Data Act
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – BUSINESS TO CONSUMER AND BUSINESS TO BUSINESS DATA SHARING
Chapter III – OBLIGATIONS FOR DATA HOLDERS OBLIGED TO MAKE DATA AVAILABLE PURSUANT TO UNION LAW
Chapter IV – UNFAIR CONTRACTUAL TERMS RELATED TO DATA ACCESS AND USE BETWEEN ENTERPRISES
Chapter V – MAKING DATA AVAILABLE TO PUBLIC SECTOR BODIES, THE COMMISSION, THE EUROPEAN CENTRAL BANK AND UNION BODIES ON THE BASIS OF AN EXCEPTIONAL NEED
Chapter VI – SWITCHING BETWEEN DATA PROCESSING SERVICES
Chapter VII – UNLAWFUL INTERNATIONAL GOVERNMENTAL ACCESS AND TRANSFER OF NON-PERSONAL DATA
Chapter VIII – INTEROPERABILITY
Chapter IX – IMPLEMENTATION AND ENFORCEMENT
Chapter X – SUI GENERIS RIGHT UNDER DIRECTIVE 96/9/EC
Chapter XI – FINAL PROVISIONS
Recitals (119)
Chapter IX – IMPLEMENTATION AND ENFORCEMENT
Article 40
Penalties
1. Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive.
2. Member States shall by 12 September 2025 notify the Commission of those rules and measures and shall notify it without delay of any subsequent amendment affecting them. The Commission shall regularly update and maintain an easily accessible public register of those measures.
3. Member States shall take into account the recommendations of the EDIB and the following non-exhaustive criteria for the imposition of penalties for infringements of this Regulation:
(a) the nature, gravity, scale and duration of the infringement;
(b) any action taken by the infringing party to mitigate or remedy the damage caused by the infringement;
(c) any previous infringements by the infringing party;
(d) the financial benefits gained or losses avoided by the infringing party due to the infringement, insofar as such benefits or losses can be reliably established;
(e) any other aggravating or mitigating factor applicable to the circumstances of the case;
(f) infringing party’s annual turnover in the preceding financial year in the Union.
4. For infringements of the obligations laid down in Chapter II, III and V of this Regulation, the supervisory authorities responsible for monitoring the application of General Data Protection Regulation (GDPR) may within their scope of competence impose administrative fines in accordance with Article 83 of General Data Protection Regulation (GDPR) and up to the amount referred to in Article 83(5) of that Regulation.
5. For infringements of the obligations laid down in Chapter V of this Regulation, the European Data Protection Supervisor may impose within its scope of competence administrative fines in accordance with Article 66 of EU Institutions Data Protection Regulation (EUDPR) up to the amount referred to in Article 66(3) of that Regulation.