Fines
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Administrative fines imposed for GDPR violations
Overview
20 sources · Jul 23, 2026Legal Framework
Article 83 GDPR establishes the general conditions under which supervisory authorities may impose administrative fines for GDPR violations. The provision sets a two-tier maximum penalty structure. Under Article 83(4), violations of controller and processor obligations under Articles 8, 11, 25–39, 42, and 43 are subject to fines up to €10 million or, for undertakings, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. Article 83(5) elevates the ceiling to €20 million or 4% of worldwide annual turnover for violations of basic principles for processing (Articles 5, 6, 7, 9), data subject rights (Articles 12–22), transfers to third countries (Articles 44–49), and non-compliance with orders or processing restrictions imposed by supervisory authorities.
Article 83(2) requires authorities to consider the nature, gravity, and duration of the infringement, the number of data subjects affected, the level of damage suffered, the intentional or negligent character of the infringement, mitigating or aggravating factors, and the degree of cooperation with the authority. Article 83(3) provides that fines may be imposed in addition to, or instead of, corrective measures under Article 58(2). The AI Act (Article 100) and NIS2 (Article 34) replicate this administrative-fine model for their respective regulatory domains, applying similar turnover-based ceilings and criteria.
Key Developments
The CJEU in UI v Österreichische Post AG clarified that Articles 83 and 84 GDPR serve a punitive purpose independent of individual damage claims under Article 82. Administrative fines and civil compensation are complementary instruments: fines encourage systemic compliance, while Article 82 actions reinforce operational protection and deter recurrence. This means a controller may face both regulatory fines and civil liability for the same infringement.
The CJEU in Deutsche Wohnen SE v Staatsanwaltschaft Berlin confirmed that the turnover-based ceilings apply specifically to "undertakings," drawing on EU competition law concepts to determine whether an entity qualifies. The Court emphasized that the maximum amounts under Article 83(4) and (5) represent hard caps, and authorities must individually calibrate fines below those ceilings based on the Article 83(2) criteria.
The EDPB's Guidelines 04/2022 on the calculation of administrative fines provide a structured methodology, directing supervisory authorities to follow a multi-step process: determine the starting point based on the legal basis and turnover, then adjust upward or downward based on aggravating and mitigating circumstances, and finally check against the statutory maximum. This methodology aims to harmonize divergent national approaches.
The Italian Garante's €850,000 fine against a network of agencies processing data on behalf of Acea Energia demonstrates that liability extends to processors and their sub-processors, and that the interconnected nature of data flows across corporate networks can aggregate exposure significantly.
Practical Guidance
Map your processing activities to the correct fine tier. Violations of transparency obligations and lawful basis requirements (Articles 5, 6, 12–22) carry the higher 4% ceiling under Article 83(5), while technical and organizational obligation breaches (Articles 25–39) fall under the 2% tier under Article 83(4). Prioritize remediation accordingly.
Calculate group-level turnover exposure. The "undertaking" concept means fines are assessed against the consolidated worldwide annual turnover of the entire corporate group, not the individual subsidiary. Conduct group-wide risk assessments to understand maximum exposure.
Document mitigation efforts contemporaneously. Article 83(2) explicitly rewards cooperation with the supervisory authority and corrective action taken. Maintain audit trails of remediation steps, DPIA outcomes, and internal investigations to demonstrate good faith during enforcement proceedings.
Prepare for concurrent civil and administrative exposure. Following UI v Österreichische Post AG, a single infringement can trigger both regulatory fines and data subject compensation claims. Budget for both contingencies in incident response planning.
Monitor processor and sub-processor chains. The Italian Garante enforcement illustrates that liability propagates through processing networks. Contractual indemnities, audit rights, and breach notification clauses with processors must align with your own regulatory exposure under Article 83.