OUT-LAW NEWS

European Data Protection Board consults on new GDPR fining framework

A close-up on an abstract design of a display

The guidelines focus on the threshold at whether a fine should be imposed. iStock.


New European Data Protection Board (EDPB) draft guidelines are designed harmonise how data protection authorities decide whether to impose fines for breaches of the General Data Protection Regulation (GDPR), introducing a five-step methodology to bring greater consistency to enforcement across the EU, an expert has said.

The draft guidelines focus on the threshold questions of whether a fine should be imposed at all and how fines should interact with other corrective powers available to regulators, including warnings, reprimands and processing bans.

The EDPB’s proposed methodology consists of five steps. Regulators must first determine whether the infringement in question is one that can attract a fine, before establishing whether the party under investigation can be held liable. They must then assess whether the infringement was committed intentionally or negligently. The final two stages involve considering the aggravating and mitigating factors in Article 83(2) GDPR and determining whether the infringement is sufficiently minor that a reprimand may be more appropriate than a financial penalty.

The approach bears similarities to existing guidance issued by the UK Information Commissioner’s Office (ICO), which also requires consideration of factors such as the seriousness of the infringement, culpability, mitigating actions and the need for penalties to be effective, proportionate and dissuasive.

“However, the EDPB draft offers additional detail on liability and culpability that could signal emerging difference between EU and UK enforcement practice,” said Malcolm Dowden, data protection law expert at Pinsent Masons.

Paragraph 42 of the draft states that controllers remain liable for infringements committed by processors acting on their behalf, unless the processor acts outside the controller’s instructions, processes data for its own purposes, or otherwise departs from the agreed processing framework. In those circumstances, the processor may become a separate controller under Article 28(10) GDPR and bear liability for the relevant processing activities.

Dowden said: “The inference is that the EDPB will continue to focus its enforcement and fines on controllers, looking to processors only in exceptional circumstances.”

“That position may be contrasted with recent UK enforcement activity. The ICO has demonstrated a willingness to pursue processors directly in connection with data security failings. The EDPB's latest draft may therefore point to a degree of divergence between the direction of travel for EU supervisory authorities and the UK's post-Brexit data protection regulator,” he said.

The draft also places significant emphasis on culpability as a prerequisite for fines. Paragraph 47 states that an infringement must have been committed intentionally or negligently before a financial penalty can be imposed, while paragraph 48 makes clear that Article 83 GDPR does not permit administrative fines in the absence of wrongful conduct. According to the EDPB, a “culpable infringement” is an unwritten but necessary condition of imposing a fine.

“This underlines a point of distinction between regulatory enforcement/fines which require intent or negligence and claims for compensation which require only infringement plus proof of material or non-material damage suffered by the data subject,” said Dowden.

The consultation on the draft guidelines is open until 13 November.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.