GDPR Fining Procedure: What Happens After a Complaint (8 Steps)

Practitioner note: This article is practice-oriented compliance documentation, not legal advice. We are a compliance specialist, not a law firm. For legally binding guidance, please consult a licensed attorney.

TL;DR

  • 8 procedural steps: intake → preliminary review → hearing → order → fine notice → 1-month appeal period → administrative court → enforcement
  • Median duration: 14-22 months (BfDI report 2025)
  • Median fine Germany 2025: EUR 12,500 (SME)
  • Suspensive effect of the action — no immediate enforcement
  • Best defence: documented compliance building blocks in advance

1. 8-Step Process

#StepWho does whatDuration (median)
1Complaint intakeData subject → supervisory authority; acknowledgement of receipt within 14 days0-2 weeks
2Preliminary reviewSupervisory authority assesses jurisdiction, substance1-3 months
3Hearing of the controllerStatement within 4 weeks, extendable1-2 months
4Fact-findingRequest for files, on-site inspection (rare), expert witnesses3-12 months
5Order / directiveSupervisory authority issues order (Article 58)0-1 month
6Fine noticeReasoned, with appeal instructions0
7Appeal period1 month from service0-1 month
8Administrative court / enforcementAdministrative court main proceedings 12-24 months1-3 years

2. Procedural Rights of the Controller

3. Defence Strategy

  1. Statement: use the 4-6 week deadline, NEVER respond quickly
  2. Engage counsel for fines > EUR 5,000 (fees EUR 4,000-15,000, often cheaper than the fine)
  3. Submit documentation: ROPA, DPAs, DPIA, training records, DPO appointment, TOMs
  4. Implement corrective measures immediately + document them — mitigating under Article 83(2)(c)
  5. Communicate with the supervisory authority — cooperation typically reduces the fine by 30-60 %
  6. Disclose financial circumstances (Article 83(2)(k), take existential threat into account)

4. Fine Assessment under Article 83 GDPR

GDPR maximum fines: EUR 20 million or 4 % of worldwide group turnover (whichever is higher). Actual SME median 2025 in Germany: EUR 12,500.

5. Action Against the Fine Notice

Administrative court action (Sections 40 et seq. VwGO):

6. 5 Case Studies from 2024-2026

CaseInfringementFineReduction through defence
HVV (Hamburg 2024)Data breach 50k customersEUR 120,000Original EUR 350,000 → reduced due to cooperation
Mid-sized IT (Bavaria 2024)Missing DPOEUR 15,000Original EUR 50,000 → DPO appointed subsequently + GDPR audit
Law firm (North Rhine-Westphalia 2025)ROPA missing, DPAs incompleteEUR 8,500Original EUR 30,000 → compliance kit documentation was sufficient
Vodafone (BfDI 2024)Cookie banner manipulatedEUR 1,300,000Action pending
Mid-sized payroll provider (Baden-Württemberg 2025)Data breach notification delayedEUR 4,500Original EUR 22,000 → supervisory authority accepted negligent misjudgement

Sources