About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



12 Int'l Data Priv. L. 1 (2022)

handle is hein.journals/intldatpc12 and id is 1 raw text is: 



International Data Privacy Law, 2022, Vol. 12, No. 1


Putting a price on data protection infringement



Mona Naomi Lintvedt *


Introduction

The  EU  General  Data Protection  Regulation  (GDPR)' has
a dual  purpose:  To  protect  individuals  against infringe-
ment  of their personal data and  to ensure free flow of per-
sonal   data  in  the  internal  market.2   The   regulation
therefore has both  a human  rights and  a business purpose.
   The   GDPR has substantial administrative fines for
non-compliance with the regulation. The fines can be is-
sued  to the  controller, ie the entity responsible  for  the
processing  of personal data,3 and  the processor, ie the en-
tity processing personal  data on  behalf of the controller.4
The  fines are designed  to make   non-compliance a costly
mistake  for both  large and  small entities. The maximum
fines are 10 or 20 million EUR   depending   on  the serious-
ness of infringements.  In  the case of an undertaking,   the
maximum can be set to 2 or 4 per cent of the global an-
nual turnover  of the preceding  financial year.5
   The   fines  are  imposed by the Data Protection
Authority   (DPA)   in the respective  EU  Member States.6
The  use  of fines as an  enforcement   tool  may  therefore


*Mona Naomi Lintvedt, Norwegian Research Centre for Computers and Law
('NRCCL'), Department of Private Law, University of Oslo, Norway. E-mail:
m.n.lintvedt@jus.uio.no
Work on this article was carried out under the aegis of the research project
'Vulnerabilty in the Robot Society' ('VIROS'), funded by the Norwegian
Research Council. Thanks are due to professor Jukka Mah6nen and professor
Lee A Bygrave for their encouragement and support, to colleagues at the
NRCCL  Beata Paragi and Dag Wiese Schartum, as well as to the anonymous
reviewer for the very valuable suggestions and comments. The usual disclaimer
applies.
Funding by the Norwegian Research Council, grant number 288285.
No conflict of interest.
1   Regulation (EU) 2016/679 of the European Parliament and of the
    Council of 27 April 2016 on the protection of natural persons with regard


2
3
4
5
6


to the processing of personal data and on the free movement of such
data, and repealing Directive 95/46/EC (General Data Protection
Regulation), OJ 2016 L 119/1.
GDPR, Art 1.
GDPR, Art 4(7).
GDPR, Art 4(8).
GDPR, Art 83.
With the exception of Denmark and Estonia, where the legal systems do
not allow the DPAs to impose administrative fines. Instead, the fines are
imposed as a criminal penalty and following a misdemeanour procedure
respectively, cf GDPR, Art 83(9) and Recital 151. In Ireland, the adminis-
trative fines imposed by the DPA must be confirmed by the court, cf
Data Protection Act 2018, ss 141-43.


© The Author(s) 2021. Published by Oxford University Press.
This is an Open Access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0/), which
permits unrestricted reuse, distribution, and reproduction in any medium, provided the original work is properly cited.


1