Now that the GDPR has been around force for nearly 2 yrs, the UK’s Information Commissioner’s Office (“ICO”), plus a amount of other EU supervisory authorities, has begun to issue fines to infringing data controllers and processors for failure to adequately do something about their personal data breach notification obligations and protect personal data they handle.
In evaluating the enforcement of data breaches up to now, this website will first consider the way the competent supervisory authority is set, in addition to how they investigate and choose a data breach. We shall think about the ICO’s role after and during the Brexit transition period, following which we shall consider how fines for data breaches have already been calculated in the united kingdom. We shall also briefly compare the united kingdom method of the German model.
How may be the competent supervisory authority determined?
Assuming the organisation is made in the EU, the main element indicate consider is if the breach occurred in the context of cross-border processing of personal data.
If this answer is not any, then your competent supervisory authority may be the authority of the united states where in fact the controller whose processing was suffering from the breach is set up. For instance, if the employee database of a London-based company suffered a malware attack and data was exfiltrated by the malicious perpetrator, then your ICO will be the competent authority. In exceptional cases, other supervisory authorities may potentially (also) be competent; for instance, where in fact the processing involves data of people from the single EU Member State besides that of the controller, the supervisory authority of this other EU Member State would also be competent.
The recent headline cases, including that of global airline British Airways, reinforce the theory that data breaches tend to be multi-jurisdictional. A data breach arising out of cross-border processing could occur in two situations (Article 4.23 of the GDPR):
- where a breach impacts the processing of establishments in a number of countries (for instance, a ransomware attack on a pan-European band of companies); or
- where a breach affects individuals in multiple countries (for instance, an online payments company’s servers being hacked, resulting in financial data of residents of several EU countries being affected).
In this example, the competent authority to research the breach may be the ‘Lead authority’, which in accordance with Art 56.hands down the GDPR may be the authority of the ‘main establishment’[1] or of the single establishment of the controller. The lead supervisory authority will investigate and propose a draft decision concerning the data breach.
The lead authority must cooperate with supervisory authorities concerned in the decision-making process to be able to reach consensus. This mechanism is normally referred to as the ‘One-stop-shop’. Concerned supervisory authorities include the ones that are located in EU countries:
- where other establishments suffering the breach can be found;
- where individuals substantially affected/likely to be substantially suffering from the breach reside; or
- where the complaint has been lodged.
For example, in the British Airways case, where personal data of around 500,000 customers (likely including residents of multiple Member States) were compromised in the incident, the ICO has been investigating this case as lead supervisory authority with respect to other EU Member State data protection authorities.
Concerned supervisory authorities may express objections to the draft decision. If the lead supervisory authority will not follow the objections or will not believe the objections are relevant or reasoned, they need to submit the problem to the consistency mechanism for dispute resolution by the European Data Protection Board (“EDPB”). In cases like this, the EDPB can make a standard binding opinion on the problem following a vote.
However, in a few cross-border cases, there is absolutely no lead authority. Even though the info breach is cross-border insofar since it impacted the processing completed by establishments in a number of EU Member States, none of the establishments may qualify because the ‘main establishment’ as established in Article 4.16 of the GDPR. In such instances, all authorities of the countries influenced by the breach could be competent pursuant to Articles 55 and 58 of the GDPR. Organisations without lead authority in the EU will never be able to utilize the ‘One-stop-shop’ mechanism.
Will the ICO’s competence as a lead authority change in the Brexit transition period and beyond?
The ICO will keep up with the lead for current cases before end of the transition period. For cases initiated between 31 January 2020 and the finish of the transition period, it’ll end up being the lead authority or supervisory authority concerned, relative to the GDPR. The ICO has confirmed this in its updated Brexit FAQs.
The ICO also states that it “will take part in the co-operation and consistency mechanism under GDPR.” That said, by 31 January 2020, the ICO no more posesses member vote in the EDPB decision-making processes linked to disputes regarding data breach enforcement. This follows Articles 70 and 71 of the Withdrawal Agreement, which provide that the GDPR applies in the united kingdom according of the processing of personal data of data subjects beyond your UK, with the exclusion of Chapter VII of the GDPR, which sets forth the guidelines for the cooperation and consistency mechanisms.
The ICO can take part in EDPB meetings and mechanisms by invitation only, potentially being an observer. This might occur if the EDPB meetings discuss conditions that directly affect UK data subjects, and where in fact the ICO’s presence will be deemed beneficial. Pertaining to the cross-border data breaches, which means that through the transition period, cases where in fact the ICO was lead authority could be influenced by EDPB decisions, absent the ICO’s vote.
In respect of EU personal data collected by UK organisations through the transition period, the united kingdom will continue applying GDPR rules. Another arrangement for the post-transition period could be agreed in negotiations between your UK and the EU. These negotiations may also determine the UK’s and the ICO’s relationship with the EU following the transition period. Irrespective of their outcome, UK organisations established in the EU or offering goods and/or services to EU residents will still need to adhere to the GDPR rules and become at the mercy of enforcement by EU supervisory authorities, independently of the ICO, because of the GDPR’s broad extraterritorial application.
How have fines for data breaches been calculated up to now?
In reaction to data breaches, supervisory authorities have several corrective measures at their disposal, such as for example warnings, reprimands, or perhaps a temporary or definitive limitation, including a ban on processing (Article 58.2 of the GDPR). However, probably the most feared enforcement action has been the imposition of administrative fines.
Depending which obligations beneath the GDPR are breached, companies can face fines (Article 83 of the GDPR):
- of around 10 000 000 EUR, or regarding an undertaking, around 2 % of the full total worldwide annual turnover of the preceding financial year (for instance, for not implementing appropriate technical and organisational measures to make sure an even of security appropriate to the chance; or not notifying the breach to the supervisory authority when required (Article 83.4a of the GDPR)); and
- of around 20 000 000 EUR, or regarding an undertaking, around 4 % of the full total worldwide annual turnover of the preceding financial year, whichever is higher (for instance, for not complying with the info protection principles lay out in Article 5 (Article 83.5a of the GDPR)).
The fine is calculated in line with the meaning of an ‘undertaking’ as understood under EU competition law. All legal entities engaged within an economic activity, which form an economic unit, like a band of companies (i.e. a parent company and all involved subsidiaries) will undoubtedly be caught when calculating the fines. This application could be illustrated by the French supervisory authority’s (“CNIL”) imposition of a €50 million fine on Google LLC. CNIL considered the group turnover of Google LLC including its 70 offices in fifty countries as opposed to the turnover of its French subsidiary Google France SARL.
In determining how substantial an excellent should be, the supervisory authority must think about the criteria lay out in Article 83 of the GDPR. In the ICO’s first (also to date, only) GDPR fine in December 2019 against London-based pharmacy Doorstep Dispensaree, it considered factors lay out in the GDPR like the following:
- the nature, gravity and duration of the infringement;
- any action taken by the controller or processor to cooperate with the supervisory authority also to mitigate the damage suffered by data subjects; and
- the amount of responsibility of the controller or processor considering technical and organisational security measures implemented by them.
In addition, within the last pre-GDPR penalty notice issued by the ICO upon DSG Retail Limited, the ICO outlined a summary of aggravating and mitigating factors they would consider in enforcement proceedings. Of note, aggravating factors included how passive the party was in monitoring/detecting the security breach, whist mitigating factors included how committed the party was to subsequently improve its internal processes in order to avoid future breaches.
In contrast to the united kingdom, the Conference of the German Data Protection Authorities (“DSK”) has had a different approach, that is not currently binding for cross-border cases. Essentially, DSK’s fining guidelines calculate the fine by first calculating an everyday rate in line with the annual turnover of the undertaking, and subsequently multiplying this rate by way of a factor that depends upon the severe nature of the deed. Although DSK’s model is relatively helpful in providing transparency on the calculation of fines in Germany, it remains to be observed whether the ceiling-first method of fines will undoubtedly be found appropriate for Article 83 of the GDPR.
Given the intention of harmonisation over the EU, it’ll be interesting to see if the EDPB issues any updates to the Article 29 Working Party guidelines on the application form and setting of administrative fines (October 2017).
Conclusions
Firstly, we wish to underline the significance of experiencing a lead authority, specifically for multi-national companies, or companies which process the info of data subjects over the EU Member States. You can find clear logistical and financial advantages to being able to build relationships an individual lead authority in case of a cross-border personal data breach investigation. Along with benefiting from an individual point of contact, it provides a significant rest from being investigated by multiple supervisory authorities independently. This alternative may bring about increased costs linked to legal, human and frequently financial resources for the business.
Before the finish of the Brexit transition period, those companies which now have their main establishment in the united kingdom may decide to reassess the location of these lead authority to 1 of the continental EU member states. It is because, save for a particular arrangement which may be agreed with the EU, the united kingdom will undoubtedly be considered a third country for the purposes of the GDPR following the end of the transition period. Doing this will enable these businesses to gain access to the logistical and financial benefits discussed above. However, it really is worth noting that this type of reorganisation may incur charges for the company, connected with business functions/personnel/ infrastructure allocation, that ought to equally be looked at.
Lastly, we wish to highlight the significance of companies going for a note of the many aggravating and mitigating factors that supervisory authorities have considered ahead of issuing corrective measures carrying out a personal data breach. Specifically, companies should:
- cooperate with the authorities post-breach;
- implement technical and organisational measures in order to avoid and minimize future data breaches; and
- establish processes and staff training to cope with data breaches efficiently and based on the GDPR.
SPB will continue monitoring current practices and trends with regards to personal data breaches.
[1] Within this is of Article 4.16 of the GDPR.
The post Data Breach Enforcement in the united kingdom and in the EU: Cross-Border Issues appeared first on SECURITY & PRIVACY // BYTES.

