Skip to main content
Category: Supervisory Authorities & Enforcement

Warning

Also known as: Admonition, Caution
Simply put

A warning is a statement or signal that alerts someone to a possible danger, problem, or unpleasant outcome so they can take precautions. It can be communicated in different ways and can range in strength from mild to urgent.

Formal definition

In its general, dictionary sense, a warning is the act of warning, or a communication (spoken, written, or signalled) intended to make a recipient aware of a possible danger, risk, or adverse consequence, thereby prompting caution or corrective action. The evidence provided defines the term only in its ordinary-language sense and does not establish any specialised data protection or GDPR-specific meaning; practitioners should note that where the word appears in a regulatory context (for example, as a corrective measure or supervisory tool), the applicable legal instrument's own definition should be consulted and verified against the current official text.

Why it matters

In ordinary usage, a warning is a communication that alerts a recipient to a possible danger, problem, or unpleasant outcome so they can take precautions or corrective action. Its significance lies in its function: it shifts awareness to a person who may otherwise be unaware of a risk, enabling them to respond before harm occurs. Warnings can vary in strength from mild cautions to urgent alarms, and they can be delivered in different forms, whether spoken, written, or signalled.

The evidence provided defines the term only in this general, dictionary sense and does not establish any specialised data protection or GDPR-specific meaning. This distinction matters because the word 'warning' also appears in regulatory contexts, for example as a corrective measure or supervisory tool. Practitioners should not assume that the ordinary-language meaning maps directly onto any technical or statutory use. Where the term appears in a legal instrument, the applicable instrument's own definition governs and should be consulted and verified against the current official text.

Who it's relevant to

Data protection officers and compliance leads
Those working in privacy and compliance should be aware that 'warning' has an ordinary meaning distinct from any regulatory sense. Where the term appears in a data protection context, the applicable legal instrument's own definition should be consulted rather than relying on the general dictionary meaning captured here.
Legal practitioners
Lawyers reviewing documents or advising clients should treat the general definition as a starting point only. Because the evidence does not establish a GDPR-specific meaning, any use of the term in a statutory or supervisory context requires verification against the current official text of the relevant instrument.
General readers and drafters
Anyone drafting communications intended to alert others to possible danger, risk, or adverse consequences can rely on the ordinary sense of the term, noting that warnings vary in form and strength and are chosen to fit the nature of the risk communicated.

Inside Warning

Corrective power
A warning is one of the corrective powers available to a supervisory authority. It is generally used to signal that intended processing operations are likely to infringe the GDPR, allowing the controller or processor to adjust before proceeding. Practitioners should verify the specific power and its conditions against the current official text of the Regulation.
Forward-looking nature
Unlike a reprimand, which typically addresses processing that has already occurred, a warning is generally directed at intended or planned processing operations that are likely to breach the Regulation. It is anticipatory rather than reactive in most cases.
Addressee
A warning may be issued to a controller or to a processor. The two roles are distinct, and the addressee of a warning should be identified according to who is responsible for the intended processing at issue.
Trigger condition
The relevant condition is that the intended processing operations are, in the supervisory authority's assessment, likely to infringe the Regulation. This is an assessment-based threshold rather than a finding of an established breach.
Relationship to other measures
A warning sits alongside other corrective measures (such as reprimands, orders, and, where applicable, administrative fines). Its use does not by itself preclude further action, and a subsequent measure may follow if the processing proceeds and results in an infringement.

Common questions

Answers to the questions practitioners most commonly ask about Warning.

Is a warning the same as a fine, or does it always lead to one?
No. A warning is a distinct corrective measure and is not itself a monetary penalty. It generally addresses processing operations that are likely to infringe the applicable rules, and it does not automatically escalate to a fine. Whether any further measure follows depends on the supervisory authority's assessment of the circumstances. You should verify the specific powers and their labelling against the current official text of the Regulation and any relevant national implementing law.
Does a warning mean an infringement has already occurred?
Not necessarily. A warning is typically forward-looking and generally concerns processing operations that are likely to infringe the applicable provisions, rather than confirming that a breach has already taken place. This distinguishes it from measures directed at conduct that has already occurred. The precise threshold and framing can be a matter of interpretation and guidance, so treat the boundary as context-dependent and confirm against the current text.
Who within an organisation should receive and act on a warning from a supervisory authority?
In most cases the warning would be routed to those accountable for the relevant processing, which typically includes the data protection officer where one is appointed, alongside the controller's or processor's compliance and legal functions. As a practical matter, the recipient depends on your internal governance structure, so it is generally advisable to define in advance which role owns regulator correspondence. This is an operational point rather than a fixed legal requirement, and internal allocation can vary.
How should we document our response to a warning?
It is generally good practice to record the warning, the processing operations it concerns, your assessment of the issue, and any steps taken in response, so that the accountability position can be demonstrated. Retaining this alongside related records typically supports a coherent audit trail. The appropriate level of detail is a matter of judgment and risk, and there is no single prescribed format, so align documentation with your existing governance approach.
Should receiving a warning prompt us to revisit our risk assessments?
In most cases, yes as a matter of prudence. Because a warning typically flags processing that is likely to infringe, it can be a useful trigger to reassess the relevant processing and any associated risk analysis. Whether a formal reassessment is warranted depends on the nature of the concern raised. This is a practical suggestion rather than a stated obligation flowing from the warning itself, so scope any review to your circumstances.
Can we treat a warning as the end of the matter once we have adjusted our processing?
Not reliably. A warning may be one step in a broader supervisory engagement, and a supervisory authority retains its other powers depending on how matters develop. It is generally safer to treat your response as ongoing and to monitor for any follow-up rather than assuming closure. Because outcomes are context and risk dependent, avoid concluding that a matter is fully resolved without confirming the position with the authority where appropriate.

Common misconceptions

A warning and a reprimand are the same thing.
They are distinct corrective tools. A warning is generally directed at intended processing that is likely to infringe the Regulation, whereas a reprimand typically addresses processing that has already taken place. Practitioners should not treat the terms interchangeably.
Receiving a warning means a fine will necessarily follow, or conversely that no further action is possible.
A warning does not automatically lead to a fine, nor does it exhaust the supervisory authority's options. Whether any further corrective measure follows is context and risk dependent and typically turns on whether the controller or processor proceeds with the processing and whether an infringement results.
A warning is a definitive legal finding that processing is unlawful.
A warning generally reflects the supervisory authority's assessment that intended processing is likely to infringe the Regulation. It signals risk rather than conclusively establishing a breach, and the ultimate lawfulness of the processing remains subject to assessment.

Best practices

Treat a warning as a signal to reassess the intended processing before it goes live, and document the changes made in response.
Confirm whether the warning is addressed to your organisation as controller or as processor, and align your remediation to the correct role and its responsibilities.
Re-examine the legal basis and, where special category data is involved, the additional condition relied upon, rather than assuming the intended processing is compliant.
Do not assume a warning ends the matter; prepare for the possibility of further corrective measures if the processing proceeds and results in an infringement.
Verify the specific corrective power, its conditions, and any applicable article references against the current official text of the Regulation and relevant regulator guidance, noting that positions can vary between member states and under the UK GDPR.
Engage privacy counsel or your data protection officer early to assess the identified risk and to decide whether to amend, pause, or proceed with the processing.