Back to the hub

GDPR fines: how much can a violation cost?

GDPR fines come in two tiers under Article 83. Lower-tier breaches, such as records or security failures, reach 10 million euros or 2% of total worldwide annual turnover, whichever is higher. Upper-tier breaches, such as no lawful basis or ignoring data-subject rights, reach 20 million euros or 4%, whichever is higher.

Applies to: Any controller or processor subject to the GDPR; the turnover-based cap applies to undertakings, so larger groups face the percentage figure rather than the euro cap.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

The headline number people remember about the GDPR is a big one, and it is real, but it is only half the story. Article 83 sets two tiers of fine, and the cap is whichever is higher of a fixed euro figure and a percentage of worldwide turnover. For a small company the euro figure usually bites; for a large group the percentage does, and it is much larger. Here is how each tier works and what pushes a breach into the higher one.

The two tiers of GDPR fine

Article 83(4) sets the lower tier: up to 10 million euros, or in the case of an undertaking up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. It covers the more operational duties, such as records of processing, security of processing, data-protection-by-design, and the obligations of processors. Article 83(5) sets the upper tier: up to 20 million euros, or up to 4% of total worldwide annual turnover, whichever is higher. It covers the serious failures, including the basic principles for processing, having a valid lawful basis, the conditions for consent, data-subject rights such as the right to data portability, and unlawful international transfers.

Why the percentage matters more than the euro figure

The phrase "whichever is higher" is the part businesses miss. For an undertaking, the fine is capped at the greater of the euro amount and the turnover percentage, and the percentage is calculated on the whole group's global turnover, not the revenue of one subsidiary or one product. So the 20 million euro figure is a floor for large companies, not a ceiling. A company with billions in turnover is exposed to a fine measured in the hundreds of millions, which is why the largest GDPR penalties have dwarfed the headline euro caps.

How regulators set the amount

Fines are imposed by national supervisory authorities, the data protection regulator in each member state, and Article 83(1) requires that each one be effective, proportionate and dissuasive. Article 83(2) lists the factors that move the number up or down: the nature, gravity and duration of the breach, how many people were affected, whether it was intentional or negligent, what you did to mitigate it, your history, and how well you cooperated. A fine can be imposed on its own or alongside a corrective order, such as a ban on a particular kind of processing, which is sometimes the more disruptive outcome.

What actually draws a fine

In practice the common triggers are processing with no valid lawful basis, weak security that leads to a breach, ignoring or mishandling data-subject requests, and unlawful transfers of data outside the EU. Most of these are avoidable with groundwork rather than heroics: a lawful basis recorded for each activity, a record of processing, reasonable security, and a breach plan. If you are not sure the regulation even reaches you, start with does the GDPR apply to your SaaS.

Next step

If the GDPR applies to you, the cheapest way to manage fine exposure is to close the gaps regulators actually penalise before they matter. The free 2-minute Obligation Scan flags where you are missing a lawful basis, records, or the rights processes that sit in the upper tier, so you can act on the duties rather than price a penalty later. The GDPR compliance hub sets out the full set.

Compliance checklist

  • Know your tier exposure: 2% or 10 million euros for lower-tier duties, 4% or 20 million euros for the core principles and rights.
  • Secure a lawful basis for every activity, since processing with none is an upper-tier breach.
  • Keep records of processing and a working data-subject-request process, as gaps here draw fines.
  • Maintain reasonable security and a breach-notification plan, because security failures sit in the lower tier and a breach raises scrutiny.
  • Document your mitigation, since cooperation and remediation are factors that reduce the amount under Article 83(2).

Sources

Last verified: 2026-08-07

Informational, not legal advice.