Oireachtas Joint and Select Committees
Wednesday, 14 June 2017
Joint Oireachtas Committee on Justice, Defence and Equality
General Scheme of Data Protection Bill 2017: Discussion
10:10 am
Ms Helen Dixon:
The GDPR provides for an ability for us to impose sanctions and fines. The type of sanctions we can impose are warnings and we can issue enforcement notices requiring rectification and so on. Under Article 83 of the GDPR, there is a presumption that where there is a sanction in contemplation and we have identified an infringement such that a sanction is in scope, Article 83 provides for the presumption that it will include an administrative fine. With regard to such administrative fines, in the case of the most serious infringements they can be up to €20 million or 4% of the global turnover of undertakings. There is some discretion in terms of the administrative fines we can impose. With regard to Article 83 of the GDPR, it sets out that initially we would look at whether a sanction is in scope in terms of the infringement that we are looking at; we would assess that based on the gravity and duration of the infringement.
Then it provides for a range of criteria that we would take into account as mitigation factors in terms of the quantum of the fine we would impose, so there is some prescription in the GDPR for how we would go about that process.
No comments