GDPR
What are the fines for GDPR law violation in practice?
GDPR fines are assessed individually. There is no fixed price for each violation, and the maximum percentages are not automatically charged.
The two main ceilings are €10 million or 2% of an undertaking’s worldwide annual turnover, and €20 million or 4%, depending on the infringement. In each tier, the higher amount applies, using turnover from the preceding financial year. These are ceilings, not standard penalties.
Under the EDPB’s fine calculation guidelines, regulators consider:
The seriousness and duration of the infringement, the people affected and the harm caused.
The types of personal data involved.
Whether the conduct was intentional or negligent.
Previous infringements, corrective action and cooperation.
The undertaking’s turnover and whether the final amount is proportionate and sufficiently deterrent.
Actual penalties can be much smaller than the headline maximums. For example, on 12 March 2026, the CNIL fined a distance-selling company €5,000 for failures involving information about individuals’ rights and the right of access. That decision illustrates a specific case, not a standard tariff for similar businesses.
Türkçe
English