The headline figure of “up to EUR 20 million” does not apply to state and municipal institutions. In Lithuania they are subject to separate, much lower limits, and those limits are set by law.
Article 33(1) of the Law on the Legal Protection of Personal Data (ADTAĮ) provides that, for infringements of points (a), (b) and (c) of Article 83(4) GDPR, a public authority or body is subject to a fine of up to 0.5 per cent of its current-year budget and of its other gross annual income received in the previous year, but not more than thirty thousand euros.
Article 33(2) ADTAĮ provides that, for infringements of points (a) to (e) of Article 83(5) GDPR, the fine is up to 1 per cent of the same income, but not more than sixty thousand euros.
These are the two real upper limits for a school, a nursery, a museum, an outpatient clinic or a municipal administration.
The limit is not automatic
There is an exception that has to be said out loud.
The same provision states that a public authority or body carrying out economic commercial activity is subject to the general GDPR fine levels. This means the cap is not granted automatically because of an organisation’s legal form.
In practice this matters for institutions that provide paid services alongside their public functions: renting out premises, running paid training, or providing paid healthcare or leisure services. Whether a particular infringement relates to that part of the activity is a matter of assessment, and it is not decided by the institution’s name.
So the statement “they cannot fine us more than thirty thousand” is a starting assumption, not a guarantee.
The outcome is not necessarily a fine
The outcome of an investigation is not necessarily a financial penalty: it may be a reprimand and an order to take a specific action.
These measures are provided for in Article 58(2) GDPR: the supervisory authority may issue a reprimand (point (b)), order compliance with a person’s request to exercise their rights (point (c)) or order the erasure of data (point (g)), and may impose a fine in addition to, or instead of, these measures (point (i)). So there may be no financial fine at all. What remains is the duty to do what the person asked for in the first place, and an order that can no longer be ignored.
The sequence can look like this. Article 17 GDPR gives the right to request erasure of data. The organisation does not respond to the request, or refuses it, the person complains to the authority, and the authority orders the same action that would have taken five minutes at the start.
Why publicity is a bigger consequence than the fine
Article 14-1(1) ADTAĮ provides that the decision is published on the authority’s website.
For many institutions this matters more than the fine itself, and it is the real message of this page. A fine is a one-off line in the budget. A publicly available decision that names the institution and describes what it did wrong stays findable in search results and reaches parents, patients, visitors and council members.
For the head of an institution this means something simple: when deciding whether it is worth spending an hour on a proper reply to a data subject, the comparison is not with the fine but with a public decision.
The risk in an institution is not necessarily an attack
When people talk about risk, they picture a hack. But a breach can be an entirely everyday one: personal data sent by email to the wrong recipient. A wrong address from autocomplete, an attachment with the whole list instead of one entry, “reply all” where a reply to one person was needed.
From a real case. When a personal data breach was reported, two things were done: the breach register was filled in, and a short guidance note was prepared on how to share personal data safely by email. Over the whole period of our work with that institution, this was the first breach reported.
This is normal, not a disaster. An organisation that has recorded one incident over a long period is not disorganised. It is an organisation where the incident was noticed and written down. Article 33(5) GDPR requires all personal data breaches to be documented, including those that do not have to be notified to the authority.
An empty breach register at an inspection does not mean there were no breaches. It may also mean that nobody is recording them.
What to do about it
Three things give the most for the least effort:
- a breach register with at least one entry, and a person who knows they are the one who fills it in;
- one address where data subject requests arrive, and a time limit counted from receipt, not from when the request reached the lawyer;
- one paragraph-long guidance note on sending by email, because this is where mistakes are easy to make.
None of them is a project. All three together take less than a day.
How to start
If you want to know which of the two limits applies to your institution, and whether your activity has an economic commercial part, write to us with the type of institution and a short description of the paid services you provide. We provide this assessment free of charge.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: GDPR audit, compliance documents and advice.