How GDPR fines are calculated
Article 83 of the GDPR outlines how the fines will be calculated prior to assessing the penalties to violators. The ten major criteria that authorities will use to determine fines will include:
- Did the offender meet the standards for data protection certifications?
- Did the offender cooperate with authorities investigating the data breach?
- What type of personal data was accessed due to the breach?
- Did the offender have a history of allowing such data breaches?
- Was the data breach due to the offender’s negligence or intentional action?
- What actions did the offender take to mitigate the damage?
- What was the nature and extent of the damage caused by the data breach?
- When did the offender notify the regulatory authorities and the affected parties about the data breach?
- What preventative measures did the offender take prior to the data breach?
- What other mitigating circumstances were involved in the data breach?