Back to GDPR

GDPR Fines: Tiers, Calculation, and the Largest Penalties

GDPR Fines: Tiers, Calculation, and the Largest Penalties Photo: Unsplash

GDPR fines are the part of the regulation that makes headlines, with penalties now reaching hundreds of millions of euros for the largest companies. But fines are only one of the tools regulators use, and most enforcement actions against smaller companies look very different from the famous cases. This guide explains how GDPR fines are structured, how regulators calculate them, the largest fines to date, and what companies can do to reduce their exposure.

Key takeaways

  • There are two tiers. Up to €10 million or 2% of worldwide annual turnover, and up to €20 million or 4% of worldwide annual turnover, whichever is higher in each tier.
  • Fines are decided case by case. Article 83 lists factors such as the nature, gravity, and duration of the infringement, intent or negligence, mitigation, and cooperation with the regulator.
  • Fines are not the only consequence. Regulators can order processing to stop, require corrective action, or ban data transfers, and people can claim compensation under Article 82.
  • The largest fines involve big tech, often over international data transfers, lawful basis for processing, and children's data.
  • Most exposure comes from basics, such as missing lawful basis, weak security, late breach notification, and ignoring data subject requests.

How GDPR fines are structured

Article 83 of GDPR sets two maximum levels:

Tier Maximum fine Examples of infringements
Lower tier Up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher Controller and processor obligations such as records of processing, security of processing, breach notification, DPIAs, DPO requirements, and processor contracts
Upper tier Up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher The basic principles of processing, lawful basis and consent, data subject rights, international transfers, and failing to comply with a regulator's order

For companies that are part of a group, turnover is generally assessed at the level of the undertaking, which can mean the whole corporate group.

The UK GDPR follows the same structure, with maximums of £8.7 million or 2% and £17.5 million or 4%.

How regulators decide the amount

Supervisory authorities must make each fine "effective, proportionate and dissuasive". Article 83(2) lists the factors they weigh, including:

  • The nature, gravity, and duration of the infringement, and the number of people affected
  • Whether it was intentional or negligent
  • Actions taken to mitigate the damage
  • The degree of responsibility, considering the technical and organizational measures in place
  • Previous infringements
  • Cooperation with the supervisory authority
  • The categories of personal data affected, especially special category data
  • How the authority learned of the infringement, including whether the company reported it
  • Adherence to approved codes of conduct or certification mechanisms
  • Any financial benefit gained or losses avoided

The European Data Protection Board has published guidelines on calculating fines to make the approach more consistent across member states.

Other enforcement powers

Under Article 58, regulators can also:

  • Issue warnings and reprimands
  • Order a company to bring processing into compliance, or to satisfy data subject requests
  • Impose a temporary or permanent ban on processing
  • Order the suspension of data flows to a third country
  • Order the rectification or erasure of data

For many companies, a processing ban or an order to stop transfers is more disruptive than a fine. Separately, Article 82 gives individuals the right to claim compensation for damage caused by infringements, and representative actions can bundle many claims together.

Some of the largest GDPR fines

Company Fine Year Authority Main issue
Meta Platforms Ireland €1.2 billion 2023 Irish Data Protection Commission Transfers of EU user data to the US
Amazon Europe €746 million 2021 Luxembourg CNPD Processing for targeted advertising
TikTok €530 million 2025 Irish Data Protection Commission Transfers of EU user data to China and transparency
Instagram (Meta) €405 million 2022 Irish Data Protection Commission Processing of children's data
LinkedIn €310 million 2024 Irish Data Protection Commission Lawful basis for behavioral analysis and targeted advertising
Uber €290 million 2024 Dutch Data Protection Authority Transfers of driver data to the US

Many of these decisions have been appealed, and amounts can change on appeal. The pattern is clear, though: international transfers, lawful basis for advertising, and children's data draw the largest penalties.

What smaller companies are actually fined for

Enforcement against small and midsize companies usually involves fines in the thousands to hundreds of thousands of euros, for issues such as:

  • Insufficient security, such as unencrypted data, weak access controls, or unpatched systems that led to a breach
  • Late or missing breach notification to the regulator within 72 hours
  • Ignoring data subject requests, especially access and deletion requests
  • No lawful basis for marketing emails or tracking, including cookies set without valid consent
  • Excessive retention of personal data with no defined deletion period
  • Missing processor agreements with vendors that handle personal data
  • Unlawful CCTV or employee monitoring

How to reduce your exposure

  1. Know your data. Maintain records of processing so you know what you hold, why, and where it goes.
  2. Document a lawful basis for every processing purpose, and get valid consent where consent is the basis.
  3. Secure personal data with access control, encryption, logging, and regular testing proportionate to the risk.
  4. Prepare for breaches. Have a tested process to assess incidents and notify the regulator within 72 hours when required.
  5. Handle data subject requests on time, usually within one month.
  6. Put processor agreements in place with customers and subprocessors, and a valid mechanism for international transfers.
  7. Run DPIAs before starting high-risk processing.
  8. Cooperate and self-report. Regulators treat cooperation and prompt notification as mitigating factors.

For what building a compliance program costs, see GDPR compliance cost. For a full plan, see our GDPR compliance checklist.

How SecureSlate helps

SecureSlate's GDPR program combines compliance software with a dedicated compliance lead for one fixed price:

  • Your compliance lead maps your personal data, builds your records of processing, runs DPIAs, and puts processor agreements in place.
  • The platform keeps security evidence current, so you can show the technical and organizational measures regulators look for.
  • Security controls are shared with SOC 2 and ISO 27001, so you build them once.

FAQ

What is the maximum GDPR fine?

The maximum is €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. It applies to infringements such as violating the basic processing principles, data subject rights, or international transfer rules.

Who issues GDPR fines?

National supervisory authorities in each EU member state, such as the Irish Data Protection Commission or France's CNIL. For cross-border processing, the lead authority is usually the one where the company has its main EU establishment, with other authorities involved through the EDPB's cooperation process.

Do small businesses get GDPR fines?

Yes, although fines against small businesses are usually far smaller than the headline cases. Regulators also often use warnings, reprimands, and corrective orders for smaller organizations, especially first-time infringements.

What is the largest GDPR fine ever?

The largest to date is the €1.2 billion fine against Meta Platforms Ireland in 2023, issued by the Irish Data Protection Commission over transfers of EU user data to the United States.

Can GDPR fines be appealed?

Yes. Companies can challenge decisions in the national courts of the member state that issued them, and several large fines have been appealed or reduced.

Disclaimer (legal note)

This article is for general information only and is not legal advice. Fine amounts and case outcomes may change on appeal. GDPR obligations depend on your specific processing activities. Consult qualified legal counsel for your situation.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.8(252 reviews)

Keep reading

Sep 29, 2026 · GDPR

Australian Privacy Principles for Small Business: Does the Privacy Act Apply to You?

Jun 25, 2026 · GDPR

Data Privacy Week

Jun 25, 2026 · GDPR

GDPR Certification

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?