Skip to main content
Category: Supervisory Authorities & Enforcement

Corrective Powers

Also known as: Supervisory authority corrective powers, Article 58 corrective powers
Simply put

Corrective powers are the enforcement tools that data protection regulators can use to bring organisations that handle personal data back into line with data protection law. These typically include measures such as issuing warnings and reprimands, and imposing other remedies to address non-compliance. They allow regulators to respond when a controller or processor is not following the rules.

Formal definition

Corrective powers are a category of supervisory authority powers set out in Article 58 GDPR (and mirrored in the UK GDPR), enabling a supervisory authority to take enforcement action against controllers and processors to secure compliance. Per the evidence, these powers include issuing warnings to a controller or processor where intended processing operations are likely to infringe the Regulation, issuing reprimands, and imposing further corrective measures. The evidence packet identifies warnings, reprimands, and the imposition of measures as examples but does not enumerate the full statutory list; practitioners should verify the complete set of corrective powers (which may include ordering compliance, bans on processing, and administrative fines) against the current official text of Article 58 GDPR and the applicable national or UK implementing law. The specific exercise and availability of individual powers can vary with member state implementing law and regulator practice.

Why it matters

Corrective powers are the mechanism through which data protection law moves from principle to practice. Without enforceable tools, the obligations placed on controllers and processors would carry little practical weight. Corrective powers give supervisory authorities the ability to intervene when personal data is not being handled in line with the applicable rules, ranging from formal warnings about intended processing that is likely to infringe the Regulation, through to reprimands and the imposition of other corrective measures. For organisations, this means that non-compliance is not merely a theoretical risk but something a regulator can act upon directly.

The existence and scope of these powers shape how organisations approach data protection governance. Because a supervisory authority can respond both to processing that has already occurred and, through warnings, to processing that is merely intended and likely to infringe, organisations have reason to assess compliance proactively rather than reactively. The evidence indicates that warnings, reprimands, and the imposition of measures are among the tools available, but the full statutory list is not enumerated here and should be verified against the current text of Article 58 GDPR and applicable implementing law.

It is important to treat corrective powers as context-dependent rather than fixed. The specific powers available and how they are exercised can vary with member state implementing law and regulator practice, and there may be differences between how the GDPR and the UK GDPR operate in this area. Practitioners relying on a particular power should confirm its availability and scope against the official text and relevant national provisions rather than assuming a uniform position across jurisdictions.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for an organisation's data protection posture need to understand that a supervisory authority can respond to both actual and intended processing that is likely to infringe. This makes proactive assessment of processing operations valuable, since a warning may be issued before processing begins. DPOs should verify the full range of corrective powers available in their jurisdiction against the current official text.
Controllers and Processors
Corrective powers apply directly to both controllers and processors, meaning enforcement risk is not confined to one role. Organisations acting in either capacity should be aware that regulators can issue warnings, reprimands, and impose measures to secure compliance, and that the precise powers and how they are used may vary with implementing law and regulator practice.
Privacy and Data Protection Lawyers
Advisers assessing enforcement exposure should treat the examples here, warnings, reprimands, and the imposition of measures, as a partial illustration rather than the complete list. The full set of corrective powers, including any that may be more severe, should be confirmed against Article 58 GDPR, the UK GDPR, and relevant national implementing provisions, noting potential divergence between jurisdictions.

Inside Corrective Powers

Warnings and Reprimands
Corrective powers include the ability of a supervisory authority to issue warnings to a controller or processor that intended processing operations are likely to infringe the Regulation, and to issue reprimands where processing has infringed. These are generally the lower-intensity end of the corrective spectrum and do not themselves impose a financial penalty.
Orders to Comply
A supervisory authority can typically order a controller or processor to bring processing operations into compliance, in a specified manner and within a specified period. This can include ordering that data subject requests be complied with, or ordering rectification, erasure, or restriction of processing.
Communication and Notification Orders
Powers can extend to ordering the controller to communicate a personal data breach to affected data subjects where relevant obligations apply.
Limitations, Bans, and Suspensions
Corrective powers include imposing a temporary or definitive limitation on processing, including a ban, and ordering the suspension of data flows to a recipient in a third country or to an international organisation. The precise application is subject to assessment of the circumstances.
Certification and Authorisation Actions
A supervisory authority can withdraw a certification or order a certification body to withdraw one, or refuse to issue a certification where requirements are not met.
Administrative Fines
Where appropriate, a supervisory authority may impose an administrative fine in addition to, or instead of, other corrective measures, depending on the circumstances of each individual case. The specific fine tiers and maximum amounts should be verified against the current official text of the Regulation.

Common questions

Answers to the questions practitioners most commonly ask about Corrective Powers.

Are corrective powers limited to imposing administrative fines?
No. Fines are only one of several corrective powers available to supervisory authorities. The range typically includes warnings, reprimands, orders to bring processing into compliance, orders to comply with data subject requests, temporary or definitive limitations (including bans) on processing, orders to rectify or erase data, and the withdrawal of certifications, among others. An authority may use these tools instead of, or alongside, a fine, and the choice depends on the circumstances of the case. You should verify the specific list and its wording against the current official text.
Does a supervisory authority always have to impose the most severe corrective measure available?
No. The exercise of corrective powers is generally governed by principles of proportionality, and authorities are expected to select measures that are appropriate to the nature, gravity, and consequences of the infringement. In some cases a warning or reprimand may be sufficient, while in others more intrusive measures such as a processing ban may be warranted. Because this is a context-dependent and discretionary assessment, outcomes can vary between cases and between regulators.
How should an organisation respond when it receives a corrective order from a supervisory authority?
In most cases the response should begin by identifying precisely what the order requires, the deadline for compliance, and the legal basis cited. Organisations typically document the required actions, assign accountability internally, and preserve records demonstrating the steps taken. Because procedural rights, including the possibility of challenging a decision, can depend on national procedural law and the specifics of the order, it is advisable to obtain qualified legal advice and to verify applicable timelines against the relevant authority's guidance.
What internal records help demonstrate compliance if corrective powers are exercised?
Records that evidence accountability generally assist here, such as documentation of processing activities, legal bases relied upon, risk assessments, and steps taken to address any identified deficiencies. Where an order requires specific remediation, keeping a dated log of actions taken in response can help demonstrate good faith and compliance. The precise records that are persuasive will depend on the nature of the order and the authority's expectations.
Can corrective powers apply to both controllers and processors?
Corrective powers can, in principle, be directed at the relevant actor depending on the infringement and that actor's role. Because controllers and processors have distinct obligations, an order should be read carefully to identify which party it addresses and which obligations it concerns. Where multiple parties are involved in the same processing, more than one may be subject to measures. The exact application depends on the facts and the authority's assessment.
How can an organisation prepare in advance for the possibility of corrective measures?
Preparation typically focuses on maintaining an accountable compliance posture, so that any deficiency can be identified and remediated quickly. This generally includes keeping documentation current, having internal escalation and response procedures, and monitoring relevant regulatory guidance. Because the availability and framing of corrective powers can evolve and can vary with national implementing law, organisations should periodically verify their understanding against current official sources and, where appropriate, seek qualified advice.

Common misconceptions

Corrective powers always mean a fine.
Administrative fines are only one category of corrective power. Supervisory authorities have a range of measures, from warnings and reprimands to orders, bans, and suspensions of data flows. A fine may be imposed instead of or in addition to other measures, and its use is context and risk dependent rather than automatic.
Corrective powers apply only to controllers.
Many corrective powers can be directed at both controllers and processors, reflecting the distinct roles and obligations each holds under the Regulation. The appropriate addressee depends on which entity is responsible for the relevant processing conduct.
A supervisory authority's corrective decision is a fixed and final outcome that applies uniformly across the EU.
How corrective powers are exercised can vary between regulators, may be subject to national procedural rules and member state implementing law, and is generally subject to judicial remedy. Practitioners should treat any specific outcome as case-specific rather than a settled uniform standard.

Best practices

Map which corrective powers your supervisory authority can exercise and identify whether your organisation would be addressed as a controller or a processor for the processing in question.
Maintain accountability documentation so that, if an order to comply or bring processing into conformity is issued, you can demonstrate remediation within the specified period.
Treat orders to suspend third-country data flows as a live risk by keeping an inventory of transfers and the transfer tools and supplementary measures relied on, recognising these mechanisms can evolve.
Prepare internal escalation and response procedures for warnings and reprimands so that lower-intensity measures are actioned before they escalate to bans, limitations, or fines.
Verify current fine tiers, procedural rules, and any national derogations against the official Regulation text and applicable implementing law rather than relying on summaries.
Preserve your right to an effective judicial remedy by documenting the reasoning behind processing decisions and engaging early and cooperatively with the supervisory authority.