Since its implementation in 2018, the General Data Protection Regulation (GDPR) has reshaped global data privacy standards. While its principles are well understood, the methodology applied by Data Protection Authorities (DPAs) to calculate fines remains complex.

The Fine Tiers

GDPR Article 83 establishes two tiers of administrative fines, depending on the nature of the infringement:

  • Standard Tier (Up to €10 million or 2% of global turnover): Applies to administrative failures, such as failing to maintain records of processing activities (Article 30), not conducting a Data Protection Impact Assessment (Article 35), or failing to implement privacy by design (Article 25).
  • Higher Tier (Up to €20 million or 4% of global turnover): Applies to severe violations affecting fundamental rights, such as breaching the core principles of processing (Article 5), lack of lawful basis (Article 6), violating data subject rights (Articles 12-22), or unauthorized international data transfers (Articles 44-49).

Calculation Methodology (EDPB Guidelines 04/2022)

To ensure consistency across the EU, the European Data Protection Board (EDPB) adopted binding guidelines outlining a five-step methodology for calculating fines:

Step 1: Identifying the Infringement

The DPA assesses whether the infringement involves one or multiple processing operations. If multiple infringements occur in the same operation, the fine cannot exceed the maximum amount for the gravest infringement.

Step 2: Starting Amount

The starting amount is calculated based on three factors:

  1. Nature of Infringement: Determining if it falls under the standard or higher tier.
  2. Seriousness: Classified as low, medium, or high severity based on the number of subjects affected, the purpose of processing, the level of damage, and the intentional or negligent character of the infringement.
  3. Turnover of the Undertaking: The starting amount is adjusted proportionally to the global annual turnover of the parent company (the "undertaking").

Step 3: Aggravating and Mitigating Factors

The starting amount is adjusted based on specific circumstances (Article 83(2)):

  • Aggravating: Previous infringements, failure to notify the DPA promptly, financial benefits gained from the breach.
  • Mitigating: Proactive mitigation of damage, high degree of cooperation with the DPA, robust previous technical/organizational measures.

Step 4: Legal Maximums

The calculated amount is verified against the statutory maximums (€10m/2% or €20m/4%).

Step 5: Effectiveness, Proportionality, and Dissuasiveness

The final amount is adjusted to ensure it serves as an effective deterrent without being disproportionate.

Notable Enforcement Precedents

  • Meta (Ireland DPA, 2023): €1.2 billion. For transferring EU user data to the US without adequate safeguards (Article 46).
  • Amazon (Luxembourg DPA, 2021): €746 million. For processing user data for targeted advertising without valid consent (Article 6).
  • H&M (Hamburg DPA, 2020): €35.2 million. For excessive monitoring and profiling of employee data.

Compliance Requirements

To mitigate enforcement risk, organizations must document their processing activities comprehensively, conduct regular DPIAs for high-risk operations, and ensure a rapid response protocol for data breaches (within 72 hours).