Back to the hub

How are GDPR fines calculated?

GDPR fines are set case by case under Article 83, which requires them to be effective, proportionate and dissuasive. A supervisory authority weighs eleven factors in Article 83(2), such as the gravity, duration and intentional or negligent character of the infringement, then applies the EDPB's five-step method within the Article 83(4) and (5) caps.

Applies to: Controllers and processors subject to the GDPR that need to understand how a supervisory authority sets an administrative fine under Article 83 and the EDPB's fining methodology.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

The headline GDPR numbers, 20 million euros or 4% of global turnover, are a ceiling, not a going rate. Actual fines are worked out case by case, and understanding the method matters because the same breach can land very differently depending on how you handled it. A supervisory authority is not free to pick a figure; Article 83 tells it what to weigh, and the European Data Protection Board has published a method that harmonises how the sum is built.

The starting rule in Article 83(1)

Article 83(1) sets the frame: every administrative fine must be effective, proportionate and dissuasive, decided on the facts of the individual case. That single sentence does a lot of work. It means a fine is not a fixed penalty attached to a breach, but a figure calibrated to the organisation and the conduct, and it is why turnover, not just the nature of the breach, feeds into the amount.

The two turnover-based tiers

The caps come in two tiers. Under Article 83(4), lower-tier infringements, such as breaching the obligations of controllers and processors, are capped at 10 million euros or 2% of total worldwide annual turnover of the preceding year, whichever is higher. Under Article 83(5), the most serious infringements, including the basic principles for processing, the lawful bases, and data-subject rights, are capped at 20 million euros or 4% of turnover, whichever is higher. Because the cap is the higher of a fixed sum or a turnover percentage, large groups face exposure far above the euro figures. The GDPR fines and penalties page sets out which articles sit in each tier.

The eleven factors in Article 83(2)

Within the applicable cap, Article 83(2) lists the factors that move a fine up or down. They include the nature, gravity and duration of the infringement and the number of data subjects affected; whether it was intentional or negligent; any action taken to mitigate the damage; the degree of responsibility given the measures in place; any relevant previous infringements; the degree of cooperation with the supervisory authority; the categories of personal data affected; how the authority became aware of the breach, in particular whether you reported it; compliance with prior orders; adherence to approved codes of conduct or certification; and any other aggravating or mitigating factor, such as financial benefit gained. These are the levers your response to an incident actually pulls.

The EDPB's five-step method

The European Data Protection Board's Guidelines 04/2022 turn those factors into a repeatable calculation of five steps. First, identify the processing operations and evaluate Article 83(3), which caps several linked infringements at the amount for the gravest one. Second, set a starting point from the infringement's classification and seriousness and the undertaking's turnover. Third, adjust for aggravating and mitigating circumstances tied to past or present behaviour. Fourth, confirm the relevant legal maximum is not exceeded. Fifth, check the final figure is effective, proportionate and dissuasive, and adjust if not. The method is why cooperation and early breach notification genuinely reduce a fine rather than just reading well.

Next step

If you want to understand your own exposure, the free 2-minute Obligation Scan checks whether the GDPR applies to you and flags the obligations whose breach sits in the higher fining tier. The GDPR compliance hub sets out those obligations so you can reduce the factors that drive a fine up before an incident, not after.

Compliance checklist

  • Identify which provisions you may have infringed and whether Article 83(3) applies, because several breaches from the same or linked operations are capped at the amount for the gravest one.
  • Place the infringement in the right tier: the Article 83(4) band of 10 million euros or 2% of turnover, or the Article 83(5) band of 20 million euros or 4%.
  • Assess the Article 83(2) seriousness factors, especially the nature, gravity and duration, the intentional or negligent character, and the categories of personal data affected.
  • Weigh the aggravating and mitigating circumstances the EDPB method applies next, such as previous infringements, cooperation, and how the authority learned of the breach.
  • Document mitigation early: steps to reduce damage, cooperation with the authority, and adherence to approved codes of conduct all pull the figure down under Article 83(2).

Sources

Last verified: 2026-08-10

Informational, not legal advice.