Why classifying GDPR fines as criminal penalties impacts your insurance coverage

Another important CJEU judgment! Whether GDPR administrative fines are “criminal penalties” or not is a relevant issue for both insurability and indemnification clauses (e.g. “Y agrees to indemnify and hold Z harmless for data protection violations”). Today’s CJEU’s judgment in case C-27/22 strengthens the position of those who raised concerns regarding GDPR fine insurance and indemnification clauses… perhaps it’s time for you to review your liability clauses and insurance policies?
[Hint: there are alternative approaches that work better]

The judgment doesn’t reveal anything spectacularly new, as the ingredients have been there for a while (and the judgment quotes case C?97/21 a lot), but it applies the reasoning of “when is an administrative fine a criminal penalty?” to an area of law that is very close to data protection law: unfair commercial practices.

A few key excerpts (machine translation, due to EN version not yet being available):

Para 45: “three criteria are relevant to this assessment. The first is the legal classification of the offence under domestic law, the second is the nature of the offence itself and the third is the severity of the penalty that the person concerned is likely to suffer.

1st criterion: para. 48: “the application of Article 50 of the Charter is not limited solely to proceedings and penalties which are classified as “criminal” by national law, but extends – irrespective of such classification in national law – to proceedings and penalties which must be regarded as criminal in nature on the basis of the other two criteria

2nd criterion:
– para 49: “it is in the very nature of criminal sanctions that they are intended both to punish and to prevent unlawful conduct. On the other hand, a measure that merely compensates for the damage caused by the offence in question is not criminal in nature.
– para. 52: “although the aim of this provision was to deprive the undertaking concerned of the undue competitive advantage, the fact remains that the fine varies according to the seriousness and duration of the infringement in question, attesting to a certain gradation and progressiveness in the determination of the penalties that may be imposed” [see the GDPR fine parallels?]

3rd criterion: para 54: “it is sufficient to point out that an administrative fine of up to five million euros has a high degree of severity which is likely to support the analysis that this fine is criminal in nature, within the meaning of Article 50 of the Charter

The rest of the judgment concerns the principle “ne bis in idem”, which the CJEU says applies in this context – in a GDPR context, this is also relevant, as national law sometimes also allows criminal prosecution.

As usual, reach out if you need assistance with the implications for your organisation!

Judgment (FR & IT only currently): https://lnkd.in/epzhCVZv
Edit: now other languages available, including English

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗