Responsibility of companies for breaching EU rules | Legal and economic risks

Share

In recent years, European authorities have imposed fines worth billions of euros on companies of all sizes and sectors for regulatory non-compliance. The question is no longer whether your organization will be affected by the EU regulatory framework, but rather what is the responsibility of companies for breaching EU rules.

Ignorance or inaction is no longer an option. The European Union has accelerated its legislative output, creating a complex legal ecosystem with strict enforcement. This tightening represents a structural change in the way Europe conceives corporate responsibility, the protection of its citizens, and the integrity of its single market.

This regulatory framework obliges companies—from multinationals to small and medium-sized enterprises—to integrate EU compliance if they want to avoid fines, costly litigation, and severe reputational damage. The fines already imposed demonstrate that the EU not only legislates, but also actively enforces and sanctions operators who violate its rules. In this article, we will break down the regulations that are redefining corporate obligations, offering an overview of current risks and the best practices to ensure compliance.

The new european paradigm: why has risk increased for companies?

The exponential rise in risk for companies operating in or with the European Union is not a coincidence, but the result of fundamental changes in Brussels’ regulatory approach. Therefore, understanding these transformations is essential.

From recommendation to obligation: the era of regulations

For decades, much of European legislation was shaped through Directives. These rules set objectives that each Member State was required to “transpose” into its national law, which often resulted in a mosaic of 27 different interpretations, with varying levels of requirements and sanctions.

However, this model has now given way to the primacy of directly applicable Regulations. Rules such as the General Data Protection Regulation (GDPR) or the Artificial Intelligence Act (AI Act) have the force of law across the entire EU from the moment they enter into effect, without the need for national transposition.

As a result, this creates a unified framework with the same rules and a harmonized sanctioning regime coordinated by European authorities. For companies, this means less room for local interpretation and a much more direct and consistent exposure to risk throughout the single market.

Brussels effect” and EU jurisdiction

The regulatory power of the European Union is expanding more and more. The so-called “Brussels Effect” describes the extraterritorial reach of European legislation. If your company, based in the United States, Latin America, or Asia, offers goods or services to consumers in the EU, monitors the behavior of European citizens, or is part of the supply chain of a European company, it is highly likely that it falls under regulations such as the GDPR, the Digital Services Act (DSA), or sustainability directives.

This principle drastically expands the risk. European authorities can investigate and sanction foreign companies that breach EU rules, making compliance with EU legislation an indispensable requirement. Therefore, the responsibility of companies for breaching EU rules does not stop at Europe’s borders but extends globally.

The focus on comprehensive responsibility

The traditional vision of corporate responsibility, centered only on the quality and safety of the final product, has become obsolete. New generation of European regulations imposes a duty of due diligence that covers the entire corporate chain.

Regulations such as the Corporate Sustainability Reporting Directive (CSRD) and, in particular, the Corporate Sustainability Due Diligence Directive (CSDDD), oblige companies to actively identify, prevent, and mitigate the negative impacts of their operations—and those of their subsidiaries and suppliers—on human rights and the environment.

Consequently, responsibility is no longer limited to what a company does, but also includes what its business partners do. This shift requires greater transparency and traceability, elevating compliance to the level of supervising the entirety of operations. Ultimately, this evolution redefines the responsibility of companies for breaching EU rules, setting higher standards for corporate governance and accountability.

The principle of primacy of EU law establishes that European rules prevail over national provisions. This principle, consolidated by the Court of Justice of the European Union (CJEU), guarantees the uniformity and effectiveness of European law. Furthermore, it allows certain provisions of EU law to be directly invoked before national courts. A distinction is made between:

  • Vertical direct effect: individuals can require States to comply with European rules.
  • Horizontal direct effect: EU rules can create rights and obligations between private parties.

For companies, this duality implies the need for compliance programs that prevent risks both in relation to public authorities and third parties.

The CJEU case law has consolidated the concepts of primacy and direct effect. The Van Gend en Loos judgment (1963) recognized the direct effect of European rules vis-à-vis individuals, while the Costa/ENEL judgment (1964) established the supremacy of Community law over national law. For companies, this dual dimension reinforces the necessity of compliance programs designed to mitigate risks both against public institutions and private actors.

Horizontal direct effect and private claims

Horizontal direct effect is particularly relevant because it allows individuals to rely directly on EU provisions in private relationships, including relationships between citizens and companies. While traditionally direct effect was associated with the vertical dimension—namely, the possibility of invoking EU rules against Member States—its scope has gradually expanded toward the horizontal plane.

The CJEU has acknowledged that certain provisions that are sufficiently clear, precise, and unconditional may exert an indirect horizontal direct effect. An example can be found in the fields of labor rights and non-discrimination, where case law has consolidated the possibility for workers to invoke provisions of untransposed directives against their private employers. This obliges companies to adapt their internal policies in order to avoid sanctions.

Consequently, the private sector is compelled to comply with EU law, which requires constant monitoring of European case law, since private claims based on EU rules are increasingly frequent and have a direct impact on the civil, contractual, and regulatory responsibility of companies for breaching EU rules.

Risk areas | EU Regulations every company must monitor

Identifying the specific regulations that apply to a business is the first step toward effective risk management. The EU regulatory landscape is broad, but several areas stand out due to their cross-sector impact and their high sanctioning potential.

Data protection and privacy (GDPR)

Although the General Data Protection Regulation (GDPR) has been in force since 2018, many companies still underestimate its scope. The most well-known risk is the fines, which can reach up to €20 million or 4% of the company’s total global annual turnover. However, the true impact often lies in additional consequences such as:

  • Reputational damage: A data breach severely erodes customer trust.
  • Prohibition of data processing: Data protection authorities (DPAs) have the power to impose partial or total bans on a company’s data processing activities. In practice, this can mean the paralysis of marketing, sales, or even the company’s core business model.
  • Litigation and collective actions: The GDPR grants individuals the right to claim compensation for damages, opening the door to costly lawsuits and, increasingly, collective redress actions.

💡 Practical Example: The €1.2 billion fine imposed on Meta in 2023 for transferring European user data to the United States was a record-breaking sanction. In addition, the company was ordered to suspend such transfers, forcing it to restructure data processes—demonstrating the power of supervisory authorities beyond mere financial penalties.

Ultimately, these risks highlight that non-compliance is not limited to fines but extends directly to the responsibility of companies for breaching EU rules, reshaping corporate strategies and compliance priorities across industries.

The Digital Ecosystem (digital services act and digital markets act)

The EU’s Digital Services legislative package has created a new framework of responsibility for the online environment:

  • The Digital Services Act (DSA) imposes obligations of transparency and due diligence in content moderation, online advertising, and seller traceability on platforms. Its main objective is to combat disinformation and illegal content. Penalties for non-compliance can reach up to 6% of a company’s global annual turnover.
  • The Digital Markets Act (DMA) focuses on fairness and competition, imposing specific obligations and prohibitions on large online platforms designated as “gatekeepers.” Its goal is to prevent abuse of dominant position and ensure fairer digital markets. Here, fines can rise up to 10% of worldwide turnover—or even 20% in the case of repeated infringements.

💡 Who is affected? The DSA applies gradually to a wide range of intermediary services: internet access providers, hosting services, marketplaces, social networks, and all kinds of platforms that host third-party content.

If your company operates in the digital environment or works with influencers, it is essential to assess which obligations apply. Failing to do so could trigger severe regulatory consequences and reinforce the responsibility of companies for breaching EU rules in the digital ecosystem.

Sustainability and corporate reporting (CSRD and the EU Taxonomy)

Sustainability has become both a legal and financial obligation. The European Green Deal is driving a wave of legislation that conditions access to financing and to the market itself.

Corporate Sustainability Reporting Directive (CSRD) requires a much larger number of companies (including some non-European firms with substantial activity in the EU) to provide standardized and verified reporting on their environmental, social, and governance (ESG) impacts, risks, and opportunities. Emerging concept of greenwashing means that inaccurate, misleading, or unverified reporting may lead not only to regulatory sanctions but also to litigation from investors and consumers, as well as the loss of access to sustainable financing under the EU Taxonomy.

Moreover, the Corporate Sustainability Due Diligence Directive (CSDDD) will require large companies to identify, prevent, and mitigate adverse impacts on human rights and the environment not only in their own operations but also in those of their subsidiaries and across their entire value chain. This shifts compliance responsibility well beyond the company itself.

Competition and Antitrust

Competition law is the area most closely monitored by the European Commission. Anticompetitive practices are pursued rigorously, and the fines are significant. The main risks include:

  • Cartels: Secret agreements between competitors to fix prices, divide markets, or restrict production.
  • Abuse of dominant position: A company with a very high market share cannot use its power to drive out competitors or exploit consumers.

The Commission has repeatedly demonstrated its ability to impose multi-billion-euro fines in high-profile cases against companies across all sectors, ranging from technology to pharmaceuticals to the automotive industry. Recent practice shows record fines against tech companies for abuse of dominance in competition matters, hundreds of millions in penalties for serious GDPR infringements, and sanctions against financial entities for breaching regulations overseen by ESMA.

Ultimately, the responsibility of companies for breaching EU rules in regulated sectors or risk areas can be extremely high, although liability is by no means limited to these industries.

Administrative sanctions (types and examples)

The responsibility of companies for breaching EU rules is primarily manifested through administrative sanctions, imposed by the European Commission and sectoral agencies to ensure the effectiveness of EU law. These sanctions are not only punitive but also deterrent and corrective.

Types of Administrative Sanctions

The different types of fines can be broken down as follows:

  • Coercive fines: intended to force a company to end an unlawful practice, such as a cartel or abuse of dominant position.
  • Daily periodic penalty payments: imposed when a company fails to comply with a Commission decision, generating a continuous financial cost until full compliance is achieved.
  • Suspension or limitation of activity: particularly relevant in regulated sectors such as air transport, energy, or financial services, where infringements can pose systemic risks.
  • Prohibition from contracting with public administration: an increasingly common measure that temporarily bars sanctioned companies from participating in public tenders.

Recent Illustrative cases of the responsibility of companies for breaching EU rules

Google Shopping (antitrust)

The Commission imposed a fine of more than €2.4 billion for abuse of dominant position in the price comparison market. This case reflects the severity of competition law sanctions.

Meta/Facebook (GDPR)

Data protection authorities, under the GDPR framework, have imposed fines amounting to hundreds of millions of euros for unlawful processing of personal data.

Ryanair (passenger rights)

The airline has faced multiple sanctions for breaching EU rules on air passenger compensation and assistance, including temporary bans on operating certain routes.

Criteria for determining the amount of financial penalties

The amount of administrative sanctions is set based on objective and proportionate criteria, such as:

  • The seriousness and duration of the infringement.
  • The overall turnover of the company.
  • Whether the conduct was intentional or negligent.
  • The deterrent effect of the fine on the sector.

In addition, the Commission may impose fines of up to 10% of worldwide annual turnover, making non-compliance with EU rules a top-tier risk. Ultimately, administrative sanctions in the EU are a clear reminder that compliance is not optional but an essential obligation to ensure business continuity and competitiveness.

Beyond sanctions: The hidden costs of non-compliance

When discussing the responsibility of companies for breaching EU rules, the consequences of non-compliance go far beyond monetary fines. These are indirect yet long-lasting consequences that cut across reputation, operations, and the sustainability of the business.

Reputational damage and loss of trust

Damage to corporate reputation is one of the most severe effects of regulatory non-compliance. A public investigation for infringement of EU law can erode the trust of customers, investors, and business partners. Often, the cost of rebuilding brand credibility is higher and more enduring than the fine itself, directly affecting the company’s competitiveness in European markets.

Exclusion from public procurement and corporate contracts

Another major risk is exclusion from public tenders and corporate contracts. Increasingly, European institutions, national authorities, and large corporations require suppliers to provide compliance certifications and a clean regulatory record. A company sanctioned for breaching EU rules may be automatically disqualified from participating in strategic projects, losing large-scale business opportunities.

Litigation costs and internal resources

The costs of legal defense and internal resources also represent a significant economic burden. A regulatory investigation or an EU sanctioning procedure requires mobilizing substantial resources for legal defense and corporate restructuring. In addition, companies may face collective lawsuits resulting from the infringement, further increasing financial exposure and reputational damage.

Business interruption and process redesign

Regulatory breaches can also lead to cease-and-desist orders or mandatory modifications of business processes. Such measures result in immediate operational disruption, affecting sales, production, and supply chains. In regulated sectors such as energy, transport, or financial services, a forced redesign of processes may involve multimillion-euro investments and loss of market share to competitors.

Civil liability for breaching EU law

The responsibility of companies for breaching EU rules may also materialize through civil liability toward clients, competitors, or consumers.

Non-contractual liability toward third parties

Companies that fail to comply with obligations under EU law may be sued for damages. These lawsuits do not necessarily require a prior contractual relationship; it is sufficient that consumers, competitors, or other economic operators suffer direct harm as a result of the infringement.

The Francovich Doctrine and its current projection

The Francovich doctrine, developed by the CJEU, established that individuals have the right to claim compensation from a Member State when it fails to transpose an EU directive and causes harm. Although originally applied against States, the doctrine has inspired a growing trend in private litigation, where claims are filed directly against companies that benefit from regulatory breaches.

Collective actions under Directive 2020/1828

Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers has significantly expanded the scope of corporate civil liability. Consumer associations and qualified entities can now bring collective lawsuits for infringements of EU law, ranging from data protection to abusive practices in the digital market.

💡 An example can be found in collective actions stemming from GDPR breaches, where large technology platforms have faced joint lawsuits filed by thousands of users in multiple Member States.

Recent CJEU Case law imposing direct obligations on companies

Recently, the Court of Justice of the European Union (CJEU) has issued several landmark rulings that reinforce corporate obligations under EU law. These decisions have consolidated the immediate applicability of European norms and the responsibility of companies for breaching EU rules. Below are the most relevant cases and their practical impact:

Schrems II and the data privacy framework (International data transfers)

The Schrems II ruling (C-311/18) imposed on European companies the obligation to strengthen safeguards in the transfer of personal data. The CJEU stressed that compliance with the Data Privacy Framework must be strict, requiring companies to carry out transfer impact assessments and implement contractual clauses before transferring data outside the EU.

C-300/21 Facebook Ireland

The CJEU held that users are entitled to compensation for GDPR violations even without proving concrete economic damage, as long as they can demonstrate moral or psychological harm. This ruling significantly expands the scope of liability for technology companies and the private sector, multiplying the potential for both individual and collective litigation in cases of non-compliance.

Amazon Marketplace (Platform liability for illegal products)

The CJEU confirmed that digital platforms cannot be considered mere passive intermediaries when they actively participate in product distribution. Consequently, companies can be held directly liable for the commercialization of illegal or defective goods through their marketplaces. This jurisprudence reinforces the growing trend toward greater co-responsibility of online platforms, in line with the Digital Services Act (DSA).

Uber (service classification and employment obligations)

The Court reiterated that Uber is not merely an intermediary between drivers and users but must be classified as a transport service provider. This means that the company is subject to national and international regulations in areas such as labor law, taxation, and competition law—directly impacting its business model.

First judgments on the whistleblowing Directive and the CSDDD

The CJEU has confirmed that companies of a certain size and turnover must implement effective reporting channels, protection systems against retaliation, and due diligence mechanisms. This obliges companies to adapt their internal policies to demanding European standards.

Responsibility of companies for breaching European Union rules

Multilevel Compliance: European commission and national authorities

This concept refers to the coordination between the European Commission and national authorities, ensuring that companies comply both with supranational regulations and with the specific local provisions of each Member State. Among the most significant challenges are:

  • Coordination: EU institutions such as the European Commission oversee the enforcement of regulations and directives at the supranational level, while local authorities carry out inspections and procedures within their national territory. This dual enforcement system requires companies to establish effective internal mechanisms.
  • Risk of parallel investigations: Infringements in areas such as competition, data protection, or sustainability may trigger simultaneous proceedings in different Member States, multiplying exposure to sanctions and reputational risks.
  • Compliance strategies: Companies are advised to implement compliance programs that include audits, continuous training, and risk assessments. Moreover, proactive cooperation with authorities—both national and European—helps mitigate regulatory risks and demonstrates good faith.

To fully assess the responsibility of companies for breaching EU rules, we also carry out tailored legal analyses in European Union and International Law, allowing for comprehensive compliance that covers both supranational and national dimensions.

From 2026 onward, the European Union regulatory framework will continue to evolve, setting new standards of compliance and liability for companies across multiple sectors. Companies will need to adapt to stricter rules in artificial intelligence, sustainability, cybersecurity, and corporate governance. In this context, understanding the responsibility of companies for breaching EU rules will be crucial.

It is essential to have specialized legal advice to protect corporate reputation, minimize risks, and ensure compliance with new legal obligations. Our firm specializes in Regulatory Law, European Union Law, and Corporate Law.

Contact our compliance experts today by calling +32 465 345 345 or emailing info@arthurmarin.com.

💡 Protect and prepare your company for emerging regulatory trends, ensuring continuity in full compliance with European legislation.

Frequently Asked Questions (FAQ)

Which types of companies are affected by these EU regulations?

EU regulations affect all companies operating in the internal market, regardless of size or nationality. This includes SMEs and multinational corporations, as well as non-EU companies offering goods or services to European consumers. Sectors such as energy, transport, telecommunications, financial services, and digital are especially regulated, but no economic activity is exempt.

What is corporate criminal liability in the European context?

Corporate criminal liability means that a company can be sanctioned criminally—in addition to administratively—for certain unlawful acts. While each Member State regulates this differently, the EU promotes common standards in sensitive areas such as corruption, financial fraud, money laundering, and environmental crimes.

Can my company be fined in Europe even if it has no physical presence there?

Yes. Many EU rules have extraterritorial reach. For example, the General Data Protection Regulation (GDPR) applies to any company, inside or outside the EU, that processes personal data of European citizens. Similarly, competition rules allow for sanctions against foreign companies if their practices affect the internal market.

Where should I start if I want to implement a compliance program?

The first step is conducting a regulatory analysis to identify which EU regulations directly affect the company’s sector and activities. From there, it is recommended to:

  • Design internal policies and codes of conduct aligned with European law.
  • Provide training on compliance culture.
  • Establish internal whistleblowing channels in accordance with Directive (EU) 2019/1937.
  • Regularly audit and review procedures.

Which sectors are most exposed to EU sanctions?

Sectors such as technology, energy, transport, financial services, and telecommunications are particularly monitored by the European Commission and sectoral agencies. However, any company operating in the internal market must comply with EU law, regardless of size or sector.

What is the difference between administrative sanctions and civil liability in the EU?

Administrative sanctions are imposed by the European Commission or sectoral agencies (e.g., fines, cease-and-desist orders). Civil liability arises from claims by individuals or consumers, potentially leading to compensation payments.

Are subsidiaries also liable for breaches committed by the parent company?

Yes. The CJEU applies the “single economic entity” doctrine, which allows both the parent company and its subsidiaries to be jointly sanctioned when they operate as a single economic unit, even if the subsidiary did not directly participate in the infringement.

What reputational consequences can an EU sanction have?

Beyond the fine itself, sanctioned companies often appear in official announcements and media coverage, which can seriously undermine trust among customers and investors.

Can an SME be sanctioned as severely as a multinational?

Fines are calculated proportionally based on turnover. Although absolute amounts are smaller, the financial impact on an SME can be even more significant relative to its size.

How do EU sanctions interact with national sanctions?

EU sanctions do not exclude national sanctions. In some cases, companies may face double exposure: decisions by the European Commission and sanctions imposed by national authorities in competition, data protection, or financial markets.

What recent examples illustrate the responsibility of companies for breaching EU rules?

Notable examples include record fines imposed by the Commission on large tech companies for abuse of dominant position, hundreds of millions in penalties for GDPR violations, and cases involving market manipulation in financial sectors overseen by ESMA.

Latest posts

we talk?

Let´s work together

Contact us

info@arthurmarin.com

Call us

+32 465 34 53 45

Scroll to Top