TwitterDeutsche Version
Fines
Court Decision

Landmark Decisions for the Practice of Imposing Fines

Landmark Decisions of the ECJ
Datum17. April 2024

The European Court of Justice (ECJ) has handed down two landmark rulings that will significantly facilitate the work of supervisory authorities and thereby advance the practice of imposing sanctions. We have summarized below what this means specifically for companies.

Fines may be imposed on legal entities

In the case Deutsche Wohnen that a fine can be imposed on a legal entity. The company’s liability for the fine therefore does not depend on whether a violation by a natural person acting as a company representative has been established beforehand. The company itself may be the recipient of the fine. The European Court of Justice (ECJ) even ruled that the restriction contained in the German Administrative Offenses Act (OWiG)—which requires that a violation be established on the part of a natural person—is contrary to the GDPR. This significantly simplifies the work of the authorities and will almost certainly lead to more fines for data protection violations in the future.  

Liability for Data Protection Violations by Data Processors

In addition, the ECJ recently confirmed that even then liability for data protection violationsü& exists if these were committed by a processor and not by the controller’s own employees, provided that the processing operations in question were carried out on behalf of the controller and the breach thus occurred in the course of fulfilling the contract. This decision highlights just how important it is to carefully select the service provider to whom personal data is entrusted. A thorough review of the contract before signing, as well as a simultaneous assessment of the adequacy of the technical and organizational measures (TOM) implemented by the service provider, are essential.

Regular reviews of the TOMs implemented by the data processor after the contract takes effect are equally important. Furthermore, it is advisable to exercise the existing right to conduct audits of contractual partners in order to ensure, even during the partnership, that the data provided is processed in compliance with data protection regulations.

BayLDA’s Plans

In its Activity Report for 2023, the BayLDA reports the highest number of fines to date since the GDPR came into effect. In total, sanctions amounting to approximately 3.8 million euros were imposed, including fines in the seven-figure range, although the recipients of these fines remained unknown. Looking ahead, the BayLDA announced that it would consistently impose sanctions for violations, which—given the recent ECJ rulings—suggests a further increase in the number of fines.

Sources