GDPR Enforcement and DPAs

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Chapters VI-VIII establish supervisory authority (DPA) structure, cooperation mechanisms (one-stop-shop), and enforcement framework. National DPAs supervise; EDPB coordinates; CJEU is the ultimate interpretive authority. Penalties up to €20M or 4% global annual turnover. Eight years of enforcement (2018-2026) has produced a substantial body of decisions and case law.

Supervisory authorities (Chapter VI)

Independence (Article 52)

DPAs:

  • Independent in performance of tasks.
  • Free from external influence (direct or indirect).
  • Cannot seek or take instructions.
  • Adequate resources and budget.

Tasks (Article 57)

Each DPA shall:

  • Monitor and enforce GDPR.
  • Promote public awareness.
  • Advise national parliament, government, other institutions.
  • Promote controller / processor awareness.
  • Provide information to data subjects on rights exercise.
  • Handle complaints lodged by data subjects.
  • Cooperate with other DPAs.
  • Conduct investigations.
  • Monitor developments affecting protection.
  • Adopt SCCs (where applicable).
  • Establish DPIA-required lists per Article 35(4)-(5).
  • Provide advice on prior consultation (Article 36).
  • Encourage codes of conduct and certification mechanisms.
  • Approve / monitor / withdraw certifications.
  • Approve / monitor codes of conduct.
  • Authorize BCRs.

Powers (Article 58)

DPAs have:

  • Investigative powers: order controller/processor to provide information, conduct investigations including audits, review certifications, notify controllers/processors of alleged infringements, obtain access to all personal data and information.
  • Corrective powers: issue warnings, reprimands, orders to comply with data subject rights, orders to bring processing into compliance, orders to communicate breaches, temporary or definitive limitation/ban on processing, orders to rectify/erase/restrict, withdraw certification, impose administrative fines, order suspension of data flows to third country.
  • Authorization and advisory powers: advise controllers, issue opinions, authorize processing, advise on BCRs, approve SCCs/BCRs.

One-stop-shop mechanism (Articles 60-66)

For cross-border processing (processing in establishment in multiple member states, or substantially affecting data subjects in multiple member states):

  • Lead supervisory authority: DPA of main establishment of controller or processor. Single point of investigation and enforcement for cross-border matters.
  • Concerned supervisory authorities: DPAs in member states where data subjects affected.

Operation:

  • Lead DPA conducts investigation, drafts decision.
  • Concerned DPAs can submit relevant and reasoned objections.
  • Disagreements escalated to EDPB consistency mechanism (Article 65).
  • EDPB binding decisions resolve disputes.

The one-stop-shop reduces forum-shopping by data subjects but concentrates enforcement load on lead DPAs (notably Ireland and Luxembourg, headquarters of many US tech companies).

EDPB (European Data Protection Board)

Articles 68-76:

  • Composed of heads of national DPAs + EDPS.
  • Independent body with legal personality.
  • Tasks include: ensure consistent application, issue guidelines, examine questions, accredit certification bodies, advise Commission, issue opinions on draft adequacy decisions and SCCs.

EDPB binding decisions (Article 65)

For cross-border cases with DPA disagreement:

  • Lead DPA refers to EDPB.
  • EDPB issues binding decision (typically within one month).
  • Lead DPA implements EDPB decision.

EDPB binding decisions have produced significant enforcement outcomes:

  • Meta WhatsApp €225M fine (2021) — increased from Ireland DPC's initial draft after EDPB binding decision.
  • Various Meta / Instagram fines escalated through EDPB consistency mechanism.

Penalty framework (Article 83)

Conditions for imposing administrative fines (Article 83(2))

Fines effective, proportionate, dissuasive. Factors considered:

  • Nature, gravity, duration of infringement.
  • Intentional or negligent character.
  • Action taken to mitigate damage.
  • Degree of responsibility (technical and organizational measures).
  • Previous infringements.
  • Degree of cooperation with DPA.
  • Categories of personal data affected.
  • Manner DPA became aware of infringement.
  • Compliance with previous corrective orders.
  • Adherence to approved codes / certifications.
  • Other aggravating or mitigating factors (e.g., financial benefits obtained).

Tier 1 (Article 83(4))

Up to €10M or 2% of global annual turnover (whichever higher) for violations of:

  • Controller / processor obligations (records of processing, processor agreements).
  • Article 28 processor obligations.
  • Joint controller obligations (Article 26).
  • Representative obligations (Article 27).
  • Some controller obligations (Article 24, 25 design/default).
  • Certification body obligations.
  • Monitoring body obligations.

Tier 2 (Article 83(5))

Up to €20M or 4% of global annual turnover (whichever higher) for violations of:

  • Basic principles (Article 5, 6, 7, 9).
  • Data subject rights (Articles 12-22).
  • Cross-border transfer provisions (Articles 44-49).
  • Supervisory authority orders (Article 58(2)).

Tier 3 (Article 83(6))

Up to €20M or 4% for non-compliance with supervisory authority orders.

SME mitigation

Article 83(2) factors include size, financial situation. SME fines proportional, but no formal SME exemption.

Notable enforcement actions

Largest fines (cumulative through May 2026)

YearEntityAmountBasisDPA
2023Meta€1.2BSchrems II SCCs without supplementary measuresIreland DPC (EDPB binding)
2021Amazon€746MVarious GDPR violationsLuxembourg CNPD
2022Meta (Instagram)€405MChildren's dataIreland DPC (EDPB binding)
2023TikTok€345MChildren's dataIreland DPC
2024Uber€290MInternational transfersNetherlands DPA
2021WhatsApp€225MTransparencyIreland DPC (EDPB binding)
2023Meta€390MCombined ad-related casesIreland DPC (EDPB binding)
2024LinkedIn€310MTargeted advertisingIreland DPC
2024Meta€91MPassword storage in plain textIreland DPC
2024Clearview AI€30.5MFacial recognition without basisNetherlands DPA

Smaller fines (tens to hundreds of thousands of euros) common across DPAs for various violations.

Categories of enforcement

  • Cookie consent / transparency: France CNIL particularly active (Google, Facebook, Amazon fines).
  • Children's data: Ireland DPC several major cases (Instagram, TikTok).
  • International transfers: Ireland DPC + EDPB binding decisions (Meta).
  • Special category data: various DPAs.
  • Direct marketing without basis: routine across DPAs.
  • Insufficient TOM / security: routine.
  • Insufficient breach response: routine.
  • Records of processing missing: routine.
  • DPIA missing for high-risk processing: increasing.

Data subject complaints and remedies

Right to lodge complaint (Article 77)

Any data subject can lodge complaint with any DPA. DPA receives, investigates (or transfers to competent DPA), informs complainant of progress and outcome.

Right to judicial remedy against DPA (Article 78)

Data subject can appeal DPA decision to national courts.

Right to judicial remedy against controller/processor (Article 79)

Data subject can pursue direct action against controller/processor in member state courts.

Compensation (Article 82)

Material or non-material damage from infringement gives right to compensation. CJEU has clarified (e.g., Österreichische Post C-300/21, 2023) that mere infringement is not enough; actual damage required.

Class actions and representative action

Article 80 — data subject mandates qualified representative (NGO, association) to lodge complaints, pursue rights, claim compensation.

EU Representative Actions Directive (Directive (EU) 2020/1828, applicable since June 2023) provides further framework.

noyb (Schrems' organization) is the most prominent example — files multiple complaints, has driven significant enforcement.

DPA cooperation and consistency

  • Article 60: lead / concerned DPA cooperation.
  • Article 61: mutual assistance.
  • Article 62: joint operations.
  • Articles 63-67: consistency mechanism (EDPB).

Cooperation has matured over eight years but remains uneven. Some Member State DPAs more aggressive (France CNIL, Italy Garante, Spain AEPD); others slower (Ireland DPC notably criticized for slow cross-border enforcement).

  • AI-related enforcement emerging: Italian Garante's ChatGPT investigation (2023) was first major AI-related GDPR action. More AI-specific decisions expected as AI Act + GDPR coordination develops.
  • Schrems II / DPF enforcement: Meta €1.2B underlines stakes; potential Schrems III pending.
  • Children's data focus: Ireland DPC several major fines.
  • Behavioral advertising: ongoing pressure on consent quality, legitimate interests basis for advertising.
  • Automated decision-making: SCHUFA Holding (C-634/21, 2023) tightened Article 22 application.
  • Cumulative learning effect: enforcement decisions building interpretive case law; predictability improving.

SRE and AI-agent fit notes

What attracts enforcement attention

  • Cross-border transfers without proper safeguards (Meta €1.2B template).
  • Insufficient security (data breaches).
  • Behavioral advertising without proper basis.
  • Children's data processing.
  • Special category data without exception.
  • Article 22 automated decision-making without safeguards.
  • Cookie consent quality.
  • Direct marketing without basis.
  • Right of access / erasure / portability handling failures.

AI-specific enforcement risk

  • Hallucinations about real individuals → potential rectification/accuracy violations.
  • Processing of personal data in training without basis.
  • Automated decision-making without Article 22 safeguards.
  • Cross-border transfers to model providers without DPF or SCCs.
  • Insufficient security around AI feature data flows.
  • Children's data in AI training or features.

Vendor enforcement risk

  • Model provider enforcement actions affect downstream organizations.
  • Track vendor enforcement history as due-diligence input.
  • Anthropic, OpenAI, Google all subject to DPA scrutiny.

Stefan-context implementation sketch

  • For client engagements: AC's GDPR program established; engagement work fits within client compliance scope.
  • For vault: not enforcement-relevant (own data, no cross-border issues, no commercial processing).
  • For vendor due diligence: track model providers' DPA-related actions and enforcement history.
  • Personal awareness: ICO / CNIL / BfDI / DPC publications as ongoing reading for enforcement trajectory.

See also