The General Data Protection Regulation (GDPR) gives supervisory authorities across Europe the power to impose significant fines on organisations that fail to comply with data protection law. These fines are not limited to large multinational companies and can apply to businesses of any size that process personal data.
The financial penalties can reach up to twenty million euros or a percentage of global turnover, whichever is higher. For many organisations, the risk of reputational damage and loss of customer trust is just as serious as the financial cost. Understanding how fines are calculated and what triggers them is therefore essential for effective compliance.
The two tiers of GDPR fines
Under the GDPR, infringements are divided into two levels of administrative fines. This tiered approach reflects the seriousness of the breach and ensures that penalties are proportionate.
Lower Tier
Organisations can face fines of up to ten million euros or two per cent of global annual turnover, whichever is higher. This level usually applies to failures in administrative obligations, such as not keeping proper records of processing activities, not reporting a data breach on time, or neglecting to appoint a Data Protection Officer when required.
Higher Tier
For more serious infringements, fines can reach up to twenty million euros or four per cent of global annual turnover, whichever is higher. These fines are reserved for breaches that undermine the core principles of data protection, such as processing without a lawful basis, violating the rights of individuals, or making unlawful international data transfers.
Example of a lower-tier Infringement
In March 2021, the Spanish Data Protection Authority (AEPD) fined Filigrana Comunicación, SLU a total of €8,000. This fine was for hosting personal data of internship applicants on its website (data that had been sourced from publicly available lists) without obtaining the prior consent of the data subjects. The fine was broken down into violations of three GDPR articles: €2,000 for infringing Article 6(1), €2,000 for breaching Article 14, and €4,000 for violating Article 13.
Example of a higher-tier Infringement
In 2025, Ireland’s Data Protection Commission (DPC) imposed a record-breaking fine on TikTok of €530 million. This fine was divided into €485 million for unlawfully transferring European user data to servers in China and €45 million for failing to properly disclose these transfers in its privacy policy. This case serves as a stark example of a higher-tier infringement, involving significant breaches of both the principles for international data transfers and transparency obligations.
How regulators decide the size of the fine
Supervisory authorities do not apply GDPR fines arbitrarily. Article 83 sets out a list of factors that regulators must consider when determining the size of a penalty. These include:
- Nature, gravity and duration of the infringement – Regulators assess how severe the breach was, how many individuals were affected, and for how long it continued.
- Intentional or negligent character – A deliberate disregard of obligations is treated more seriously than an accidental error.
- Mitigation efforts – Steps taken by the organisation to limit harm or promptly correct the breach can reduce the fine.
- Categories of personal data affected – The misuse of sensitive data, such as health or biometric information, generally attracts higher penalties.
- Past infringements – A track record of non-compliance can increase the fine.
- Cooperation with the authority – Organisations that engage openly and provide assistance during investigations are often treated more leniently.
- Adherence to codes of conduct or certification – Participation in approved schemes demonstrates a proactive compliance culture and may influence the final decision.
These criteria allow regulators to balance deterrence with proportionality, ensuring that fines reflect both the seriousness of the breach and the conduct of the organisation.
Practical steps to reduce risk
While the prospect of large GDPR fines can seem daunting, organisations can take practical measures to reduce their exposure. Compliance is not only about avoiding penalties but also about demonstrating accountability and building trust with customers. Key steps include:
Maintain clear records of processing
Keep an up-to-date record of all data processing activities, including the purposes, categories of data, and legal bases relied upon.
Conduct Data Protection Impact Assessments (DPIAs)
Carry out DPIAs for high-risk processing activities to identify and mitigate risks before they materialise.
Appoint a Data Protection Officer (DPO) where required
Ensure the DPO has sufficient independence, authority and resources to oversee compliance.
Train staff regularly
Employees should understand their data protection responsibilities, particularly around handling requests from individuals and reporting breaches.
Prepare breach response procedures
Establish clear internal protocols to detect, investigate and report breaches within the seventy-two-hour window.
Review contracts with processors and partners
Confirm that third parties handling data on your behalf provide adequate guarantees of GDPR compliance.
By embedding these practices into daily operations, organisations can demonstrate accountability, reduce the likelihood of infringements and show regulators that they take data protection seriously.
Need support with GDPR compliance?
If your organisation is based outside the EU but processes the personal data of individuals within the Union, you are legally required under Article 27 of the GDPR to appoint an EU-based representative. This requirement applies to many businesses that sell to EU customers or monitor their behaviour online.
EU Business Partners provides this representation service and helps non-EU organisations demonstrate compliance with GDPR obligations. We act as your point of contact with EU supervisory authorities and data subjects, ensuring you meet legal requirements with confidence.
To learn more about how we can support you, view our plans here.





0 Comments