Levels of Fines and Criminal Sanctions
The GDPR has two tiers of fines. Higher-level fines (up to four percent of global revenue or €20 million, whichever is greater) target core processing, data subject rights, and transfers. Lower-level fines (up to two percent or €10 million) target administrative duties.
How this supports CIPP/US study
Use this lesson to identify the disclosure, workplace or cross-border rule that changes the result in a fact pattern. Continue with the CIPP/US study plan.
Notable fines include Instagram (€405 million, children's data), Facebook (€265 million, data scraping), and Amazon (€746 million, lack of consent for cookies).
| Tier | Maximum | Targets |
|---|---|---|
| Higher-level fines | Greater of €20 million or 4% of global annual revenue | Basic principles of processing (incl. conditions of consent, lawfulness, special-category data), data subject rights, and transfers outside the EU |
| Lower-level fines | Greater of €10 million or 2% of global annual revenue | Data protection by default/design, records of processing, cooperation with DPAs, security, breach notification to DPAs and subjects, designation of a DPO |
In addition to administrative fines, member states may impose criminal sanctions; the chapter notes at least ten countries had adopted them.
Key terms - quick answers
What is “Higher-level fines”?
What is “Lower-level fines”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.