FULL ARTICLE TEXT
Article 83 in full
Article 83: General conditions for imposing administrative fines
1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.
2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to a list of factors (points (a) to (k)), including the nature, gravity and duration of the infringement, its intentional or negligent character, and the degree of cooperation with the supervisory authority.
3. If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.
4. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43; (b) the obligations of the certification body pursuant to Articles 42 and 43; (c) the obligations of the monitoring body pursuant to Article 41(4).
5. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9; (b) the data subjects' rights pursuant to Articles 12 to 22; (c) the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49; (d) any obligations pursuant to Member State law adopted under Chapter IX; (e) non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2) or failure to provide access in violation of Article 58(1).
6. Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher.
Read the full text on EUR-Lex (CELEX 32016R0679, Article 83).
The two tiers, and which articles fall in each
The single most important thing Article 83 does is sort every GDPR obligation into one of two ceilings. The tier is not a matter of discretion: it follows mechanically from which provision was infringed. The lower tier covers the machinery of compliance; the upper tier covers the rights and principles that the machinery exists to protect.
LOWER TIER / TIER 1
€10M or 2%
Article 83(4). Controller, processor and body obligations.
- Arts 8, 11: child's consent, processing not requiring identification
- Arts 25-39: data protection by design, records, security (Art 32), breach notification (Arts 33-34), DPIAs (Art 35), the DPO (Arts 37-39)
- Arts 42, 43: certification and certification-body duties
- Art 41(4): monitoring-body duties
UPPER TIER / TIER 2
€20M or 4%
Article 83(5) and (6). The substantive rules.
- Arts 5, 6, 7, 9: processing principles, lawful basis, consent, special categories
- Arts 12-22: transparency and data subject rights (access, erasure, portability, objection)
- Arts 44-49: international transfers (Chapter V)
- Chapter IX: national-law obligations
- Art 83(6): ignoring a supervisory authority's order
A single decision can straddle both tiers. Where a controller both fails to secure data (Article 32, lower tier) and processes it without a lawful basis (Article 6, upper tier), the authority calculates within the higher ceiling. Article 83(3) then caps the combined fine for the same or linked processing at the amount for the gravest infringement, so the tiers do not simply stack.
How the cap actually bites: fixed amount versus turnover
Each tier is a maximum expressed two ways, and the higher of the two applies. For a small controller with, say, 4 million euros of annual turnover, 4% is 160,000 euros, well below the 20 million euro figure, so the fixed 20 million euro amount is the theoretical ceiling and the fine is set far beneath it using the Article 83(2) factors. For a multinational the arithmetic inverts: 4% of a hundred-billion-euro group turnover dwarfs 20 million euros, so the percentage becomes the operative ceiling. This is why the largest fines on the register are quoted as absolute euro amounts that far exceed 20 million: they are percentages of very large turnovers, still sitting below the 4% maximum after the Article 83(2) weighting.
The turnover figure is the total worldwide annual turnover of the whole undertaking, not the EU-only revenue and not the turnover of the specific legal entity that was fined. Undertaking is read in the EU competition-law sense, so a subsidiary's exposure is calculated on the global revenue of the corporate group of which it forms part. In the WhatsApp decision the DPC assessed the fine against the turnover of the Meta parent undertaking, not WhatsApp Ireland in isolation.
Setting the amount within the ceiling: Article 83(2)
The tier fixes the ceiling; Article 83(2) fixes the amount beneath it. The authority gives due regard to ten factors: the nature, gravity and duration of the infringement; its intentional or negligent character; actions taken to mitigate the damage; the degree of responsibility given the technical and organisational measures in place; relevant previous infringements; the degree of cooperation with the authority; the categories of personal data affected; how the authority became aware of the infringement; compliance with any previously ordered measures; and adherence to approved codes of conduct or certification. Each factor can push the figure up (aggravating) or down (mitigating). The British Airways decision is the clearest worked example: an initially proposed fine of around 204 million euros was reduced to 22 million after cooperation, remedial action and the pandemic's economic impact were weighed in.
Our how GDPR fines are calculated guide walks through each of the ten factors with real decisions, and the Article 83 fine calculator on the homepage estimates a range from the same inputs.
Beyond the fine: corrective powers
Article 83(2) makes clear that an administrative fine can be imposed instead of, or in addition to, the corrective measures in Article 58(2). Those measures, warnings, reprimands, compliance orders, temporary or permanent processing bans, suspension of data flows to a third country, and orders to rectify or erase data, often carry greater operational weight than the monetary penalty. Meta was ordered to suspend transatlantic transfers alongside its 1.2 billion euro fine, an order that threatened the architecture of the service itself. Ignoring such an order is itself an upper-tier infringement under Article 83(6).