GDPR has two fine tiers, set by Article 83.

Lower tier: up to €10 million or 2% of global annual turnover, whichever is higher — for administrative failures such as poor records, missing DPO, or failing to notify a breach in time.

Upper tier: up to €20 million or 4% of global annual turnover, whichever is higher — for breaching core principles, processing without a lawful basis, invalid consent, or denying data subject rights.

Both are maximums. Typical fines are a small fraction of the cap, and small businesses far more often receive a reprimand or a corrective order than a fine.

The two fine tiers

€10m / 2%
Lower tier — whichever is higher. Administrative and procedural obligations.
€20m / 4%
Upper tier — whichever is higher. Core principles, lawful basis, consent, and individual rights.

Note the word higher. For a company with €10 million turnover, 4% is €400,000, so the €20 million figure applies as the cap. For a company with €50 billion turnover, 4% is €2 billion, and that becomes the cap. The percentage only bites for very large organisations — which is precisely why the record fines are all against multinationals.

"Global annual turnover" means the whole undertaking. Regulators calculate against the total worldwide revenue of the corporate group in the preceding financial year, not the revenue of the specific subsidiary that broke the rules.

Which violations fall into which tier

ViolationTierArticle
Processing without a lawful basisUpperArt. 6
Invalid consent (pre-ticked, bundled, hard to withdraw)UpperArt. 7
Breaching the core principles (fairness, minimisation, purpose limitation)UpperArt. 5
Ignoring access, deletion or portability requestsUpperArts. 12–22
Unlawful international data transfersUpperArts. 44–49
Failing to implement appropriate security measuresLowerArt. 32
Not notifying a breach within 72 hoursLowerArts. 33–34
No records of processing activitiesLowerArt. 30
Failing to appoint a required DPO or EU representativeLowerArts. 27, 37
No data processing agreement with a processorLowerArt. 28

The pattern: things that harm individuals directly sit in the upper tier; things that make you harder to supervise sit in the lower tier. Consent failures — the most common issue on small websites — are upper tier.

How a fine is actually calculated

Article 83(2) lists eleven factors a supervisory authority must weigh. In practice these decide whether a violation costs you a warning or a life-changing number:

The European Data Protection Board's fine calculation guidelines add a common methodology: authorities start from the seriousness of the violation and the size of the undertaking, set a starting amount, then adjust up or down for aggravating and mitigating factors before checking against the legal maximum.

The practical lever: cooperation and demonstrable good faith. An organisation that self-reports, cooperates, and shows it had a genuine (if flawed) compliance programme routinely lands an order to fix rather than a fine. Documentation is what makes that argument possible.

The biggest fines on record

OrganisationAmountAuthority & yearIssue
Meta€1.2bnIreland, 2023EU–US data transfers without adequate safeguards
Amazon€746mLuxembourg, 2021Advertising without valid consent
Meta (Instagram)€405mIreland, 2022Children's data exposed by default settings
TikTok€345mIreland, 2023Children's accounts public by default
Google€150mFrance (CNIL), 2022Refusing cookies harder than accepting them
Facebook€60mFrance (CNIL), 2022Same cookie refusal issue

Two things stand out. Every one of these is a very large company, and several concern consent design rather than a data breach. The CNIL cookie fines in particular were about interface design — the number of clicks to refuse versus accept.

What this means for a small business

The honest picture, absent the scare marketing:

The cost that is not the fine. Responding to a regulator means legal fees, staff time, and producing documentation you may not have. For most small businesses that burden exceeds the eventual penalty — and it is entirely avoidable by keeping basic records.

Cookie banner enforcement

Cookie compliance is enforced more than almost anything else, for a structural reason: a regulator can assess it from the outside. No investigation is needed to see that your banner has an "Accept all" button and no reject option.

The recurring findings:

If you only fix one thing, fix the banner. Our guides on whether you need one and the tools that block scripts properly cover the practical side.

Penalties that are not fines

Article 58 gives authorities corrective powers that are often more disruptive than money:

For most businesses, a processing ban is the genuinely existential outcome. A fine is survivable; being ordered to stop using your customer database is not.

How to reduce your exposure

  1. Fix consent first It is upper tier, externally visible, and the most commonly enforced. A CMP that genuinely blocks scripts pre-consent closes most of the risk.
  2. Write down what you process Article 30 records are lower tier on their own, but they are the evidence that makes every other defence credible.
  3. Have a working rights process Ignoring a deletion request is the single most common route from an annoyed individual to a regulator's desk.
  4. Publish an accurate privacy policy Not a copied one. A policy describing processing you do not do is itself a misstatement.
  5. Sign DPAs with your processors Your email platform, host, analytics and payment providers. Most publish one you accept by using the service.
  6. Know your 72-hour breach path Decide in advance who assesses a breach and who notifies. The clock starts when you become aware, not when you finish investigating.
Start where enforcement starts

Consent is the most-fined failure

Cookie and consent violations are the easiest thing for a regulator to spot and the most frequently penalised. A consent platform that blocks before consent, offers equal accept and reject, and logs decisions removes the bulk of the exposure.

Frequently asked questions

How much are GDPR fines?

GDPR sets two maximum tiers under Article 83. The lower tier is up to €10 million or 2% of global annual turnover, whichever is higher, and covers administrative failures such as inadequate records or failing to notify a breach. The upper tier is up to €20 million or 4% of global annual turnover, whichever is higher, and covers breaches of core principles, consent failures and violations of data subject rights.

What is the largest GDPR fine ever issued?

€1.2 billion, issued by Ireland's Data Protection Commission against Meta in May 2023 over transfers of European user data to the United States without adequate safeguards. Amazon received a €746 million fine from Luxembourg's authority in 2021, and Meta has received several further fines in the hundreds of millions.

Can a small business be fined under GDPR?

Yes. GDPR has no small-business exemption, and national authorities regularly issue four and five figure fines to small companies and even sole traders. In practice, small businesses are far more likely to receive a warning, a reprimand or an order to fix something than a large fine — but enforcement usually starts with a complaint from a customer, employee or competitor rather than a proactive audit.

What triggers a GDPR investigation?

Most investigations begin with a complaint from an individual — often a former employee, a customer whose deletion request was ignored, or a privacy activist. Other triggers include a self-reported data breach, media coverage, referral from another regulator, and sector-wide sweeps where an authority reviews many sites for the same issue, such as cookie banners.

Is 4% of turnover based on my company or my whole group?

It is based on the total worldwide annual turnover of the entire undertaking in the preceding financial year, not just the entity that committed the violation. For companies inside a corporate group, regulators generally use the group's global revenue, which is why fines against subsidiaries of large groups can far exceed the subsidiary's own revenue.

Do cookie banner violations get fined?

Yes, and they are among the most commonly enforced issues because they are visible from the outside — a regulator can check a banner without an investigation. France's CNIL has issued some of the largest cookie-related fines, including €150 million against Google and €60 million against Facebook in January 2022, primarily because refusing cookies took more clicks than accepting them.

Do GDPR fines apply to companies outside the EU?

Yes. GDPR applies extraterritorially to any organisation processing EU residents' personal data, and the largest fines on record have all been against US-headquartered companies. Enforcement against a small non-EU company with no European presence is harder in practice, but regulators can also order processing to stop, which effectively cuts off the EU market. See GDPR for US companies.

How do GDPR fines compare to CCPA penalties?

They work differently. GDPR fines are percentage-capped and can reach billions. CCPA penalties are per-violation — currently $2,663 per violation and $7,988 for intentional violations or those involving minors — but each affected consumer can count as a separate violation, so totals still escalate. See our CCPA compliance checklist and GDPR vs CCPA comparison.

Related reading