Between effectiveness, proportionality and dissuasiveness: Developments on the establishment and application of fines by the Spanish Data Protection Authority under GDPR

Under the Data Protection Directive, fines were determined by local legislation only. The GDPR on the other hand has stablished common grounds for the application of fines by local DPAs as well as thresholds for the fine amounts according to the severity of the violations as well as the framework within which DPAs should apply the fines. This article aims to present the developments of the application of sanctions by the Spanish Data Protection Authority – which has been one of the most actives in Europe when it comes to sanctioning – and to analyze the compatibility of some concrete sanctions with the control parameters of Arts. 83 (1) and 84 (1) GDPR, effectiveness, proportionality and dissuasiveness.