Photo: Unsplash
GDPR fines are the part of the regulation that makes headlines, with penalties now reaching hundreds of millions of euros for the largest companies. But fines are only one of the tools regulators use, and most enforcement actions against smaller companies look very different from the famous cases. This guide explains how GDPR fines are structured, how regulators calculate them, the largest fines to date, and what companies can do to reduce their exposure.
Key takeaways
- There are two tiers. Up to €10 million or 2% of worldwide annual turnover, and up to €20 million or 4% of worldwide annual turnover, whichever is higher in each tier.
- Fines are decided case by case. Article 83 lists factors such as the nature, gravity, and duration of the infringement, intent or negligence, mitigation, and cooperation with the regulator.
- Fines are not the only consequence. Regulators can order processing to stop, require corrective action, or ban data transfers, and people can claim compensation under Article 82.
- The largest fines involve big tech, often over international data transfers, lawful basis for processing, and children's data.
- Most exposure comes from basics, such as missing lawful basis, weak security, late breach notification, and ignoring data subject requests.
How GDPR fines are structured
Article 83 of GDPR sets two maximum levels:
| Tier | Maximum fine | Examples of infringements |
|---|---|---|
| Lower tier | Up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher | Controller and processor obligations such as records of processing, security of processing, breach notification, DPIAs, DPO requirements, and processor contracts |
| Upper tier | Up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher | The basic principles of processing, lawful basis and consent, data subject rights, international transfers, and failing to comply with a regulator's order |
For companies that are part of a group, turnover is generally assessed at the level of the undertaking, which can mean the whole corporate group.
The UK GDPR follows the same structure, with maximums of £8.7 million or 2% and £17.5 million or 4%.
How regulators decide the amount
Supervisory authorities must make each fine "effective, proportionate and dissuasive". Article 83(2) lists the factors they weigh, including:
- The nature, gravity, and duration of the infringement, and the number of people affected
- Whether it was intentional or negligent
- Actions taken to mitigate the damage
- The degree of responsibility, considering the technical and organizational measures in place
- Previous infringements
- Cooperation with the supervisory authority
- The categories of personal data affected, especially special category data
- How the authority learned of the infringement, including whether the company reported it
- Adherence to approved codes of conduct or certification mechanisms
- Any financial benefit gained or losses avoided
The European Data Protection Board has published guidelines on calculating fines to make the approach more consistent across member states.
Other enforcement powers
Under Article 58, regulators can also:
- Issue warnings and reprimands
- Order a company to bring processing into compliance, or to satisfy data subject requests
- Impose a temporary or permanent ban on processing
- Order the suspension of data flows to a third country
- Order the rectification or erasure of data
For many companies, a processing ban or an order to stop transfers is more disruptive than a fine. Separately, Article 82 gives individuals the right to claim compensation for damage caused by infringements, and representative actions can bundle many claims together.
Some of the largest GDPR fines
| Company | Fine | Year | Authority | Main issue |
|---|---|---|---|---|
| Meta Platforms Ireland | €1.2 billion | 2023 | Irish Data Protection Commission | Transfers of EU user data to the US |
| Amazon Europe | €746 million | 2021 | Luxembourg CNPD | Processing for targeted advertising |
| TikTok | €530 million | 2025 | Irish Data Protection Commission | Transfers of EU user data to China and transparency |
| Instagram (Meta) | €405 million | 2022 | Irish Data Protection Commission | Processing of children's data |
| €310 million | 2024 | Irish Data Protection Commission | Lawful basis for behavioral analysis and targeted advertising | |
| Uber | €290 million | 2024 | Dutch Data Protection Authority | Transfers of driver data to the US |
Many of these decisions have been appealed, and amounts can change on appeal. The pattern is clear, though: international transfers, lawful basis for advertising, and children's data draw the largest penalties.
What smaller companies are actually fined for
Enforcement against small and midsize companies usually involves fines in the thousands to hundreds of thousands of euros, for issues such as:
- Insufficient security, such as unencrypted data, weak access controls, or unpatched systems that led to a breach
- Late or missing breach notification to the regulator within 72 hours
- Ignoring data subject requests, especially access and deletion requests
- No lawful basis for marketing emails or tracking, including cookies set without valid consent
- Excessive retention of personal data with no defined deletion period
- Missing processor agreements with vendors that handle personal data
- Unlawful CCTV or employee monitoring
How to reduce your exposure
- Know your data. Maintain records of processing so you know what you hold, why, and where it goes.
- Document a lawful basis for every processing purpose, and get valid consent where consent is the basis.
- Secure personal data with access control, encryption, logging, and regular testing proportionate to the risk.
- Prepare for breaches. Have a tested process to assess incidents and notify the regulator within 72 hours when required.
- Handle data subject requests on time, usually within one month.
- Put processor agreements in place with customers and subprocessors, and a valid mechanism for international transfers.
- Run DPIAs before starting high-risk processing.
- Cooperate and self-report. Regulators treat cooperation and prompt notification as mitigating factors.
For what building a compliance program costs, see GDPR compliance cost. For a full plan, see our GDPR compliance checklist.
How SecureSlate helps
SecureSlate's GDPR program combines compliance software with a dedicated compliance lead for one fixed price:
- Your compliance lead maps your personal data, builds your records of processing, runs DPIAs, and puts processor agreements in place.
- The platform keeps security evidence current, so you can show the technical and organizational measures regulators look for.
- Security controls are shared with SOC 2 and ISO 27001, so you build them once.
FAQ
What is the maximum GDPR fine?
The maximum is €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. It applies to infringements such as violating the basic processing principles, data subject rights, or international transfer rules.
Who issues GDPR fines?
National supervisory authorities in each EU member state, such as the Irish Data Protection Commission or France's CNIL. For cross-border processing, the lead authority is usually the one where the company has its main EU establishment, with other authorities involved through the EDPB's cooperation process.
Do small businesses get GDPR fines?
Yes, although fines against small businesses are usually far smaller than the headline cases. Regulators also often use warnings, reprimands, and corrective orders for smaller organizations, especially first-time infringements.
What is the largest GDPR fine ever?
The largest to date is the €1.2 billion fine against Meta Platforms Ireland in 2023, issued by the Irish Data Protection Commission over transfers of EU user data to the United States.
Can GDPR fines be appealed?
Yes. Companies can challenge decisions in the national courts of the member state that issued them, and several large fines have been appealed or reduced.
Disclaimer (legal note)
This article is for general information only and is not legal advice. Fine amounts and case outcomes may change on appeal. GDPR obligations depend on your specific processing activities. Consult qualified legal counsel for your situation.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
