The caps
- Tier 1 (Art. 83(4)): up to €10M or 2% of global turnover
- Tier 2 (Art. 83(5)): up to €20M or 4% of global turnover
"Whichever is higher" — so a €10B company faces up to €400M.
The EDPB 5-step method (Guidelines 04/2022)
What actually reduces fines
- Self-report breaches within 72 hours
- Full cooperation with the DPA
- Documented privacy-by-design measures
- Valid transfer safeguards (SCCs + TIA)
Estimate your exposure
→ [GDPR Fine Calculator](/tools/gdpr-fines) — model your fine range based on violation type, turnover, and mitigating factors.
Source
[EDPB Guidelines 04/2022](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-042022-calculation-administrative-fines-under_en)