Quick answer: Every GDPR (DSGVO) fine issued by a European supervisory authority is published to a public register — the GDPR CMS Enforcement Tracker on CMS.law, the EDPB final-decisions registry, and the individual authority's press-release archive. Each entry states the legal articles cited, the fine amount, the company sector, and the described violation. Reading those registers is the cheapest enforcement-intelligence you will ever buy — and on Devotel Orbit, the evidence a supervisory authority would ask for is produced by four maintained surfaces: the DSAR queue, the Data Processing Agreement and sub-processor register, consent management, and the breach incident register. Roll them into one GDPR pack with the one-click evidence binder.
What European regulators actually publish
GDPR fines are not press-studio artillery — they are administrative decisions, and across the EU and EEA supervisory authorities have a standing legal duty to publish them. The public record is much richer than a headline amount; if you read registers rather than newswire summaries, you get the full citation structure back.
Three sources carry the signal:
- GDPR CMS Enforcement Tracker — CMS.law maintains a cross-authority register of every fine, with article citations, fine amount, and defendant sector in a filterable table.
- EDPB final decisions — the European Data Protection Board publishes final decisions in cross-border cases (GDPR Article 60 cooperation), binding across member states.
- National press-releases — Germany's Landesbeauftragte für Datenschutz (LfD) state offices, France's CNIL, Spain's AEPD, Italy's Garante, and every other authority publish their own decisions directly, usually first.
The entry fields are consistent across sources: the GDPR articles cited (Art. 5, 6, 13, 15, 17, 28, 30, 32, 33, 35, 44 are the recurring set), the fine amount, the sector (which you should treat as a classifier — CPaaS tenants are not immune just because the top fines land on big-tech platforms), and the violation description, which tells you what the regulator actually penalized — not "bad security", but "no lawful basis for processing marketing contact lists" or "32-day average DSAR response".
Article 44 cross-border transfers, Article 5(1)(f) integrity-and-confidentiality failures, and Article 6 missing lawful basis have collectively driven most of the total fine volume. For a communications tenant, the recurring citations below map directly to the surfaces a regulator will ask for.
Regulator → evidence map for a CPaaS tenant
Each register citation corresponds to one maintained evidence surface on Orbit. The division of responsibility is fixed: the platform assembles the evidence; the posture it records is tenant-owned.
| Regulator citation | What they asked for | Orbit surface |
|---|---|---|
| Art. 15 / Art. 17 (access / erasure) | DSAR ledger with statuses + 30-day SLA | DSAR queue |
| Art. 28 / Art. 30 (processors / records) | DPA + sub-processor catalog + RoPA | Data Processing Agreement + privacy register |
| Art. 6 / Art. 7 (lawful basis) | Consent receipts with timestamps + provenance | consent management |
| Art. 32 (security of processing) | Encryption posture, pseudonymisation, DR cadence | GDPR posture guide + evidence binder Art. 32 row |
| Art. 33 (breach notification) | Breach register + 72-hour notification attestation | breach incident register |
| Art. 44 (transfers) | Data-residency + transfer posture | voice data residency configuration |
For the single-file version of every row, generate the GDPR pack in the evidence binder — it maps these surfaces onto the GDPR article structure the supervisory authority will cite.
What the published fines actually teach
Read enough register entries and five operational patterns repeat. None of them are exotic; most fines are lost at boring checkpoints:
- Lawful basis is the most-cited defect. "We didn't have consent" beats "our encryption was weak" roughly three-to-one in published descriptions. If your consent management register cannot demonstrate per-channel opt-in/out with provenance for every contact segment you message, Art. 6 is the citation you will see.
- DSAR delay turns a request into a violation. Under Art. 12(3) you have 30 days. The publicised fines cluster around tenants with a queue but no SLA clock — the DSAR queue on Orbit tracks the jurisdiction-aware deadline so the ledger the auditor reads is the closed-in-time ledger.
- Processor chains leak outside the contract. Article 28 fines surface when a sub-processor touches personal data without a documented DPA. The published sub-processor catalog in the Data Processing Agreement surface is exactly the document the authority reads first.
- Cross-border transfers lose on paperwork, not tech. Schrems II (C-311/18) plus Art. 44 means transfers fail on missing transfer impact assessments and sub-processor lists more often than on weak encryption. Keep residency configuration current before the binder is generated.
- Retention set too long and never revisited is itself a fine. Art. 5(1)(e) storage-limitation citations target tenants whose raw message content and recordings persist past any configured window. Set the window deliberately in your data retention policy; the binder pulls it as the Art. 30/32 row.
Treat the published register as your compliance sprint backlog. Every row that lands on a peer tenant is a free tracer round for the one you might still have.
Building audit-readiness on Orbit
Audit-readiness is a posture you sustain, not a binder you generate once. Four habits:
- Close DSARs inside the legal clock. The DSAR queue — or the public intake portal — must run the 30-day jurisdiction clock for you, so a completed request is never the discovered-after-the-deadline request.
- Refresh the DPA + sub-processor catalog when processors change. The Data Processing Agreement surface carries the click-wrap executed copy and the 30-day change-notice period; regenerate it the week a sub-processor rotates.
- Capture consent with provenance. Consent management records who opted in or out, on which channel, when — aggregate counts for the binder, never contact identifiers.
- Maintain a breach register before you need it. The breach incident register attests your 72-hour notification SLA even when the register is empty — empty-but-attested is itself Art. 33 evidence.
Run a GDPR pack from the evidence binder on a quarterly cadence, and keep the tamper-evidence banner clean between cycles: the binder replays the audit-chain integrity check at generation, and a banner you clear every quarter reads as a monitored chain to an auditor.
Frequently asked questions
Do supervisory authorities really publish every fine?
Yes. GDPR Art. 58 powers plus national administrative law give authorities a standing publication duty; the CMS tracker aggregates them precisely because publication is the norm. Some authorities redact the defendant name; citation structure and amount still ship.
Is the fine amount what matters for audit prep?
No — the cited article tells you which evidence surface to harden, and the violation description tells you the failure pattern. The amount is a scoping signal (Art. 83 caps: €20M or 4% of global turnover), not a readiness signal.
Which articles should a communications tenant watch most?
Art. 6 (lawful basis) and Art. 32 (security of processing) drive the majority of fine volume; Art. 15/17 DSAR and Art. 44 transfers follow. All four map to dedicated Orbit surfaces — consent, posture guide, DSAR queue, and residency configuration respectively.
Can the evidence binder stand in for a GDPR audit?
No. The evidence binder assembles your tenant evidence into a checksummed pack; it is not a Devotel attestation. If the audit-chain integrity replay flags anything, the binder opens with a tamper-alert banner by design, ahead of its first evidence row.
The takeaway
Every GDPR fine is published, and every publication teaches you which surface to keep closed-in-time, which catalog to keep current, which register to keep attested. On Orbit those surfaces are maintained as features: DSAR queue, Data Processing Agreement, consent management, and breach incident register. Roll them into a GDPR pack with the evidence binder quarterly, and the regulator's published fine table becomes your compliance roadmap instead of your warning list. For the buyer-side evidence checklist, see The GDPR Audit Evidence Checklist.