Enforcement, remedies and penalties
The Commissioner's powers, data subjects' remedies (complaints, judicial remedies, representation, compensation and liability), and the administrative fines regime.
Article 58 — Powers
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
- (a) to order the controller and the processor, and, where applicable, the controller's or the processor's representative to provide any information it requires for the performance of its tasks;
- (b) to carry out investigations in the form of data protection audits;
- (c) to carry out a review on certifications issued pursuant to Article 42(7);
- (d) to notify the controller or the processor of an alleged infringement of this Regulation;
- (e) to obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of the Commissioner's tasks;
- (f) to obtain access to any premises of the controller and the processor, including to any data processing equipment and means, in accordance with domestic law.
- (a) to issue warnings to a controller or processor that intended processing operations are likely to infringe provisions of this Regulation;
- (b) to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation;
- (c) to order the controller or the processor to comply with the data subject's requests to exercise his or her rights pursuant to this Regulation;
- (d) to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period;
- (e) to order the controller to communicate a personal data breach to the data subject;
- (f) to impose a temporary or definitive limitation including a ban on processing;
- (g) to order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such actions to recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Article 19;
- (h) to withdraw a certification or to order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or to order the certification body not to issue certification if the requirements for the certification are not or are no longer met;
- (i) to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures referred to in this paragraph, depending on the circumstances of each individual case;
- (j) to order the suspension of data flows to a recipient in a third country or to an international organisation.
- (a) to advise the controller in accordance with the prior consultation procedure referred to in Article 36;
- (b) to issue, on the Commissioner's own initiative or on request, opinions to Parliament, the government or other institutions and bodies as well as to the public on any issue related to the protection of personal data;
- (c) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
- (d) to issue an opinion and approve draft codes of conduct pursuant to Article 40(5);
- (e) to accredit certification bodies pursuant to Article 43;
- (f) to issue certifications and approve criteria of certification in accordance with Article 42(5);
- (g) to adopt standard data protection clauses referred to in Article 28(8) and in point (d) of Article 46(2);
- (h) to authorise contractual clauses referred to in point (a) of Article 46(3);
- (i) to authorise administrative arrangements referred to in point (b) of Article 46(3);
- (j) to approve binding corporate rules pursuant to Article 47.
- (k) to provide authorisation required under regulations made under Article 47A
3A. In the 2018 Act, section 115(4) to (9) provide that the Commissioner's functions under this Article are subject to certain safeguards.
Article 77 — Right to lodge a complaint with the Commissioner
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Article 78 — Right to an effective judicial remedy against the Commissioner
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
1. Without prejudice to any other administrative or non-judicial remedy, each natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of the Commissioner concerning them.
2. Without prejudice to any other administrative or non-judicial remedy, each data subject shall have the right to a an effective judicial remedy where the Commissioner does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint lodged pursuant to Article 77.
Article 79 — Right to an effective judicial remedy against a controller or processor
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
1. Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with the Commissioner pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.
Article 80 — Representation of data subjects
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
1. The data subject shall have the right to mandate a body or other organisation which meets the conditions in section 187(3) and (4) of the 2018 Act to make a complaint under section 164A or 165 of the 2018 Act on his or her behalf, to exercise the rights referred to in Articles ... 78 and 79 on his or her behalf, and to exercise the right to receive compensation referred to in Article 82 on his or her behalf ... .
2. The Secretary of State may provide that any body, organisation or association referred to in paragraph 1 of this Article, independently of a data subject's mandate, has the right to make a complaint under section 164A or 165 of the 2018 Act and to exercise the rights referred to in Articles 78 and 79 if it considers that the rights of a data subject under this Regulation have been infringed as a result of the processing.
3. The Secretary of State may exercise the power under paragraph 2 of this Article only by making regulations under section 190 of the 2018 Act.
Article 81 — Suspension of proceedings
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Article 82 — Right to compensation and liability
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
1. Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.
2. Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.
3. A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.
4. Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and where they are, under paragraphs 2 and 3, responsible for any damage caused by processing, each controller or processor shall be held liable for the entire damage in order to ensure effective compensation of the data subject.
5. Where a controller or processor has, in accordance with paragraph 4, paid full compensation for the damage suffered, that controller or processor shall be entitled to claim back from the other controllers or processors involved in the same processing that part of the compensation corresponding to their part of responsibility for the damage, in accordance with the conditions set out in paragraph 2.
Article 83 — General conditions for imposing administrative fines
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
1. The Commissioner shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.
2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
- (a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
- (b) the intentional or negligent character of the infringement;
- (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects;
- (d) the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
- (e) any relevant previous infringements by the controller or processor;
- (f) the degree of cooperation with the Commissioner, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
- (g) the categories of personal data affected by the infringement;
- (h) the manner in which the infringement became known to the Commissioner, in particular whether, and if so to what extent, the controller or processor notified the infringement;
- (i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
- (j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and
- (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.
3. If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.
4. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to £8,700,000, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:
- (a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43;
- (b) the obligations of the certification body pursuant to Articles 42 and 43;
- (c) the obligations of the monitoring body pursuant to Article 41(4).
5. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to £17,500,000, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:
- (a) the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9;
- (b) the data subjects' rights pursuant to Articles 12 to 21;
- (ba) Article 22B or 22C (restrictions on, and safeguards for, automated decision-making);
- (c) the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44A to 49;
- (d) any obligations under Part 5 or 6 of Schedule 2 to the 2018 Act or regulations made under section 16(1)(c) of the 2018 Act;
- (e) non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the Commissioner pursuant to Article 58(2) or failure to provide access in violation of Article 58(1).
6. Non-compliance with an order by the Commissioner as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to £17,500,000, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.
10. In the 2018 Act, section 115(9) makes provision about the exercise of the Commissioner's functions under this Article.
Article 84 — Penalties
Verbatim from legislation.gov.uk (consolidated text, valid as at 2026-06-19).
Part 6 of the 2018 Act makes further provision about penalties applicable to infringements of this Regulation.
Sources
- legislation.gov.uk — UK GDPR (Regulation (EU) 2016/679 as retained), consolidated text
- ICO — UK GDPR guidance and resources
Meta
All article text above is reproduced verbatim from the consolidated UK GDPR on legislation.gov.uk, extracted mechanically from the official XML. Repealed or omitted text appears as "..." exactly as published. Amendment history is available via each article link. Each provision carries its official identifier as a trailing attribute anchor (e.g. {#article-35-2}, attributes syntax) — the same id legislation.gov.uk uses, so .../eur/2016/679/article/35/2 at the source corresponds to #article-35-2 here.