GDPR fines operate on a two-tier system that creates significant variation in the amounts businesses actually face. Understanding how fines are calculated — and what real enforcement cases show — is essential context for any business assessing its compliance risk.
The Two-Tier Fine Structure
GDPR Article 83 establishes two categories of maximum fine:
Tier 1 (up to €10 million or 2% of global annual turnover): Applies to violations of obligations including data breach notification requirements, data processor agreements and data protection by design requirements.
Tier 2 (up to €20 million or 4% of global annual turnover): Applies to violations of core GDPR principles including lawful basis for processing, consent requirements, data subject rights and international data transfers.
The critical word in both is “up to.” The maximum figures are theoretical ceilings, not standard outcomes. Regulators are required to impose fines that are “effective, proportionate and dissuasive” — which means small businesses face smaller absolute fines than large corporations, but proportionate to size and violation severity.
What Real Enforcement Cases Show
The enforcement record reveals significant variation in fine amounts based on the size of the organisation, the severity and duration of the violation, the degree of cooperation with investigators and whether the violation was negligent or intentional.
At the lower end: a Montessori school in Spain was fined €3,000 for operating a website without a cookie banner. A small company in Belgium was fined €15,000 for using pre-checked consent boxes. A Polish retailer was fined €25,000 for cookie consent failures.
At the middle range: Vueling Airlines was fined €30,000 in Spain. A French publisher was fined €750,000. An Austrian postal service was fined €18.1 million for using illegally obtained data for political profiling.
At the top: Meta has received fines of over €1.2 billion. Amazon was fined €746 million in Luxembourg. These headline figures involve global platforms with hundreds of millions of users and intentional, systemic violations — a very different situation from a small business with an uncompliant cookie banner.
Factors That Affect Fine Size
Regulators consider multiple factors when determining fine amounts:
- Nature and severity — how fundamental is the violation? Cookie consent failures are treated seriously.
- Duration — how long has the violation been ongoing? Fines increase with duration.
- Number of people affected — a national retailer’s website affects more people than a local service business.
- Intentional or negligent — intentional violations attract higher fines.
- Cooperation — businesses that cooperate with investigations and implement fixes promptly receive more favourable treatment.
- Previous violations — repeat offenders face higher fines.
- Financial situation — regulators consider the business’s ability to pay.
The Cost Comparison That Matters
Even at the lower end of the enforcement spectrum, fines for cookie consent violations run from €3,000 to €750,000 depending on the organisation and severity. Legal costs for responding to an investigation typically add €5,000 to €50,000 depending on complexity. Management time and operational disruption adds further cost that is difficult to quantify but real.
A professional compliance audit costs $540 to $1,625. The arithmetic is straightforward.
More importantly, a business that has completed a compliance audit and implemented its recommendations is in a fundamentally different legal position than one that has not. Even if a complaint is filed, demonstrating proactive compliance efforts significantly affects how regulators respond — both in terms of the severity of any enforcement action and the willingness to accept remediation rather than impose financial penalties.