Fine framework: how are GDPR fines calculated?
The GDPR has two tiers of fines (Art. 83):
- Tier 1 (Art. 83(4)): up to EUR 10 million or 2% of global annual turnover — for violations of Art. 25 (privacy by design), Art. 30 (processing register), Art. 32 (security) and Art. 33-34 (breach notification)
- Tier 2 (Art. 83(5)): up to EUR 20 million or 4% of global annual turnover — for violations of processing principles (Art. 5), legal basis (Art. 6), consent (Art. 7), data subject rights (Art. 12-22) and transfers (Art. 44-49)
Largest European fines
Unlawful transfer for advertising — EUR 1.2 billion (2023)
A major technology company was fined for transferring European users' personal data to the US without adequate safeguards. The largest GDPR fine to date.
Lesson: Non-EEA transfers without a valid basis are among the most heavily fined violations.
Insufficient legal basis for personalised ads — EUR 390 million (2023)
A social media platform was fined for using contractual necessity as a legal basis for personalised advertising.
Lack of transparency and consent — EUR 746 million (2021)
A major e-commerce company was fined for placing cookies without valid consent and insufficient transparency.
Unlawful profiling of minors — EUR 345 million (2023)
A social media platform was fined for defaulting accounts of minors (13-17) to public and insufficient child protection measures.
Dutch fines (Autoriteit Persoonsgegevens)
Inadequate security — EUR 440,000 (2022)
A healthcare institution was fined for inadequate security of medical records. Staff had unnecessary access and there was no access logging.
No DPA — EUR 525,000 (2022)
An organisation was fined for systematically failing to conclude DPAs with processors accessing client data.
Lesson: A DPA is not optional — it is mandatory for any processing by third parties.
Late breach notification — EUR 290,000 (2023)
A company reported a data breach after three months instead of within 72 hours.
Unlawful processing of national ID numbers — EUR 3.7 million (2021)
A government body processed national identification numbers without a legal basis for purposes outside its mandate.
Belgian fines (Gegevensbeschermingsautoriteit)
Cookies without valid consent — EUR 250,000 (2022)
A website operator was fined for placing tracking cookies before obtaining consent. The cookie banner presented choices unequally.
Inadequate security after breach — EUR 100,000 (2023)
After a breach, the organisation had no encryption and no regular security audits. Art. 32 is an ongoing obligation.
Denial of right to erasure — EUR 50,000 (2023)
An organisation refused an erasure request without demonstrating a valid Art. 17(3) exception.
Incomplete privacy notice — EUR 75,000 (2022)
A company's privacy notice was incomplete: recipients were not specifically named, retention periods were missing and legal bases were unclear.
How to prevent a GDPR fine
- Conclude DPAs with all parties processing personal data on your behalf (Art. 28)
- Maintain a current processing register with all processing activities, legal bases and retention periods (Art. 30)
- Implement adequate security and review regularly: encryption, access control, logging (Art. 32)
- Report breaches within 72 hours and document every incident (Art. 33-34)
- Document non-EEA transfers with SCCs, TIAs and supplementary measures (Art. 44-49)
- Respect data subject rights: access, rectification, erasure, portability (Art. 12-22)
- Conduct DPIAs for high-risk processing (Art. 35)
- Train staff on privacy awareness and your organisation's procedures