A supervisory authority is calculating an administrative fine against a logistics company and notes that the firm self-reported the breach, cooperated fully, and had certified part of its processing under an approved certification mechanism. Under Article 83 GDPR, what role do these factors play in the authority's decision?
- AThey legally bar any fine, because a controller that self-reports and is certified benefits from a statutory safe harbour against administrative penalties.
- BThey are irrelevant to the fine, since Article 83 fixes penalties solely by reference to the turnover-based percentage caps.
- CThey are mitigating circumstances the authority must take into account when deciding whether to impose a fine and in fixing its amount. Correct
- DThey are aggravating circumstances, because disclosing the breach demonstrates the controller knew it was non-compliant beforehand.
Why A is wrong: A safe-harbour reading is tempting given the cooperative conduct, but Article 83 creates no automatic immunity; these factors influence the discretionary assessment rather than removing the power to fine.
Why B is wrong: Candidates fixate on the percentage caps, but those caps are only ceilings; Article 83(2) requires the authority to weigh a list of aggravating and mitigating factors when setting the actual amount.
Why C is correct: Article 83(2) lists cooperation with the authority, the manner the infringement became known including self-notification, and adherence to approved certification mechanisms among the factors that must be given due regard, and they operate to mitigate the assessment.
Why D is wrong: Treating cooperation as proof of guilt inverts the framework; Article 83(2) frames self-notification and cooperation as mitigating, not as evidence that worsens the penalty.