• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

EDPB reports on EU Data Protection Authorities’ resources and enforcement actions

August 23, 2021 By Yung Shin Van Der Sype and Wim Nauwelaerts

Earlier this month, the European Data Protection Board (EDPB) published a report on the resources that the EU Member States make available to their Data Protection Authorities (DPA) and on the enforcement actions initiated by those DPAs.

Resources made available by the EU Member States to the DPAs

The EDPB report releases statistics on both financial and human resources that the EU Member States provide to the authorities at Member State level responsible for monitoring compliance with data protection laws. As is typical for statistical data, the numbers published by the EDPB should be interpreted in light of possible differences in the competences, activities and financial responsibilities of the DPAs at Member State level.

The following is particularly noteworthy:

  • The eighteen German supervisory authorities have received – by far – the highest budget of all DPAs in the EU, with a combined budget of € 94.793.900 in 2021.
  • Only 18% of the DPAs considers the allocated overall budget sufficient to carry out their supervisory activities.
  • Only 14% of the DPAs considers the allocated human resources sufficient to carry out their supervisory activities.
  • The majority of DPA staff has a legal background (with a few exceptions).

National and cross-border enforcement cases

Furthermore, the report provides statistics on national and cross-border enforcement cases initiated by the DPAs. In addition to the total number of enforcement cases, the report mentions:

  • The number of cases based on data subject complaints lodged with the DPAs.
  • The number of ex officio investigations initiated by the DPAs.
  • The number of cases resulting from data breach notifications.
  • Information regarding the exercise of the DPAs’ corrective powers, including the total number of cases where DPAs executed their corrective powers, the total amount of fines per year per DPA, the total number of decisions with a fine per DPA, the number of decisions with a fine per year and per DPA, and the largest fine issued thus far.
  • The total number of decisions with a fine subject to judicial appeal, as well as the related court decision. It appears that the majority of appealed DPA decisions were confirmed by the courts (with a few exceptions).
  • The average time for the DPAs to formally decide on a case (in months). This timeframe varies between two and twenty-six months. In general the time to decide on cross-border enforcement cases subject to a DPA cooperation procedure tends to be longer than the time needed to decide on cases that are limited to one EU Member State.

Finally, for each EU Member State, the report also provides information on the applicable legal deadlines to handle data subject complaints, the procedural rights of complainants and controllers, and the existing costs to appeal decisions under Article 78 GDPR.


EDPB, Overview on resources made available by Member States to the Data Protection Authorities and on enforcement actions by the Data Protection Authorities, adopted on 5 August 2021.

The report is available here: https://edpb.europa.eu/system/files/2021-08/edpb_report_2021_overviewsaressourcesandenforcement_v3_en_0.pdf.

 

Filed Under: Data Protection, Enforcement, International

About Yung Shin Van Der Sype

Yung Shin is an associate with Alston & Bird’s Technology & Privacy Group and Privacy, Cyber & Data Strategy Team. She focuses her practice on IT law and HR-related matters, including privacy and data protection, IT contracts, and corporate security.

About Wim Nauwelaerts

Wim Nauwelaerts is a partner in the Brussels office, leading Alston & Bird’s European Privacy, Cyber & Data Strategy Team. Wim has over 20 years of experience working with global companies on their data protection, privacy, and cybersecurity needs, including General Data Protection Regulation (GDPR) readiness, data transfer, data security and breach requirements, and compliance training.

[Read Bio]

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up

@ALSTONPRIVACY
Click here to follow us on Twitter

Secondary Sidebar

Categories

Recent Posts

  • Recent Exploits of Blockchain Bridges Highlight Need for Cybersecurity in Crypto and Risk of Liability
  • Germany’s Cyber Threat Landscape – Top 3 Lessons from the BKA Situation Report
  • CPPA Board Opposes American Data Privacy and Protection Act
  • SEC Settles Enforcement Actions with Broker-Dealers and Investment Advisors for Identity Protection Deficiencies
  • UK Information Commissioner’s Office Issues Warning on Ransomware Payments
Copyright © 2022 · Alston & Bird · All Rights Reserved. Privacy.