GDPR Articles 51-59, 68-76 and 77-84, Supervisory Authorities, Penalties and Remedies
Regulation (EU) 2016/679, Arts. 51-59, 68-76, 77-84
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 23 August 2026.
What it requires
- Expect an EU supervisory authority to have jurisdiction and fining power, up to the higher of EUR 20,000,000 or 4 percent of global annual turnover, over your processing of EU personal data.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Article 83(5) sets the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for the provisions listed in (a) to (e), including non-compliance with a supervisory-authority order under Article 58. Article 83(4) sets a lower tier, up to EUR 10,000,000 or 2 percent, for the controller and processor obligations in Articles 8, 11, 25 to 39, 42 and 43, which include the Article 33 and 34 breach notification duties; that lower tier is recorded on the instrument covering Articles 33 and 34.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
The data protection supervisory authority designated by each EU Member State under Article 51, coordinated on cross-border cases through the one stop shop mechanism and the European Data Protection Board (Articles 68-76).
Enforcement record
CMS GDPR Enforcement Tracker Report, 7th edition (cut-off 1 March 2026, published 21 May 2026): 2,685 fines with complete amount, date and controller information recorded across the EU/EEA since the GDPR became applicable on 25 May 2018 (3,062 including cases with incomplete information), totalling approximately EUR 6.11 billion, the first time the tracker's cumulative total crossed EUR 6 billion. actions_per_year (440) and fines_per_year (approximately EUR 487.6 million) are the report's own comparison against its prior, 2025 edition (roughly a one-year interval between editions), not a fixed calendar year; trend is recorded as rising on that reported increase. Counts DPA-imposed administrative fines only; the report does not separately track private civil claims under Article 82. This is the Regulation's enforcement record as a whole. Articles 51 to 59, 68 to 76 and 77 to 84 establish the supervisory authorities, penalties and remedies the record describes, but the figures themselves are not specific to those articles alone.
- As of
- 2 September 2026
- Trend
- Rising
- Currency
- EUR
- Source link
- https://cms.law/en/int/publication/GDPR-Enforcement-Tracker-Report/numbers-and-figures
- Total fines
- 6,110,000,000
- Fines per year
- 487,600,000
- Actions per year
- 440
What it reaches
Obligation class
Governance
Also on the record
EEA status
- Annex
- XI
- Status
- Incorporated
- Force date
- 20 July 2018
- Joint committee decision number
- 154/2018
- Source link
- https://www.efta.int/eea-lex/32016r0679
- Decision date
- 6 July 2018
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Each Member State designates an independent supervisory authority (Article 51) with investigative and corrective powers, including orders and bans on processing (Article 58); cross border cases route through a lead authority under the one stop shop mechanism (Articles 56, 60-63), coordinated by the European Data Protection Board (Articles 68-76).
Article 83 sets administrative fines up to the higher of EUR 20,000,000 or 4 percent of global annual turnover for infringements of the core provisions, and up to the higher of EUR 10,000,000 or 2 percent for other provisions.
Article 82(1) arms a direct private right of action, letting any person who suffered material or non-material damage claim compensation from the controller or processor, though the Court of Justice held actual, if not necessarily serious, damage must be shown rather than the mere fact of infringement (UI v Österreichische Post, Case C-300/21, 4 May 2023). Article 80 lets a not for profit body pursue a complaint or judicial remedy on a data subject's behalf.
The Representative Actions Directive (EU) 2020/1828 separately lists Regulation (EU) 2016/679 in its Annex I, letting a qualified entity bring a representative action for collective consumer redress over a General Data Protection Regulation (GDPR) infringement. The Dutch, Italian and French data protection authorities each took enforcement action against Clearview AI over the same underlying conduct, the Netherlands imposing EUR 30.5 million in a decision dated 16 May 2024.
The Hellenic Data Protection Authority separately fined Clearview EUR 20,000,000 for the same conduct, illustrating Article 83 penalties applied to biometric data drawn from public sources.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Official Journal text, EUR-Lex, Regulation (EU) 2016/679
CJEU Case C-300/21
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.