CIPP-E - European Data Protection: Scope and Accountability - Section 4.5

Know the procedures related to GDPR violations, the tiers of fines that may be imposed, and understand the conditions for class actions and data subject compensation.

Distinguish the two Article 83 GDPR fine tiers - up to 10 million EUR or 20 million EUR and their turnover equivalents - and the factors supervisory authorities weigh when setting penalties. Understand the Article 82 right to compensation for material or non-material damage and the conditions under which representative class actions may be brought on behalf of data subjects.

Article 83 GDPRadministrative finesArticle 82 GDPRclass actioncompensation

Practice question for this objective

Free sampleEuropean Data Protection: Scope and Accountabilitymedium

A supervisory authority is calculating an administrative fine against a logistics company and notes that the firm self-reported the breach, cooperated fully, and had certified part of its processing under an approved certification mechanism. Under Article 83 GDPR, what role do these factors play in the authority's decision?

  • AThey legally bar any fine, because a controller that self-reports and is certified benefits from a statutory safe harbour against administrative penalties.
  • BThey are irrelevant to the fine, since Article 83 fixes penalties solely by reference to the turnover-based percentage caps.
  • CThey are mitigating circumstances the authority must take into account when deciding whether to impose a fine and in fixing its amount. Correct
  • DThey are aggravating circumstances, because disclosing the breach demonstrates the controller knew it was non-compliant beforehand.
Recognise that cooperation, self-notification, and approved certification are mitigating factors the authority must weigh under Article 83(2) when setting a fine. Article 83(2) directs supervisory authorities to give due regard to a defined set of factors, including the degree of cooperation, how the infringement came to light, and adherence to approved codes or certification, so that the fine reflects conduct rather than being fixed mechanically by the caps.

Why A is wrong: A safe-harbour reading is tempting given the cooperative conduct, but Article 83 creates no automatic immunity; these factors influence the discretionary assessment rather than removing the power to fine.

Why B is wrong: Candidates fixate on the percentage caps, but those caps are only ceilings; Article 83(2) requires the authority to weigh a list of aggravating and mitigating factors when setting the actual amount.

Why C is correct: Article 83(2) lists cooperation with the authority, the manner the infringement became known including self-notification, and adherence to approved certification mechanisms among the factors that must be given due regard, and they operate to mitigate the assessment.

Why D is wrong: Treating cooperation as proof of guilt inverts the framework; Article 83(2) frames self-notification and cooperation as mitigating, not as evidence that worsens the penalty.

See more CIPP-E practice questions, answers explained.

More in this domain

Back to all European Data Protection: Scope and Accountability objectives, or the CIPP-E cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.