Key Takeaways
- GDPR fines run on two tiers: up to €10 million or 2% of global annual turnover for less severe violations, and up to €20 million or 4% for the most serious ones, whichever figure is higher in each tier.
- Cumulative GDPR fines have passed €6.3 billion, though the exact total depends on which tracker you use, since no single official EU-wide register exists.
- Amazon's €746 million fine, long cited as the second-largest ever issued, was annulled by a Luxembourg court in March 2026 on procedural grounds, not because the underlying violation was found to be lawful.
- Any organization processing EU residents' data can be fined, regardless of where it's headquartered; individuals face a separate, much smaller penalty regime under national law, not GDPR's corporate fine structure.
- Nine specific fines against named companies, from Meta's record €1.2 billion penalty to smaller five- and six-figure enforcement actions, are covered in their own dedicated case studies linked throughout this guide.
- Fines aren't just for billion-dollar companies: a small German chat app was fined €20,000 in 2018 for storing passwords in plain text, showing the same rules apply well below headline scale.
A GDPR fine can reach €20 million or 4% of a company's global annual turnover, whichever is higher, but that ceiling only applies to the most serious violations, and most enforcement actions land well below it. Cumulative fines since GDPR took effect now exceed €6 billion, spread across more than 3,000 individual cases ranging from a few hundred euros to over a billion. Below: the actual two-tier fine structure, what regulators weigh before setting a number, and answers to who can actually be fined and how the process works.
Secure Privacy is a cookie and consent management platform built to keep the compliance gaps that trigger these fines, unlawful cookie tracking, inadequate consent records, missing legal basis, from happening in the first place.
What Are the Two Tiers of GDPR Fines?
GDPR Article 83 sets two fine tiers, and which one applies depends on which provision was violated, not how large the company is. The lower tier, up to €10 million or 2% of global annual turnover, whichever is higher, covers violations like inadequate record-keeping, failing to appoint a required Data Protection Officer, or not reporting a data breach on time. The upper tier, up to €20 million or 4% of global annual turnover, whichever is higher, covers the core principles: unlawful processing, ignoring a valid consent withdrawal, or violating a data subject's fundamental rights.
"Whichever is higher" is the detail most summaries get backwards or drop entirely. For a small company, the flat euro figure is usually the binding number. For a large multinational, 2% or 4% of global turnover can dwarf the flat cap, which is why Meta's €1.2 billion fine and Amazon's now-annulled €746 million figure were both calculated as a percentage of revenue, not the flat ceiling.
Article 83(2) lists ten factors a data protection authority has to weigh before setting the actual number within that ceiling, not just default to the maximum:
| Factor | What it covers |
|---|---|
| Nature, gravity, and duration | How severe the violation was and how long it went on |
| Intentional or negligent | Whether it was a deliberate choice or an oversight |
| Mitigating action | Steps taken to reduce harm to affected people |
| Technical and organizational measures | Whether reasonable safeguards existed beforehand |
| Prior violations | Whether the organization has been sanctioned before |
| Cooperation with the authority | Whether the organization cooperated during the investigation |
| Categories of data affected | Whether special-category or children's data was involved |
| How the authority learned of it | Self-reported versus discovered independently |
| Compliance with prior orders | Whether earlier corrective orders were followed |
| Other aggravating or mitigating factors | Financial benefit gained, or any other relevant circumstance |
This is why two violations that look similar on paper can result in very different fines. A company that self-reports, cooperates fully, and had reasonable safeguards in place going in gets weighed differently than one that didn't, even under the same Article.
How Much Have GDPR Fines Totaled So Far?
There's no single official EU-wide register, so the honest answer depends on which tracker you check and when. CMS's Enforcement Tracker, continuously updated and independently checkable, put the running total at €6.31 billion across 3,206 cases as of August 28, 2026. DLA Piper's January 2026 GDPR Fines and Data Breach Survey, which surveys data protection authorities directly rather than compiling published decisions, put the figure closer to €7.1 billion, with roughly €1.2 billion issued in 2025 alone.
The gap between the two isn't a contradiction to resolve, it's a methodology difference: one counts individually documented and verified fines, the other captures some enforcement activity that authorities report but that never gets a dedicated public case file. Treat both as directionally accurate rather than reconciling them to one exact figure, and check the live tracker link below rather than trusting any hard-coded number you read elsewhere, since this total moves every month.
What Are the Biggest GDPR Fines Issued So Far?
Meta holds the record by a wide margin: a €1.2 billion fine from Ireland's Data Protection Commission in May 2023 over unlawful EU-to-US data transfers, separate from Meta's earlier €390 million fine over its ad-personalization consent basis. TikTok has drawn two major fines from two different authorities: €530 million from Ireland's DPC over international data transfers, and a separate €14.5 million from the UK's ICO specifically over children's data handling.
Amazon's case is the one worth getting right rather than repeating the old headline number. Luxembourg's CNPD fined Amazon €746 million in 2021, long cited as the second-largest GDPR fine ever issued, but Luxembourg's Administrative Court annulled that fine in March 2026. The court didn't clear Amazon of wrongdoing; it found the CNPD had skipped required procedural steps (weighing intent and proportionality) and sent the case back rather than upholding the fine as issued. The underlying finding that Amazon's practices violated GDPR still stands. Smaller but still significant fines have landed on Criteo (€40 million), Marriott ($125 million under the UK's post-Brexit regime), and Germany's 1&1 Telecom ($10.6 million), each covered in more depth in its own case study.
What Actually Causes Most GDPR Fines?
Fines cluster around a handful of recurring failure types rather than being evenly spread across every possible violation:
| Violation type | What it looks like | Example |
|---|---|---|
| No valid legal basis | Processing or sharing data without consent, contract, or another Article 6 basis | Meta's €1.2 billion fine, over transferring EU user data to the US without a valid transfer mechanism |
| Inadequate security (Article 32) | Missing encryption, plaintext password storage, weak access controls | Knuddels, fined €20,000 after storing passwords in plain text |
| Transparency failures | Vague or missing privacy notices, unclear cookie disclosures | Common basis for smaller DPA enforcement actions across the EU |
| Ignoring data subject rights | Failing to honor access, deletion, or objection requests within the required timeframe | A frequent secondary finding alongside larger enforcement actions |
| Unlawful cross-border transfer | Moving EU data outside the EU without an adequate mechanism | TikTok's €530 million fine over EEA-to-China transfers |
| Children's data mishandling | Processing minors' data without appropriate safeguards or age verification | TikTok's separate €14.5 million UK ICO fine |
A GDPR fine doesn't require a headline-scale breach to land. Knuddels, a small German chat app, was fined just €20,000 in 2018 for storing user passwords in plain text after a breach, well below what its underlying security failure could have drawn under the full tier structure. The DPA cited the company's prompt breach notification and cooperation with the investigation, exactly the Article 83(2) factors covered above, as the reason the fine landed far below the maximum. It's a useful data point against the assumption that only billion-euro companies actually get fined.
Who Can Actually Be Fined Under GDPR?
Any organization that processes personal data belonging to people in the EU can be fined, regardless of where that organization is headquartered. GDPR's territorial scope reaches beyond the EU's borders whenever a company offers goods or services to EU residents or monitors their behavior, so "we're not based in Europe" isn't itself a defense.
Individuals aren't fined under GDPR's corporate penalty structure at all. A company's employees, executives, or a Data Protection Officer can face personal liability in some member states, but that comes from national implementing law or separate criminal statutes, not GDPR's own Article 83 fine mechanism, which is aimed at the organization as a data controller or processor.
There's no fixed minimum fine either. Enforcement actions have landed in the low hundreds of euros for narrow, low-impact violations, all the way up to the billion-euro figures above. The ten-factor weighing process in Article 83(2) applies at every scale, not just to headline-making cases.
What Does the Fining Process Actually Look Like?
A GDPR fine doesn't happen in a single step. It typically starts with an investigation, either triggered by a complaint, a data breach notification, or a data protection authority's own audit activity. If the authority finds a violation, it issues a draft decision, which under the GDPR's cooperation mechanism can involve other EU authorities if the case crosses borders. The organization can respond and contest findings before a final decision and fine amount are issued. After that, the organization can appeal to national courts, which is exactly the path that led to Amazon's fine being annulled rather than the CNPD's underlying findings being reinstated automatically. In rare cases, affected individuals can also pursue separate civil claims for damages, independent of the regulatory fine itself.
Building compliance in ahead of an investigation is the only point in that timeline where the outcome is still fully in an organization's control. A consent management platform that keeps a verifiable, timestamped record of what consent was actually given, and blocks tracking until it is, addresses the single most common trigger across the enforcement actions cited above: processing that outran its actual legal basis. Secure Privacy logs every consent decision with a timestamp specifically so that record exists before a regulator ever asks for one, not after.
For a broader, forward-looking view of where enforcement is trending by sector and authority, this site's own quarterly enforcement heat map tracks that separately from the historical fines covered here.
FAQ
What are the two tiers of GDPR fines?
The lower tier reaches €10 million or 2% of global annual turnover, whichever is higher, for violations like inadequate records or late breach reporting. The upper tier reaches €20 million or 4%, whichever is higher, for violations of GDPR's core principles like unlawful processing or ignoring data subject rights.
How much have GDPR fines totaled in total?
Around €6.3 billion across roughly 3,200 documented cases as of August 2026, per CMS's continuously updated Enforcement Tracker. A separate survey-based estimate from DLA Piper puts the figure closer to €7.1 billion; the gap reflects different counting methods, not a factual dispute.
What is the biggest GDPR fine ever issued?
Meta's €1.2 billion fine from Ireland's Data Protection Commission in May 2023, over unlawful EU-to-US data transfers. It remains the largest GDPR fine on record.
Is Amazon's €746 million fine still valid?
No, not as originally issued. Luxembourg's Administrative Court annulled it in March 2026 over a procedural error in how the fine was calculated, though the underlying finding of a GDPR violation wasn't overturned. The case was sent back rather than resolved outright.
Can a business outside the EU be fined under GDPR?
Yes. GDPR applies to any organization that offers goods or services to people in the EU or monitors their behavior, regardless of where that organization is based.
Can a small business actually get fined under GDPR?
Yes. Knuddels, a small German chat app, was fined €20,000 in 2018 for storing passwords in plain text after a breach, well below the billion-euro figures that dominate headlines. Fine size scales with the violation and the company's response, not just company size.
What's the most common cause of a GDPR fine?
Missing legal basis for processing (including unlawful cross-border transfers) and inadequate security measures under Article 32 account for most major enforcement actions, from Meta's transfer-basis fine to Knuddels' plaintext-password fine.
Is there a minimum GDPR fine?
No fixed minimum exists. Fines have ranged from a few hundred euros for narrow violations to over a billion euros for the most serious cases, with the actual number set case by case under Article 83(2)'s ten weighing factors.




