Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.
Can everyone just stop repeating this, pretty please? That is the maximum penalty. You'd have to try really, really hard to get that kind of penalty. For minor transgressions, you're likely to get away with a reprimand.
There are options to appeal, so you're not at the mercy of one regulator/judge/<x>. Europe and the GDPR are no different.
EU banks not dealing with Americans/FATCA is simply down to it not being worth the effort. Luckily, the GDPR wasn't written in such an absolute way. It doesn't apply to non-EU companies doing business outside the EU, even if they might get the occasional European using their services (unless they specifically go after EU subjects). For example, a Japanese company selling specialty arcade joysticks and I, as a UK resident buy one using yen, not pound sterling. Even though they might ship to the UK, as they ship to loads of places, they aren't doing business in the Union, and they don't have to follow the GDPR.
I find this really ridiculous as well. To run a business, there's lots of rules you have to follow which can result in fines and even jail time if you make mistakes (taxes for example where the rules are complex). If every small transgression for every rule was hit with the maximum penalty, nobody would be able to risk doing anything.
The large GDPR fines to me seem to be aimed at big companies so more than a slap on the wrist can be issued for abusing vast amounts of personal information. I don't think small companies need to be blocking EU users because they're worried they might make a mistake in how they implement their newsletter consent checkbox for example.
https://gdpr-info.eu/art-83-gdpr/
Here are some cases. The first is a company that was processing sensitive data (health data) who had to register with the ICO in the UK. They didn't register. They were not fined at all, because they were asked to register and did so. (Last paragraph). https://www.bloomberg.com/news/articles/2018-04-26/u-k-healt...
Here's an organisation that had video interviews with children who were the victims of sexual abuse. The organisation put these videos on DVDs with no encryption, and sent them through regular mail. The DVDs were lost. This is a repeat of a previous data loss from this organsition. Despite the severity of this breach, and the repeat, and the lack of protective action, the organisation was not fined the maximum available fine. https://ico.org.uk/action-weve-taken/enforcement/crown-prose...
Since the GDPR will be enforced in the UK by ICO, there's very little speculation in the parent post.
Because it's bound to apply a bunch of other rules in setting penalties by the same regulation that set the maximum cited. Saying that every offense will get the maximum is saying that the government will ignore the regulation, in which case you can just as justifiably say that any behavior, even if it isn't a violation of the rules, will get a fine of €1.337 quintillion, or 1,000% of global combined GDP, whichever is greater.
Heck, even ignoring the casd-by-case factors that must be considered, the 4% or €20 million maximum is much greater than the maximum for many violations, there are only certain GDPR violations that have that maximum.
But they do need a credible threat to really punish wilful disregard of the law, for companies that profit from breaking the rules. We see how well it works when the fine costs less than the profits from breaking the rules. The EU is making sure that this will not be the case for the GDPR.
Because I'm sure EU companies will be given lots of leeway, but non EU companies will not, and no one wants to be the example.
So yah, people are right to block the EU first, and figure out the details later.
No they absolutely do not.
I bet you are going to tell me proportionate somehow makes it all better, but for companies that make money this way, the amount of money they make this way in proportion to their income is basically all of it.
So you can bet regulators will go for the full amount.
No company in their right mind is going to rely on the mercy of an EU court toward a non-EU company.
Proportionate means „proportionate to the infraction“. That is simply not up for debate or „internet troll‘s opinion“, that‘s established law.
Generally true, but it should be read with proportionate as meaning as large as necessary to be effective -- if a warning is sufficient to ensure compliance, then the effective clause suggests a fine is NOT warranted.
> "proportionate" = relative to revenue
_Absolutely_ not - proportionate to the _infringement_. There is no other reading that makes sense here.
> "dissuasive" = make them an example so no one else will dare.
Dissuasive also encompasses encouraging companies to cooperate with regulators and make a best effort to comply. If they are going to get the maximum fine for a minor breach, even if they made a full effort to comply and merely overlooked something, they are _not_ dissuaded from ignoring the GDPR in its entirety.
> So you can bet regulators will go for the full amount.
Certainly not. Going for the full amount, regardless of the circumstances and ignoring the factors they MUST consider, is going to result in the fines being overturned by the courts, which undermines their position, doesn't fulfill the purpose of the fine (if the company successfully challenges it), and doesn't fulfill the aims of the GDPR. Ignoring the law to go for the maximum fine would be a terrible decision for a regulator to make, and you can look at the history of enforcement of the DPD to see that regulators _don't_ generally go for the maximum fine.