EN
Technology

GDPR fines must be calculated based on total worldwide annual turnover

logo
Legal news
calendar 14 March 2025
globus Denmark, Sweden, Norway

The European Court of Justice has established that fines for breaches of the GDPR must be calculated based on a percentage of the worldwide annual turnover. The case shows that fines do not only affect the individual data controller, but the entire undertaking.

In a criminal case for breach of the GDPR against a chain of furniture stores, a dispute arose over whether the fine should be based on the total turnover of the entire undertaking. The Danish Data Protection Agency initially proposed to issue a fine of DKK 1.5 million, but the District Court only imposed a fine of DKK 100,000.

The company's total turnover was DKK 1.8 billion, but the total turnover of the undertaking was about three times that. As a result, the fine would be significantly different depending on what turnover it should be based on. The Danish Western High Court asked the European Court of Justice for clarification.

The European Court of Justice determined that the term “undertaking” should be understood in the same way as in competition law. That means that fines must be calculated as a percentage based on the total worldwide annual turnover within the entire undertaking, not just the individual company. At the same time, the European Court of Justice emphasized that it is crucial that fines are effective, proportionate and dissuasive. 

IUNO’s opinion

Unsurprisingly, the case shows that a breach of the data protection rules by an individual controller can impact the entire organization. This is a good example of how important it is to have strong compliance work across the entire organization.

IUNO recommends that companies ensure proper compliance with the fundamental requirements under the data protection rules. In this specific case, the company breached the rules on data retention by unlawfully storing information on approximately 385,000 customers. We have previously written about a fine for breaching the data retention rules here.

[The European Court of Justice judgement of 13 February 2025 i case C-383/23]

In a criminal case for breach of the GDPR against a chain of furniture stores, a dispute arose over whether the fine should be based on the total turnover of the entire undertaking. The Danish Data Protection Agency initially proposed to issue a fine of DKK 1.5 million, but the District Court only imposed a fine of DKK 100,000.

The company's total turnover was DKK 1.8 billion, but the total turnover of the undertaking was about three times that. As a result, the fine would be significantly different depending on what turnover it should be based on. The Danish Western High Court asked the European Court of Justice for clarification.

The European Court of Justice determined that the term “undertaking” should be understood in the same way as in competition law. That means that fines must be calculated as a percentage based on the total worldwide annual turnover within the entire undertaking, not just the individual company. At the same time, the European Court of Justice emphasized that it is crucial that fines are effective, proportionate and dissuasive. 

IUNO’s opinion

Unsurprisingly, the case shows that a breach of the data protection rules by an individual controller can impact the entire organization. This is a good example of how important it is to have strong compliance work across the entire organization.

IUNO recommends that companies ensure proper compliance with the fundamental requirements under the data protection rules. In this specific case, the company breached the rules on data retention by unlawfully storing information on approximately 385,000 customers. We have previously written about a fine for breaching the data retention rules here.

[The European Court of Justice judgement of 13 February 2025 i case C-383/23]

Receive our newsletter

Anders

Etgen Reitz

Partner

Kirsten

Astrup

Managing associate

Similar

logo
Technology

27 February 2025

Review and use of private e-mails led to severe criticism

logo
Technology

15 January 2024

Expensive right of access requests

logo
Technology

28 September 2023

Seven commandments when closing the business e-mail account

logo
Technology

19 September 2023

Unfair design practices resulted in a 345 million euro fine

logo
Technology

14 September 2023

Accessible personnel files resulted in a data breach

logo
Technology

14 September 2023

Deadline to establish whistleblower schemes for medium-sized companies approaching

The team

Anders

Etgen Reitz

Partner

Kirsten

Astrup

Managing associate