Skip to main content
Praxikon

Direct answer · GDPR

What fine applies to an infringement of the GDPR, for example a missing DPIA?

Short answer

The GDPR has two tiers of fines. Up to EUR 10 million or, for an undertaking, 2% of total worldwide annual turnover applies to, among others, the DPIA obligation, security and breach notification (Article 83(4)). Up to EUR 20 million or 4% applies to the principles and legal bases, the rights of data subjects and transfers (Article 83(5)). A missing DPIA can lead to a fine on its own.

Direct answer · GDPR

Fines under the GDPR

The GDPR has two tiers of fines. Up to EUR 10 million or, for an undertaking, up to 2% of total worldwide annual turnover if that is higher, for infringements of, among others, Articles 25 to 39 (Article 83(4)(a)). These include the DPIA obligation (Article 35), security (Article 32) and the notification of personal data breaches (Articles 33 and 34). Up to EUR 20 million or 4% for infringements of the principles and legal bases, the rights of data subjects and the rules on transfers (Article 83(5)). The absence of a required DPIA can therefore lead to a fine on its own: the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) fined International Card Services EUR 150,000 for not carrying out a DPIA for the digital identification of customers.

For you to establish

  • Which article was infringed? That determines the tier of the fine.

Articles

  • Art. 83(4)(a) GDPR Infringements of Articles 8, 11, 25 to 39, 42 and 43: up to EUR 10 million or 2% of total worldwide annual turnover.
  • Art. 83(5)(a) to (c) GDPR Principles and legal bases, rights of data subjects, transfers: up to EUR 20 million or 4%.
  • Art. 83(2) GDPR What the supervisory authority takes into account when setting the amount.

Guidelines and decisions

Enforcement

Read the article Check your own case General interpretation, not legal advice. The official source remains authoritative.

Check your own situation

Describe your system or project in the free case check and get a reasoned first assessment of, among other things, the DPIA obligation, Article 22 GDPR and the AI Act, with the source for every conclusion.

Go to the free case check
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist