GDPR fines are the numbers that made data protection a board-level topic: up to 20 million euros or 4 percent of worldwide annual revenue, whichever is higher. Here is how the system actually works, what regulators fine in practice, and the answer to a question people ask more than you would expect: can an individual be fined under GDPR?
The two tiers of GDPR fines
| Tier | Maximum | Typical violations |
|---|---|---|
| Lower tier | 10 million EUR or 2 percent of worldwide revenue | Missing records, failure to notify a breach, no data protection officer where required |
| Upper tier | 20 million EUR or 4 percent of worldwide revenue | No legal basis for processing, invalid consent, ignoring data subject rights, unlawful transfers |
Regulators weigh the nature and duration of the violation, the number of people affected, whether it was intentional or negligent, cooperation, and past history. Most fines land far below the maximums, but the ceiling is what makes negotiation serious.
Can individuals be fined under GDPR?
Yes, in specific situations. GDPR applies to anyone who processes personal data outside a purely personal or household activity. A sole trader running a client list, a landlord filming a shared entrance, an individual publishing other people's data: all have been fined by European regulators, usually in the hundreds to thousands of euros. What GDPR does not do is fine an employee personally for their employer's violation: the controller, the organization, answers for that. The "household exemption" covers your personal address book and family photos, not your side business.
What gets fined in practice
- Invalid cookie consent has driven some of the most publicized penalties, including nine-figure fines against major platforms for making refusal harder than acceptance.
- Data breaches with poor security behind them remain the steadiest source of fines.
- Ignoring access or erasure requests turns a single complaint into an investigation.
- Transfers without safeguards to countries lacking adequate protection.
How Quebec's Law 25 compares
Quebec's Law 25 borrowed the GDPR formula and raised it: administrative penalties up to $10 million CAD or 2 percent of worldwide revenue, penal sanctions up to $25 million CAD or 4 percent, and a minimum of $1,000 in punitive damages that an individual can claim directly for an intentional or grossly negligent breach. If your site serves both Europe and Canada, the compliance work overlaps almost entirely: prior consent, real blocking of trackers, and provable records.
The cheapest fine is the one that never happens
Cookie consent is the most visible compliance surface you have. A free scan shows in minutes whether your site fires trackers before consent, the violation regulators check first.