GDPR has two fine tiers, set by Article 83.
Lower tier: up to €10 million or 2% of global annual turnover, whichever is higher — for administrative failures such as poor records, missing DPO, or failing to notify a breach in time.
Upper tier: up to €20 million or 4% of global annual turnover, whichever is higher — for breaching core principles, processing without a lawful basis, invalid consent, or denying data subject rights.
Both are maximums. Typical fines are a small fraction of the cap, and small businesses far more often receive a reprimand or a corrective order than a fine.
The two fine tiers
Note the word higher. For a company with €10 million turnover, 4% is €400,000, so the €20 million figure applies as the cap. For a company with €50 billion turnover, 4% is €2 billion, and that becomes the cap. The percentage only bites for very large organisations — which is precisely why the record fines are all against multinationals.
Which violations fall into which tier
| Violation | Tier | Article |
|---|---|---|
| Processing without a lawful basis | Upper | Art. 6 |
| Invalid consent (pre-ticked, bundled, hard to withdraw) | Upper | Art. 7 |
| Breaching the core principles (fairness, minimisation, purpose limitation) | Upper | Art. 5 |
| Ignoring access, deletion or portability requests | Upper | Arts. 12–22 |
| Unlawful international data transfers | Upper | Arts. 44–49 |
| Failing to implement appropriate security measures | Lower | Art. 32 |
| Not notifying a breach within 72 hours | Lower | Arts. 33–34 |
| No records of processing activities | Lower | Art. 30 |
| Failing to appoint a required DPO or EU representative | Lower | Arts. 27, 37 |
| No data processing agreement with a processor | Lower | Art. 28 |
The pattern: things that harm individuals directly sit in the upper tier; things that make you harder to supervise sit in the lower tier. Consent failures — the most common issue on small websites — are upper tier.
How a fine is actually calculated
Article 83(2) lists eleven factors a supervisory authority must weigh. In practice these decide whether a violation costs you a warning or a life-changing number:
- Nature, gravity and duration — how many people, how long, how sensitive the data
- Intentional or negligent — deliberate violations are treated far more harshly
- Mitigation — what you did to limit damage once you knew
- Technical and organisational measures — whether you had reasonable safeguards in place
- Previous infringements — repeat offenders pay more
- Cooperation with the authority — this one moves the number a lot
- Categories of data affected — health, biometric and other special category data escalate everything
- How the authority found out — self-reporting is treated better than being caught
- Compliance with prior orders — ignoring a previous instruction is expensive
- Codes of conduct or certification — adherence counts in your favour
- Financial benefit gained — profit made from the violation can be stripped out
The European Data Protection Board's fine calculation guidelines add a common methodology: authorities start from the seriousness of the violation and the size of the undertaking, set a starting amount, then adjust up or down for aggravating and mitigating factors before checking against the legal maximum.
The biggest fines on record
| Organisation | Amount | Authority & year | Issue |
|---|---|---|---|
| Meta | €1.2bn | Ireland, 2023 | EU–US data transfers without adequate safeguards |
| Amazon | €746m | Luxembourg, 2021 | Advertising without valid consent |
| Meta (Instagram) | €405m | Ireland, 2022 | Children's data exposed by default settings |
| TikTok | €345m | Ireland, 2023 | Children's accounts public by default |
| €150m | France (CNIL), 2022 | Refusing cookies harder than accepting them | |
| €60m | France (CNIL), 2022 | Same cookie refusal issue |
Two things stand out. Every one of these is a very large company, and several concern consent design rather than a data breach. The CNIL cookie fines in particular were about interface design — the number of clicks to refuse versus accept.
What this means for a small business
The honest picture, absent the scare marketing:
- You are unlikely to be proactively audited. Authorities are under-resourced and prioritise cases affecting many people.
- You are quite likely to receive a complaint eventually. Former employees and customers whose deletion requests were ignored are the most common complainants.
- First contact is usually a letter, not a fine. Most authorities open with questions and a request for documentation.
- The response determines the outcome. Ignoring the letter converts a fixable problem into an enforcement action.
- Four and five figure fines against small firms are real. They are just not newsworthy, so they do not shape public perception.
Cookie banner enforcement
Cookie compliance is enforced more than almost anything else, for a structural reason: a regulator can assess it from the outside. No investigation is needed to see that your banner has an "Accept all" button and no reject option.
The recurring findings:
- Refusing takes more clicks than accepting
- Cookies set before any choice is made
- Pre-ticked category boxes
- No way to withdraw consent later
- "Continuing to browse means you accept" — never valid consent under GDPR
If you only fix one thing, fix the banner. Our guides on whether you need one and the tools that block scripts properly cover the practical side.
Penalties that are not fines
Article 58 gives authorities corrective powers that are often more disruptive than money:
- Processing bans — an order to stop processing certain data, which can shut down a product line
- Suspension of data flows — the mechanism behind the Meta transfer case
- Mandatory compliance orders with hard deadlines
- Public reprimands — reputational, and permanently on the record
- Compensation claims — Article 82 lets individuals sue for material and non-material damage, independently of any regulatory fine
For most businesses, a processing ban is the genuinely existential outcome. A fine is survivable; being ordered to stop using your customer database is not.
How to reduce your exposure
- Fix consent first It is upper tier, externally visible, and the most commonly enforced. A CMP that genuinely blocks scripts pre-consent closes most of the risk.
- Write down what you process Article 30 records are lower tier on their own, but they are the evidence that makes every other defence credible.
- Have a working rights process Ignoring a deletion request is the single most common route from an annoyed individual to a regulator's desk.
- Publish an accurate privacy policy Not a copied one. A policy describing processing you do not do is itself a misstatement.
- Sign DPAs with your processors Your email platform, host, analytics and payment providers. Most publish one you accept by using the service.
- Know your 72-hour breach path Decide in advance who assesses a breach and who notifies. The clock starts when you become aware, not when you finish investigating.
Consent is the most-fined failure
Cookie and consent violations are the easiest thing for a regulator to spot and the most frequently penalised. A consent platform that blocks before consent, offers equal accept and reject, and logs decisions removes the bulk of the exposure.
Frequently asked questions
How much are GDPR fines?
GDPR sets two maximum tiers under Article 83. The lower tier is up to €10 million or 2% of global annual turnover, whichever is higher, and covers administrative failures such as inadequate records or failing to notify a breach. The upper tier is up to €20 million or 4% of global annual turnover, whichever is higher, and covers breaches of core principles, consent failures and violations of data subject rights.
What is the largest GDPR fine ever issued?
€1.2 billion, issued by Ireland's Data Protection Commission against Meta in May 2023 over transfers of European user data to the United States without adequate safeguards. Amazon received a €746 million fine from Luxembourg's authority in 2021, and Meta has received several further fines in the hundreds of millions.
Can a small business be fined under GDPR?
Yes. GDPR has no small-business exemption, and national authorities regularly issue four and five figure fines to small companies and even sole traders. In practice, small businesses are far more likely to receive a warning, a reprimand or an order to fix something than a large fine — but enforcement usually starts with a complaint from a customer, employee or competitor rather than a proactive audit.
What triggers a GDPR investigation?
Most investigations begin with a complaint from an individual — often a former employee, a customer whose deletion request was ignored, or a privacy activist. Other triggers include a self-reported data breach, media coverage, referral from another regulator, and sector-wide sweeps where an authority reviews many sites for the same issue, such as cookie banners.
Is 4% of turnover based on my company or my whole group?
It is based on the total worldwide annual turnover of the entire undertaking in the preceding financial year, not just the entity that committed the violation. For companies inside a corporate group, regulators generally use the group's global revenue, which is why fines against subsidiaries of large groups can far exceed the subsidiary's own revenue.
Do cookie banner violations get fined?
Yes, and they are among the most commonly enforced issues because they are visible from the outside — a regulator can check a banner without an investigation. France's CNIL has issued some of the largest cookie-related fines, including €150 million against Google and €60 million against Facebook in January 2022, primarily because refusing cookies took more clicks than accepting them.
Do GDPR fines apply to companies outside the EU?
Yes. GDPR applies extraterritorially to any organisation processing EU residents' personal data, and the largest fines on record have all been against US-headquartered companies. Enforcement against a small non-EU company with no European presence is harder in practice, but regulators can also order processing to stop, which effectively cuts off the EU market. See GDPR for US companies.
How do GDPR fines compare to CCPA penalties?
They work differently. GDPR fines are percentage-capped and can reach billions. CCPA penalties are per-violation — currently $2,663 per violation and $7,988 for intentional violations or those involving minors — but each affected consumer can count as a separate violation, so totals still escalate. See our CCPA compliance checklist and GDPR vs CCPA comparison.