Analysis

How Much Can I Actually Be Fined Under GDPR?

The €20M / 4% figure is a ceiling, not a typical outcome. Here's what fine amounts actually look like in practice across company sizes, not just the headline maximums.

Published September 1, 2026·Last updated September 1, 2026

The “€20 million or 4% of global annual revenue” figure gets quoted constantly, and it’s real, but it’s the statutory maximum, not a typical outcome, and it’s easy to come away thinking every GDPR violation risks an eight-figure fine. For the overwhelming majority of businesses, that’s not the realistic exposure. Here’s what fine amounts actually look like once you separate the ceiling from the norm.

The two tiers, briefly

GDPR sets two maximum tiers depending on which provisions are violated:

  • Up to €10M or 2% of global annual revenue (whichever is higher) for violations like inadequate security measures, missing records of processing, or failing to notify a breach.
  • Up to €20M or 4% of global annual revenue (whichever is higher) for violations of core principles, unlawful processing, violating data subject rights, or unlawful international transfers.

We break down exactly how regulators calculate within these ceilings, including the factors that push a fine up or down, in our fine-mechanics guide. This piece is about what actually happens in practice, at different business sizes.

What the biggest fines actually look like

The fines that make headlines, Meta’s €1.2 billion transfer-mechanism fine, Amazon’s €746 million advertising-consent fine, are almost exclusively large multinational companies with systemic, long-running violations affecting millions of users, often involving repeated regulatory warnings ignored over years. We go through the pattern behind these in our biggest GDPR fines analysis. These cases are not representative of what a small or mid-size business risks for a first-time, isolated compliance gap.

What fines actually look like for smaller businesses

Regulators are required by Article 83 to consider proportionality, factors include the nature and duration of the violation, whether it was negligent or intentional, how many people were affected, and whether the business cooperated and took corrective action. In practice, this means:

  • Small businesses with isolated, first-time violations (a missing cookie banner, a slow DSAR response) far more often see warnings, corrective orders, or fines in the low thousands to tens of thousands of euros, not headline-scale penalties.
  • Fine amounts scale with harm and revenue. A small business’s 4% revenue ceiling is a small business’s 4%, not a proportional share of Meta’s fine, the percentage-of-revenue mechanism is specifically designed to scale down for smaller entities.
  • Repeated or willful violations escalate quickly. A business that ignores a regulator’s warning and continues the same violation faces materially higher fines than one that fixes the issue promptly after being flagged.

The realistic exposure most businesses should plan around

For a typical small-to-mid-size business, the highest-probability GDPR risk isn’t a nine-figure fine, it’s a combination of: a complaint or audit triggering scrutiny, a finding of a specific technical gap (cookie consent, DSAR handling, missing DPA), and a fine or corrective order scaled to that specific gap and the business’s size. That’s still real money and real reputational cost, but it’s a different risk profile than the headline cases suggest.

Our recommendation

Usercentrics

Since consent and cookie-banner gaps are among the most commonly cited violations in actual enforcement actions, getting that specific control right closes off one of the most probable paths to a fine, well before revenue-scale exposure becomes relevant. Usercentrics is built around exactly that control.

Try Usercentrics

What actually reduces your exposure

  1. Fix known gaps proactively, cooperation and prompt correction are explicit mitigating factors under Article 83.
  2. Document your compliance efforts, a documented, good-faith compliance program is evidence against a finding of negligence or willfulness.
  3. Don’t wait for a complaint to check your cookie consent setup, it’s the single most commonly cited issue in real enforcement actions against smaller businesses.

This analysis is educational and not legal advice. Actual fine amounts depend on regulator discretion and case-specific facts; consult a privacy attorney for guidance on your specific risk exposure.