GDPR

Knowledge Base | GDPR | What are the GDPR violations that lead to fines?

What are the GDPR violations that lead to fines?

Fines can arise from failures in how personal data is collected, used, protected or managed. A data leak is not required: unlawful processing can attract a fine even where no security incident occurs.

Infringements covered by the GDPR’s administrative fine provisions include:

  • Processing without a valid lawful basis, or relying on GDPR consent that is invalid or cannot be demonstrated.

  • Failing to provide clear privacy information or unlawfully refusing access, erasure or other individual rights.

  • Collecting excessive information, keeping it unnecessarily or using it for incompatible purposes.

  • Failing to implement appropriate security or meet applicable breach-notification requirements.

  • Missing required processor agreements, processing records, impact assessments or data protection officer appointments.

  • Transferring personal data internationally without a valid transfer mechanism and any necessary safeguards.

  • Failing to cooperate with the supervisory authority or comply with its orders.

The applicable fine tier depends on the provisions breached. Core principles, individual rights and international transfer infringements can fall within the higher tier. A fine is not automatic: the authority must establish an intentional or negligent infringement and assess the circumstances.