How big could a GDPR fine get for your business? Enter your annual worldwide turnover and see the theoretical maximum exposure under both penalty tiers of Article 83 – plus how real enforcement compares.
–
These are theoretical maximums. Regulators set actual fines using the Article 83(2) factors – nature and duration of the infringement, intent or negligence, mitigation, cooperation, previous violations and more. Most fines land far below the cap, but “far below” can still hurt. Not legal advice.
Which violations fall under which tier?
| Tier | Cap | Typical violations |
|---|---|---|
| Lower – Art. 83(4) | €10M or 2% of worldwide turnover | Controller/processor obligations: records of processing, security measures, breach notification, data protection by design, DPO requirements |
| Upper – Art. 83(5) | €20M or 4% of worldwide turnover | Core principles: lawful basis, consent conditions, data subject rights (access, erasure…), unlawful international transfers |
Small businesses are not exempt. The percentage caps make headlines with big tech, but the flat €10M/€20M caps apply to everyone – and European DPAs routinely fine small companies four and five figures for missing privacy policies, unlawful cookies or ignored access requests. See the top GDPR mistakes WordPress site owners make.
How real fines compare
| Company | Fine | Year | What for |
|---|---|---|---|
| Meta | €1.2 billion | 2023 | Unlawful EU-US data transfers (Facebook data) |
| Amazon | €746 million | 2021 | Advertising consent violations |
| TikTok | €530 million | 2025 | Transfers of EEA user data to China, transparency failures |
| €225 million | 2021 | Transparency failures | |
| €50 million | 2019 | Lack of valid consent for ads personalization |
Reduce your exposure the boring way: a compliant privacy policy, a proper cookie consent setup, and a documented data audit address the violations regulators actually fine small websites for. Start with our free GDPR compliance checker.
