Since the EU GDPR came into force in May 2018, supervisory authorities across Europe have issued thousands of fines — against multinationals and small businesses alike. Understanding how fines are calculated, what triggers them, and how to avoid them is essential for any business that processes EU personal data.
The two tiers of GDPR fines
Article 83 of the EU GDPR establishes two tiers of administrative fines:
Tier 1 — Up to €10 million or 2% of global turnover
These apply to infringements of obligations relating to:
- Data protection by design and by default (Article 25)
- Records of processing activities (Article 30)
- Security of processing (Article 32)
- Data breach notification (Articles 33–34)
- Data Protection Impact Assessments (Articles 35–36)
- Obligations of processors and sub-processors (Articles 28–29)
- Certification and codes of conduct (Articles 40–43)
Tier 2 — Up to €20 million or 4% of global turnover
These apply to the most serious infringements, including:
- Processing without a lawful basis (Article 6)
- Violations of consent requirements (Article 7)
- Violations of data subject rights (Articles 12–22)
- Unlawful international data transfers (Articles 44–49)
- Failure to provide required privacy information (Articles 13–14)
Factors that affect the size of a fine
Supervisory authorities don't automatically impose maximum fines. Article 83(2) lists the factors they must consider:
- Nature, gravity, and duration of the infringement
- Intentional or negligent character of the violation
- Degree of responsibility — was there appropriate technical and organisational measures in place?
- Prior infringements — a clean record reduces fines; repeat violations increase them
- Cooperation with the supervisory authority — proactive engagement is consistently rewarded
- Categories of data affected — health, financial, children's data attract higher fines
- Remedial action taken — fixing the problem promptly reduces penalties
- Financial situation of the organisation — regulators consider ability to pay, especially for SMEs
Real GDPR fine examples
Meta (Ireland DPC) — €1.2 billion (2023)
The largest GDPR fine ever issued. Meta was fined for transferring EU users' personal data to the US without adequate safeguards following the invalidation of Privacy Shield. This is a Tier 2 fine related to unlawful international transfers.
Amazon (Luxembourg CNPD) — €746 million (2021)
Amazon's advertising targeting system was found to process personal data without a valid legal basis and without adequate transparency. A landmark fine demonstrating that advertising practices are firmly within GDPR scope.
Google (France CNIL) — €150 million (2022)
Google's cookie consent mechanism was found to make it harder to refuse cookies than to accept them. The CNIL required Google to make the "refuse all" option as easy to access as "accept all."
Small business fines
GDPR enforcement is not limited to tech giants. Supervisory authorities regularly fine small businesses:
- A Portuguese hospital was fined €400,000 for allowing unauthorised staff access to patient records
- A Bulgarian telecommunications company was fined €250,000 for a data breach affecting customer records
- A German social media monitoring company was fined €14.5 million for inadequate data retention policies
- Numerous small businesses across Europe have received fines of €5,000–€50,000 for missing or inadequate Privacy Policies
What triggers a GDPR investigation?
Investigations are typically triggered by:
- Data subject complaints — a customer complaining to a supervisory authority is the most common trigger
- Data breach notifications — you are required to notify your supervisory authority within 72 hours of a breach, which opens an investigation
- Media coverage — high-profile privacy incidents attract regulatory attention
- Own-initiative investigations — some DPAs proactively audit sectors or companies
- Referrals from other DPAs — under the one-stop-shop mechanism
⚠ One unhappy customer contacting their national supervisory authority is enough to trigger a formal investigation. This is why having a clear, compliant Privacy Policy — and responding promptly to privacy requests — matters even for small businesses.
The most common GDPR violations for small businesses
- No Privacy Policy, or one that doesn't meet Article 13/14 requirements — the single most common issue
- Invalid cookie consent — pre-ticked boxes, no "reject all" option, or consent banners that don't actually record consent
- No lawful basis stated — processing personal data without identifying and documenting the legal basis
- Failing to respond to data subject requests — you have one calendar month to respond to access, erasure, and other requests
- Unlawful international transfers — sending data to US processors without SCCs or an adequacy decision in place
- Inadequate security measures — preventable data breaches caused by poor password hygiene, unencrypted data, or outdated software
How to reduce your GDPR fine risk
The most effective risk reduction steps for small businesses are:
- Have a compliant Privacy Policy — covering all Article 13/14 mandatory disclosures, updated to reflect your actual practices
- Implement a proper cookie consent mechanism — an opt-in consent banner with a genuine "reject all" option
- Document your lawful bases — know and record the legal basis for each processing activity
- Respond to privacy requests promptly — acknowledge within 72 hours, respond within one month
- Sign Data Processing Agreements — with every third-party processor handling EU personal data
- Notify breaches within 72 hours — proactive notification is consistently treated as a mitigating factor
- Cooperate with regulators — being open and responsive significantly reduces fine outcomes
DataShark generates a personalised EU GDPR Privacy Policy and Data Processing Agreement for your business in under 3 minutes. Both documents cover all mandatory Article 13 disclosures, your specific processors, and your lawful bases — from €10.
Ready to generate your GDPR policy?
Answer a few questions about your business and get a personalised, legally-structured document in minutes.
Start free — from £29 →