EU Regulation 2016/679 - Decision Register

ARTICLE 83 GDPR / ADMINISTRATIVE FINES

Article 83 GDPR Fines, the Two Administrative-Fine Tiers

Article 83 is the fining article. It sets two maximum tiers, ties each GDPR obligation to one of them, and lists the factors that fix the amount. Everything on this register is calculated within its ceilings.

Lower tier, Art 83(4)

€10M or 2% turnover

Upper tier, Art 83(5)

€20M or 4% turnover

Cap rule

Whichever is higher

Turnover basis

Worldwide, whole undertaking

Amount set by

Art 83(2), 10 factors

EDUCATIONAL ONLY

This page is a reference summary of a published regulator decision. It is not legal advice. Consult a qualified data protection lawyer for advice on your specific situation. The UK GDPR is a separate regime from the EU GDPR following Brexit. Always read the source decision in full before relying on any figure or quote.

DIRECT ANSWER / THE TWO TIERS

What are the GDPR Article 83 fine tiers?

Article 83 sets two maximum administrative-fine tiers, and the supervisory authority applies whichever figure is higher, the fixed euro cap or the percentage of the undertaking's total worldwide annual turnover in the preceding financial year.

LOWER TIER / ARTICLE 83(4)

€10M or 2%

Controller and processor obligations: security (Art 32), breach notification (Arts 33-34), DPO (Arts 37-39), DPIAs (Art 35), records and by-design duties (Arts 8, 11, 25-39), plus certification (Arts 42, 43) and monitoring bodies (Art 41(4)).

UPPER TIER / ARTICLE 83(5)

€20M or 4%

The core rules: processing principles and lawful basis (Arts 5, 6, 7, 9), data subject rights (Arts 12-22), international transfers (Arts 44-49), Chapter IX national-law obligations, and non-compliance with a supervisory authority's order (Art 83(6)).

FULL ARTICLE TEXT

Article 83 in full

Article 83: General conditions for imposing administrative fines

1. Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive.

2. Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to a list of factors (points (a) to (k)), including the nature, gravity and duration of the infringement, its intentional or negligent character, and the degree of cooperation with the supervisory authority.

3. If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement.

4. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43; (b) the obligations of the certification body pursuant to Articles 42 and 43; (c) the obligations of the monitoring body pursuant to Article 41(4).

5. Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9; (b) the data subjects' rights pursuant to Articles 12 to 22; (c) the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49; (d) any obligations pursuant to Member State law adopted under Chapter IX; (e) non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2) or failure to provide access in violation of Article 58(1).

6. Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher.

Read the full text on EUR-Lex (CELEX 32016R0679, Article 83).

The two tiers, and which articles fall in each

The single most important thing Article 83 does is sort every GDPR obligation into one of two ceilings. The tier is not a matter of discretion: it follows mechanically from which provision was infringed. The lower tier covers the machinery of compliance; the upper tier covers the rights and principles that the machinery exists to protect.

LOWER TIER / TIER 1

€10M or 2%

Article 83(4). Controller, processor and body obligations.

  • Arts 8, 11: child's consent, processing not requiring identification
  • Arts 25-39: data protection by design, records, security (Art 32), breach notification (Arts 33-34), DPIAs (Art 35), the DPO (Arts 37-39)
  • Arts 42, 43: certification and certification-body duties
  • Art 41(4): monitoring-body duties

UPPER TIER / TIER 2

€20M or 4%

Article 83(5) and (6). The substantive rules.

  • Arts 5, 6, 7, 9: processing principles, lawful basis, consent, special categories
  • Arts 12-22: transparency and data subject rights (access, erasure, portability, objection)
  • Arts 44-49: international transfers (Chapter V)
  • Chapter IX: national-law obligations
  • Art 83(6): ignoring a supervisory authority's order

A single decision can straddle both tiers. Where a controller both fails to secure data (Article 32, lower tier) and processes it without a lawful basis (Article 6, upper tier), the authority calculates within the higher ceiling. Article 83(3) then caps the combined fine for the same or linked processing at the amount for the gravest infringement, so the tiers do not simply stack.

How the cap actually bites: fixed amount versus turnover

Each tier is a maximum expressed two ways, and the higher of the two applies. For a small controller with, say, 4 million euros of annual turnover, 4% is 160,000 euros, well below the 20 million euro figure, so the fixed 20 million euro amount is the theoretical ceiling and the fine is set far beneath it using the Article 83(2) factors. For a multinational the arithmetic inverts: 4% of a hundred-billion-euro group turnover dwarfs 20 million euros, so the percentage becomes the operative ceiling. This is why the largest fines on the register are quoted as absolute euro amounts that far exceed 20 million: they are percentages of very large turnovers, still sitting below the 4% maximum after the Article 83(2) weighting.

The turnover figure is the total worldwide annual turnover of the whole undertaking, not the EU-only revenue and not the turnover of the specific legal entity that was fined. Undertaking is read in the EU competition-law sense, so a subsidiary's exposure is calculated on the global revenue of the corporate group of which it forms part. In the WhatsApp decision the DPC assessed the fine against the turnover of the Meta parent undertaking, not WhatsApp Ireland in isolation.

Setting the amount within the ceiling: Article 83(2)

The tier fixes the ceiling; Article 83(2) fixes the amount beneath it. The authority gives due regard to ten factors: the nature, gravity and duration of the infringement; its intentional or negligent character; actions taken to mitigate the damage; the degree of responsibility given the technical and organisational measures in place; relevant previous infringements; the degree of cooperation with the authority; the categories of personal data affected; how the authority became aware of the infringement; compliance with any previously ordered measures; and adherence to approved codes of conduct or certification. Each factor can push the figure up (aggravating) or down (mitigating). The British Airways decision is the clearest worked example: an initially proposed fine of around 204 million euros was reduced to 22 million after cooperation, remedial action and the pandemic's economic impact were weighed in.

Our how GDPR fines are calculated guide walks through each of the ten factors with real decisions, and the Article 83 fine calculator on the homepage estimates a range from the same inputs.

Beyond the fine: corrective powers

Article 83(2) makes clear that an administrative fine can be imposed instead of, or in addition to, the corrective measures in Article 58(2). Those measures, warnings, reprimands, compliance orders, temporary or permanent processing bans, suspension of data flows to a third country, and orders to rectify or erase data, often carry greater operational weight than the monetary penalty. Meta was ordered to suspend transatlantic transfers alongside its 1.2 billion euro fine, an order that threatened the architecture of the service itself. Ignoring such an order is itself an upper-tier infringement under Article 83(6).

FREQUENTLY ASKED

About Article 83 GDPR fines

What are the GDPR Article 83 fine tiers?
Article 83 sets two maximum fine tiers, and the supervisory authority applies whichever amount is higher, the fixed cap or the percentage of worldwide annual turnover. The lower tier under Article 83(4) is up to 10 million euros or 2% of total worldwide annual turnover, and covers controller and processor obligations such as security (Article 32), breach notification (Articles 33 and 34), appointing a Data Protection Officer (Articles 37 to 39), and data protection impact assessments (Article 35). The upper tier under Article 83(5) is up to 20 million euros or 4% of total worldwide annual turnover, and covers the core rules: the basic principles and lawful basis for processing (Articles 5, 6, 7 and 9), data subject rights (Articles 12 to 22), and international data transfers (Articles 44 to 49).
Is it 2% or 4% of turnover, and of what turnover?
It depends on which article was infringed. Lower-tier infringements (Article 83(4)) are capped at 2%, upper-tier infringements (Article 83(5) and (6)) at 4%. In both cases the percentage is calculated on the total worldwide annual turnover of the entire undertaking in the preceding financial year, not just EU revenue, and not just the turnover of the specific subsidiary. The concept of undertaking follows EU competition law and can extend to the whole corporate group, which is why a subsidiary's fine can be based on the global revenue of its parent.
Does the authority use the fixed amount or the percentage?
Whichever is higher. Article 83(4) reads 'up to 10 000 000 EUR, or in the case of an undertaking, up to 2% of the total worldwide annual turnover, whichever is higher', and Article 83(5) uses the same 'whichever is higher' construction for the 20 million euro / 4% tier. For a small controller with modest turnover the fixed euro cap is usually the binding ceiling; for a multinational the turnover percentage is far larger and becomes the ceiling. The fine actually imposed is set below that ceiling using the Article 83(2) factors.
What is the difference between tier 1 and tier 2 GDPR fines?
Tier 1 (the lower tier, Article 83(4), up to 10 million euros or 2%) covers administrative and procedural obligations: the controller and processor duties in Articles 8, 11 and 25 to 39, certification-body obligations (Articles 42 and 43), and monitoring-body obligations (Article 41(4)). Tier 2 (the upper tier, Article 83(5), up to 20 million euros or 4%) covers the substantive rules whose breach most directly harms individuals: the processing principles and lawful basis (Articles 5, 6, 7, 9), data subject rights (Articles 12 to 22), transfers to third countries (Articles 44 to 49), and any national-law obligations under Chapter IX. Non-compliance with a supervisory authority's order carries the upper-tier 20 million / 4% ceiling under Article 83(6).
Can GDPR fines exceed 4% of global turnover?
The 4% or 20 million euro cap applies per infringement. A single investigation can identify multiple separate infringements, but Article 83(3) provides that where a controller or processor intentionally or negligently infringes several provisions in the same or linked processing operations, the total fine may not exceed the amount specified for the gravest individual infringement. So a single set of linked violations is capped at the highest applicable tier, not the sum of the tiers. Separate, unlinked processing operations can each attract their own fine, and member states may add national penalties, including criminal sanctions in some countries, alongside the administrative fine.
What are the Article 83(2) factors that set the actual amount?
Once the tier ceiling is fixed, Article 83(2) lists the factors the authority weighs to set the amount within that ceiling: the nature, gravity and duration of the infringement; whether it was intentional or negligent; actions taken to mitigate damage; the degree of responsibility given the technical and organisational measures in place; relevant previous infringements; the degree of cooperation with the authority; the categories of personal data affected; how the authority became aware of the breach; compliance with any previously ordered measures; and adherence to approved codes of conduct or certification. Our how-fines-are-calculated guide walks through each factor with real decisions.
Which real fines sit at the top of the upper tier?
The largest single GDPR fine to date is Meta's 1.2 billion euros (DPC, May 2023) for unlawful Chapter V transfers, an Article 44 to 49 upper-tier matter. The second largest is TikTok's 530 million euros (DPC, May 2025), also a Chapter V transfers case. Both illustrate that for the largest undertakings the 4% turnover ceiling, not the 20 million euro figure, is the operative cap, and that the headline fine still sits below that theoretical maximum after the Article 83(2) weighting.

CROSS-REFERENCES

Where Article 83 is applied

METHODOLOGY

How Fines Are Calculated

The 10 Article 83(2) factors with real decisions and a full British Airways walkthrough.

Open reference →

CALCULATOR

Article 83 Fine Calculator

Estimate a fine range from tier, turnover and the aggravating and mitigating factors.

Open reference →

REGISTER

Full Decision Register

Every indexed fine, each calculated within an Article 83 tier ceiling.

Open reference →

UPPER TIER CASE

Meta €1.2B (2023)

The largest single GDPR fine. An Article 44-49 transfers matter at the top of the 4% tier.

Open reference →

LOWER TIER ARTICLE

Article 32 Security

The archetypal lower-tier obligation: appropriate technical and organisational measures.

Open reference →

UPPER TIER ARTICLE

Articles 44-49 Transfers

The upper-tier transfer rules behind the two largest fines on the register.

Open reference →

SOURCES & CITATIONS

Primary sources

Figures as of August 2026. Verified against published DPA decisions.

REGISTER UPDATED 2026-04-28