GDPR Enforcement: May 2023

SJ
Steptoe LLP
Contributor
In more than 100 years of practice, Steptoe has earned an international reputation for vigorous representation of clients before governmental agencies, successful advocacy in litigation and arbitration, and creative and practical advice in structuring business transactions. Steptoe has more than 500 lawyers and professional staff across the US, Europe and Asia.
Agencia Española de Protección de Datos (Spain) Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Persona (Romania)
Worldwide Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Fines May 2023

1330294a.jpg

Top 3 Most Active Regulators by Volume of Fines

  1. Agencia Española de Protección de Datos (Spain)
  2. Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Persona (Romania)
  3. Garante per la protezione dei dati personali (Italy)

Fines May 2023

1330294b.jpg

Top 3 Most Active Regulators by Value of Fines

  1. Data Protection Commission (Ireland)
  2. The Information Commissioners Office (UK)
  3. Commission Nationale de l'Informatique et des Libertés – CNIL (France)

Fines YTD May 2023

1330294c.jpg

Top 3 Most Active Regulators by Volume of Fines

  1. Agencia Española de Protección de Datos (Spain)
  2. Garante per la protezione dei dati personali (Italy)
  3. Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romania)

Fines YTD May 2023

1330294d.jpg

Top 3 Most Active Regulators by Value of Fines

  1. Data Protection Commission (Ireland)
  2. The Information Commissioners Office (UK)
  3. Úřad pro ochranu osobních údajů (Czech Republic)

Top Fine

  • The Irish Data Protection Authority (DPA) determined that personal data transferred to the US under the updated Standard Contractual Clauses (SCCs) nevertheless breached the GDPR. 
  • The European Data Protection Board required the Irish DPA to impose a record fine of €1.2 billion.
  • The decision is being appealed but is a reminder that organizations should not rely on SCCs alone when transferring EEA data to the US.

Key Takeaways

  • When considering AI, ensure that it meets the 'privacy by design' principles. AI is the next large battleground for data privacy with Clearview AI and OpenAI / ChatGPT as high-profile examples.
  • Regulators are active across almost all European jurisdictions demonstrating a need for broad compliance.
  • While the largest fines are reserved for multi-nationals, the vast majority of GDPR fines are against comparatively small organizations and public authorities.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

GDPR Enforcement: May 2023

Worldwide Privacy
Contributor
In more than 100 years of practice, Steptoe has earned an international reputation for vigorous representation of clients before governmental agencies, successful advocacy in litigation and arbitration, and creative and practical advice in structuring business transactions. Steptoe has more than 500 lawyers and professional staff across the US, Europe and Asia.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More