Home Blog Biggest GDPR Fines

Jump to Section

Quick Facts — GDPR Compliance Lawyers

GDPR fines have been a hot topic since the law’s European inception. To avoid incurring penalties, data controllers and processors should have the proper protocols and contracts in place, including data transfer agreements , data processing agreements , and data protection agreements .

In this article, we help you understand penalties surrounding GDPR violations, offer real-world examples, and show you how to calculate GDPR fines.

What is the Penalty for a GDPR Violation?

The penalties for a General Data Protection Regulation (GDPR) violation can result in up to twenty million euros or four percent of the company’s global annual revenue from the previous year, whichever number is higher. EU legislators impose fines for penalties to enforce data protection compliance.

You can learn more about the GDPR through this web page .

GDPR Fine Examples

It is hard to imagine the magnitude of how massive GDPR fines can grow. Since penalties are variable according to the number of records exposed and the severity of the breach, they can easily reach the multi-million dollar range. In the last few years, there have been several high-profile GDPR breach cases with alarmingly high fines.

Here is an explanation of nine GDPR fine examples below:

Example 1. Amazon: $877 Million

Amazon received a massive GDPR fine. The violation relates to the companies cookie policy and consent procedures. This GDPR fine is not the first received by Amazon as they faced a $40,000 fine at the tail-end of 2020.

Example 2. Google: $56.6 Million

In 2019, Google received its fine in March 2020 and was the largest on record until the Amazon violation. They were fined for how Google communicated privacy policies to users. In this case, Google should have offered end-users more information in their privacy policy and user agreement .

Example 3. H & M: $41 million

German authorities fined H & M around $41 million for employee data violations. H & M did not take proper precautions to protect employee days off and unnecessarily shared videos of meetings with 50 other H & M managers. These meetings were used to make decisions about the employee’s performance without their knowledge or consent.

Example 4. British Airways: $26 million

British Airways received a GDPR fine related to a 2018 incident. Their fine was the result of a breached computer system that affected over 400,000 customers. Customer information, payment details, and log-in information were exposed at the time of the breach.

Example 5. Marriott: $23.8 million

After a database breach, Marriott hotels exposed 383 million guest records, and hackers obtained all collected customer information. The company could have avoided the fine if they had paid due diligence after acquiring Starwood Hotels.

Example 6. Google: $8.3 million

Google received another fine in 2020 for a GDPR violation. Sweden fined Google for failing to remove search result listings under the right to be forgotten principle. The search provider should have honored this right by ensuring that a process was available to respond to erasure requests without unnecessary delay.

Example 7. Fastweb: $5.5 million

This Italian telecommunications company received a massive fine in 2021 after engaging in telemarketing without obtaining consumer consent. The company was using fake or false telephone numbers that were not registered with communication operators, and Fastweb should have obtained consumer consent beforehand since this standard is very high.

Example 8. Bulgaria’s National Revenue Agency: $3 million

Bulgaria’s National Revenue Agency received a fine after a data breach affected five million people. The information leaked included names, contact details, and tax information. The agency failed to take proactive and effective technological measures to protect the data in its control.

All GDPR penalties are paid to the Information Commissioner’s Office (ICO) and into a government fund owned by the treasury. GDPR fines are utilized to fund public resources and services, and most European nations use the structure.

This article also contains examples of GDPR fines.

Meet some lawyers on our platform

Ryenne S.

953 projects on CC
CC verified
View Profile

Daniel R.

312 projects on CC
CC verified
View Profile

Stephen R.

15 projects on CC
CC verified
View Profile

Lori B.

192 projects on CC
CC verified
View Profile

How are GDPR Fines Calculated?

GDPR fines are calculated in generally the same manner as described in this article. However, several factors influence the total fine amount, including company size, size class, subcategory, average annual turnover, and the facts and circumstances of the violation. You should always work with a legal professional to help you determine if the GDPR fine you are receiving is fair and how to protect unfair or incorrect amounts.

Here are five steps for calculating GDPR fines:

Step 1. Categorize Your Company’s Size

Start by categorizing your company’s size. You can find your GDPR size class and subcategories through the GDPR website for more information.

Step 2. Account for Your Average Annual Turnover

After locating your company’s subgroup, determine the average annual turnover to which your company belongs. If your annual turnover exceeds 500 million euros, the maximum fine of two or four percent should be applied to your situation.

Step 3. Divide Your Average Annual Turnover by 360

In this next step, you will divide your average annual turnover by 360. This calculation determines the fine’s basic economic value.

Step 4. Classify the Basic Value Factor

Take the number from step three and classify the basic value factor. This number is defined as the severity of your offense. Determination of your basic value factor is based on concrete facts and circumstances and listed as light, medium, severe, or very severe.

Step 5. Adjust the Calculation

Finally, you will want to take your calculated amount and adjust it for the circumstances both in favor of and against the tortfeasor. Typically, these circumstances surround offense-related details, such as proceeding length and company insolvency. Depending upon the facts and circumstances, there could be reductions or increases that apply to your final number.

For greater clarity on calculating a GDPR fine, you can use the following formula to help:

Average annual turnover x Basic value factor = Amount of fine

It is not always easy to calculate a GDPR violation without professional help. Here is a web page that discusses penalties for GDPR violations.

Maximum Fine for Breach of GDPR

The maximum fine for a breach of the GDPR is 20 million euros or four percent of the preceding year’s revenues. A company will receive a penalty that is the greater of the two numbers. However, not every violation results in a data protection fine.

There is a wide range of other actions that they can take against offending companies, including:

  • Issuing reprimands and warnings
  • Temporarily or permanently banning data processing rights
  • Ordering the restriction or erasure of personally identifiable information (PII)
  • Rescinding data transfer rights to other countries

There are a host of penalties that the GDPR can impose. Check out this article for examples of GDPR breach costs.

Can an Individual be Fined for GDPR Breach?

Yes, an individual can be fined for a GDPR breach if they engage in a legitimate business. Otherwise, the violation falls under criminal activity and subsequent legal charges. If you have questions about whether you could be fined for a GDPR breach, speak with GDPR compliance lawyers to apply the law to your situation.

GDPR compliance is essential when soliciting Europeans and collecting their information. Otherwise, severe fines and penalties are on the line, not to mention the damage to your brand and intellectual property. Privacy lawyers in your state will help you understand the rules provided in the GDPR and how to structure your agreements so that they meet the requirements.


ContractsCounsel is not a law firm, and this post should not be considered and does not contain legal advice. To ensure the information and advice in this post are correct, sufficient, and appropriate for your situation, please consult a licensed attorney. Also, using or accessing ContractsCounsel's site does not create an attorney-client relationship between you and ContractsCounsel.


Need help with a GDPR Compliance?

Create a free project posting
Clients Rate Lawyers 4.9 Stars
based on 19,284 reviews

Meet some of our Lawyers

Alexander N. on ContractsCounsel
View Alexander
5.0 (62)
Member Since:
June 17, 2024

Alexander N.

Founder
Free Consultation
Los Angeles, California
10 Yrs Experience
Licensed in CA
University of Southern California Gould School of Law

Having overseen over $1.2 billion in transaction value, we are able to provide top-tier service at affordable rates, with much more personalized attention and fast turnarounds. After working for a AM Law Top 100 firm, I started my own firm and have been lucky enough to represent numerous conglomerates (FOX, Endeavor, etc.), promising startups, small businesses and private individuals. Our areas of expertise - Business Formations and Operating Agreements; Capital Raises and Debt Financing; Commercial Transactions; M&A; Real Estate; Intellectual Property; Employment and Hiring; Outside General Counsel; Corporate Agreements and Governance; Litigation and Dispute Resolution. We have been featured in The Wall Street Journal, Marketwatch, Yahoo Finance, Variety, Business Insider, Los Angeles Magazine, the LA Times, and others. We are driven by an unwavering commitment to our clients, going above and beyond to deliver results.

Recent  ContractsCounsel Client  Review:
5.0

"Very fast turnaround time, easy to work with, appreciate the contract review!"

Tim E. on ContractsCounsel
View Tim
4.8 (63)
Member Since:
August 12, 2020

Tim E.

Founding Member/Attorney
Free Consultation
Cleveland, OH
12 Yrs Experience
Licensed in OH
Cleveland State University College of Law

Tim advises small businesses, entrepreneurs, and start-ups on a wide range of legal matters. He has experience with company formation and restructuring, capital and equity planning, tax planning and tax controversy, contract drafting, and employment law issues. His clients range from side gig sole proprietors to companies recognized by Inc. magazine.

Recent  ContractsCounsel Client  Review:
5.0

"Tim was excellent! I gave him project details (liability waiver and rental agreement) and what I needed and he produced the day he said he would with ZERO revisions needed. Highly recommend."

Scott S. on ContractsCounsel
View Scott
5.0 (62)
Member Since:
October 27, 2021

Scott S.

Attorney
Free Consultation
New York, NY
19 Yrs Experience
Licensed in NY
Benjamin Cardozo School of Law

I specialize in business law and contracts, with an emphasis on commercial transactions and negotiations, document drafting and review, employment, business formation, e-commerce, technology, healthcare, privacy, commercial real estate, data security and compliance. Specifically, I've drafted, reviewed and/or negotiated thousands of MSA's, NDA's, TOS', SAAS, sales, service, managed services, referral, reseller, royalty, finder’s fee, employment, contractor, consulting, advertising, marketing, manufacturing, distribution, management, artist, author, agency, photography, rental, lease, vendor, partnership, website, platform, application, privacy, non-compete, non-circumvent, confidentiality, IP ownership and licensing agreements so I'm very familiar with these types of documents. Practicing law since 2006, I worked in-house before starting my own solo practitioner law firm in 2011. I've worked with individuals and start-ups, Fortune 500 companies, and every type of entity in between, always providing quality legal work that fits the exact needs of the person and/or business. I’m a graduate of the Benjamin Cardozo Law School and also have an English degree from Penn.

Recent  ContractsCounsel Client  Review:
5.0

"Very helpful and appreciated being able to go over the contract revisions and clarification questions I had, thank you!"

Edward R. on ContractsCounsel
View Edward
5.0 (1)
Member Since:
August 20, 2023

Edward R.

Attorney
Free Consultation
San Diego, CA
23 Yrs Experience
Licensed in CA
University of San Diego

I have been a California since 2003 when I graduated from the University of San Diego School of Law and have worked in-house and at several major law firms before starting my own practice. I specialize in intellectual property and other business-related issues and have helped many entrepreneurs grow their ideas into profitable businesses.

Recent  ContractsCounsel Client  Review:
5.0

"An amazing attorney with excellent communication! We hired him for a Trademark application and we were pleased with every aspect of the process. Highly recommend!!"

Thomas B. on ContractsCounsel
View Thomas
Member Since:
July 2, 2023

Thomas B.

Attorney
Free Consultation
Indianapolis
36 Yrs Experience
Licensed in IN
Indiana University

Accomplished Attorney with 33 years of experience assisting clients with their legal needs, including reviewing and drafting of various contracts and agreements.

George K. on ContractsCounsel
View George
Member Since:
July 2, 2023

George K.

Owner & Managing Partner
Free Consultation
Denver, No. CO, Steamboat Springs
28 Yrs Experience
Licensed in CO
Whittier School of Law

I've represented small, medium, and Fortune 500 companies in business and litigation matters over the past twenty years. Working for various clients exposed me to a wide range of practice areas and issues. I now manage and own my firm. Contract review and drafting, negotiating agreements and settlements, and defending a variety of lawsuits is the heart of my practice. I'm efficient, solution driven, and work well with clients, other parties, and opposing counsel. I was awarded the American Jurisprudence Award in Advanced Legal Writing and am an excellent writer. I'm also the recipient of the Outstanding Young Lawyer Award and the ABA Military Pro Bono Project Outstanding Services Award. I'm a Marine Corps veteran. My attitude, experience, and expertise will help you achieve your goals.

Eleanor W. on ContractsCounsel
View Eleanor
Member Since:
July 3, 2023

Eleanor W.

Attorney
Free Consultation
Bellevue, WA
14 Yrs Experience
Licensed in WA
Seattle University School of Law

I have been working as a document review attorney since 2011. I have also done some business and estate planning work. I am fluent in English, Chinese, French, and Japanese.

Find the best lawyer for your project

Browse Lawyers Now

See Real GDPR Compliance Projects

New York GDPR Website Privacy and Contractual Clause Drafting
  • New York
  • 5 lawyer bids
  • $850 - $1,750
View Details
Maryland GDPR Complaint Response Drafting
  • Maryland
  • 2 lawyer bids
  • $1,200 - $1,350
View Details
Virginia Attorney Needed to Review Privacy and Cookie Policies for Car Aggregator Platfor Review
  • Virginia
  • 5 lawyer bids
  • $249 - $1,400
View Details

Quick, user friendly and one of the better ways I've come across to get ahold of lawyers willing to take new clients.

View Trustpilot Review

Need help with a GDPR Compliance?

Create a free project posting
Clients Rate Lawyers 4.9 Stars
based on 19,284 reviews
CONTRACT LAWYERS BY TOP CITIES
See All Privacy Lawyers
GDPR FINES LAWYERS BY CITY
See All GDPR Fines Lawyers

Contracts Counsel was incredibly helpful and easy to use. I submitted a project for a lawyer's help within a day I had received over 6 proposals from qualified lawyers. I submitted a bid that works best for my business and we went forward with the project.

View Trustpilot Review

I never knew how difficult it was to obtain representation or a lawyer, and ContractsCounsel was EXACTLY the type of service I was hoping for when I was in a pinch. Working with their service was efficient, effective and made me feel in control. Thank you so much and should I ever need attorney services down the road, I'll certainly be a repeat customer.

View Trustpilot Review

I got 5 bids within 24h of posting my project. I choose the person who provided the most detailed and relevant intro letter, highlighting their experience relevant to my project. I am very satisfied with the outcome and quality of the two agreements that were produced, they actually far exceed my expectations.

View Trustpilot Review

Need help with a GDPR Compliance?

Create a free project posting
Clients Rate Lawyers 4.9 Stars
based on 19,284 reviews

Want to speak to someone?

Get in touch below and we will schedule a time to connect!

Request a call

Find lawyers and attorneys by city