← Back to blog
EU Privacy Law

GDPR Fines: How Much Can You Be Fined and How to Avoid It

By DataShark · 24 June 2026 · 7 min read
?>

Since the EU GDPR came into force in May 2018, supervisory authorities across Europe have issued thousands of fines — against multinationals and small businesses alike. Understanding how fines are calculated, what triggers them, and how to avoid them is essential for any business that processes EU personal data.

The two tiers of GDPR fines

Article 83 of the EU GDPR establishes two tiers of administrative fines:

Tier 1 — Up to €10 million or 2% of global turnover

These apply to infringements of obligations relating to:

Tier 2 — Up to €20 million or 4% of global turnover

These apply to the most serious infringements, including:

In both tiers, fines are the higher of the monetary cap or the percentage of turnover — meaning large multinationals face proportionally much higher penalties than the stated euro amounts suggest.

Factors that affect the size of a fine

Supervisory authorities don't automatically impose maximum fines. Article 83(2) lists the factors they must consider:

Real GDPR fine examples

Meta (Ireland DPC) — €1.2 billion (2023)

The largest GDPR fine ever issued. Meta was fined for transferring EU users' personal data to the US without adequate safeguards following the invalidation of Privacy Shield. This is a Tier 2 fine related to unlawful international transfers.

Amazon (Luxembourg CNPD) — €746 million (2021)

Amazon's advertising targeting system was found to process personal data without a valid legal basis and without adequate transparency. A landmark fine demonstrating that advertising practices are firmly within GDPR scope.

Google (France CNIL) — €150 million (2022)

Google's cookie consent mechanism was found to make it harder to refuse cookies than to accept them. The CNIL required Google to make the "refuse all" option as easy to access as "accept all."

Small business fines

GDPR enforcement is not limited to tech giants. Supervisory authorities regularly fine small businesses:

What triggers a GDPR investigation?

Investigations are typically triggered by:

⚠ One unhappy customer contacting their national supervisory authority is enough to trigger a formal investigation. This is why having a clear, compliant Privacy Policy — and responding promptly to privacy requests — matters even for small businesses.

The most common GDPR violations for small businesses

  1. No Privacy Policy, or one that doesn't meet Article 13/14 requirements — the single most common issue
  2. Invalid cookie consent — pre-ticked boxes, no "reject all" option, or consent banners that don't actually record consent
  3. No lawful basis stated — processing personal data without identifying and documenting the legal basis
  4. Failing to respond to data subject requests — you have one calendar month to respond to access, erasure, and other requests
  5. Unlawful international transfers — sending data to US processors without SCCs or an adequacy decision in place
  6. Inadequate security measures — preventable data breaches caused by poor password hygiene, unencrypted data, or outdated software

How to reduce your GDPR fine risk

The most effective risk reduction steps for small businesses are:

  1. Have a compliant Privacy Policy — covering all Article 13/14 mandatory disclosures, updated to reflect your actual practices
  2. Implement a proper cookie consent mechanism — an opt-in consent banner with a genuine "reject all" option
  3. Document your lawful bases — know and record the legal basis for each processing activity
  4. Respond to privacy requests promptly — acknowledge within 72 hours, respond within one month
  5. Sign Data Processing Agreements — with every third-party processor handling EU personal data
  6. Notify breaches within 72 hours — proactive notification is consistently treated as a mitigating factor
  7. Cooperate with regulators — being open and responsive significantly reduces fine outcomes

DataShark generates a personalised EU GDPR Privacy Policy and Data Processing Agreement for your business in under 3 minutes. Both documents cover all mandatory Article 13 disclosures, your specific processors, and your lawful bases — from €10.

Ready to generate your GDPR policy?

Answer a few questions about your business and get a personalised, legally-structured document in minutes.

Start free — from £29 →