- The nature, severity and duration of the infringement, taking into account the nature, scope or purpose of the processing in question, the number of persons affected and the extent of the damage suffered by them.
- The deliberate or careless nature of the infringement.
- The measures taken by the controller or the processor to limit the damage to the data subjects involved.
- The extent to which the controller or the processor is responsible, considering the technical and organizational measures that had to be taken under articles 25 and 32 of the GDPR.
- Previous infringements, where relevant, by the controller or the processor.
- The level of cooperation with the Dutch DPA to remedy the infringement and reduce the possible, negative consequences of it.
- The categories of personal data affected by the infringement.
- The manner in which the Dutch DPA has been notified of the infringement and whether the controller or the processor has reported the infringement.
- In how far the controller or the processor has complied with any previous measures imposed by the Dutch DPA, as referred to in article 58 (2) of the GDPR.
- Compliance with approved codes of conduct in accordance with article 40 of the GDPR or with approved certification mechanisms referred to in article 42 of the GDPR.
- Any other circumstances that may be regarded as aggravating or mitigating factors, such as financial gains realised, or losses avoided, whether or not directly arising from the infringement.