started · updated
GDPR and privacy law violations carry heavy sanctions
Violations of personal data protection regulations, specifically the General Data Protection Regulation (GDPR), can result in three distinct types of consequences: administrative sanctions, criminal liability, and civil damages.
Administrative fines imposed by the Data Protection Authority can reach up to 20 million euros or 4% of a company's total global turnover. Beyond these fines, individuals or entities may face criminal proceedings under the Italian Privacy Code and civil lawsuits for damages suffered by the affected parties.
The regulatory framework is built on the EU GDPR and the Italian Privacy Code (D. Lgs. n. 196/2003, as updated). These rules apply to all entities regardless of size, meaning small businesses are subject to the same legal obligations and potential penalties as large corporations, with sanctions calibrated to the specific risks of the data processing activities.
Entities
European Union · GDPR · Garante per la protezione dei dati personali