NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new →
GDPR Fines and Penalties: What Changed in 2026
Learn

GDPR Fines and Penalties: What Changed in 2026

·Alexander Sverdlov

The GDPR caps administrative fines at EUR 20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, for the most serious infringements, and at EUR 10 million or 2% for the rest. Article 83 has not been amended. What has changed is everything around it. The Court of Justice has ruled that a fine needs an infringement committed intentionally or negligently, and that the turnover is the whole group's. The European Data Protection Board publishes the method authorities use to set the amount, and on 17 September 2026 it adopted draft guidelines, for public consultation, on when to fine at all. And 2026 has brought some of the largest decisions yet, alongside the annulment of one of the best known.

The rules reach beyond the EU. Under Article 3(2) the GDPR applies to a controller or processor not established in the Union when it offers goods or services to people in the Union or monitors their behaviour there, and Article 27 then requires a representative in the Union. This guide takes each piece in turn: the tiers, whose turnover counts, fault, how the amount is built, the 2026 decisions, and the penalties that are not fines. For the incident side of the same exposure, see incident reporting deadlines by regulation.

QuestionShort answerSource
Maximum fineEUR 20 million or 4% of worldwide annual turnover, whichever is higherGDPR Article 83(5) and 83(6)
Lower tierEUR 10 million or 2%, whichever is higherGDPR Article 83(4)
Several infringementsTotal capped at the amount for the gravest, for the same or linked processingGDPR Article 83(3)
Whose turnoverThe undertaking in the competition law sense, so the groupRecital 150; CJEU C-807/21
FaultIntent or negligence must be establishedCJEU C-807/21 and C-683/21
How the amount is setFive steps, starting from seriousness and turnoverEDPB Guidelines 04/2022
New procedureCross-border procedural rules apply from 2 April 2027Regulation (EU) 2025/2518, Article 37
GDPR fine ceilings by provision: Article 83(4) up to 2% of turnover or EUR 10 million if higher, Article 83(5) up to 4% or EUR 20 million if higher, Article 83(6) up to 4% for not complying with an order, and Article 83(7) leaving fines on public bodies to each Member State

What are the GDPR fine tiers?

Two ceilings, each the higher of a fixed sum and a share of turnover. Article 83(4) sets up to EUR 10 million or, for an undertaking, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. It covers the controller and processor obligations in Articles 8, 11, 25 to 39, 42 and 43: data protection by design, records of processing, security, breach notification, DPIAs, the DPO. Article 83(5) doubles both figures for the basic principles and lawful bases in Articles 5, 6, 7 and 9, the data subject rights in Articles 12 to 22, international transfers under Articles 44 to 49, and non-compliance with an order of the supervisory authority. Article 83(6) repeats the higher ceiling for ignoring an order under Article 58(2).

Article 83(3) limits stacking. Where a controller or processor intentionally or negligently infringes several provisions "for the same or linked processing operations", the total "shall not exceed the amount specified for the gravest infringement." That is a cap on the total, not a rule that only one fine is imposed: the Irish DPC's 2025 TikTok decision consisted of EUR 485 million for Article 46(1) and EUR 45 million for Article 13(1)(f).

Whose turnover counts?

The group's. Recital 150 says that where fines are imposed on an undertaking, "an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU", the competition law concept. The Court of Justice applied it in Deutsche Wohnen (C-807/21) on 5 December 2023; in the Court's press release, "where the addressee of the fine forms part of a group of companies, the calculation of that fine must be based on the turnover of the entire group." A subsidiary with modest revenue inside a large group is exposed on the group's figure.

Can a company be fined without fault?

No. In the same judgments, C-807/21 and C-683/21, the Court held that a fine requires an infringement "committed wrongfully, that is to say, intentionally or negligently." The bar is not high: that is the case "where the controller could not have been unaware of the infringing nature of its conduct, regardless of whether or not it was aware of the infringement." A legal person is liable for its staff and need not have its management body involved, and the fine cannot be made conditional on first identifying a responsible individual.

Fault has consequences in practice. On 12 March 2026 Luxembourg's Cour administrative annulled the EUR 746 million fine the CNPD imposed on Amazon in 2021. The CNPD's own statement says the court annulled it on the basis of a development in Court of Justice case law that came after the CNPD's decision, in particular on whether Amazon showed a degree of negligence, while the main findings were confirmed. A fine decision now has to establish fault, not just the infringement.

Venvera GDPR dashboard showing the gap assessment score, processing activities, DPIAs completed, open data subject requests, active processing agreements, open breaches and international transfers

How do supervisory authorities calculate the amount?

With a five step method from EDPB Guidelines 04/2022, adopted after consultation on 24 May 2023. First, identify the processing operations and apply Article 83(3). Second, set a starting point from the tier, the seriousness of the infringement and the turnover. Third, apply aggravating and mitigating circumstances. Fourth, check the legal maximum, which no increase may exceed. Fifth, test whether the result is effective, dissuasive and proportionate.

The starting point is where the numbers live. For an infringement of low seriousness the authority picks a point "between 0 and 10% of the applicable legal maximum"; medium is between 10 and 20%; high is between 20 and 100%. Smaller undertakings then get a turnover adjustment: at a turnover of EUR 2 million or less, authorities may proceed on 0.2% to 0.4% of the starting amount; from EUR 2 million to 10 million, 0.3% to 2%; from EUR 10 million to 50 million, 1.5% to 10%. The Article 83(2) factors, from the duration of the infringement and the number of people affected to cooperation, previous infringements and whether you notified, are what move a case up or down.

Whether to fine at all is the subject of the newer EDPB Guidelines 04/2026, adopted for public consultation on 17 September 2026. They set out another five steps. The first three are legal preconditions, the third being intent or negligence. If the Article 83(2) factors show a minor infringement, "as a general rule, the supervisory authority will not impose an administrative fine"; if not, "there is a strong presumption to impose an administrative fine." They are a consultation draft, so they may change.

How a supervisory authority builds a GDPR fine under EDPB Guidelines 04/2022: identify the processing operations, set the starting point, apply aggravating and mitigating factors, apply the legal maximum, and check the result is effective, proportionate and dissuasive

What changed in 2026?

Not Article 83. Four things moved around it. The decisions got larger: on 21 August 2026 the Dutch Autoriteit Persoonsgegevens fined Uber EUR 824,990,000 for fully automated decisions about drivers and insufficient information to them, and Uber has appealed; on 21 September 2026 the Irish DPC fined Google EUR 403 million following an inquiry into its processing of location data. The Amazon fine was annulled, as above. The EDPB opened its consultation on when to fine. And the procedural rules are fixed: Regulation (EU) 2025/2518, published on 12 December 2025, lays down additional procedural rules for cross-border enforcement and applies from 2 April 2027. Under its Article 19, a lead authority considering a fine must list in its preliminary findings the main elements it intends to rely on, including the Article 83(2) factors, so you see the case before the decision.

One more item is a proposal, not law. The Commission's digital omnibus, COM(2025) 837 of 19 November 2025, proposes amendments to the GDPR among other acts; as proposed, it does not amend Article 83.

Which decisions set the scale?

These are recent decisions, with figures from each authority's own announcement. Several are under appeal.

CompanyAuthorityAmountWhat it was for
Meta Platforms IrelandIrish DPC, decision of 12 May 2023EUR 1.2 billionTransfers to the US in breach of Article 46(1), plus an order to suspend them
UberDutch AP, 21 August 2026EUR 824,990,000Fully automated decisions about drivers; under appeal
TikTokIrish DPC, announced 2 May 2025EUR 530 millionTransfers to China under Article 46(1) and transparency under Article 13(1)(f)
GoogleIrish DPC, 21 September 2026EUR 403 millionProcessing of location data
LinkedInIrish DPC, 24 October 2024EUR 310 millionLawful basis, transparency and fairness for behavioural analysis and targeted advertising
UberDutch AP, 2024EUR 290 millionTransfers of drivers' data to the US

What penalties are there besides fines?

Often the more expensive ones. Article 58(2) gives authorities corrective powers that run alongside a fine or instead of it, including "a temporary or definitive limitation including a ban on processing" under point (f) and the power "to order the suspension of data flows to a recipient in a third country" under point (j). The Meta decision ordered the suspension of future transfers to the US; the TikTok decision ordered transfers to China to stop if processing was not brought into compliance within six months. For a business built on that data flow, the order matters more than the fine.

Then there is private liability: under Article 82(1) anyone who has suffered "material or non-material damage" from an infringement can claim compensation from the controller or processor. Article 84 requires Member States to set other penalties, in particular for infringements not covered by Article 83. Article 83(7) leaves fines on public authorities to each Member State, and recital 151 explains that in Denmark and Estonia, whose legal systems do not provide for administrative fines, fines are imposed through the courts or a misdemeanour procedure.

GDPR exposure beyond the fine: Article 58(2) orders, Article 58(2)(f) bans on processing, Article 82 damages claims, Article 84 national penalties, the Article 83(2) criteria and the Article 3(2) reach to companies outside the EU

What the other results get wrong

Page one for this query is mostly vendor blogs and statistics pages. Four errors recur. Several say 4% of "revenue" or "sales"; the text says total worldwide annual turnover of the preceding financial year, and since Deutsche Wohnen that means the group's. Some drop "whichever is higher" from the lower tier, which makes EUR 10 million read like a fixed cap. Several still list Amazon's EUR 746 million as a standing fine, months after the Cour administrative annulled it. And at least one reads Article 83(3) as meaning a single fine is imposed for the most serious violation, when it caps the total and decisions such as TikTok's impose separate fines for separate infringements.

An illustrative view of the records a supervisory authority asks for first: processing activities recorded, breaches logged with a decision, DPIAs for high risk processing, and data subject requests past the one month deadline

Work out your own exposure

Fill this in before you need it. The Article 83(2) factors reward the organisation that can show its records on the first day of an inquiry.

QuestionYour answerWhy it matters
What was group worldwide turnover last financial year?Sets the ceiling; recital 150 and C-807/21.
Do you offer goods or services to, or monitor, people in the EU from outside it?Article 3(2); Article 27 representative.
Is every processing activity in your Article 30 record, with a lawful basis?Articles 5, 6 and 30; the upper tier covers lawful basis.
Which transfers outside the EEA rely on which Article 46 safeguard?The Meta and TikTok decisions were transfer cases.
Is any decision about people fully automated?The 2026 Uber decision turned on it.
Are breaches logged with the notify or do not notify decision recorded?Article 83(2)(h) looks at whether you notified.
How many data subject requests are past the one month deadline?Articles 12 to 22 sit in the upper tier.

Start with the GDPR compliance checklist and the Article 30 register template, or take the free compliance check. Venvera's GDPR module keeps the register, DPIAs, the breach clock, transfers and data subject requests in one place, so the evidence that moves an Article 83(2) assessment already exists. The same logic for NIS2 is in our guide to NIS2 fines and penalties.

Venvera GDPR gap assessment, a completed 48 question assessment across eight chapters with an overall score
The bottom line on GDPR fines: the ceiling is the higher of a fixed sum and a share of group turnover

Frequently asked questions

What is the maximum GDPR fine?

EUR 20 million or 4% of the undertaking's total worldwide annual turnover of the preceding financial year, whichever is higher, under Article 83(5) and 83(6).

Is the 4% calculated on profit or on the subsidiary's revenue?

Neither. It is turnover, and the undertaking is understood in the competition law sense, so the Court of Justice has held it is the turnover of the whole group.

Can several fines be added up?

For the same or linked processing operations, the total cannot exceed the amount for the gravest infringement. Separate fines within that cap are possible.

Does the GDPR apply to companies outside the EU?

Yes, under Article 3(2), when they offer goods or services to people in the Union or monitor their behaviour there. Article 27 then requires a representative in the Union, subject to narrow exceptions.

Has anything in Article 83 changed in 2026?

No. The case law, the EDPB guidance and the procedural rules around it have, and Regulation (EU) 2025/2518 applies from 2 April 2027.

Primary sources

Article text from Regulation (EU) 2016/679: Articles 3(2), 27, 58(2), 82, 83 and 84, recitals 150 and 151. Case law from the Court of Justice press release 184/23 on C-683/21 and C-807/21. Method from EDPB Guidelines 04/2022 and EDPB Guidelines 04/2026. Procedure from Regulation (EU) 2025/2518. Decisions from the DPC on Meta, TikTok, LinkedIn and Google, the Autoriteit Persoonsgegevens on Uber and the CNPD on Amazon. Several decisions are under appeal; check their status before citing them.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING