prevent breaches of protection of personal data. Consequently, sanctions are available not only for actual breaches of protection of personal data but also for breaches
of various compliance obligations.
The sanctioning policy of the GDPR uses pragmatic assessment of a number of
practically relevant facts related to respective breach of obligations. In particular,
imposing fines is subject to assessment of the following criteria laid down in Art. 83
(2) of the GDPR:
(a) the nature, gravity and duration of the infringement taking into account the nature scope
or purpose of the processing concerned as well as the number of data subjects affected
and the level of damage suffered by them;
(b) the intentional or negligent character of the infringement;
(c) any action taken by the controller or processor to mitigate the damage suffered by data
subjects;
(d) the degree of responsibility of the controller or processor taking into account technical
and organisational measures implemented by them pursuant to Articles 25 and 32;
(e) any relevant previous infringements by the controller or processor;
(f) the degree of cooperation with the supervisory authority, in order to remedy the
infringement and mitigate the possible adverse effects of the infringement;
(g) the categories of personal data affected by the infringement;
(h) the manner in which the infringement became known to the supervisory authority, in
particular whether, and if so to what extent, the controller or processor notified the
infringement;
(i) where measures referred to in Article 58(2) have previously been ordered against the
controller or processor concerned with regard to the same subject-matter, compliance
with those measures;
(j) adherence to approved codes of conduct pursuant to Article 40 or approved certification
mechanisms pursuant to Article 42; and
(k) any other aggravating or mitigating factor applicable to the circumstances of the case,
such as financial benefits gained, or losses avoided, directly or indirectly, from the
infringement.
Direct administrative sanctions for breaches of obligations laid down in the
GDPR are fines. Breaches in obligations listed in Art. 83(4) of the GDPR, i.e. mostly
compliance obligations, are subject to fines amounting up to 10 mil. EUR or 2% of
worldwide turnover. Breaches of obligations listed in Art. 83(5) of the GDPR, i.e.
mostly protective obligations related to rights of data subjects, are subject to fines
amounting up to 20 mil. EUR or 4% of worldwide turnover.
The GDPR also lays down powers of DPAs to impose corrective administrative
measures to recover lack of compliance or breaches of protection. These measures
listed in Art. 58(2) of the GDPR can be imposed upon controllers or processors,
depending on circumstances of particular cases, solely or along fines.
Maximum fines in the GDPR are substantially higher than those laid down in the
Act No. 101/2000 Sb. The past limit for fines under the Act No. 101/2000 Sb. was
10 mil. CZK (approx. 400,000 EUR) and there was even no possibility to charge a
fine based on corporate turnover. Moreover, the sanctioning policy of the Czech
DPA had been, compared to other DPAs of the EU member-states, very modest, as
regular fines amounted mostly to hundreds or single thousands EUR.
National Report: Czech Republic
151
Précédent

- 160/540

Suivant