GDPR Certification Topic

How Are GDPR Fines Calculated? Article 83 & EDPB Guidelines

Updated: 08/2026 • Evidence-based on Article 83 GDPR and EDPB Guidelines 04/2022
GDPR fines are calculated using a five-step methodology that starts by identifying the infringement, determining a baseline amount based on the company's worldwide turnover and the severity of the breach, applying aggravating or mitigating factors, checking against the absolute statutory caps, and ensuring proportionality. This standardized approach by the European Data Protection Board (EDPB) ensures consistent enforcement across the EU.

Key Facts

Primary Law:
Article 83 GDPR
Methodology:
EDPB Guidelines 04/2022
Maximum Limit:
€20 million or 4% of global turnover

What is the maximum fine under the GDPR?

The absolute maximum administrative fine under the GDPR is up to €20 million or 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher, for serious infringements (Article 83(5)). For less serious infringements, such as failing to maintain records of processing activities, the limit is up to €10 million or 2% of total worldwide annual turnover, whichever is higher (Article 83(4)).

It is a common misconception that every GDPR violation automatically results in a multi-million euro fine. The statutory limits are merely "caps". In reality, supervisory authorities determine the final amount using a precise calculation method to ensure the fine is "effective, proportionate and dissuasive" (Article 83(1)).

The EDPB 5-Step Methodology for Calculating Fines

To calculate the exact fine, supervisory authorities follow a five-step methodology established in the EDPB Guidelines 04/2022 on the calculation of administrative fines. This prevents arbitrary decision-making.

StepAction by Supervisory Authority
Step 1Identify the processing operations and evaluate whether they constitute single or multiple infringements (Article 83(3)).
Step 2Determine the starting point for further calculation based on the nature, gravity, and duration of the infringement, taking into account the turnover of the undertaking.
Step 3Evaluate aggravating and mitigating circumstances related to the controller's or processor's past and present behavior, and adjust the starting amount accordingly (Article 83(2)).
Step 4Verify that the adjusted amount does not exceed the relevant legal maximums (the €10m/2% or €20m/4% caps).
Step 5Ensure that the final fine is effective, proportionate, and dissuasive, considering the undertaking's overall financial situation.

Which factors increase or decrease a GDPR fine?

During Step 3 of the calculation, supervisory authorities adjust the fine based on aggravating and mitigating factors listed in Article 83(2) GDPR.

Aggravating factors that can significantly increase the fine include intentional or highly negligent behavior, failure to take action to mitigate the damage suffered by data subjects, previous similar infringements, or poor cooperation with the supervisory authority.

Mitigating factors that can reduce the fine include proactive steps taken to mitigate damage (e.g., immediate data breach notification and rapid containment), adherence to approved codes of conduct or certification mechanisms, and a high degree of transparency and cooperation with the authority.

Are DPOs personally liable for GDPR fines?

No, Data Protection Officers (DPOs) are not personally liable for administrative fines under Article 83 GDPR; the fines are exclusively levied against the controller or the processor.

Under Article 38(3) GDPR, the controller or processor must ensure that the DPO "does not receive any instructions regarding the exercise of those tasks." Consequently, the legal responsibility for GDPR compliance, and thus the liability for fines, remains entirely with the organisation (the controller or processor), not the individual acting as DPO. For more on the DPO's role, refer to our guide on DPO requirements.

Frequently Asked Questions

How are GDPR fines calculated?
GDPR fines are calculated using a 5-step methodology established by the EDPB in Guidelines 04/2022. Supervisory authorities first identify the processing operations, evaluate the starting point of the fine based on the severity and turnover, adjust for aggravating or mitigating factors, ensure the fine does not exceed statutory caps, and finally check for proportionality.
What is the maximum fine under the GDPR?
Under Article 83(5), the maximum fine for serious infringements (like violating basic principles or data subject rights) is up to €20 million or 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher.
Does a company turnover affect the GDPR fine?
Yes, turnover plays a central role. Under the EDPB Guidelines 04/2022, a company’s worldwide annual turnover is used to adjust the starting amount of the fine to ensure it is effective and dissuasive, and it also dictates the absolute legal maximum (2% or 4%).
Are Data Protection Officers (DPOs) personally liable for GDPR fines?
No. Under the GDPR, administrative fines under Article 83 are levied against the controller or the processor, not the Data Protection Officer. The DPO acts in an advisory capacity.

Master the GDPR for your DPO Exam

Test your knowledge on Article 83, fines, and all GDPR requirements with our realistic mock exams.

Start Free Practice Test

Primary Sources & Verification

  • Regulation (EU) 2016/679 (GDPR), Article 83 (General conditions for imposing administrative fines) - EUR-Lex
  • European Data Protection Board (EDPB), Guidelines 04/2022 on the calculation of administrative fines under the GDPR (adopted 24 May 2023) - EDPB

Community context: Questions about how exact fine amounts are determined are frequent in privacy communities and DPO exams. The EDPB Guidelines 04/2022 provide the definitive harmonized answer across the EU.