The DORA regulation (Digital Operational Resilience Act) introduces severe penalties for non-compliance with its requirements. Sanctions may include high fines and other administrative actions, such as restrictions on financial institutions’ activities. Penalties are imposed for failure to fulfill obligations related to ICT risk management, improper incident reporting, or lack of appropriate digital resilience procedures.
Table of Contents
- What is the DORA regulation and who does it apply to?
- What are the main objectives of introducing penalties in the DORA regulation?
- Who is authorized to impose penalties for DORA violations?
- What specific DORA violations result in penalties?
- What types of penalties does the DORA regulation provide?
- What is the maximum amount of financial penalties for DORA violations?
- What determines the amount of imposed penalties?
- Do penalties apply only to financial entities or also to ICT service providers?
- What penalties face natural persons responsible for violations?
- Are there mitigating circumstances when imposing penalties?
- What does the procedure for imposing penalties for DORA violations look like?
- Is an appeal available against an imposed penalty?
- What are the consequences of not paying an imposed penalty?
- Is information about imposed penalties made public?
- How long must an entity expect the possibility of penalty after violation detection?
What is the DORA regulation and who does it apply to?
The DORA regulation (Digital Operational Resilience Act) is a key legal act of the European Union aimed at strengthening the digital resilience of the financial sector. It introduces uniform requirements for network security and IT systems for financial entities operating in the EU. DORA covers a wide range of financial institutions, regardless of their size or operational complexity. Entities covered by the regulation include:
- Banks and credit institutions
- Investment firms
- Insurance and reinsurance companies
- Payment institutions and electronic money institutions
- Stock exchanges and trading platforms
- Investment and pension funds
- Rating agencies
- Crypto-asset service providers
Importantly, DORA applies not only to financial institutions themselves but also to their key ICT service providers. This means that technology companies serving the financial sector must also adapt to the regulation’s requirements.
DORA entered into force on January 16, 2023, but full implementation of its requirements is mandatory from January 17, 2025. This gives entities covered by the regulation time to adapt their systems and processes to the new requirements.
The DORA regulation is a response to growing cyber threats in the financial sector. Its goal is to ensure that financial institutions can effectively counter attacks, detect incidents, and quickly restore normal operations in case of disruptions.
📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać
What are the main objectives of introducing penalties in the DORA regulation?
The introduction of a penalty system in the DORA regulation has several key objectives designed to ensure effective implementation and compliance with new digital resilience requirements in the financial sector.
First and foremost, penalties are intended to have a deterrent function. High financial sanctions are meant to discourage financial institutions and ICT service providers from disregarding DORA requirements. The prospect of severe financial consequences should motivate entities to prioritize cybersecurity issues and invest in appropriate technical and organizational solutions.
The second important objective is to ensure a level playing field in the EU financial market. A uniform penalty system aims to guarantee that all entities will be treated the same way, regardless of the member state in which they operate. This prevents situations where some institutions could gain a competitive advantage by not complying with DORA requirements.
Penalties also aim to protect the stability of the EU financial system. By enforcing high cybersecurity standards, DORA seeks to minimize the risk of serious incidents that could threaten the functioning of the entire financial sector.
An important aspect is also building customer and investor trust. Severe penalties for DORA violations are meant to show that the EU takes digital security issues in the financial sector seriously, which should translate into greater trust in financial institutions operating in the Union.
Finally, the penalty system is designed to ensure effective enforcement of DORA provisions. It provides supervisory authorities with tools to enforce compliance with the regulation and quickly respond to detected violations.
In summary, penalties in DORA are meant not only to punish violations but primarily to stimulate a proactive approach to cybersecurity in the EU financial sector.
Who is authorized to impose penalties for DORA violations?
The authority to impose penalties for violations of the DORA regulation has been granted to several key institutions at the European Union level and supervisory authorities in individual member states. This structure is designed to ensure effective enforcement at different levels and in different sectors of the financial market.
At the EU level, the European Supervisory Authorities (ESAs) play a key role:
-
European Banking Authority (EBA)
-
European Securities and Markets Authority (ESMA)
-
European Insurance and Occupational Pensions Authority (EIOPA)
These institutions have the authority to impose penalties on key ICT service providers that have been deemed “critical” under DORA. They can conduct audits, request information and documentation, and impose financial penalties if violations are found.
At the national level, the competent supervisory authorities in each EU member state have the authority to impose penalties. In the case of Poland, this may be, for example, the Polish Financial Supervision Authority (KNF). These authorities are responsible for supervising financial institutions operating in their territory and have the right to impose penalties for DORA violations.
It is worth emphasizing that DORA introduces a cooperation mechanism between national authorities and ESAs. In the case of cross-border violations or issues concerning critical ICT service providers, national authorities may cooperate with ESAs to coordinate supervisory and sanctioning actions.
DORA also provides for the possibility of delegating certain supervisory and sanctioning powers between authorities. This is to ensure flexibility and effectiveness in enforcing provisions, especially in the case of entities operating in multiple jurisdictions.
It is important that entities authorized to impose penalties must act in accordance with the principles of proportionality and effectiveness. This means that penalties should be adequate to the severity of the violation and effective in preventing similar incidents in the future.
What specific DORA violations result in penalties?
The DORA regulation provides for a number of specific violations for which penalties may be imposed. These cover various aspects of IT risk management, information security, and operational resilience. Here are the most important categories of violations:
-
Failure to comply with ICT risk management requirements. This concerns the lack of implementation of appropriate risk management frameworks, inadequate risk identification and assessment, or insufficient control measures.
-
Violations related to incident reporting. Penalties apply for untimely reporting of serious ICT-related incidents or lack of appropriate reporting procedures.
-
Non-compliance with digital resilience testing requirements. DORA requires regular testing, including penetration tests and attack simulations. Lack of such tests or improper execution can result in penalties.
-
Violations in managing risk related to ICT service providers. This concerns the lack of appropriate supplier selection procedures, insufficient monitoring of their activities, or lack of contingency plans.
-
Non-compliance with requirements for sharing information about threats and vulnerabilities. DORA encourages sharing information to increase the overall resilience of the sector.
-
Lack of appropriate business continuity and disaster recovery plans. Penalties may be imposed for not having or not updating such plans.
-
Violations related to data protection and information security. This includes insufficient measures to protect customer data or lack of appropriate access management procedures to systems.
-
Non-compliance with requirements for change management in ICT systems. DORA requires a controlled change introduction process to minimize risk.
-
Lack of appropriate management oversight of digital resilience issues. DORA emphasizes the involvement of senior management in these matters.
-
Violations related to outsourcing ICT services. This concerns the lack of appropriate contracts, insufficient oversight of suppliers, or lack of exit plans.
It is worth emphasizing that this list is not exhaustive, and supervisory authorities have some flexibility in interpreting DORA violations. It is crucial that entities covered by the regulation actively monitor their systems and processes for compliance with DORA requirements to avoid potential penalties.
What types of penalties does the DORA regulation provide?
The DORA regulation introduces a wide range of penalties that can be imposed on entities violating its provisions. The variety of sanctions is intended to ensure flexibility in enforcing provisions and adapting the penalty to the severity of the violation. Here are the main types of penalties provided for in DORA:
-
Financial penalties - these are the most severe sanctions, which can reach millions of euros or represent a significant percentage of an entity’s annual turnover. The amount of financial penalties is meant to be significant enough to effectively deter violations.
-
Administrative orders - supervisory authorities may issue binding orders obliging an entity to take specific corrective actions or cease certain practices. These may concern, for example, implementing specific security measures or changing risk management processes.
-
Public warnings - in the case of less serious violations, the supervisory authority may issue a public warning identifying the entity and describing the nature of the violation. Such a sanction can have a significant impact on the institution’s reputation.
-
Temporary suspension of activities - in extreme cases, when violations are serious and repeated, the supervisory authority may order temporary suspension of specific ICT-related activities or services.
-
Revocation of business authorization - this is the most severe sanction, applied in cases of the most serious and systematic violations. It may result in a complete ban on conducting business in the financial sector.
-
Ban on holding management positions - DORA provides for the possibility of imposing a temporary or permanent ban on holding management positions in financial institutions for persons responsible for serious violations.
-
Order to conduct an audit - the supervisory authority may order an independent audit of ICT systems and risk management processes at the expense of the entity violating the provisions.
-
Order to implement a remedial plan - an entity may be obliged to develop and implement a detailed remedial plan aimed at eliminating identified irregularities.
-
Periodic financial penalties - in the case of ongoing violations, the supervisory authority may impose periodic financial penalties, charged for each day of violation.
-
Restriction or suspension of specific ICT services - in case of serious threats related to specific ICT services, the supervisory authority may order their restriction or temporary suspension.
It is worth emphasizing that supervisory authorities have some freedom in selecting appropriate sanctions, guided by the principle of proportionality. This means that penalties should be adequate to the severity of the violation, the size of the entity, and potential effects on financial stability. The goal is not only to punish violations but primarily to encourage entities to improve their practices in digital resilience.
What is the maximum amount of financial penalties for DORA violations?
The DORA regulation provides for severe financial penalties for violations of its provisions, establishing maximum limits that can be imposed on entities not complying with requirements. The amount of these penalties is intended to effectively deter violations and emphasize the importance of cybersecurity in the financial sector.
The maximum amount of financial penalties in DORA is specified at two levels:
-
Penalty expressed in monetary value: The maximum penalty can be up to 10,000,000 euros (ten million euros). This is an absolute upper limit, independent of the size or turnover of the entity.
-
Penalty expressed as a percentage of annual turnover: Alternatively, the penalty can be up to 2% of the entity’s total annual worldwide turnover for the previous financial year. This option is particularly important for large financial institutions, where a turnover-based penalty can significantly exceed the 10 million euro limit.
In practice, the authority imposing the penalty chooses the higher of these two amounts. This means that for large financial institutions, potential penalties can reach tens or even hundreds of millions of euros. It is worth emphasizing that these are maximum limits, and the actual amount of the penalty will depend on many factors, including the severity of the violation, its effects, the entity’s cooperation with supervisory authorities, or corrective actions taken.
DORA also provides for the possibility of imposing penalties on natural persons responsible for violations. In such cases, the maximum penalty can be up to 5,000,000 euros (five million euros). For certain types of violations, especially those related to key DORA requirements, such as ICT risk management or reporting serious incidents, penalties may be even higher. In such cases, the maximum penalty can reach up to 3% of the entity’s total annual worldwide turnover.
It should be remembered that in addition to financial penalties, DORA also provides for other sanctions that can be applied in conjunction with financial penalties or independently. These may include public warnings, administrative orders, or even suspension or revocation of business authorization.
The amount of maximum penalties in DORA reflects the growing importance of cybersecurity in the financial sector and the EU’s determination to ensure a high level of digital resilience of financial institutions.
What determines the amount of imposed penalties?
The amount of penalties imposed for violations of the DORA regulation is not arbitrary but depends on a number of factors that supervisory authorities must consider when determining a specific sanction. This flexibility is intended to ensure that penalties are proportionate and effective. Here are the key factors affecting the amount of imposed penalties:
-
Severity and duration of the violation: More serious violations that lasted longer will be punished more severely. Supervisory authorities will assess the potential impact of the violation on financial stability and customer data security.
-
Degree of entity responsibility: It will be considered whether the violation was the result of intentional action, negligence, or factors beyond the entity’s direct control.
-
Financial situation of the entity: The penalty should be severe but should not threaten the financial stability of the institution. Supervisory authorities will take into account the size and turnover of the entity.
-
Profits gained or losses avoided as a result of the violation: If the entity achieved financial benefits as a result of the violation, the penalty may be increased accordingly to offset these gains.
-
Cooperation with the supervisory authority: Entities that actively cooperate with supervisory authorities, report violations, and take quick corrective actions can expect more lenient treatment.
-
Previous violations: Repeated violations or a history of previous penalties may lead to harsher sanctions.
-
Measures taken to prevent similar violations in the future: Supervisory authorities will consider what steps the entity has taken to strengthen its systems and processes to avoid similar incidents.
-
Impact on customers and the market: Violations that had a direct negative impact on customers or financial market stability will be treated more severely.
-
Systemic importance of the entity: Larger and more significant financial institutions may be treated more severely due to the potentially greater impact of their violations on the financial system.
-
Mitigating or aggravating circumstances: Supervisory authorities will consider any additional factors that may affect the assessment of the violation.
It is worth emphasizing that supervisory authorities are obliged to be guided by the principle of proportionality when imposing penalties. This means that sanctions should be adequate to the violation and effective in preventing similar incidents in the future, but should not be excessively burdensome.
DORA also requires supervisory authorities to publish guidelines on the application of penalties, which is intended to ensure greater transparency and predictability of the penalty imposition process. Entities covered by DORA should carefully familiarize themselves with these guidelines to better understand what factors may affect the amount of potential penalties.
Do penalties apply only to financial entities or also to ICT service providers?
The DORA regulation introduces a comprehensive approach to digital resilience in the financial sector, covering not only financial entities but also key ICT service providers. This is a significant change compared to previous regulations, reflecting the growing importance of external technology providers in the functioning of the financial sector.
Penalties provided for in DORA can be imposed on both financial entities and ICT service providers that have been deemed “critical” under the regulation. Here are the key aspects concerning penalties for ICT service providers:
-
Definition of critical providers: DORA introduces the concept of “critical ICT service providers.” These are technology companies whose services are considered key to the functioning of the financial sector. Examples include cloud computing providers, data processing services, or payment systems.
-
Direct supervision: Critical ICT service providers are subject to direct supervision by the European Supervisory Authorities (ESAs). This means they can be subjected to audits, inspections, and other supervisory actions.
-
Scope of responsibility: ICT service providers can be penalized for violations related to security, business continuity, or risk management in the scope of services provided to financial entities.
-
Amount of penalties: The maximum penalties for ICT service providers are the same as for financial entities - they can reach 10 million euros or 2% of annual worldwide turnover, whichever is higher.
-
Additional sanctions: In addition to financial penalties, critical ICT service providers may be subject to other sanctions, such as administrative orders or a ban on providing services to the financial sector in the EU.
-
Contractual liability: DORA requires that contracts between financial entities and ICT service providers contain clauses regarding compliance with the regulation’s requirements. Violation of these clauses may lead to contractual liability.
-
International cooperation: In the case of ICT service providers from outside the EU, DORA provides for international cooperation mechanisms in supervision and enforcement.
-
Proportionality: Similar to financial entities, penalties imposed on ICT service providers must be proportionate to the severity of the violation and potential effects on the financial sector.
Including ICT service providers in the scope of DORA and the possibility of imposing penalties on them is intended to ensure a comprehensive approach to cybersecurity in the financial sector. It is recognized that ICT supply chain security is crucial to the overall digital resilience of financial institutions.
Financial entities should be aware that the selection and supervision of ICT service providers becomes even more critical in the context of DORA. They must ensure that their suppliers are able to meet the regulation’s requirements and cooperate in the event of inspections or audits.
What penalties face natural persons responsible for violations?
The DORA regulation provides for the possibility of imposing penalties not only on legal entities but also on natural persons responsible for violations. This is an important element of the regulation, aimed at increasing personal responsibility of persons managing and making key decisions in cybersecurity and operational resilience.
Here are the key aspects concerning penalties for natural persons under DORA:
-
Maximum amount of financial penalties: For natural persons, the maximum financial penalty can be up to 5,000,000 euros (five million euros). This is a significant amount intended to effectively deter negligence and violations.
-
Scope of responsibility: Penalties can be imposed on board members, senior management, and other persons responsible for managing ICT risk and making decisions in this area.
-
Types of violations: Natural persons can be penalized for various violations, including failure to fulfill supervisory duties, ignoring risk warnings, negligence in managing ICT security, or non-compliance with incident reporting requirements.
-
Ban on holding management positions: In addition to financial penalties, DORA provides for the possibility of imposing a temporary or permanent ban on holding management positions in financial institutions for persons responsible for serious violations.
-
Publication of penalty information: Information about penalties imposed on natural persons may be made public, which can have a significant impact on the professional reputation of the person.
-
Criminal liability: It is worth noting that DORA does not exclude the possibility of prosecuting natural persons criminally if violations meet the criteria of a crime under national law.
-
Factors affecting the amount of penalty: When determining the amount of penalty for a natural person, factors such as the severity of the violation, degree of responsibility, cooperation with supervisory authorities, or previous violations are taken into account.
-
Right to defense: Natural persons who have been penalized have the right to appeal the decision and present their position to the relevant authorities.
-
Liability insurance: DORA does not prohibit financial institutions from insuring their employees against liability, but penalties imposed on natural persons cannot be directly covered by the entity.
-
Education and awareness: In the context of potential penalties for natural persons, financial institutions should emphasize education and raising awareness of management regarding DORA requirements.
The introduction of the possibility of imposing penalties on natural persons in DORA is intended to strengthen the culture of responsibility in cybersecurity at the highest levels of the organization. It is meant to encourage decision-makers to treat digital resilience issues as a strategic priority and actively engage in ICT risk management.
Persons holding management positions in financial institutions should be aware of the potential personal liability arising from DORA and actively engage in ensuring compliance with the regulation’s requirements.
Are there mitigating circumstances when imposing penalties?
The DORA regulation, although it introduces severe penalties for violations, also provides for a number of mitigating circumstances that can affect the final amount of sanctions. Consideration of these factors is intended to ensure a fair and proportionate approach to imposing penalties. Here are the key mitigating circumstances that may be taken into account:
-
Active cooperation with supervisory authorities: Entities that fully cooperate with supervisory authorities during investigations and voluntarily disclose information about violations can expect more lenient treatment.
-
Rapid implementation of corrective actions: If an entity immediately after detecting a violation takes effective corrective actions and implements measures to prevent similar incidents in the future, this may be considered a mitigating circumstance.
-
Lack of previous violations: Entities that have not previously had a history of violations of cybersecurity and operational resilience regulations may be treated more leniently.
-
Unintentional nature of the violation: If the violation was the result of an unintentional error or oversight rather than deliberate action or gross negligence, this may affect the mitigation of the penalty.
-
Limited impact of the violation: If the effects of the violation were limited and did not have a significant impact on customers, financial stability, or market integrity, this may be considered a mitigating circumstance.
-
Proactive reporting of violation: Entities that themselves detect and report a violation to supervisory authorities before it is discovered otherwise can expect more favorable treatment.
-
Implementation of advanced security systems: If an entity has invested significant resources in advanced security and ICT risk management systems that go beyond DORA’s minimum requirements, this may be considered a mitigating factor.
-
Transparency and openness: Full transparency in communication with supervisory authorities and willingness to provide all relevant information can contribute to mitigating potential sanctions.
-
Difficult financial situation: In exceptional cases, when imposing the full penalty could threaten the financial stability of the entity, supervisory authorities may take this into account when determining the amount of sanctions.
-
Active participation in industry initiatives: The entity’s involvement in industry initiatives aimed at improving cybersecurity and sharing threat information may be viewed positively.
-
Comprehensive training programs: Implementation of extensive training programs for employees in cybersecurity and DORA requirements may be considered a mitigating circumstance.
-
Voluntary disclosure of incident information: Entities that voluntarily disclose information about security incidents, even when not required to do so, can expect more favorable treatment.
It is worth emphasizing that the assessment of mitigating circumstances is made individually for each case. Supervisory authorities have some freedom in interpreting and weighing various factors. Entities covered by DORA should be aware of these potential mitigating circumstances and actively strive to meet them, not only to avoid severe penalties but primarily to improve their overall digital resilience.
At the same time, it should be remembered that the existence of mitigating circumstances does not automatically guarantee mitigation of the penalty. The final decision always belongs to the supervisory authority, which must consider all aspects of the violation and its potential effects on the financial sector.
What does the procedure for imposing penalties for DORA violations look like?
The procedure for imposing penalties for violations of the DORA regulation is a complex process designed to ensure fairness, transparency, and effectiveness in enforcing provisions. Here are the key stages of this procedure:
-
Detection of violation: The process begins with the detection of a potential violation. This can occur as a result of routine inspections, audits, reports from third parties, or self-disclosure by the financial institution.
-
Preliminary analysis: The competent supervisory authority conducts a preliminary analysis of the collected information to assess whether there are grounds to initiate formal proceedings.
-
Initiation of proceedings: If the preliminary analysis indicates a possible violation, the supervisory authority formally initiates proceedings. The entity concerned is informed of this.
-
Evidence collection: The supervisory authority collects detailed information and evidence regarding the violation. This may include requesting documentation, conducting on-site inspections, or interviewing witnesses.
-
Right to be heard: The entity against which proceedings are conducted has the right to present its position and explanations. This may include written statements or oral hearings.
-
Assessment of violation: The supervisory authority conducts a detailed assessment of the collected evidence, taking into account the severity of the violation, its effects, mitigating and aggravating circumstances.
-
Consultations: In the case of cross-border violations or issues concerning critical ICT service providers, the supervisory authority may consult with other competent authorities or European Supervisory Authorities (ESAs).
-
Decision to impose penalty: Based on the assessment conducted, the supervisory authority makes a decision to impose a penalty. This decision includes justification, the amount of the penalty, and information about the right to appeal.
-
Notification of penalty: The entity is officially notified of the imposed penalty. The notification contains detailed information about the violation, the amount of the penalty, and justification for the decision.
-
Right to appeal: The entity has the right to appeal the decision to impose a penalty. The appeal procedure may include an internal review of the decision by the supervisory authority or an appeal to the competent court.
-
Publication of penalty information: In accordance with DORA requirements, information about imposed penalties is usually made public, unless publication could threaten financial market stability or an ongoing investigation.
-
Enforcement of penalty: After the decision becomes final, the supervisory authority proceeds to enforce the imposed penalty. In the case of financial penalties, the entity has a specified time to pay the imposed amount.
-
Monitoring of corrective actions: The supervisory authority monitors whether the entity implements required corrective actions and adapts to DORA requirements.
It is worth emphasizing that the procedure for imposing penalties may differ depending on jurisdiction and the specifics of the case. DORA requires supervisory authorities to publish detailed guidelines on penalty imposition procedures, which is intended to ensure greater transparency and predictability of the process.
Entities covered by DORA should be aware of this procedure and prepared to actively participate in each of its stages. It is crucial to maintain full transparency, cooperate with supervisory authorities, and be ready to quickly implement corrective actions in case violations are detected.
Is an appeal available against an imposed penalty?
Yes, the DORA regulation provides for the right to appeal an imposed penalty. This is a key element of the procedure, ensuring fairness and the possibility of reconsidering the case. Here are the most important aspects concerning the appeal process:
-
Right to appeal: Every entity on which a penalty has been imposed under DORA has the right to appeal this decision. This applies to both legal entities and natural persons.
-
Appeal deadline: DORA specifies a specific deadline for filing an appeal, usually 30 days from the date of receiving the decision to impose a penalty. The exact deadline should be clearly specified in the penalty decision.
-
Form of appeal: The appeal must be submitted in writing and contain detailed justification as to why the entity believes the penalty decision should be changed or annulled.
-
Authorities reviewing appeals: Depending on jurisdiction and the nature of the case, an appeal may be reviewed by:
-
Internal appeals body within the supervisory institution
-
Independent administrative tribunal
-
Competent national court
-
Suspension of penalty execution: Filing an appeal does not always automatically suspend execution of the imposed penalty. However, the entity may request suspension of penalty execution pending review of the appeal.
-
Appeal review procedure: The authority reviewing the appeal analyzes the entire case, including arguments presented by the appealing entity and the position of the supervisory authority. This may include additional hearings or requesting additional documents.
-
Possible appeal outcomes: After reviewing the appeal, the appeals authority may:
-
Uphold the original penalty decision
-
Reduce the amount of the penalty
-
Annul the penalty in its entirety
-
Refer the case for reconsideration by the supervisory authority
-
Justification of decision: The decision on the appeal must be detailed and justified, explaining the reasons for upholding, changing, or annulling the original penalty.
-
Further appeal measures: In case of dissatisfaction with the appeal outcome, the entity may have the right to further appeal measures, including higher courts or European tribunals.
-
Appeal costs: The appealing entity usually bears the costs associated with the appeal process. However, in case of a positive appeal outcome, it may be possible to recover these costs.
-
Transparency of process: DORA requires that the appeal process be transparent. Information about appeal outcomes may be published, with appropriate confidentiality protection measures.
-
Impact on reputation: It is worth remembering that the very fact of appealing a penalty may impact the entity’s reputation. Therefore, it is important to carefully consider whether the appeal is justified and has a chance of success.
The right to appeal is a key element ensuring fairness and balance in the penalty imposition process under DORA. Entities covered by the regulation should be aware of this right and prepared to use it effectively if needed. At the same time, the best strategy is to strive for full compliance with DORA requirements to avoid situations where appealing imposed penalties would be necessary.
What are the consequences of not paying an imposed penalty?
Failure to pay a penalty imposed under the DORA regulation can lead to serious consequences for the entity. Supervisory authorities have a range of enforcement tools to ensure effective execution of imposed sanctions. Here are the key consequences that an entity that does not pay the imposed penalty must expect:
-
Additional financial penalties: Failure to pay the penalty within the specified deadline may result in the imposition of additional financial penalties, including late payment interest. This can significantly increase the total amount to be paid.
-
Forced execution: Supervisory authorities may initiate forced execution of the penalty. This may include seizure of the entity’s assets, blocking bank accounts, or other legal measures aimed at enforcing payment.
-
Suspension or revocation of license: In extreme cases, persistent evasion of penalty payment may lead to suspension or even revocation of the license to conduct business in the financial sector.
-
Public announcement of non-payment: Supervisory authorities may publicly announce information about the entity’s failure to pay the penalty. This can have serious reputational consequences and affect customer and business partner trust.
-
Personal liability of management: In some cases, liability for non-payment of the penalty may be extended to board members or senior management. This may lead to personal financial or professional sanctions.
-
Impact on credit rating: Failure to pay the penalty may negatively affect the entity’s credit rating, which may hinder access to financing and increase borrowing costs.
-
Additional audits and inspections: An entity that does not pay imposed penalties may be subjected to more frequent and rigorous audits and inspections by supervisory authorities.
-
Restrictions on activities: Supervisory authorities may impose restrictions on some aspects of the entity’s activities, for example, prohibit introducing new products or services until the penalty is settled.
-
Impact on relations with regulators: Failure to pay the penalty may significantly worsen the entity’s relations with supervisory authorities, which may have long-term negative consequences for the business.
-
Court proceedings: Ultimately, the matter of the unpaid penalty may go to court, which involves additional legal costs and potentially harsher sanctions.
-
Impact on corporate transactions: Unpaid penalties may constitute a significant obstacle in conducting corporate transactions such as mergers or acquisitions.
-
International consequences: In the case of entities operating in multiple jurisdictions, failure to pay a penalty in one country may have consequences for activities in other EU countries.
It is worth emphasizing that the consequences of not paying the penalty may be significantly more serious and costly than the penalty itself. Therefore, even if the entity does not agree with the imposed penalty, it is usually more cost-effective to pay it (subject to the right to appeal) than to expose oneself to additional sanctions and complications.
Entities covered by DORA should treat imposed penalties as a priority and settle them within the specified deadline if possible. In case of financial difficulties, it is worth considering negotiations with the supervisory authority regarding the possibility of spreading payment into installments or other forms of settlement.
Is information about imposed penalties made public?
Yes, the DORA regulation provides that information about imposed penalties is generally made public. This is an important element of transparency and is intended to increase the effectiveness of the deterrent effect of penalties. Here are the key aspects concerning public disclosure of penalty information:
-
Obligation to publish: Supervisory authorities are required to publish information about imposed penalties on their official websites. This information should be easily accessible and updated regularly.
-
Scope of published information: Published information typically includes:
-
Name of the entity or person on whom the penalty was imposed
-
Type and nature of the violation
-
Amount of the imposed penalty
-
Corrective actions taken
-
Publication deadline: Information about penalties should be published immediately after the penalty decision becomes final (i.e., after exhaustion of appeal measures or expiration of the appeal deadline).
-
Availability time of information: DORA requires that information about penalties remain publicly available for at least five years from the date of publication.
-
Anonymization: In certain circumstances, supervisory authorities may decide to publish penalty information in an anonymized manner, especially when disclosure of the entity’s identity could cause disproportionate harm.
-
Personal data protection: When publishing information about penalties imposed on natural persons, supervisory authorities must comply with personal data protection regulations, including GDPR.
-
Exceptions to publication obligation: In exceptional cases, publication of penalty information may be delayed or completely omitted if it could:
-
Threaten financial market stability
-
Harm an ongoing investigation
-
Cause disproportionate harm to the parties involved
-
Right to object: The entity on which the penalty was imposed has the right to object to publication of penalty information if it believes publication could cause disproportionate harm.
-
Information update: Supervisory authorities are required to update published information, for example, in case of successful appeal of the penalty or its modification.
-
Impact on reputation: Public disclosure of penalty information can have a significant impact on the entity’s reputation. This may lead to loss of customer, business partner, or investor trust.
-
Industry context: Publication of penalty information allows other entities in the sector to draw conclusions and take preventive actions in their organizations.
-
International reach: Due to the cross-border nature of many financial institutions, penalty information may impact the entity’s reputation and activities internationally.
Public disclosure of penalty information is an important tool in enforcing DORA provisions. On the one hand, it serves as a deterrent, motivating entities to comply with regulations. On the other hand, it ensures transparency of supervisory authorities’ actions and allows the public to assess the effectiveness of enforcement.
For entities covered by DORA, this means that violations may have consequences extending beyond financial penalties. The potential impact on reputation and stakeholder trust may be equally, if not more, severe than the penalty itself. Therefore, ensuring DORA compliance should be treated as a priority not only from a regulatory perspective but also as an element of reputational risk management.
How long must an entity expect the possibility of penalty after violation detection?
The issue of the period during which an entity may be held liable for a DORA violation is important from both a legal and operational perspective. The DORA regulation introduces certain time frames, but it is worth remembering that they may be interpreted in the context of national law of individual EU member states. Here are the key aspects concerning this issue:
-
Statute of limitations period: DORA introduces a general statute of limitations period for violations. It typically amounts to 5 years from the moment the supervisory authority detects the violation.
-
Start of statute of limitations: The statute of limitations period begins when the supervisory authority learns of the violation or has reasonable grounds to suspect that a violation has occurred.
-
Interruption of statute of limitations: The running of the statute of limitations may be interrupted by supervisory authority actions related to investigation or proceedings concerning the violation. After each such action, the statute of limitations period begins anew.
-
Maximum period: DORA establishes a maximum period after which a violation can no longer be prosecuted. This typically amounts to 10 years from the date of committing the violation, regardless of the moment of its detection.
-
Continuing violations: In the case of violations of a continuing or repeated nature, the statute of limitations period may be counted from the moment the violation ceases.
-
Differences in national law: EU member states may introduce longer statute of limitations periods in their national law, but cannot shorten them below the minimum specified in DORA.
-
Documentation and evidence: Entities should keep appropriate documentation and evidence of DORA compliance for a period exceeding the potential statute of limitations period to be able to defend themselves in case of possible charges.
-
Obligation to report violations: DORA imposes on entities an obligation to report certain types of violations. Failure to report a violation may be treated as a separate violation, with its own statute of limitations period.
-
Impact on business planning: A long period of potential liability means that entities must take into account the risk associated with DORA violations in their long-term financial and operational planning.
-
Organizational changes: In the case of mergers, acquisitions, or other significant organizational changes, liability for previous DORA violations may pass to the new entity.
-
International cooperation: In the case of entities operating in multiple jurisdictions, supervisory authorities may cooperate in prosecuting violations, which may affect practical aspects of statute of limitations.
-
Continuous improvement: A long period of potential liability emphasizes the importance of continuous monitoring and improvement of DORA-related processes, even if no violations have been detected.
The long period during which an entity must expect the possibility of penalty being imposed emphasizes the importance that the EU attaches to digital resilience issues in the financial sector. For entities covered by DORA, this means the need to maintain high standards of cybersecurity and ICT risk management for a long time, even if there are no direct signals of violations.
It is also worth noting that an active approach to DORA compliance, including regular audits, employee training, and system updates, may be viewed as a mitigating circumstance in case of possible proceedings, even if initiated many years after the alleged violation.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
Learn More
Explore related articles in our knowledge base:
- DORA vs. the FSA’s Recommendation D: How do past implementations help with compliance with the new regulation?
- What Are the Penalties for Non-Compliance with the NIS2 Directive? Guide to Consequences of Violating New Cybersecurity Regulations
- What Are the DORA Directive Requirements? Key Aspects of Digital Operational Resilience Regulation
- DORA: one year of application - how the regulation changed the financial sector
- DORA Regulation - Everything You Need to Know
Explore Our Services
Need cybersecurity support? Check out:
- DORA Compliance Audit - DORA regulation preparation
- Incident Response - rapid response to security incidents
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
Related topics
See also:
