EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines
NL-context Zorginstellingen die AI gebruiken moeten nu nauwkeurig aantonen dat datalekken of privacy‑schendingen niet opzettelijk of nalatig zijn, anders riskeren ze stevige boetes volgens de nieuwe EU‑richtlijnen.
Samenvatting
EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines. Brussels, 21 September – During its latest plenary, the EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR and the final version of its guidelines on the interplay between the Digital Services Act (DSA) and the GDPR. The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures. The GDPR significantly increased the corrective powers of DPAs, with fines serving as an important instrument for effective enforcement. The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe. EDPB Deputy Chair, Jelena Virant Burnik Data Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine: the DPA checks if the infringement can lead to a fine, by finding support either directly in the GDPR or in national law. the DPA determines whether the party under investigation may be fined for the infringement in question. Whether the controller or the processor is liable depends on who is bound by the breached provision. the DPA assesses whether the infringement has been committed intentionally or negligently, since a culpable infringement is a condition for the imposition of a fine. the DPA assesses possible aggravating and mitigating factors. If the infringement is minor, there will generally be no fine and a reprimand may be issued instead; if it is not minor, there is a strong presumption that a fine should be imposed. the DPA assesses whether imposing an administrative fine would be effective, proportionate and dissu...
Waarom dit ertoe doet
Nieuwe regelgeving heeft directe gevolgen voor zorginstellingen die AI-systemen inzetten of plannen in te zetten.
Context (AI-duiding)
Klik op “Toon context” om AI-duiding op te halen.
Scores
De mate waarin dit signaal de Nederlandse gezondheidszorg kan beïnvloeden (1 = minimaal, 5 = transformatief).
Hoe snel actie of aandacht nodig is (1 = kan wachten, 5 = onmiddellijke aandacht vereist).
De mate van onzekerheid over de uitkomst of timing (1 = zeer voorspelbaar, 5 = zeer onzeker).
Tags
Bronnen
- EDPB harmonises fining methodology and adopts final DSA-GDPR guidelinesEuropean Data Protection Board (EDPB) —
Relevant voor
Pipeline versie: 0.2.0 | Gegenereerd door: pipeline