in force 2024-05-20 MODIFIED+1,391 −15§
Amended by Regulation (EU) 2024/1183 32024R1183
applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)
dates added to the text: 2022-12-14
Sources disagree about what is listed, not about the text — the text comparison and the EU's own amendment metadata found this change; the amending act's instructions do not mention it. All are shown; none is overruled.
The single-paragraph provision requiring Member States to lay down effective, proportionate and dissuasive penalties has become paragraph 1, now prefaced by a reference to Article 31 of Directive (EU) 2022/2555 and otherwise rephrasing the penalty description as 'those penalties' rather than 'the penalties provided for'.
Two new paragraphs have been added: paragraph 2 requires Member States to ensure that infringements by qualified and non-qualified trust service providers are subject to administrative fines of a maximum of at least EUR 5000000 for a natural person, or EUR 5000000 or 1% of total worldwide annual turnover for a legal person, whichever is higher, and paragraph 3 addresses how, depending on the legal system of the Member State, such fines may be initiated by a competent supervisory body and imposed by competent national courts, with a requirement that such remedies be effective and have an equivalent effect to administrative fines imposed directly by supervisory authorities.
Cited: Art. 16, v1 · Art. 16, v2
text before / after
texts differ too much for an inline diff; shown separately
before (32014R0910)
Article 16 Penalties Member States shall lay down the rules on penalties applicable to infringements of this Regulation. The penalties provided for shall be effective, proportionate and dissuasive.
after (02014R0910-20240520)
Article 16 Penalties 1. Without prejudice to Article 31 of Directive (EU) 2022/2555 of the European Parliament and of the Council Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80)., Member States shall lay down the rules on penalties applicable to infringements of this Regulation. Those penalties shall be effective, proportionate and dissuasive. 2. Member States shall ensure that infringements of this Regulation by qualified and non-qualified trust service providers be subject to administrative fines of a maximum of at least: (a) EUR 5000000 where the trust service provider is a natural person; or (b) where the trust service provider is a legal person, EUR 5000000 or 1 % of the total worldwide annual turnover of the undertaking to which the trust service provider belonged in the financial year preceding the year in which the infringement occurred, whichever is higher. 3. Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fine is initiated by the competent supervisory body and imposed by competent national courts. The application of such rules in those Member States shall ensure that those legal remedies are effective and have an equivalent effect to administrative fines imposed directly by supervisory authorities.