Skip to main content
Category: Supervisory Authorities & Enforcement

Turnover-Based Fines

Also known as: Revenue-Based Fines, Turnover-Linked Administrative Fines
Simply put

Turnover-based fines are financial penalties whose maximum amount is calculated by reference to a company's overall revenue rather than a fixed cash cap alone. The intent of linking a penalty to turnover is to make it meaningful and proportionate to the size of the organization, so that larger enterprises face correspondingly larger potential exposure. The specific percentages, thresholds, and how turnover is measured depend on the applicable law and regulatory guidance.

Formal definition

A turnover-based fine is an administrative penalty structure in which the maximum permissible fine is expressed, at least in part, as a percentage of an undertaking's total worldwide annual turnover, typically calculated on the preceding financial year, with the applicable ceiling being the higher of a fixed monetary cap or the turnover-linked percentage. This model is a general enforcement-design concept and is applied in various regulatory regimes; the precise percentage tiers, the definition of the relevant 'undertaking' and its turnover, and the aggregation of group revenue are determined by the governing statute and the interpretive guidance and case law applicable to it. Where such fines arise under a specific instrument, practitioners should confirm the exact article, percentage thresholds, turnover definition, and mitigating and aggravating factors against the current official text, as the evidence available here does not substantiate the specifics of any particular regime and general guidance may diverge between regulators.

Why it matters

Turnover-based fines change the calculus of regulatory risk for large organizations. Where a penalty is capped only at a fixed cash amount, that ceiling may be trivial relative to a multinational's revenue and offer little deterrent effect. Linking the maximum exposure to a percentage of overall turnover is designed to keep penalties proportionate to the size of the enterprise, so that the potential downside scales with the organization's economic weight rather than remaining a predictable cost of doing business.

For compliance leads and boards, this structure means that the financial stakes of a serious infringement cannot be assessed in isolation from group revenue. The concept elevates data protection and other regulated conduct from an operational concern to a matter of enterprise financial risk, which in turn affects how organizations budget for compliance, structure governance, and assess the materiality of potential enforcement.

The specifics matter greatly and vary by regime. The applicable percentage tiers, how 'turnover' and the relevant 'undertaking' are defined, whether group revenue is aggregated, and the mitigating and aggravating factors an authority must weigh are all determined by the governing law and its interpretive guidance. Because these details drive the actual exposure figure, readers should confirm the exact thresholds and turnover definition against the current official text of the relevant regulation rather than relying on a general description.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for assessing regulatory risk need to understand that potential penalty exposure may scale with group revenue rather than being capped at a fixed sum. This affects how the materiality of an infringement is communicated internally and how compliance programs are prioritized and resourced. The exact thresholds and turnover definition should be confirmed against the applicable regulation.
Legal Advisers and In-House Counsel
Counsel advising on enforcement risk must identify how the relevant 'undertaking' and its turnover are defined under the governing instrument, whether group revenue is aggregated, and which aggravating and mitigating factors an authority weighs. These determinations drive the actual exposure figure and require reference to the current statutory text and interpretive guidance, which may differ between regulators.
Boards and Senior Management
Directors and executives concerned with enterprise financial risk should recognize that turnover-linked penalties are designed to be proportionate to organizational size, meaning a serious infringement can carry exposure that is significant relative to overall revenue. This is relevant to governance oversight, risk budgeting, and disclosure considerations.
Group and Multinational Structures
Organizations operating as part of a corporate group are particularly affected, because the aggregation of group revenue can materially increase the turnover figure used to calculate a ceiling. How the relevant undertaking and its turnover are scoped is regime-specific and should be verified against the governing law.

Inside Turnover-Based Fines

Statutory Basis (Article 83)
GDPR Article 83 sets out the framework for administrative fines, including the general conditions supervisory authorities apply when imposing them and the requirement that fines be effective, proportionate, and dissuasive in each individual case.
Two-Tier Fine Structure
Article 83 establishes two maximum thresholds. The lower tier caps fines at up to EUR 10 million or 2 % of total worldwide annual turnover of the preceding financial year, whichever is higher, for certain infringements. The higher tier caps fines at up to EUR 20 million or 4 % of total worldwide annual turnover, whichever is higher, for more serious infringements. Readers should verify the current thresholds and figures against the official GDPR text, as the euro amounts and the exact allocation of infringements to each tier are set by the Regulation.
Turnover as the Calculation Reference
Where the percentage cap applies, the reference point is total worldwide annual turnover of the preceding financial year. The concept of 'undertaking' relevant to calculating turnover generally draws on EU competition law meaning, which can bring group-level turnover into scope; the precise application is subject to guidance and case law and can be contested.
'Whichever is Higher' Mechanic
For each tier, the applicable maximum is the greater of the fixed euro figure or the turnover percentage. This means larger enterprises can face fines materially above the fixed amounts, while the fixed amount typically operates as the effective ceiling for smaller entities with limited turnover.
Assessment Criteria
Article 83 lists factors that authorities weigh when deciding whether to impose a fine and its amount, such as the nature, gravity, and duration of the infringement, its intentional or negligent character, mitigation efforts, and prior infringements. These criteria mean the maximum caps are ceilings rather than default amounts, and actual fines are determined case by case.
Member State Variation
Article 83 permits certain national derogations, for example regarding fines on public authorities and bodies, and national procedural rules can affect how fines are imposed. The UK GDPR contains an analogous fining regime with figures expressed in pounds sterling; practitioners should confirm the applicable regime and current figures for the relevant jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Turnover-Based Fines.

Does the GDPR always fine organizations the maximum percentage of their global turnover?
No. The turnover-based figures in Article 83 (broadly, up to 2 % or up to 4 % of total worldwide annual turnover of the preceding financial year, depending on which category of infringement applies) are statutory maximums, not standard or default amounts. The actual fine, where one is imposed at all, is determined case by case. Article 83(2) requires supervisory authorities to consider factors such as the nature, gravity and duration of the infringement, whether it was intentional or negligent, mitigating actions taken, and cooperation with the authority. In many cases fines fall well below the ceiling, and authorities also have non-monetary corrective powers. You should verify the exact percentages and infringement categories against the current official text of Article 83.
Is a GDPR fine calculated only against the individual legal entity that committed the infringement?
Not necessarily. The concept of 'undertaking' can be relevant to how turnover is assessed, and in some circumstances turnover may be considered at a broader group level rather than that of a single subsidiary. This is an area shaped by EU competition-law concepts and by guidance and case law rather than a self-contained formula in the Regulation text, and interpretations can differ between regulators and remain subject to development. Organizations should treat the scoping of relevant turnover as a matter requiring specific legal assessment rather than assuming it is limited to one entity.
Which turnover figure and reference period should we use when assessing potential exposure?
Article 83 refers, for the higher tier, to total worldwide annual turnover of the preceding financial year. For internal risk assessment you would typically identify the relevant financial year's audited turnover and consider whether group-level turnover could be in scope given the undertaking analysis noted above. Because the correct scoping can be contested and fact-dependent, it is generally advisable to model a range of scenarios rather than a single figure, and to confirm the precise wording and reference period against the current official text.
How should the possibility of turnover-based fines feed into our risk assessment or DPIA process?
Fine exposure is one input into an overall assessment of risk, but it should not be treated as the sole or primary measure of harm. A Data Protection Impact Assessment under Article 35 focuses on risks to the rights and freedoms of data subjects rather than on financial penalties to the organization. Turnover-based exposure is more relevant to enterprise or compliance risk registers. In practice, organizations often document both the likelihood of an infringement and the range of corrective measures an authority could apply, recognizing that outcomes are context and risk dependent.
What mitigating steps are typically relevant if a supervisory authority is assessing a fine?
Article 83(2) lists factors an authority weighs, which generally include the degree of responsibility taking into account technical and organizational measures implemented, prompt notification and cooperation, actions taken to mitigate damage to data subjects, and adherence to approved codes of conduct or certification mechanisms where applicable. Maintaining demonstrable accountability documentation can support these points. The weight given to each factor is at the authority's discretion and can vary between regulators, so no single measure guarantees a reduced outcome.
Do the same turnover-based fine levels apply under the UK GDPR and across all member states?
The UK GDPR contains its own fining framework broadly mirroring the structure of the EU regime, but it is administered by the UK regulator and the applicable currency and interpretation can differ, so it should be verified separately. Within the EU, the maximum percentages derive from the Regulation itself, but member state implementing law and national procedural rules can affect how fines are imposed and enforced, and enforcement practice varies between supervisory authorities. Positions in the public sector may also differ where national law limits fines on public bodies. Confirm the applicable regime for each jurisdiction against the current official texts.

Common misconceptions

The fine is always 4 % of turnover.
The 4 % (and 2 %) figures are maximum ceilings under Article 83, not automatic or typical amounts. The applicable maximum for a tier is the higher of the fixed euro figure or the turnover percentage, and the actual fine is set case by case using the Article 83 assessment criteria, so it is generally well below the cap.
Turnover means only the offending entity's revenue.
The reference is total worldwide annual turnover of the preceding financial year, and the 'undertaking' concept can, subject to guidance and case law, bring group-level turnover into the calculation. The precise scope can be contested and should be assessed on the facts.
Turnover-based fines work like income-based 'day-fine' penalties in criminal law.
GDPR fines under Article 83 are administrative fines imposed by supervisory authorities against undertakings, calculated against annual turnover with fixed euro alternatives. They are a distinct mechanism from personal-income day-fine models used in some criminal justice systems and should not be conflated.

Best practices

Map your infringement scenarios to the correct Article 83 tier (lower or higher) rather than assuming the top rate, and document the reasoning.
Calculate potential exposure using both the fixed euro figure and the turnover percentage, applying the 'whichever is higher' rule, and verify current figures against the official GDPR text.
Clarify how 'undertaking' and group turnover may apply to your corporate structure, and take advice where group-level turnover could be in scope.
Confirm the applicable regime and figures for each relevant jurisdiction, distinguishing EU GDPR from UK GDPR and accounting for possible member state derogations, for example for public bodies.
Treat the caps as ceilings and prepare to evidence the Article 83 mitigating factors, such as remediation, cooperation, and absence of prior infringements, that inform the actual amount.
Re-check thresholds, guidance, and case law periodically, since interpretation of turnover-based fines continues to develop and figures should not be treated as permanently fixed.