Get Demo
↑

GDPR Fines and Penalties: The Two Tiers and the Largest Fines to Date

Article 83 sets two administrative fine tiers —.

Published: September 2026 Compliance · GDPR 8–12 min read

Article 83 empowers supervisory authorities to impose administrative fines. There are two tiers, and the ceiling is the higher of a fixed euro amount or a percentage of undertaking worldwide annual turnover.

Related: GDPR hub · Principles · Breach notification.

Locked fine tiers (Art 83): up to €10 million or 2% of worldwide annual turnover or up to €20 million or 4% (higher tier), whichever is higher, depending on which provisions were infringed. Authorities also weigh Art 83(2) factors (nature, intent, mitigation, cooperation, prior offences, etc.).

Two Tiers

Tier
Ceiling
Typical provision themes
Lower
€10M or 2%
e.g. certain controller/processor obligations, certification bodies, some monitoring duties
Higher
€20M or 4%
e.g. basic principles, data subject rights, transfers, non-compliance with orders

Notable Enforcement Themes

Exact fine amounts change with new decisions; treat press headlines as illustrations, not a tariff schedule.

How CyberSilo Helps

Reduce Fine Exposure with Demonstrable Controls

Pair legal counsel with living RoPA, security evidence, and rights workflows before enforcement starts.

Frequently Asked Questions

What is the maximum GDPR fine?

Under Article 83, up to €20 million or 4% of worldwide annual turnover, whichever is higher, for the higher tier of infringements.

Is every violation fined at 4%?

No. A lower tier (up to €10M or 2%) applies to other provisions. Authorities also apply Article 83(2) criteria.

Can authorities ban processing?

Yes. Corrective powers under Article 58 include warnings, orders, and temporary or definitive bans on processing.

GDPR hub · Checklist · Certification · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!