website\",\"url\":\"https:\/\/legal-test.planit.legal\/\",\"name\":\"PLANIT\/\/LEGAL\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/legal-test.planit.legal\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/legal-test.planit.legal\/#\/schema\/person\/616f088d80b0ac267989a17c228fb541\",\"name\":\"Dr. Bernd Schmidt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/legal-test.planit.legal\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/28b706926e56255094d69874054ac2fd30bf041ff7919877d4072a8dd8e4d31c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/28b706926e56255094d69874054ac2fd30bf041ff7919877d4072a8dd8e4d31c?s=96&d=mm&r=g\",\"caption\":\"Dr. Bernd Schmidt\"},\"url\":\"https:\/\/planit.legal\/en\/author\/bschmidt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2 - PLANIT\/\/LEGAL","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/","og_locale":"en_US","og_type":"article","og_title":"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2 - PLANIT\/\/LEGAL","og_description":"The European Parliament has most recently adopted the General Data Protection Regulation (GDPR). Part of this new data protection framework are dramatically increased sanctions for violations of data protection law. When the GDPR enters into force, the blunt sword for enforcing data protection requirements will suddenly turn razor sharp. Companies must then be prepared for [&hellip;]","og_url":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/","og_site_name":"PLANIT\/\/LEGAL","article_published_time":"2016-04-15T20:44:50+00:00","article_modified_time":"2019-03-25T22:56:20+00:00","og_image":[{"width":384,"height":288,"url":"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg","type":"image\/jpeg"}],"author":"Dr. Bernd Schmidt","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Dr. Bernd Schmidt","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#article","isPartOf":{"@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/"},"author":{"name":"Dr. Bernd Schmidt","@id":"https:\/\/legal-test.planit.legal\/#\/schema\/person\/616f088d80b0ac267989a17c228fb541"},"headline":"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2","datePublished":"2016-04-15T20:44:50+00:00","dateModified":"2019-03-25T22:56:20+00:00","mainEntityOfPage":{"@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/"},"wordCount":1668,"commentCount":0,"image":{"@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#primaryimage"},"thumbnailUrl":"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg","articleSection":["Data Protection Sanctions","General Data Protection Regulation"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/","url":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/","name":"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2 - PLANIT\/\/LEGAL","isPartOf":{"@id":"https:\/\/legal-test.planit.legal\/#website"},"primaryImageOfPage":{"@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#primaryimage"},"image":{"@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#primaryimage"},"thumbnailUrl":"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg","datePublished":"2016-04-15T20:44:50+00:00","dateModified":"2019-03-25T22:56:20+00:00","author":{"@id":"https:\/\/legal-test.planit.legal\/#\/schema\/person\/616f088d80b0ac267989a17c228fb541"},"breadcrumb":{"@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#primaryimage","url":"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg","contentUrl":"https:\/\/planit.legal\/wp-content\/uploads\/2019\/03\/bussgeld.jpg","width":384,"height":288},{"@type":"BreadcrumbList","@id":"https:\/\/planit.legal\/en\/fines-penalties-and-damages-for-data-protection-violations-gdpr-series-part-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"","item":"https:\/\/planit.legal\/en\/"},{"@type":"ListItem","position":2,"name":"Data Protection Sanctions","item":"https:\/\/planit.legal\/en\/category\/data-protection-sanctions\/"},{"@type":"ListItem","position":3,"name":"Fines, Penalties and Damages for Data Protection Violations \u2013 GDPR Series, Part 2"}]},{"@type":"WebSite","@id":"https:\/\/legal-test.planit.legal\/#website","url":"https:\/\/legal-test.planit.legal\/","name":"PLANIT\/\/LEGAL","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legal-test.planit.legal\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/legal-test.planit.legal\/#\/schema\/person\/616f088d80b0ac267989a17c228fb541","name":"Dr. Bernd Schmidt","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/legal-test.planit.legal\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/28b706926e56255094d69874054ac2fd30bf041ff7919877d4072a8dd8e4d31c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/28b706926e56255094d69874054ac2fd30bf041ff7919877d4072a8dd8e4d31c?s=96&d=mm&r=g","caption":"Dr. Bernd Schmidt"},"url":"https:\/\/planit.legal\/en\/author\/bschmidt\/"}]}},"_links":{"self":[{"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/posts\/873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/comments?post=873"}],"version-history":[{"count":0,"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/posts\/873\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/media\/871"}],"wp:attachment":[{"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/media?parent=873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/categories?post=873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/planit.legal\/en\/wp-json\/wp\/v2\/tags?post=873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}