CJEU Preliminary Reference C-383/23 ILVA: Fine Calculation and the Undertaking Concept in GDPR Sanctioning Law

5 min readLast updated By Philipp Staiger

Procedural classification: preliminary reference C-383/23

Pending before the Court of Justice of the European Union under case number C-383/23 is a preliminary reference submitted in 2023 by a national court of a Member State. Based on the published procedural data in the CJEU register, the case concerns the interpretation of Art. 83 GDPR and in particular the relevant undertaking concept for fine calculation. A party to the proceedings is ILVA A/S; further particulars follow from the specific order for reference of the referring court.

Dr. M. Hofstetter classifies the proceeding within the recent line of CJEU case law on sanctioning law. The Court had already clarified central questions of fine law in the judgments Deutsche Wohnen of 5 December 2023 (Case C-807/21, ECLI:EU:C:2023:950) and Nacionalinis visuomenes sveikatos centras of the same day (Case C-683/21, ECLI:EU:C:2023:949). C-383/23 ILVA fits into this line and refines it. A systematic presentation of the substantive framework is set out in our GDPR guide.

Legal framework: Art. 83 GDPR and the undertaking concept

Art. 83(4) and (5) GDPR provide for administrative fines of up to EUR 10 million or EUR 20 million respectively, in the case of an undertaking up to 2 or 4 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher. The concept of undertaking is not defined in the GDPR itself. Recital 150 refers to the understanding of the undertaking concept within the meaning of Art. 101 and 102 TFEU.

The consequence of this referral is considerable. According to the settled case law of the CJEU on European competition law, the undertaking concept covers the economic unit as a whole, irrespective of its legal form. In the Deutsche Wohnen proceeding the CJEU expressly confirmed this interpretation for GDPR sanctioning law. C-383/23 ILVA further concretises the practical application, in particular the questions raised in the specific order for reference on the calculation of the relevant turnover.

Procedural questions in the order for reference

Based on the published procedural documents, the preliminary reference concerns questions of interpretation relating to the concrete calculation of the fine under Art. 83 GDPR. At the centre stands the question whether and to what extent the calculation must take account of the turnover of the directly acting entity or of the turnover of the economic unit as a whole. As the Advocate General's Opinion will note, this question is of considerable importance for the practice of the national supervisory authorities.

A further procedural question concerns the consideration of the degree of fault under Art. 83(2)(b) GDPR and the weighting of the assessment criteria set out in Art. 83(2) GDPR. As at the time of publication, the Advocate General's Opinion and the final judgment of the competent chamber of the Court are awaited. Controllers should follow the development of the proceeding closely, as the interpretive line has direct implications for risk assessment in group structures.

Fine, order and decision in GDPR sanctioning law

The precise differentiation of the supervisory instruments is also of significance in the context of C-383/23 ILVA. The fine under Art. 83 GDPR covers the administrative fine; it is imposed by way of a fine notice or a corresponding decision of the competent supervisory authority. The order under Art. 58(2) GDPR is a corrective measure intended to change the controller's processing practice. The decision as an administrative act covers both elements and the related reasoning.

In the order for reference in C-383/23, the calculation of the fine is likely to take centre stage. However, the interpretation of the undertaking concept also affects the addressing of orders. Group structures with multiple controllers must clarify against which entity an order can be directed and how far the corrective effect reaches. A. Brunner notes, from the perspective of an ISO 27001 lead auditor, that clear governance documentation significantly simplifies the question of addressing.

Consequences for group structures

The CJEU line on the undertaking concept has direct consequences for group structures with Swiss parent or subsidiary companies. Where the maximum fine bracket under Art. 83(5) GDPR is calculated on the basis of group turnover, an infringement by a small group entity can lead to a fine that far exceeds its own turnover volume. Controllers should align their group governance accordingly.

Three structural measures are central. First, central group-wide data protection guidelines should be established to limit the reproach of fault under Art. 83(2)(b) GDPR. Second, the allocation of responsibilities between group entities should be clearly documented, in particular with regard to the question of joint controllership under Art. 26 GDPR. Third, intra-group data transfers should rest on a robust legal basis, typically Binding Corporate Rules under Art. 47 GDPR or Standard Contractual Clauses under Art. 46(2)(c) GDPR.

What this means for Swiss companies

K. Aebischer brings the perspective of a Swiss SME CISO. Swiss controllers are directly affected in two constellations. First, where they fall within the scope of the GDPR under Art. 3(2) GDPR and are thereby subject to the sanctioning regime under Art. 83 GDPR. The maximum fine bracket is in this case calculated on the worldwide group turnover and not on the turnover of the Swiss entity alone.

Second, the Swiss DSG (Federal Act on Data Protection / FADP), which entered into force on 1 September 2023, applies in parallel. Art. 60 et seq. DSG provide for fines of up to CHF 250,000 for the wilful breach of certain duties. Unlike under Art. 83 GDPR, the Swiss fines are primarily directed at natural persons, which gives rise to an autonomous risk dimension. A comparative overview of the two sanctioning regimes is provided in our DSG guide (German-language pillar).

Implementation duties for DACH clients

From the proceeding C-383/23 ILVA and the broader CJEU line on sanctioning law, four concrete implementation duties for DACH clients can be derived. First, group governance should be documented, including the allocation of responsibilities for data protection between the entities. Second, internal escalation processes should exist that, in the event of supervisory proceedings, ensure the prompt information of group management.

Third, the risk assessment in the data protection management system should take account of the potential group fine bracket and not merely the turnover of the directly affected entity. Fourth, insurance coverage for data protection breaches should be reviewed against the CJEU line on group turnover. N. Köhler notes that communication towards management should present this risk dimension precisely and without minimisation. A comparative consideration of the roles DPO and CISO is set out in our overview DPO vs. CISO.

How SIDD supports you

SIDD accompanies controllers in preparing for the consequences derivable from C-383/23 ILVA. In our mandate as external DPO under GDPR Art. 37 we take responsibility for the ongoing monitoring of conformity and the communication with the European supervisory authorities. In our mandate as Swiss data protection advisor under Art. 10 DSG we manage the parallel Swiss duties under the DSG.

For controllers without an establishment in the Union we provide the EU Representative under Art. 27 GDPR. As at the time of publication, the Advocate General's Opinion and the final judgment of the competent chamber of the CJEU in C-383/23 are awaited. SIDD follows the proceeding on an ongoing basis and supports controllers in the timely adjustment of their governance to the respective interpretive line. A comparison of the representative regimes in the EU and UK is provided in our overview EU vs. UK Representative.

CJEU Preliminary Reference C-383/23 ILVA: Fine Calculation and the Undertaking Concept in GDPR Sanctioning Law

INSIGHT

All
21 February 2026
Philipp Staiger
The preliminary reference C-383/23 ILVA concerns the interpretation of Art. 83 GDPR and in particular the relevant turnover concept for fine calculation. The article analyses the procedural questions and derives consequences for DACH compliance.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.