This document is designed to guide supervisory authorities in the application and enforcement of the GDPR, focusing on a shared interpretation of Article 83. The document outlines guidance for each criterion included in Article 83 such as "the nature, gravity and duration of the infringement", "the intentional or negligent character of the infringement", "any action taken by the controller or processor to mitigate the damage suffered by data subjects", "the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32" and others.
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2017-10-03
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Official guidance