The GDPR caps administrative fines at EUR 20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, for the most serious infringements, and at EUR 10 million or 2% for the rest. Article 83 has not been amended. What has changed is everything around it. The Court of Justice has ruled that a fine needs an infringement committed intentionally or negligently, and that the turnover is the whole group's. The European Data Protection Board publishes the method authorities use to set the amount, and on 17 September 2026 it adopted draft guidelines, for public consultation, on when to fine at all. And 2026 has brought some of the largest decisions yet, alongside the annulment of one of the best known.
The rules reach beyond the EU. Under Article 3(2) the GDPR applies to a controller or processor not established in the Union when it offers goods or services to people in the Union or monitors their behaviour there, and Article 27 then requires a representative in the Union. This guide takes each piece in turn: the tiers, whose turnover counts, fault, how the amount is built, the 2026 decisions, and the penalties that are not fines. For the incident side of the same exposure, see incident reporting deadlines by regulation.
| Question | Short answer | Source |
|---|---|---|
| Maximum fine | EUR 20 million or 4% of worldwide annual turnover, whichever is higher | GDPR Article 83(5) and 83(6) |
| Lower tier | EUR 10 million or 2%, whichever is higher | GDPR Article 83(4) |
| Several infringements | Total capped at the amount for the gravest, for the same or linked processing | GDPR Article 83(3) |
| Whose turnover | The undertaking in the competition law sense, so the group | Recital 150; CJEU C-807/21 |
| Fault | Intent or negligence must be established | CJEU C-807/21 and C-683/21 |
| How the amount is set | Five steps, starting from seriousness and turnover | EDPB Guidelines 04/2022 |
| New procedure | Cross-border procedural rules apply from 2 April 2027 | Regulation (EU) 2025/2518, Article 37 |
What are the GDPR fine tiers?
Two ceilings, each the higher of a fixed sum and a share of turnover. Article 83(4) sets up to EUR 10 million or, for an undertaking, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. It covers the controller and processor obligations in Articles 8, 11, 25 to 39, 42 and 43: data protection by design, records of processing, security, breach notification, DPIAs, the DPO. Article 83(5) doubles both figures for the basic principles and lawful bases in Articles 5, 6, 7 and 9, the data subject rights in Articles 12 to 22, international transfers under Articles 44 to 49, and non-compliance with an order of the supervisory authority. Article 83(6) repeats the higher ceiling for ignoring an order under Article 58(2).
Article 83(3) limits stacking. Where a controller or processor intentionally or negligently infringes several provisions "for the same or linked processing operations", the total "shall not exceed the amount specified for the gravest infringement." That is a cap on the total, not a rule that only one fine is imposed: the Irish DPC's 2025 TikTok decision consisted of EUR 485 million for Article 46(1) and EUR 45 million for Article 13(1)(f).
Whose turnover counts?
The group's. Recital 150 says that where fines are imposed on an undertaking, "an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU", the competition law concept. The Court of Justice applied it in Deutsche Wohnen (C-807/21) on 5 December 2023; in the Court's press release, "where the addressee of the fine forms part of a group of companies, the calculation of that fine must be based on the turnover of the entire group." A subsidiary with modest revenue inside a large group is exposed on the group's figure.
Can a company be fined without fault?
No. In the same judgments, C-807/21 and C-683/21, the Court held that a fine requires an infringement "committed wrongfully, that is to say, intentionally or negligently." The bar is not high: that is the case "where the controller could not have been unaware of the infringing nature of its conduct, regardless of whether or not it was aware of the infringement." A legal person is liable for its staff and need not have its management body involved, and the fine cannot be made conditional on first identifying a responsible individual.
Fault has consequences in practice. On 12 March 2026 Luxembourg's Cour administrative annulled the EUR 746 million fine the CNPD imposed on Amazon in 2021. The CNPD's own statement says the court annulled it on the basis of a development in Court of Justice case law that came after the CNPD's decision, in particular on whether Amazon showed a degree of negligence, while the main findings were confirmed. A fine decision now has to establish fault, not just the infringement.

How do supervisory authorities calculate the amount?
With a five step method from EDPB Guidelines 04/2022, adopted after consultation on 24 May 2023. First, identify the processing operations and apply Article 83(3). Second, set a starting point from the tier, the seriousness of the infringement and the turnover. Third, apply aggravating and mitigating circumstances. Fourth, check the legal maximum, which no increase may exceed. Fifth, test whether the result is effective, dissuasive and proportionate.
The starting point is where the numbers live. For an infringement of low seriousness the authority picks a point "between 0 and 10% of the applicable legal maximum"; medium is between 10 and 20%; high is between 20 and 100%. Smaller undertakings then get a turnover adjustment: at a turnover of EUR 2 million or less, authorities may proceed on 0.2% to 0.4% of the starting amount; from EUR 2 million to 10 million, 0.3% to 2%; from EUR 10 million to 50 million, 1.5% to 10%. The Article 83(2) factors, from the duration of the infringement and the number of people affected to cooperation, previous infringements and whether you notified, are what move a case up or down.
Whether to fine at all is the subject of the newer EDPB Guidelines 04/2026, adopted for public consultation on 17 September 2026. They set out another five steps. The first three are legal preconditions, the third being intent or negligence. If the Article 83(2) factors show a minor infringement, "as a general rule, the supervisory authority will not impose an administrative fine"; if not, "there is a strong presumption to impose an administrative fine." They are a consultation draft, so they may change.
What changed in 2026?
Not Article 83. Four things moved around it. The decisions got larger: on 21 August 2026 the Dutch Autoriteit Persoonsgegevens fined Uber EUR 824,990,000 for fully automated decisions about drivers and insufficient information to them, and Uber has appealed; on 21 September 2026 the Irish DPC fined Google EUR 403 million following an inquiry into its processing of location data. The Amazon fine was annulled, as above. The EDPB opened its consultation on when to fine. And the procedural rules are fixed: Regulation (EU) 2025/2518, published on 12 December 2025, lays down additional procedural rules for cross-border enforcement and applies from 2 April 2027. Under its Article 19, a lead authority considering a fine must list in its preliminary findings the main elements it intends to rely on, including the Article 83(2) factors, so you see the case before the decision.
One more item is a proposal, not law. The Commission's digital omnibus, COM(2025) 837 of 19 November 2025, proposes amendments to the GDPR among other acts; as proposed, it does not amend Article 83.
Which decisions set the scale?
These are recent decisions, with figures from each authority's own announcement. Several are under appeal.
| Company | Authority | Amount | What it was for |
|---|---|---|---|
| Meta Platforms Ireland | Irish DPC, decision of 12 May 2023 | EUR 1.2 billion | Transfers to the US in breach of Article 46(1), plus an order to suspend them |
| Uber | Dutch AP, 21 August 2026 | EUR 824,990,000 | Fully automated decisions about drivers; under appeal |
| TikTok | Irish DPC, announced 2 May 2025 | EUR 530 million | Transfers to China under Article 46(1) and transparency under Article 13(1)(f) |
| Irish DPC, 21 September 2026 | EUR 403 million | Processing of location data | |
| Irish DPC, 24 October 2024 | EUR 310 million | Lawful basis, transparency and fairness for behavioural analysis and targeted advertising | |
| Uber | Dutch AP, 2024 | EUR 290 million | Transfers of drivers' data to the US |
What penalties are there besides fines?
Often the more expensive ones. Article 58(2) gives authorities corrective powers that run alongside a fine or instead of it, including "a temporary or definitive limitation including a ban on processing" under point (f) and the power "to order the suspension of data flows to a recipient in a third country" under point (j). The Meta decision ordered the suspension of future transfers to the US; the TikTok decision ordered transfers to China to stop if processing was not brought into compliance within six months. For a business built on that data flow, the order matters more than the fine.
Then there is private liability: under Article 82(1) anyone who has suffered "material or non-material damage" from an infringement can claim compensation from the controller or processor. Article 84 requires Member States to set other penalties, in particular for infringements not covered by Article 83. Article 83(7) leaves fines on public authorities to each Member State, and recital 151 explains that in Denmark and Estonia, whose legal systems do not provide for administrative fines, fines are imposed through the courts or a misdemeanour procedure.
What the other results get wrong
Page one for this query is mostly vendor blogs and statistics pages. Four errors recur. Several say 4% of "revenue" or "sales"; the text says total worldwide annual turnover of the preceding financial year, and since Deutsche Wohnen that means the group's. Some drop "whichever is higher" from the lower tier, which makes EUR 10 million read like a fixed cap. Several still list Amazon's EUR 746 million as a standing fine, months after the Cour administrative annulled it. And at least one reads Article 83(3) as meaning a single fine is imposed for the most serious violation, when it caps the total and decisions such as TikTok's impose separate fines for separate infringements.
Work out your own exposure
Fill this in before you need it. The Article 83(2) factors reward the organisation that can show its records on the first day of an inquiry.
| Question | Your answer | Why it matters |
|---|---|---|
| What was group worldwide turnover last financial year? | Sets the ceiling; recital 150 and C-807/21. | |
| Do you offer goods or services to, or monitor, people in the EU from outside it? | Article 3(2); Article 27 representative. | |
| Is every processing activity in your Article 30 record, with a lawful basis? | Articles 5, 6 and 30; the upper tier covers lawful basis. | |
| Which transfers outside the EEA rely on which Article 46 safeguard? | The Meta and TikTok decisions were transfer cases. | |
| Is any decision about people fully automated? | The 2026 Uber decision turned on it. | |
| Are breaches logged with the notify or do not notify decision recorded? | Article 83(2)(h) looks at whether you notified. | |
| How many data subject requests are past the one month deadline? | Articles 12 to 22 sit in the upper tier. |
Start with the GDPR compliance checklist and the Article 30 register template, or take the free compliance check. Venvera's GDPR module keeps the register, DPIAs, the breach clock, transfers and data subject requests in one place, so the evidence that moves an Article 83(2) assessment already exists. The same logic for NIS2 is in our guide to NIS2 fines and penalties.

Frequently asked questions
What is the maximum GDPR fine?
EUR 20 million or 4% of the undertaking's total worldwide annual turnover of the preceding financial year, whichever is higher, under Article 83(5) and 83(6).
Is the 4% calculated on profit or on the subsidiary's revenue?
Neither. It is turnover, and the undertaking is understood in the competition law sense, so the Court of Justice has held it is the turnover of the whole group.
Can several fines be added up?
For the same or linked processing operations, the total cannot exceed the amount for the gravest infringement. Separate fines within that cap are possible.
Does the GDPR apply to companies outside the EU?
Yes, under Article 3(2), when they offer goods or services to people in the Union or monitor their behaviour there. Article 27 then requires a representative in the Union, subject to narrow exceptions.
Has anything in Article 83 changed in 2026?
No. The case law, the EDPB guidance and the procedural rules around it have, and Regulation (EU) 2025/2518 applies from 2 April 2027.
Primary sources
Article text from Regulation (EU) 2016/679: Articles 3(2), 27, 58(2), 82, 83 and 84, recitals 150 and 151. Case law from the Court of Justice press release 184/23 on C-683/21 and C-807/21. Method from EDPB Guidelines 04/2022 and EDPB Guidelines 04/2026. Procedure from Regulation (EU) 2025/2518. Decisions from the DPC on Meta, TikTok, LinkedIn and Google, the Autoriteit Persoonsgegevens on Uber and the CNPD on Amazon. Several decisions are under appeal; check their status before citing them.





