GDPR administrative fines depend on the infringement, the statutory maximum and the circumstances assessed by the supervisory authority. A maximum is not an automatic penalty or an expected cost. This guide explains the two tiers, the assessment factors and the operational decisions that can reduce non-compliance.
This article breaks down the penalty framework, explains how to read enforcement examples, and outlines a concrete strategy for minimising your exposure.
How Are GDPR Fines Calculated?
The GDPR establishes two tiers of administrative fines in Articles 83 and 84 GDPR — see our detailed breakdown of the Article 83 fine structure and calculation.
The two-tier penalty structure
Lower tier – up to EUR 10 million or two percent of the organisation’s total worldwide annual turnover of the preceding financial year, whichever is higher. This tier applies to infringements of obligations on controllers and processors, including conditions for children’s consent, records of processing activities, and data protection by design.
Upper tier – up to EUR 20 million or four percent of worldwide annual turnover, whichever is higher. This tier covers the most serious violations: breaches of the core data privacy principles, infringements of data subject rights, and unlawful international data transfers.
These are maximum ceilings, not default amounts. The actual fine imposed depends on a range of factors that supervisory authorities must weigh in every individual case.
Factors that influence the fine amount. Article 83(2) lists the criteria that a supervisory authority must consider when setting a fine. These include:
- Nature, gravity, and duration of the infringement
- Intentional or negligent character of the violation
- Actions taken to mitigate the damage suffered by data subjects
- Degree of responsibility, considering the technical and organisational measures implemented under the accountability principle
- Previous infringements by the controller or processor
- Degree of cooperation with the supervisory authority
- Categories of personal data affected, with special categories attracting closer scrutiny
- How the authority became aware – whether through a complaint, audit, or the organisation’s own notification
The EDPB Guidelines on the calculation of administrative fines harmonise this process across EEA member states, introducing a methodology that supervisory authorities should follow to determine the starting amount, aggravating and mitigating factors, and the applicable legal maximum.
How Should Enforcement Examples Be Read?
A useful enforcement example connects the established facts to the specific obligations breached and the authority’s reasoning. Check whether the amount described is a proposed penalty, a final administrative decision or a result subsequently changed on appeal.
Landmark penalties
Enforcement examples must identify the decision date, infringed provisions, amount imposed and known procedural status. Distinguish GDPR fines from sanctions under national rules implementing ePrivacy: the CNIL’s Google cookie decision, for example, explains its Article 82 French Data Protection Act basis. Similar privacy subject matter does not make every penalty a GDPR Article 83 fine.
When comparing cases, use the actual decision and avoid aggregating unlike legal regimes or presenting an unverified tracker figure as a current enforcement statistic. The EDPB’s final fines guidelines provide a structured assessment method; they do not supply a universal average fine or a guaranteed mitigation percentage.
How Can Organisations Reduce Their Risk of GDPR Fines?
Preventing enforcement action requires a proactive, structured approach to compliance. The following measures address the most common triggers for GDPR fines.
Build a comprehensive compliance programme
A well-documented compliance programme is the strongest defence against significant penalties. Start with a thorough GDPR compliance checklist that covers every processing activity in your organisation. Ensure your records of processing are current, your legal bases are clearly documented, and your privacy notices are transparent and up to date.
Understanding the full scope of GDPR requirements is essential. Many fines stem not from deliberate misconduct but from incomplete implementation – organisations that address consent but neglect data retention, or that secure their databases but forget to document their processing activities.
Invest in consent, transparency, and impact assessments
A significant proportion of GDPR fines relate to consent and transparency failures. Ensure that your consent mechanisms meet the standard of valid GDPR consent: freely given, specific, informed, and unambiguous. Review your cookie banners, marketing opt-ins, and privacy policies regularly.
For high-risk processing activities, a data protection impact assessment (DPIA) is mandatory under Article 35 of the GDPR. Failing to carry out a required DPIA is itself a fineable offence. DPIAs also serve a practical purpose: they force you to identify and address risks before they materialise into breaches or complaints.
Prepare for data breaches and empower your DPO
A poorly managed data breach can escalate rapidly into a significant fine. Under the GDPR, controllers must notify without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Having a tested incident response plan is critical. Our guide on how to handle data breaches provides a step-by-step framework for building one.
Where required by the regulation, appointing a Data Protection Officer (DPO) is a legal obligation. Even where not strictly required, having a dedicated privacy function sends a strong signal of accountability and ensures that compliance is maintained continuously rather than treated as a one-off project.
FAQ
Can GDPR fines be appealed?
Yes. Organisations have the right to seek judicial remedy against a supervisory authority’s decision, including the amount of a fine. Appeals are heard by national courts in the member state where the authority is established. Several high-profile penalties have been subject to legal challenge, and in some cases appeals have resulted in reductions, though the process typically takes years to resolve.
Are GDPR fines the only consequence of non-compliance?
No. Beyond administrative fines, supervisory authorities can issue enforcement notices, temporary or permanent processing bans, and orders to erase data. Non-compliance can also lead to civil claims from affected data subjects, reputational damage, and loss of business relationships. The financial exposure from class-action litigation and customer churn can exceed the fine itself.
Do GDPR fines apply to small businesses?
Yes. Small size is not a general exemption from GDPR; first assess whether the processing falls within its material and territorial scope. While supervisory authorities consider the financial capacity of the organisation when setting a penalty, small businesses are not exempt. National regulators have sanctioned SMEs for violations such as missing privacy notices, non-compliant CCTV systems, and failure to respond to access requests within the statutory timeframe. Maintaining a solid compliance programme is therefore essential for organisations of every scale.
Conclusion
GDPR fines are a central pillar of the regulation’s enforcement architecture. They are designed to be dissuasive, proportionate, and effective. With cumulative penalties running into the billions and individual fines reaching record-breaking levels, the financial stakes are significant for organisations of every size.
The most reliable way to avoid GDPR fines is to treat compliance as a continuous operational function rather than a one-time project. Map your data, document your legal bases, invest in consent infrastructure, conduct impact assessments, prepare for breaches, and empower your data protection team. Each of these steps directly addresses the factors that supervisory authorities weigh when deciding whether to impose a fine and how to set its amount.