Chapter 15 of 16
The European Data Protection Board, Remedies, Liability, and Fines
The GDPR's institutional apex is an independent Union body capable of issuing guidance, opinions, and binding dispute decisions. Articles 68–84 connect that governance structure to complaints, litigation, representation, compensation, joint liability, and two major tiers of administrative fines.
Articles 68-69: What the Board Is and Why It Is Independent
A Union Body
Article 68(1) establishes the Board at Union level: "The European Data Protection Board (the ‘Board’) is hereby established as a body of the Union and shall have legal personality."
Who Sits on the Board?
The Board includes one head of a supervisory authority from each Member State and the European Data Protection Supervisor, or their representatives. States with several authorities appoint a joint representative.
Independence Is Mandatory
Article 69 requires independent action. Except for specified Commission requests, the Board shall "neither seek nor take instructions from anybody." The Commission can participate, but cannot vote.
Article 70: The Board's Core Task and Main Functions
The Core Task
Article 70(1) states: "The Board shall ensure the consistent application of this Regulation." Its role is Union-wide consistency, while national supervisory authorities retain their own tasks.
Guidance and Opinions
The Board issues guidelines, recommendations, and best practices on matters such as erasure, profiling, personal-data breaches, high risk, binding corporate rules, and international transfers.
Consistency Mechanism
The Board issues opinions on specified supervisory-authority drafts and may issue binding decisions under Article 65. It also provides guidance on Article 58 powers and Article 83 administrative fines.
Articles 70-76: Reports, Voting, Leadership, Secretariat, and Confidentiality
Transparency and Annual Reporting
The Board normally makes its guidance public and, where appropriate, consults interested parties. Its annual report is public and goes to Parliament, the Council, and the Commission.
Voting and Leadership
Ordinary decisions use simple majority: "The Board shall take decisions by a simple majority of its members." Rules of procedure need a two-thirds majority.
Secretariat and Confidentiality
The EDPS provides the secretariat, but it works exclusively under the Chair's instructions. Discussions are confidential only where the Board deems it necessary under its rules.
Board Governance in Practice: A Cross-Border Dispute
A Dispute Reaches the Board
Where supervisory authorities disagree in a consistency-mechanism case, Article 70(1)(t) gives the Board specified roles in opinions and Article 65 binding decisions.
What the Chair Does
The Chair convenes meetings, prepares agendas, notifies Article 65 decisions, and shall ensure timely performance of Board tasks, particularly in relation to Article 63.
Currency Check
Regulation (EU) 2025/2518 is in force but applies from April 2, 2027. It adds procedures around cross-border enforcement; it does not replace the GDPR wording taught in this lesson.
Articles 77-78: Complaints and Judicial Remedies Against Authorities
Where May a Complaint Be Lodged?
Article 77 permits a complaint, in particular, where the data subject has habitual residence, place of work, or where the alleged infringement occurred, if that person considers processing infringes the GDPR.
The Authority Must Inform
The authority receiving the complaint shall inform the complainant of progress and outcome, including the possibility of a judicial remedy under Article 78.
The Three-Month Trigger
Article 78 gives a judicial remedy where the competent authority does not handle the complaint or "does not inform the data subject within three months on the progress or outcome of the complaint."
Articles 79-81: Suing Controllers or Processors, Representation, and Parallel Cases
The Controller or Processor Forum
Article 79 permits proceedings where the controller or processor has an establishment. The remedy is available where the data subject considers GDPR rights were infringed through non-compliant processing.
An Alternative Forum
Proceedings may alternatively be brought where the data subject has habitual residence, unless the controller or processor is a Member State public authority acting in exercise of public powers.
Representation and Parallel Litigation
Qualified not-for-profit bodies may represent data subjects. Article 81 allows coordination, suspension, and in defined first-instance circumstances a possible decline of jurisdiction for parallel cases.
Article 82: Compensation, Liability, and Full Recovery
Compensable Harm
Article 82 covers both material and non-material damage caused by an infringement. The right is to compensation from the controller or processor for damage suffered.
Different Liability Rules
Controllers are liable for infringing processing they are involved in. Processors are liable only in the conditions Article 82(2) specifies, including processor-specific breaches or unlawful instruction-following.
Entire Damage and Recourse
For responsible participants in the same processing, "each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject." Paying parties may seek contribution.
Article 83: How Administrative Fines Are Decided
The Required Standard
Article 83(1) requires fines to be "effective, proportionate and dissuasive." The supervisory authority must apply that standard in each individual case.
A Contextual Assessment
Authorities consider gravity, duration, affected people, harm, intent or negligence, mitigation, technical and organisational responsibility, cooperation, affected data categories, and prior infringements.
Several Linked Infringements
For intentional or negligent breaches of several provisions in the same or linked operations, the total fine shall not exceed the amount specified for the gravest infringement.
Articles 83-84: The Two Fine Tiers and Other Penalties
Lower Maximum Tier
Specified obligations fall under a maximum of "up to 10 000 000 EUR" or, for an undertaking, 2% of worldwide annual turnover from the preceding financial year, whichever is higher.
Higher Maximum Tier
Basic principles, data-subject rights, transfers, and specified authority-order breaches can reach "up to 20 000 000 EUR" or 4% of worldwide annual turnover, whichever is higher.
More Than Fines
Article 84 requires Member States to establish rules on other penalties, particularly for infringements not subject to Article 83 fines. These penalties shall be effective, proportionate, and dissuasive.
Flashcards: Governance, Remedies, and Fines
Flip each card and recall the exact Article 68-84 rule before checking the answer.
- What is the Board's core Article 70 task?
- The Board shall ensure the consistent application of this Regulation.
- How does the Board ordinarily take decisions?
- The Board shall take decisions by a simple majority of its members, unless otherwise provided for in the GDPR.
- What majority is required for the Board's rules of procedure?
- A two-thirds majority of its members.
- What is the Article 78 information-inaction trigger?
- The competent supervisory authority does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint.
- What two kinds of damage can Article 82 compensate?
- Material and non-material damage, where suffered as a result of an infringement of the GDPR.
- What are Article 83's two undertaking turnover percentages?
- Up to 2% for the Article 83(4) tier and up to 4% for the Article 83(5) and 83(6) tiers, in each case with the stated EUR maximum and whichever-is-higher rule.
Quiz 1: Choosing the Correct Remedy
A data subject lodged an Article 77 complaint with the competent supervisory authority. Three months pass, and the authority has neither handled the complaint nor informed the data subject about its progress or outcome. Which statement most accurately reflects Article 78(2)?
Which remedy is available under Article 78(2)?
- The data subject has a right to an effective judicial remedy because the authority did not handle the complaint or provide the specified information within three months.
- The data subject automatically receives compensation from the supervisory authority after three months.
- The Board must impose the Article 83 higher-tier fine after three months.
- The controller must delete all personal data within three months.
Show Answer
Answer: A) The data subject has a right to an effective judicial remedy because the authority did not handle the complaint or provide the specified information within three months.
Article 78(2) provides a right to an effective judicial remedy where the competent authority does not handle the complaint or does not inform the data subject within three months on the complaint's progress or outcome. It does not itself award compensation, require deletion, or require a Board fine.
Quiz 2: Fine Tiers and Joint Liability
Test whether you can distinguish the Article 83 maximum tiers from the Article 82 rule designed to secure effective compensation.
Which pairing is correct under the GDPR provisions studied here?
- A breach of data-subject rights under Articles 12 to 22 is in the lower 10 000 000 EUR / 2% tier, and each liable party pays only its own fraction of damage.
- A breach of basic processing principles under Articles 5, 6, 7, and 9 is in the higher 20 000 000 EUR / 4% tier, and responsible parties involved in the same processing can be liable for the entire damage.
- Every GDPR infringement must receive an administrative fine, and Article 84 prohibits other penalties.
- A processor is always liable for all damage whenever it participates in processing.
Show Answer
Answer: B) A breach of basic processing principles under Articles 5, 6, 7, and 9 is in the higher 20 000 000 EUR / 4% tier, and responsible parties involved in the same processing can be liable for the entire damage.
Article 83(5)(a) places basic processing principles, including the listed consent provisions, in the higher maximum tier. Under Article 82(4), responsible controllers or processors involved in the same processing shall be liable for the entire damage to ensure effective compensation. A processor's liability remains subject to Article 82(2) and the Article 82(3) exemption.
Key Terms
- processor
- The actor whose Article 82 liability is limited to specified processor obligations or acting outside or contrary to lawful controller instructions.
- controller
- The actor whose liability is addressed in Article 82 for damage caused by processing that infringes the GDPR.
- undertaking
- The category for which Article 83 expresses the alternative fine maximum as a percentage of total worldwide annual turnover in the preceding financial year.
- data subject
- The person whose personal data are being processed and who may use the complaint, judicial-remedy, representation, and compensation rights in these Articles.
- entire damage
- The Article 82(4) rule under which each responsible controller or processor involved in the same processing can be held liable for all damage, ensuring effective compensation before later contribution claims.
- material damage
- Economic or tangible loss compensable under Article 82 where it results from a GDPR infringement.
- administrative fine
- A financial sanction imposed under Article 83, assessed in light of individual-case factors and required to be effective, proportionate, and dissuasive.
- non-material damage
- Non-economic harm compensable under Article 82 where it results from a GDPR infringement.
- consistency mechanism
- The GDPR framework, including Articles 63 to 66, through which supervisory authorities and the Board address specified cross-border or Union-wide consistency questions.
- supervisory authority
- A national authority responsible for monitoring application of the GDPR in its Member State.
- European Data Protection Board
- The Union body established by Article 68 to support consistent application of the GDPR; it has legal personality.
- European Data Protection Supervisor
- The Union-level supervisory actor that provides the Board's secretariat under Article 75 and has limited voting rights in specified Article 65 cases.