Laws and fines

GDPR fines: what companies really pay

The two GDPR fine tiers, what drives the amount, and whether the regulation applies to a site outside the EU.

Checked against sources: 30 September 2026

  • €20Mor 4% of turnover, the top tier
  • €10Mor 2% of turnover, the lower tier
  • Art. 83where the regulation sets fines

Two tiers of fines

The higher of the two applies. The maximum is rarely imposed, but the figure shows how seriously regulators take the topic.

  • Up to €10M or 2% of global annual turnover (Article 83(4)): controller duties, such as security of processing.
  • Up to €20M or 4% of turnover (Article 83(5)): processing principles, consent, data subject rights.

What drives the amount

Article 83(2) tells authorities to weigh the gravity and duration of the breach, intent, the number of people affected, the steps taken and how the company cooperated. A small site with one mistake fixed quickly pays far less than a chain that ignored complaints for years.

What regulators most often find on sites

  • Analytics and ads load before consent.
  • No privacy policy, or one without the essentials: who the controller is, why the data is used, how long it is kept.
  • A form collects data with no policy link and no consent.
  • Withdrawing consent is harder than giving it.

Frequently asked

Does GDPR apply to a site outside the EU?

Yes, if you offer goods or services to people in the EU or monitor their behavior on your site (Article 3). A site from Kazakhstan with visitors from Germany falls under the regulation.

Is there a fine for a single cookie without consent?

There is no “per-cookie” fine. The regulator assesses the breach as a whole: what loaded, how many people were affected, how fast you fixed it.

Sources

Check your site

Awe Check shows in a minute which of this is broken on your site and calculates the possible fine.

Check a site