Skip to content

Sanctions & Liability

Sanctions Regime

DORA (Art. 50–52) and FinmadiG provide for a graduated sanctions regime. DORA delegates the determination of specific sanction amounts to Member States – the following figures refer to the German implementation (FinmadiG).

Against Financial Entities (Art. 50–52 DORA, FinmadiG)

SanctionDetails
FinesEffective, proportionate and dissuasive (Art. 50(3) DORA); specific amounts per FinmadiG
Periodic penalty paymentsUp to EUR 2.5 million (FinmadiG)
Appointment of special commissionerBaFin may appoint a special commissioner
Business restrictionsRestriction or prohibition of business activities
Contract termination requirementBaFin may require termination of service provider relationships
Personal liabilityManagement personally liable for material deficiencies
Removal from officeRemoval of management members possible

Against Critical ICT Third-Party Service Providers (CTPPs, Art. 35(8) DORA)

SanctionDetails
Periodic penalty paymentsUp to 1% of average global daily turnover – per day (Art. 35(8))
Lead Overseer recommendationsBinding requests for action
Public disclosurePublication of violations
Last resortFinancial entities may be required to cease use

Against ICT Service Providers (non-CTPP)

Non-critical ICT service providers like BAUER GROUP are not subject to direct DORA sanctions. The consequences are indirect:

RiskImpact
Contract terminationFinancial entities can/must terminate contracts
ExclusionFinancial entities may not enter contracts with non-compliant providers (Art. 28(5))
Reputational damageAudit findings become known to the market
LiabilityCivil damages claims for breach of duty

Practical Liability Scenarios for BAUER GROUP

ScenarioConsequencePrevention
Incident not reported to client within 1hClient cannot meet DORA reporting deadline (4h) → fineAutomated incident pipeline
No audit access grantedBreach of contract → termination + damagesEnsure audit readiness
Subcontracting without approvalViolation of Art. 30, RTS 2025/532 → contractual penaltyImplement approval process
Data loss without exit strategyClient cannot migrate → damagesDocument exit strategy
Missing certification evidenceClient loses compliance → both affectedMaintain annual certification

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT