EU Data Protection Supervisory Discretion in GDPR Enforcement (TR v Land Hessen)
Article summary
Information Law analysis: The Court of Justice held that the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (the EU GDPR) does not oblige supervisory authorities to exercise corrective powers, such as imposing fines, in every instance of a breach. Instead, they have discretion to determine whether action is appropriate, necessary, and proportionate based on the circumstances. This case underscores the importance for data protection practitioners of advising clients not only on compliance but also on engaging effectively with supervisory authorities to mitigate enforcement risks. It further acts as an aid for practitioners who are required to advise on the potential outcomes of a minor data breach and is an illustration of the benefits of implementing proper data protection measures in the event of any breach.
Written by Adam Richardson, barrister at 4-5 Gray’s Inn Square Chambers.
Read the full analysis here.