Take-Aways (AI)
- DSK adopted a concept for calculating fines in accordance with Art. 83 GDPR on June 25, 2019.
- Turnover forms the basis; daily rate = annual turnover/360, turnover in size classes and, if applicable, group turnover used.
- Severity of the offense multiplies daily rate by factor (light 1 – 4, medium 4 – 8, severe 8 – 12, very severe ≥12).
- Further modifications: Duration, type of processing, number of data subjects, extent of damage, culpability, cooperation, previous infringements.
On June 25, 2019, the German Conference of Independent Data Protection Supervisors of the Federation and the Länder (DSK) adopted a concept for the calculation of fines under Art. 83 GDPR (cf. the Minutes of the corresponding conference).
The concept takes into account the following factors in a complex model:
- Turnover: Basis of calculation; a so-called “daily rate” is determined here, for which the turnover is divided by 360. In this context, the turnover is classified into size classes and thus gradually abstracted instead of being determined in concrete terms. Interestingly, the DSK leaves open which or whose turnover is decisive; however, the DSK has already stated earlier that it is the turnover of the group that is concerned, not that of the individual company concerned (which raises subsequent legal questions and is questionable). In any case, the turnover can be estimated if the companies concerned do not quantify it.
-
- Severity of the violation: In the 2nd step, the severity of the violation is determined primarily on the basis of the “unlawfulness salary”. The daily rate is then multiplied by a factor as follows:
- light: factor 1 – 4;
- Mean: factor 4 – 8;
- Heavy: factor 8 – 12;
- Very heavy: factor 12 or more.
- Severity of the violation: In the 2nd step, the severity of the violation is determined primarily on the basis of the “unlawfulness salary”. The daily rate is then multiplied by a factor as follows:
-
- further modification: The bus is last modified according to other criteria:
- Duration of the violation
- Type of processing
- Number affected
- Extent of damage
- further modification: The bus is last modified according to other criteria:
- These factors have the effect of reducing, neutral or increasing the fine.
- A further modification is made subsequently after the further Criteria of Art. 83 (2) GDPR, i.e., for example, according to the degree of fault, loss mitigation measures, previous violations, cooperation with supervisory authorities, etc.
As a result, this method of calculation leads to significantly higher fines than were previously issued.
A detailed summary with calculation examples can be found e.g. at Latham & Watkins.
-