Skip to content

GDPR Fines Explained: Amounts, Tiers and How They Are Set

GDPR fines have two statutory ceilings, but the final amount depends on the infringement, turnover and the authority's case-by-case assessment.

A late-lit accountancy-office diorama follows a deep-olive folder through gates and weighing trays beneath HOW A GDPR FINE IS SET, with signs for TWO CEILINGS, GRAVEST INFRINGEMENT CAPS and ELEVEN WEIGHING FACTORS.
By AI Priority Map Editorial

Quick Answer: GDPR fines have two ceilings: €10 million or 2% of worldwide annual turnover, and €20 million or 4%, whichever figure is higher. The relevant infringement selects the tier. A supervisory authority then decides whether to fine and how much by weighing the case-specific factors in Article 83.1

Summary in a mind map

GDPR Fines Explained: Amounts, Tiers and How They Are Set
│
├─ Select the ceiling
│   ├─ Lower tier: €10 million or 2% turnover
│   ├─ Higher tier: €20 million or 4% turnover
│   └─ The higher fixed or percentage figure wins
│
├─ Weigh the case
│   ├─ Gravity, duration, intention and affected people
│   ├─ Mitigation, cooperation and data categories matter
│   └─ The factors guide judgement, not a points score
│
├─ Cap linked failures
│   ├─ Identify the same or linked processing operations
│   ├─ Find the gravest infringement in that conduct
│   └─ Keep the total within its maximum
│
├─ Consider other powers
│   ├─ Warnings, reprimands and orders can apply
│   ├─ Processing restrictions may have direct impact
│   └─ Public-body fines depend on Member State rules
│
└─ Separate people’s claims
    ├─ Individuals may complain to a data authority
    ├─ Compensation concerns damage they suffered
    └─ Administrative fines do not become compensation

Two ceilings apply to different duties

The GDPR does not set one universal fine amount. Article 83 divides infringements between two maximum levels, with the higher tier reserved for failures involving central protections.1

TierMaximum for an undertakingExamples named in Article 83
Lower, Article 83(4)€10,000,000 or 2% of total worldwide annual turnover in the preceding financial year, whichever is higherController and processor obligations covered by Articles 8, 11, 25–39, 42 and 43; certification-body and monitoring-body obligations
Higher, Article 83(5)€20,000,000 or 4% of total worldwide annual turnover in the preceding financial year, whichever is higherBasic processing principles, data-subject rights, transfers to a third country or international organisation, specified Member State-law obligations, and non-compliance with an authority's order

The table states ceilings, not a tariff. An infringement in the lower tier does not automatically attract €10,000,000 or 2%. It tells the supervisory authority the upper boundary before the authority determines an effective, proportionate and dissuasive fine for the individual case.1

The distinction also prevents a simple ranking by operational inconvenience. A failure concerning records or security duties may sit in Article 83(4), while an unlawful processing principle or interference with a person's rights may enter Article 83(5). The breached provision determines the tier.

The higher of the two figures wins

For an undertaking, the percentage is not an alternative that automatically replaces the fixed euro figure. Article 83 says “whichever is higher”. The authority compares the two possible ceilings within the applicable tier.1

For example, if an undertaking's preceding-year worldwide turnover is €800 million, 2% is €16 million. For a lower-tier infringement, €16 million is higher than the fixed €10 million figure, so €16 million is the statutory ceiling. The same comparison applies between €20 million and 4% at the higher tier.1

The percentage uses total worldwide annual turnover of the preceding financial year. It is not described as the turnover of the affected product, the local office or the processing activity alone. Article 83 applies the turnover limb “in the case of an undertaking”, so the legal characterisation of the undertaking matters before the calculation can be completed.1

Neither result predicts the actual fine. A ceiling marks the greatest amount available under that tier. Article 83(1) still requires the fine imposed to be effective, proportionate and dissuasive in each individual case.1

The authority weighs the whole case

A supervisory authority must first consider whether to impose a fine and then determine the amount. Article 83(2) gives a case-specific list of matters that must receive due regard.1

Weighing factorWhat the authority examines
Nature, gravity and durationThe character, seriousness and length of the infringement
Scope and purposeThe processing concerned and its purpose
People and damageThe number of affected data subjects and damage suffered
Intention or negligenceWhether the conduct was deliberate or careless
MitigationAction taken to reduce damage to data subjects
ResponsibilityThe controller's or processor's responsibility, including measures under Articles 25 and 32
Previous infringementsRelevant history involving the controller or processor
CooperationThe degree of cooperation with the supervisory authority
Data categoriesThe types of personal data affected
How the issue became knownWhether and how the organisation notified the infringement
Other circumstancesCorrective measures, certification factors, financial benefit or avoided loss, where relevant

These factors explain why a headline maximum and a final decision are different. A short, negligent incident followed by effective mitigation presents different facts from prolonged intentional processing that affects many people and causes substantial damage. The table is not a points calculator. Article 83 requires due regard, not a mechanical score.1

Cooperation can therefore matter without erasing the infringement. Mitigation can reduce harm without proving the original processing was lawful. Conversely, a lack of financial gain does not remove the authority's duty to consider the other factors.

Linked infringements meet one gravest-infringement cap

One incident can break several GDPR duties, but Article 83(3) prevents a simple multiplication of maximums for the same or linked processing operations. Where a controller or processor intentionally or negligently infringes several provisions, the total administrative fine must not exceed the amount specified for the gravest infringement.1

The rule caps the total; it does not erase the other infringements. The authority may identify several failures, decide which is gravest and consider the combined conduct when applying Article 83(2). The maximum available for the gravest infringement remains the boundary.1

“Same or linked processing operations” is an important condition. Separate conduct cannot be assumed to fall under Article 83(3) merely because it involves the same organisation. The facts must show the relationship between the operations before the single-cap rule is applied.

The practical lesson is to map the processing behind an incident. An organisation should identify the operation, the duties engaged and whether failures arose from one connected course of conduct. An AI order-processing workflow can be a connected operation: one faulty step may cause several linked failures across its inputs, decisions and handoffs. A label such as “one breach” does not perform that analysis.

The organisation must also identify its role in that operation. The controller or processor guide explains why responsibility follows the decisions and instructions in the processing relationship rather than a convenient label.

Corrective action can be serious without a fine

A fine is one of several regulatory outcomes. Article 83(2) frames the question as whether a fine should be imposed in addition to, or instead of, measures under Article 58(2), depending on the circumstances.1

Article 58(2) allows supervisory authorities to issue warnings and reprimands, order compliance with data-subject requests, order processing to comply, require communication of a personal data breach, impose temporary or definitive processing limitations including a ban, order rectification or erasure, withdraw certification, suspend data flows and impose administrative fines.1

An order or restriction can have a direct operational effect even when no administrative fine follows. A processing ban may stop the relevant activity. An erasure order may require changes to live records. A reprimand creates a formal regulatory outcome. Financial impact is therefore not the sole measure of severity.

For teams using AI, the relationship between AI governance, UK GDPR and the EU AI Act helps separate overlapping duties before an incident turns into enforcement. Each instrument still has its own scope and remedies.

Public authorities also require national context. Article 83(7) lets each Member State set rules on whether, and to what extent, administrative fines may be imposed on public authorities and bodies established in that Member State.1 A general EU article cannot replace that country-specific rule.

The final amount belongs to the individual case

The competent supervisory authority makes the enforcement decision. EDPB Guidelines 04/2022 give authorities a five-step method: identify the processing operations and apply Article 83(3); find the starting point; evaluate aggravating and mitigating circumstances; identify the legal maximum; and test whether the final amount is effective, dissuasive and proportionate.3

The authority sets the starting amount from the Article 83 tier, the seriousness of the infringement and the undertaking's turnover. The Guidelines place a low-seriousness starting amount between 0% and 10% of the applicable legal maximum, medium seriousness between 10% and 20%, and high seriousness between 20% and 100%.3 These ranges guide the calculation; they do not turn the final amount into a fixed tariff.

Two apparently similar cases may differ in duration, affected people, damage, intention, mitigation, cooperation, data categories or previous infringements. They may also involve undertakings with different worldwide turnover. Each difference can change the authority's assessment even when a short description of the incidents sounds alike.

A published fine therefore cannot be treated as a price list for future cases. It may help illustrate how an authority approached one factual record, but Article 83 demands an individual assessment. Organisations should focus on the underlying duties and evidence rather than estimating a tolerable penalty.

People may complain and claim compensation

An administrative fine does not replace the routes available to affected people. An individual has the right to lodge a complaint with a data protection authority in the EEA Member State where the person habitually resides, works or considers that personal-data rights were not respected.2

The individual may also be entitled to compensation for damage suffered.2 Compensation and an administrative fine are different. The authority imposes a fine to enforce the GDPR. A compensation claim concerns damage to the individual. The amount of a fine is not distributed to affected people as their damages award.

These routes can exist alongside regulatory corrective action. A person may complain; the authority may investigate and use its powers; and a compensation question may be pursued separately. Each route has its own decision-maker and purpose.

What this article cannot decide

The statutory tier cannot be selected without identifying the exact provision infringed. The maximum cannot be calculated without the facts needed for the fixed-versus-turnover comparison. The final amount cannot be predicted without the authority's assessment of Article 83(2).

This article also cannot state whether a public authority can be fined in a particular Member State, because Article 83(7) leaves that question to national rules.1 Nor can it determine compensation, which depends on the individual's claim and damage rather than the administrative-fine ceiling.

National rules also matter before enforcement. For example, the UK-specific analysis of emailing businesses without consent cannot be treated as an EU-wide answer; the applicable jurisdiction and processing rule must be established first.

What to do next

Record the processing operation, each potentially infringed provision, the applicable tier and the facts relevant to Article 83(2). Keep the ceiling separate from any estimate of outcome. If several provisions are involved, document why the operations are the same or linked and which infringement may be the gravest. Obtain jurisdiction-specific legal advice for an actual enforcement matter.

Frequently asked questions

What are the two maximum levels for GDPR fines?

Article 83 creates a lower ceiling of €10,000,000 or 2% of an undertaking's preceding-year worldwide annual turnover, whichever is higher, and a higher ceiling of €20,000,000 or 4%, whichever is higher. The applicable tier depends on the duty infringed. These figures are ceilings, not standard prices for a breach.

Does the euro amount or turnover percentage apply?

The higher result applies for an undertaking. At the lower tier, compare €10,000,000 with 2% of total worldwide annual turnover in the preceding financial year. At the higher tier, compare €20,000,000 with 4%. The winning figure sets the statutory maximum; it does not determine the amount actually imposed.

Does breaking several GDPR rules mean several maximum fines?

Not for the same or linked processing operations in the situation governed by Article 83(3). Where a controller or processor intentionally or negligently infringes several provisions, the total administrative fine must not exceed the amount specified for the gravest infringement. The authority still evaluates the conduct and relevant circumstances of the case.

Must a supervisory authority impose a fine for every infringement?

No. Article 83(2) requires the authority to consider whether an administrative fine should be imposed as well as its amount. Article 58 provides corrective powers such as warnings, reprimands, orders and processing restrictions. Any fine that is imposed must be effective, proportionate and dissuasive in the individual case.

Why can similar GDPR cases produce different fine amounts?

A supervisory authority uses the EDPB's five-step methodology as applicable and assesses each case individually. It sets a starting amount from the tier, seriousness and undertaking's turnover, then considers aggravating and mitigating circumstances. Differences in those facts, the applicable ceiling and turnover can therefore lead to different final amounts.

Can an affected person receive the GDPR fine?

No. An administrative fine is imposed by a supervisory authority; it is not paid to the affected person as compensation. Separately, an individual may complain to a data protection authority in the relevant EEA location and may claim compensation for damage suffered. The complaint, fine and compensation routes serve different purposes.

Frequently Asked Questions

What are the two maximum levels for GDPR fines?
Article 83 creates a lower ceiling of €10,000,000 or 2% of an undertaking's preceding-year worldwide annual turnover, whichever is higher, and a higher ceiling of €20,000,000 or 4%, whichever is higher. The applicable tier depends on the duty infringed. These figures are ceilings, not standard prices for a breach.
Does the euro amount or turnover percentage apply?
The higher result applies for an undertaking. At the lower tier, compare €10,000,000 with 2% of total worldwide annual turnover in the preceding financial year. At the higher tier, compare €20,000,000 with 4%. The winning figure sets the statutory maximum; it does not determine the amount actually imposed.
Does breaking several GDPR rules mean several maximum fines?
Not for the same or linked processing operations in the situation governed by Article 83(3). Where a controller or processor intentionally or negligently infringes several provisions, the total administrative fine must not exceed the amount specified for the gravest infringement. The authority still evaluates the conduct and relevant circumstances of the case.
Must a supervisory authority impose a fine for every infringement?
No. Article 83(2) requires the authority to consider whether an administrative fine should be imposed as well as its amount. Article 58 provides corrective powers such as warnings, reprimands, orders and processing restrictions. Any fine that is imposed must be effective, proportionate and dissuasive in the individual case.
Why can similar GDPR cases produce different fine amounts?
A supervisory authority uses the EDPB's five-step methodology as applicable and assesses each case individually. It sets a starting amount from the tier, seriousness and undertaking's turnover, then considers aggravating and mitigating circumstances. Differences in those facts, the applicable ceiling and turnover can therefore lead to different final amounts.
Can an affected person receive the GDPR fine?
No. An administrative fine is imposed by a supervisory authority; it is not paid to the affected person as compensation. Separately, an individual may complain to a data protection authority in the relevant EEA location and may claim compensation for damage suffered. The complaint, fine and compensation routes serve different purposes.

Sources

  1. 1.Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex · 2016
  2. 2.Steps individuals can take against youEDPB · 2024
  3. 3.Guidelines 04/2022 on the calculation of administrative fines under the GDPREDPB · 2023

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.