If your organisation processes personal data, which virtually every organisation does today, understanding the General Data Protection Regulation (GDPR) breach fines is crucial. While high-profile cyber incidents often stand out, a vast range of everyday organisational failures can trigger regulatory action and significant financial penalties: from running a marketing campaign without proper consent, to failing to respond to a subject access request, to transferring data abroad without the right safeguards in place.
This article explains what the different types of GDPR infringements are which can lead to fines, which entity is responsible for enforcing the rules, real enforcement examples and importantly what steps can be taken to reduce the risks.
Who enforces the GDPR?
Across the European Union (EU), enforcement of the GDPR is handled by the relevant national data protection authority in each member state. For instance, the Irish Data Protection Commission (DPC) and French Commission Nationale de l’Informatique et des Libertés (CNIL) may both issue fines under the GDPR for organisations operating in Ireland and France respectively.
Now it is worth noting that since Brexit, UK organisations must comply with the UK GDPR as retained and amended by the Data Protection Act 2018, while organisations operating in the EU remain subject to the EU GDPR (referred to in this article as ‘GDPR’). Resultantly, in the UK the Information Commissioner’s Office (ICO) is the independent regulator which is responsible for enforcing the UK GDPR. The ICO has a wide range of investigative and corrective powers, including the power to audit organisations, issue reprimands, order remedial action, and impose administrative fines in serious cases.
In practice, the two regimes are closely aligned, but the fine structures and related monetary caps differ slightly, which is addressed below.
How are GDPR fines structured in practice?
GDPR fines operate on a two-tier system under both the UK GDPR and GDPR, with lower tier and high tier fines, for which the maximum amount is determined by the severity of the infringement.
Lower level infringements
Under Article 83(4) of the UK GDPR, infringements relating to controller and processor obligations, certification bodies, and monitoring bodies carry a maximum fine of £8,700,000, or 2% of the organisation’s total worldwide annual turnover in case of an undertaking, whichever is higher. Examples include failures around data protection by design, record-keeping obligations, security measures or breach notification requirements. The EU equivalent under the GDPR is €10 million or 2% of turnover.
More serious infringements
Article 83(5) UK GDPR provides that violations of the fundamental principles of data processing, conditions for consent, data subjects’ rights, international data transfers and non-compliance with ICO’s orders are subject to the maximum fine, being £17,500,000 or 4% of global annual turnover, whichever is greater. The EU equivalent GDPR fine is €20 million or 4% of turnover respectively. In terms of real-life example, the greatest GDPR fine to date was issued under this tier by the Irish DPC in 2023, amounting to €1.2 billion against Meta following the transfer of European users’ personal data to the United States without adequate data protection mechanisms in place.
Impact of the Data (Use and Access) Act 2025
While the GDPR fine structure is not directly impacted by the Data (Use and Access) Act 2025 (DUAA), it introduces additional considerations to the UK enforcement landscape by aligning penalties under the Privacy and Electronic Communications Regulations (PECR) with UK GDPR levels. Historically, PECR breaches such as nuisance marketing calls, unsolicited texts, and the use of non-compliant cookies were subject to a maximum fine of £500,000. Under the DUAA, with changes taking effect between June 2025 and June 2026, those maximum penalties increase substantially to £17.5 million or 4% of global annual turnover, whichever is higher. This effectively makes e-privacy enforcement equivalent to UK GDPR sanction levels and materially increases regulatory exposure for organisations engaging in electronic marketing or deploying tracking technologies.
Which factors are considered when calculating fines?
When assessing whether to fine and how much, regulators must consider a range of factors. For instance, in the UK the ICO will assess the elements listed in Article 83(2) UK GDPR, namely:
- The nature, gravity and duration of the infringement, as well as the number of data subjects affected;
- Whether it was intentional or negligent;
- Any mitigation measures taken to limit the damage caused to data subjects;
- The degree of responsibility of the data controller or processor, as well as previous infringements or warnings;
- The categories of data involved;
- How the infringement was communicated to the ICO and whether the organisation cooperated to remedy it;
- Compliance with codes of conduct or certification mechanisms; and
- Any other aggravating or mitigating factor.
Importantly, fines are intended to be effective, proportionate and dissuasive. This means a fine that would be significant for a small business may be relatively minor for a global corporation, hence the turnover-based cap. It is also important to understand that fines are not the only consequence. Following Article 58(2) UK GDPR, the ICO can also issue enforcement notices, compulsory audit requirements, and temporary or permanent bans on processing. Data subjects affected by the infringement also retain separate rights under Article 82(1) UK GDPR to claim compensation for material or non-material damage, including financial loss, reputational harm, and distress. Regulators in the EU are subject to, and follow, the same approach.
In which circumstances may GDPR fines be triggered?
Data protection laws have been strictly enforced through financial repercussions for non-compliant organisations in the EU and UK across recent years, with cumulative total of GDPR fines amounting to approximately €5.88 billion in January 2025. Although firms operating in the tech sector remain the main target for GDPR fines, regulators now examine companies from other industries like finance, healthcare and energy among others. Essentially, the scope of GDPR enforcement is broad on the regulators’ side, and so are the circumstances in which fines are likely to arise. Below are some notable practical examples of fines enforced by regulators.
· Processing without a lawful basis
Article 6 GDPR sets out 6 lawful bases which can be relied on when collecting and processing personal data, being consent, contract, legal obligation, vital interests, public task and legitimate interests. Organisations which process personal data without a lawful basis are exposed to the highest tier of GDPR fines. Indeed, LinkedIn was fined €310 million by the Irish DPC in 2024 for misusing member data for behavioural analysis and targeted advertising, which invalidly relied on consent, legitimate interests, and contractual necessity as legal bases for this processing, and failed to be transparent about it.
· Unlawful marketing
UK GDPR enforcement actions are also commonly triggered by marketing activities, especially as the ICO actively watches for organisations that contact individuals without proper consent or in breach of their right to object. This is demonstrated a 2022 fine case, where the ICO fined Easylife £1.45 million for profiling 145,400 customers by inferring medical conditions from their purchase history without their knowledge and calling them to market health products, which was described as ‘unlawful and invisible’ special category data processing. This confirms that, even where no individual has made a complaint, invisible profiling and unlawful use of special category data are taken extremely seriously by the regulators.
· Breach of fundamental data protection principles
Article 5 GDPR establishes core principles which underpin all lawful data processing: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Infringements of such principles can lead to the highest tier of fines. A good example is where the French CNIL issued a €32 million fine to Amazon France Logistique for unlawfully monitoring employees using scanner data that tracked productivity in excessive and disproportionate detail, which ultimately violated the principle of data minimisation.
· Failure to comply with data subjects’ rights
Under Articles 12-22 GDPR, individuals have rights, such as the right to be informed, to access their data, to correct, to erase, to restrict or object, and to data portability, related to the processing of their personal data. Failure to comply with these rights may trigger enforcement actions, whether by ignoring subject access requests or failing to provide information in a clear and accessible way. The Swedish Data Protection Authority fined Google €7 million for failing to comply with the right to erasure, after Google had removed URLs from search results only in EU versions of the search engine, rather than globally. This was deemed insufficient to action the individual’s right and therefore resulted in a fine.
· Insufficient security measures
While security failures and personal data breaches are just one category of GDPR violation, they remain a common one and they can be particularly costly. Article 32 UK GDPR requires organisations to implement appropriate technical and organisational measures to protect personal data. The standard is risk-based: what is appropriate depends on the nature of the data, the volume of processing, and the state of available technology. In the UK, the ICO issued a £20 million fine to British Airways after a 2018 cyberattack compromised the personal and financial details of over 400,000 customers. Investigators found that available security measures, including multi-factor authentication and appropriate access controls, were not in place and would have prevented the attack.
· Unlawful international data transfers
Failing to have an adequate transfer mechanism in place when transferring personal data outside of the UK or European Economic Area also leads to sanctions. Indeed, before transferring data to a third country, organisations must ensure that adequate protections are in place: an adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules, or another approved mechanism following Articles 44-50 GDPR. As briefly mentioned above, the largest GDPR fine was issued to Meta by the Irish DPC, amounting to €1.2 billion, as a result of transfers of EU user data to US servers without adequate protections following the invalidation of the Privacy Shield framework. This decision is currently under appeal, but it highlights that compliance with international transfer mechanisms is crucial, especially for organisations using US-based cloud services, HR platforms, or customer management systems, which may apply to a very large number of UK and Europe-based businesses.
· Mishandling children’s data
Children’s data receives heightened protection under Article 8 UK GDPR and the UK Children’s Code (the Age Appropriate Design Code). Organisations offering online services that are likely to be accessed by children face specific obligations around age verification, transparency, default settings, and parental consent. In the UK, the ICO has fined TikTok £12.7 million for a number of infringements, including TikTok’s failure to prevent up to 1.4 million UK children under 13 from using the platform, and its failure to process their data lawfully and transparently.
Responsibility
Under the UK GDPR, both data controllers, the organisations that determine the purposes and means of processing personal data, and data processors, those who process data on behalf of a data controller, such as cloud providers, payroll suppliers, or third-party marketing platforms, can be held directly liable for UK GDPR infringements and fined accordingly. While data controllers are accountable for ensuring that any processor they appoint provides sufficient guarantees of compliance, a data processor can face enforcement action where it fails to meet its UK GDPR obligations. This was confirmed in March 2025 in the UK, when the ICO issued its first monetary penalty notice directly against a data processor: Advanced Computer Software Group was fined £3.07 million for failing to implement appropriate technical and organisational security measures across systems it operated on behalf of NHS and healthcare clients. The ICO made clear that the existence of contractual arrangements between Advanced and its controller customers did not diminish Advanced’s own obligations under Article 32 UK GDPR. Therefore, responsibility for compliance does not rest with one party alone.
Steps you should take to avoid GDPR fines
The range of violations above can feel overwhelming for an organisation, but most GDPR enforcement action follows a consistent set of organisational failures. To address the most common risk areas, you should consider the following steps:
- Identify and document the lawful bases relied on for each processing activity;
- For marketing activities, ensure that consent is valid or that a Legitimate Interest Assessment has been conducted;
- Comply with data subjects’ rights by establishing clear procedures for handling Subject Access Requests, erasure requests, and objections within the required timescales, and training staff accordingly;
- To secure data appropriately, implement access controls, encryption, and multi-factor authentication, train staff on information governance matters, and have an incident response plan;
- In case of high-risk processing activities, conduct a Data Protection Impact Assessment (DPIA);
- If you transfer data to third-party countries, make sure appropriate transfer mechanisms are implemented;
- When dealing with data processors, ensure that data processing agreements are in place to regulate the processing activity and review their security practices;
- Where children’s data are involved, implement strong age verification and default-safe settings.
Building onto those recommendations, our article on the benefits of complying with data protection laws explains how good data governance builds trust, competitive advantage, and long-term business resilience.
How can IGS help
At Information Governance Services, we help organisations strengthen their data protection and information governance frameworks through practical compliance support, including:
- GDPR and UK GDPR compliance consultancy
- Data Protection Impact Assessments (DPIAs) & Legitimate Interest Assessment (LIA)
- Incident and breach management support
- Staff training and awareness programmes
- Privacy notices and fair processing materials
- Record of Processing Activities (ROPA) & Information Asset Register (IAR) support
Handling Subject Access Requests (SAR) with Zolteria®
One area of GDPR enforcement that continues to attract significant regulatory attention is the handling of data subject rights, in particular, Subject Access Requests, objections to processing, and erasure requests. Getting this wrong is not only a common source of ICO enforcement action, but also a reputational risk that is entirely avoidable. The good news is that with the right tools in place, organisations can manage these obligations seamlessly. Zolteria provides a modern solution built around good data management practices and helps organisations manage data subject requests in a more structured, safer and smarter digital environment, reducing the need for manual identity verification processes and fragmented email-based communications. By enabling secure interaction with verified individuals whose data an organisation holds, Zolteria supports more efficient, accountable and auditable handling of Subject Access Requests.
Visit the Zolteria website and sign up for a chance to win a free 3-month trial for your organisation.
Conclusion
GDPR breach fines are not limited to cyberattacks or headline data breaches. The full scope of enforcement covers unlawful marketing, consent failures, breaches of data subjects’ rights, inadequate security, and unlawful international transfers among other violations. The organisations that face the most serious consequences are typically those which do not have effective information governance procedures in place. Firms that build genuine compliance with proper policies, trained staff, and regular reviews are better placed to avoid regulatory action, and to demonstrate accountability if something does go wrong.
If you would like help reviewing your data protection obligations, understanding where your organisation’s risk lies, or upskilling your team through practical training, please contact us at info@informationgovernanceservices.com or 0208 106 7936.



