Regulation (EU) 2016/679 on the protection of individuals regarding the processing of personal data and the free movement of such data (GDPR) provides for significant administrative fines, which values will be determined by the nature, gravity, duration of the infringement, degree of guilt and categories of personal data affected by the infringement.
The maximum thresholds for fines are:
- EUR 10 000 000 or, in the case of an enterprise, up to 2% of the total annual worldwide turnover for the previous financial year, whichever is the highest – for child consent offenses, processing that does not require identification, the general obligations of the controller and its person, the security of personal data, data protection impact assessment and prior consultation, the data protection officer, the monitoring of approved codes of conduct, certification and certification bodies.
- EUR 20 000 000 or, in the case of an enterprise, up to 4% of the total annual worldwide turnover for the previous financial year, whichever is the highest – for breaches of principles relating to the processing of personal data, the legality processing, consent conditions, rights of data subjects, transfers of personal data to a recipient in a third country or an international organization, any obligations under national law concerning specific processing situations, non-compliance with an order or limitation temporary or definitive treatment or suspension of data flows issued by the supervisory authority or failure to grant access to the supervisory authority.
These are just a schematic and succinct presentation of the provisions of the new GDPR Regulation. For any questions or clarifications, please contact us by email at office@paulopol.ro.
How can we help you to implement GDPR correctly
We present you further on just a few examples of services you can get from the Paulopol Attorneys and Counselors Law Firm by outsourcing the Data Protection Officer (DPO), in order for you to implement GDPR correctly:
- Specialized consulting on the protection of personal data.
- Drafting or reviewing internal policies and data protection rules
- Legal opinions on the measures to be taken in order to comply with the legal provisions.
- Data protection audit based on the analysis of all operating regulations and internal policies.
- Drawing up codes of conduct.
- Database management consulting.
- Drawing up the transfer policies of the databases.
- Drafting and consulting on the implementation of policies on the protection of employees personal data,
These are just some of the services we can offer you related to GDPR. For details and legal assistance, please contact us by email at office@paulopol.ro.