GDPR Fines Explained: How €20M and 4% of Revenue Really Work
The '€20 million or 4% of global revenue' GDPR fine figure is a maximum, calculated per tier, not a flat penalty. Here's how the math actually works and what determines which tier applies.
The headline GDPR fine figure, up to €20 million or 4% of annual global revenue, gets repeated constantly, usually without the detail that makes it make sense: there isn’t one number, there are two tiers, and the calculation is “whichever is greater,” not a flat fee.
The two tiers, under Article 83
GDPR sets two maximum fine tiers, based on the nature of the violation:
- Lower tier: up to €10 million or 2% of annual global revenue, whichever is greater. This covers less severe violations, certain administrative and record-keeping obligations, for example.
- Upper tier: up to €20 million or 4% of annual global revenue, whichever is greater. This covers the most serious violations, breaches of core data processing principles, individual rights, or unlawful international data transfers.
“Whichever is greater” is the detail that matters for larger organizations: for a company with significant global revenue, 4% of that revenue can exceed €20 million, meaning the flat cap isn’t actually the ceiling, the percentage is. For a smaller business, the flat figure will typically be the larger (and therefore binding) number, since 2-4% of a modest revenue base is far below €10-20 million.
Why this rarely means what the headline implies
These are maximum figures a regulator can impose for the most serious findings, not typical or average penalties. Actual fines issued by EU data protection authorities have varied enormously based on the severity of the violation, whether it was a first offense, the size of the organization, and whether the company cooperated with the investigation. Most enforcement actions against small and mid-size businesses, where they occur at all, land well below the statutory maximum.
Usercentrics
Whatever your specific exposure works out to, most enforcement actions trace back to the same root cause, consent and disclosure gaps that a properly configured platform like Usercentrics is built to close.
What determines which tier and how severe
Article 83 lists factors regulators weigh: the nature, gravity, and duration of the infringement; whether it was intentional or negligent; how many people were affected; whether the organization took steps to mitigate harm; and prior compliance history. This is why two businesses with superficially similar violations can see very different outcomes, the calculation isn’t mechanical.
Where this connects to your own risk
If you’re trying to get a rough sense of your own theoretical maximum exposure under the upper tier specifically, our free GDPR fine calculator runs the revenue-based math for you, clearly labeled as an illustration of the statutory ceiling, not a prediction of what any actual enforcement action would look like.
The more useful takeaway
The size of the theoretical maximum is less actionable than understanding what actually triggers enforcement in the first place: consent that isn’t genuinely freely given, trackers firing before consent, and privacy policies that don’t match actual practice. See our piece on what a compliant cookie banner actually requires for the specific gap most sites should check first.
This guide is educational and not legal advice or a forecast of any specific enforcement outcome. For your specific situation, consult a privacy attorney.