Back to Feed
PolicySep 30, 2026

Article 31 GDPR

GDPR Article 31 infringements can lead to criminal liability and significant fines.

Summary

GDPR Article 31, concerning the right against self-incrimination, is discussed in relation to potential criminal liability and administrative fines. Infringements can result in fines up to €10 million or 2% of global annual turnover, with CJEU case law indicating that administrative fines can be considered criminal if punitive and severe. The right against self-incrimination is generally accepted to take precedence if invoked.

Full text

Help Article 31 GDPR: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:04, 16 April 2026 view sourceSfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators589 editsm ← Older edit Latest revision as of 15:45, 30 September 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators102 editsTag: Visual edit Line 248: Line 248: Infringements of the GDPR and the sanctions issued in response to any such infringements often have the capacity to be criminal in nature. Thus, in certain circumstances, GDPR infringements may give rise to the applicability of this right, as Member States are permitted to legislate criminal sanctions for infringements of the GDPR (Recital 149). Consequently, in certain jurisdictions infringements of the GDPR may give rise to criminal liability. Moreover, the imposition of a significant fine (or the threat of such a fine) may equally give rise to the right against self-incrimination. Infringements of the GDPR and the sanctions issued in response to any such infringements often have the capacity to be criminal in nature. Thus, in certain circumstances, GDPR infringements may give rise to the applicability of this right, as Member States are permitted to legislate criminal sanctions for infringements of the GDPR (Recital 149). Consequently, in certain jurisdictions infringements of the GDPR may give rise to criminal liability. Moreover, the imposition of a significant fine (or the threat of such a fine) may equally give rise to the right against self-incrimination. Article 31 GDPR gains an independent significance as it is included in the GDPR’s sanctions framework through [[Article 83 GDPR|Article&nbsp;83(4)&nbsp;GDPR.]]<ref>''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 31 GDPR, margin number 5 (Beck 2024, 4th edition); ''Klug'' in Gola, Heckmann, DS-GVO, Article 31, margin number 3 (Beck 2022, 3rd edition). </ref> [[Article 83 GDPR|Article 83(4) GDPR]] provides that the infringement of Article 31 GDPR may be subject to administrative fines up to €10 million, or in the case of an undertaking, up to 2% of the total worldwide annual turnover. CJEU case law demonstrates that administrative fines may be considered criminal if they serve a punitive purpose and have a high degree of severity, regardless of the fine’s classification as administrative under national legislation.<ref>Case C-27/22, ''Volkswagen Group Italia and Volkswagen Aktiengesellschaft'', 14 September 2023, para 55 (available [[CJEU - C‑27/22 - Volkswagen Group Italia and Volkswagen Aktiengesellschaft|here]]); Case C-97/21, ''MV – 98'', 4 May 2023 (available [https://curia.europa.eu/juris/document/document.jsf?text=&docid=273282&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=15630530 here]).</ref> Therefore, if a request made under Article&nbsp;31&nbsp;GDPR gives rise to circumstances which invoke the right against self-incrimination, it is widely accepted by commentators that the right against self-incrimination takes precedence.<ref>''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 31 GDPR, margin number 14 (Beck 2020, 3rd edition); ''Kotschy'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 31 GDPR, p. 628 (Oxford University Press 2020); ''Zierbarth'' in Sydow, Marsch, DS-GVO BDSG, Article 31 GDPR, margin number 10 (Beck 2022, 3rd edition). </ref> Article 31 GDPR gains an independent significance as it is included in the GDPR’s sanctions framework through [[Article 83 GDPR|Article&nbsp;83(4)&nbsp;GDPR.]]<ref>''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 31 GDPR, margin number 5 (Beck 2024, 4th edition); ''Klug, Rost'' in Gola, Heckmann, Rost, DS-GVO, Article 31, margin number 3 (Beck 2026, 4th edition). </ref> [[Article 83 GDPR|Article 83(4) GDPR]] provides that the infringement of Article 31 GDPR may be subject to administrative fines up to €10 million, or in the case of an undertaking, up to 2% of the total worldwide annual turnover. CJEU case law demonstrates that administrative fines may be considered criminal if they serve a punitive purpose and have a high degree of severity, regardless of the fine’s classification as administrative under national legislation.<ref>Case C-27/22, ''Volkswagen Group Italia and Volkswagen Aktiengesellschaft'', 14 September 2023, para 55 (available [[CJEU - C‑27/22 - Volkswagen Group Italia and Volkswagen Aktiengesellschaft|here]]); Case C-97/21, ''MV – 98'', 4 May 2023 (available [https://curia.europa.eu/juris/document/document.jsf?text=&docid=273282&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=15630530 here]).</ref> Therefore, if a request made under Article&nbsp;31&nbsp;GDPR gives rise to circumstances which invoke the right against self-incrimination, it is widely accepted by commentators that the right against self-incrimination takes precedence.<ref>''Hartung'', in Kühling, Buchner, DS-GVO BDSG, Article 31 GDPR, margin number 14 (Beck 2020, 3rd edition); ''Kotschy'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 31 GDPR, p. 628 (Oxford University Press 2020); ''Zierbarth'' in Sydow, Marsch, DS-GVO BDSG, Article 31 GDPR, margin number 10 (Beck 2022, 3rd edition). </ref> Commentators have suggested that the practical application of this reading would mean that Article 31 GDPR cannot be invoked by a ''SA'' to induce a controller or processor to make an admission which would give rise to criminal liability, instead a supervisory authority must use its own investigative powers to establish facts which are incumbent on itself to prove.<ref>''Zierbarth'' in Sydow, Marsch, DS-GVO BDSG, Article 31 GDPR, margin number 10 (Beck 2022, 3rd edition). </ref>Commentators have suggested that the practical application of this reading would mean that Article 31 GDPR cannot be invoked by a ''SA'' to induce a controller or processor to make an admission which would give rise to criminal liability, instead a supervisory authority must use its own investigative powers to establish facts which are incumbent on itself to prove.<ref>''Zierbarth'' in Sydow, Marsch, DS-GVO BDSG, Article 31 GDPR, margin number 10 (Beck 2022, 3rd edition). </ref> Line 272: Line 272: <references /><references /> [[Category:GDPR Articles]][[index.php?title=Category:GDPR Articles]] Latest revision as of 15:45, 30 September 2026 ← Article 31 GDPR- Cooperation with the supervisory authority → Chapter 1: General provisions Article 1: Subject-matter and objectives Article 2: Material scope Article 3: Territorial scope Article 4: Definitions Chapter 2: Principles Article 5: Principles relating to processing of personal data Article 6: Lawfulness of processing Article 7: Conditions for consent Article 8: Conditions applicable to child’s consent in relation to information society services Article 9: Processing of special categories of personal data Article 10: Processing of personal data relating to criminal convictions and offences Article 11: Processing which does not require identification Chapter 3: Rights of the data subject Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject Article 13: Information to be provided where personal data are collected from the data subject Article 14: Information to be provided where personal data have not been obtained from the data subject Article 15: Right of access by the data subject Article 16: Right to rectification Article 17: Right to erasure (‘right to be forgotten’) Article 18: Right to restriction of processing Article 19: Notification obligation regarding rectification or erasure of personal data or restriction of processing Article 20: Right to data portability Article 21: Right to object Article 22: Automated individual decision-making, including profiling Arti

Entities

GDPR (product)