Skip to main content
Category: Supervisory Authorities & Enforcement

Two-Tier Fine Structure

Also known as: Two-Tier Administrative Fine System, GDPR Fine Tiers
Simply put

The GDPR generally organises the maximum administrative fines a regulator can impose into two levels, depending on which type of obligation has been breached. Less severe breaches typically fall into a lower tier, while breaches of core data protection principles and individuals' rights typically fall into a higher tier with larger maximum amounts. The actual fine in any case is decided by the relevant supervisory authority based on the circumstances, so the tiers set ceilings rather than fixed penalties.

Formal definition

The two-tier fine structure refers to the framework in Article 83 GDPR under which administrative fines are capped at two different maximum levels according to the nature of the infringement. The lower tier applies to certain infringements set out in Article 83(4) and is generally subject to a maximum expressed as the higher of a fixed monetary ceiling or a percentage of total worldwide annual turnover of the preceding financial year; the higher tier applies to infringements set out in Article 83(5) (and, in respect of non-compliance with a supervisory authority order, Article 83(6)) and is subject to a larger maximum on the same higher-of basis. The precise monetary ceilings and turnover percentages, and the allocation of specific obligations to each tier, are stated in the Regulation text and should be verified against the current official version, as thresholds and their application in practice are set by law and informed by regulator guidance. Each individual fine is assessed against the factors in Article 83(2), and member state implementing law and derogations (for example concerning public authorities) may affect how fines apply; equivalent provisions exist under the UK GDPR and Data Protection Act with amounts expressed in sterling. Note that the evidence packet supplied does not contain any regulatory source on this term, so no source citation can be made here and readers should consult the GDPR text directly.

Why it matters

The two-tier fine structure is the mechanism that gives the GDPR much of its practical weight, because it links the seriousness of an infringement to the size of the maximum penalty a supervisory authority may impose. For organisations, understanding which obligations sit in the lower tier and which sit in the higher tier is central to assessing legal exposure, prioritising compliance work, and briefing senior management and boards on risk. Breaches touching core data protection principles, the legal bases for processing, and individuals' rights generally attract the higher ceiling, which signals that these areas warrant the most rigorous controls.

Because the tiers set maximum amounts rather than fixed penalties, the actual fine in any given case is decided by the relevant supervisory authority in light of the circumstances. This means the tier alone does not tell an organisation what it will pay; it defines the outer boundary within which a regulator exercises its discretion. Compliance programmes should therefore treat the tier as an indicator of the potential ceiling and the seriousness the legislature has attached to a category of obligation, not as a scheduled fee.

The framework also matters because its application is not uniform across every jurisdiction that has adopted a GDPR-style regime. Member state implementing law and derogations can affect how fines apply, for example in relation to public authorities, and the UK GDPR and Data Protection Act express equivalent provisions in sterling. Readers assessing exposure across multiple jurisdictions should verify the controlling text and any national variations rather than assuming a single set of figures applies everywhere.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads use the tier framework to prioritise remediation, focusing attention on obligations tied to the higher tier, such as core processing principles and individuals' rights. Mapping an organisation's obligations to their respective tiers supports risk registers and board-level reporting, though the tier indicates only the maximum ceiling and not the likely outcome of any enforcement action.
Privacy and Regulatory Lawyers
Lawyers advising on enforcement exposure need to identify the controlling provision, distinguishing Article 83(4) infringements from those under Article 83(5) and (6), and to advise clients on how the Article 83(2) factors shape the discretionary assessment of any fine. They should also account for member state derogations and, where relevant, the sterling-denominated UK GDPR equivalents, verifying figures against the current official text.
Senior Management and Boards
Executives and directors rely on the tier structure to understand the scale of potential regulatory sanction when setting risk appetite and allocating resources to data protection. The two-tier ceilings help frame worst-case exposure, but leadership should be advised that actual fines are determined case by case by the supervisory authority.
Engineers and Product Teams
Technical teams benefit from knowing that design and processing choices affecting core principles and data subject rights are generally associated with the higher fine tier. This can inform where to invest in safeguards such as data minimisation, access controls, and mechanisms to support individuals' rights, recognising that the tier reflects the seriousness the law attaches to these areas.

Inside Two-Tier Fine Structure

Lower Tier (Article 83(4) GDPR)
The first category of administrative fines, with a statutory maximum of up to €10 million, or in the case of an undertaking up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. This tier generally applies to infringements of specified controller and processor obligations, including those relating to Articles 8, 11, 25 to 39, 42 and 43. Practitioners should verify the precise list of covered provisions against the current official text of Article 83(4).
Higher Tier (Article 83(5) GDPR)
The second category of administrative fines, with a statutory maximum of up to €20 million, or in the case of an undertaking up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. This tier generally applies to more serious infringements, such as breaches of the basic principles for processing (including conditions for consent under Articles 5, 6, 7 and 9), data subjects' rights under Articles 12 to 22, and transfer provisions under Articles 44 to 49. Article 83(6) addresses non-compliance with a supervisory authority order under Article 58(2) within the higher tier. Confirm coverage against the current text.
"Whichever is higher" mechanism
For each tier, where the data controller or processor is an undertaking, the applicable ceiling is the greater of the fixed monetary cap or the turnover-based percentage. For entities that are not undertakings, the fixed monetary ceiling generally governs. The concept of 'undertaking' draws on EU competition law and can affect how turnover is calculated across corporate groups; this remains subject to interpretation and guidance.
Assessment criteria (Article 83(1)-(2))
The tier caps are maxima, not fixed penalties. Article 83 requires that fines be effective, proportionate and dissuasive, and sets out factors (such as the nature, gravity and duration of the infringement, intentional or negligent character, mitigating actions, and cooperation with the authority) that supervisory authorities weigh when setting the actual amount within the relevant tier.
Relationship to national and UK regimes
The two-tier structure is set out in EU GDPR Article 83. The UK GDPR retains an equivalent two-tier approach, with monetary caps expressed in sterling under UK implementing legislation, so figures differ from the euro amounts. Member state law may also vary certain aspects, including whether and how public authorities are fined, so the position should be checked per jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Two-Tier Fine Structure.

Does the higher fine tier (up to €20 million or 4% of turnover) apply to every GDPR infringement?
No. Article 83 GDPR sets two distinct tiers, and the applicable tier depends on which provision was infringed. The lower tier, up to €10 million or 2% of total worldwide annual turnover of the preceding financial year (whichever is higher), applies to the infringements listed in Article 83(4), which generally concern obligations of controllers and processors, certification bodies, and monitoring bodies. The higher tier, up to €20 million or 4% (whichever is higher), applies to the infringements listed in Article 83(5) and (6), which generally concern breaches of basic principles, data subjects' rights, and transfer rules, as well as non-compliance with a supervisory authority order. Reading every infringement as automatically attracting the higher tier is a common misconception; the correct tier turns on the specific article breached. Readers should verify the categorisation against the current text of Article 83.
Are the stated amounts (€10 million/2% and €20 million/4%) the fines that will be imposed?
No. These figures are statutory maximum ceilings, not fixed or default fines. Under Article 83(1), administrative fines must be effective, proportionate, and dissuasive, and Article 83(2) requires the supervisory authority to consider factors such as the nature, gravity, and duration of the infringement, whether it was intentional or negligent, mitigating actions, and cooperation, among others. The actual amount imposed is the outcome of a case-by-case assessment and is typically well below the ceiling. Treating the ceiling as the expected penalty misreads the structure. The specific calculation methodology has been addressed in supervisory authority guidance, which the reader should consult in its current form.
How do we determine which tier applies to a particular infringement?
Identify the specific GDPR provision that was breached and map it to the lists in Article 83. Infringements enumerated in Article 83(4) fall within the lower tier (up to €10 million or 2%), while those enumerated in Article 83(5), together with the situation in Article 83(6) concerning non-compliance with a supervisory authority order, fall within the higher tier (up to €20 million or 4%). Because a single set of facts can involve multiple infringements, more than one tier may be relevant. Where infringements are linked, Article 83(3) addresses how the total fine is capped. This is an area where analysis is fact-specific, so the applicable provisions should be confirmed against the current Regulation text.
How is the turnover-based percentage calculated for a company that is part of a group?
The percentage is calculated against total worldwide annual turnover of the preceding financial year, and the fine is the higher of the fixed monetary ceiling or the percentage figure. A significant interpretive question is whether 'undertaking' for this purpose is read by reference to the competition-law concept of an economic unit, which can extend turnover assessment beyond the individual legal entity to the wider corporate group. There has been guidance and case law bearing on this point, and approaches can involve nuance, so the group-level implications should be assessed carefully and verified against current authoritative sources rather than assumed.
Does the two-tier fine structure apply identically under the UK GDPR?
The UK GDPR retains a two-tier maximum fine model that parallels the EU structure, but the monetary ceilings are expressed in sterling under UK law rather than in euros, and enforcement is a matter for the UK regulator. Because the EU and UK regimes have diverged and can continue to diverge, the exact figures, procedures, and interpretations should not be assumed to be identical. Readers operating across both jurisdictions should confirm the applicable ceilings and enforcement framework under the relevant national implementing provisions.
How should the two-tier structure inform an organisation's risk assessment and internal documentation?
Organisations typically use the tier categorisation to help prioritise controls, since infringements attracting the higher tier generally concern core matters such as lawful basis, data subject rights, and international transfers. In practice this can feed into records of processing, impact assessments, and incident response planning by flagging where a breach could expose the organisation to the higher ceiling. However, the fine ceiling is only one input; the actual exposure depends on the Article 83(2) assessment factors and regulator discretion, so the tier should not be treated as a precise quantification of financial risk. Any internal risk methodology should be documented as an estimate subject to assessment and reviewed against current guidance.

Common misconceptions

Every GDPR infringement can attract the maximum €20 million / 4% fine.
The Regulation allocates infringements between two tiers. Many controller and processor obligations fall under the lower tier (up to €10 million / 2%), while the higher tier (up to €20 million / 4%) is generally reserved for more serious breaches such as those of the basic processing principles, data subjects' rights, and transfer rules. The applicable tier depends on which provision was infringed.
The tier ceilings are the fines that will actually be imposed.
The amounts in Article 83(4) and 83(5) are statutory maxima, not standard or automatic penalties. Actual fines are determined case by case using the criteria in Article 83, must be proportionate to the specific circumstances, and are frequently set well below the cap.
The turnover percentage always overrides the fixed monetary amount.
The cap is the higher of the fixed sum or the turnover percentage, applied only where the entity qualifies as an undertaking. For smaller entities the fixed figure may be the operative ceiling, and the turnover-based calculation involves interpretive questions about corporate group scope that remain subject to guidance and case law.

Best practices

Map each relevant GDPR obligation your organisation is subject to against the correct tier (Article 83(4) versus 83(5)-(6)) so that risk assessments reflect the actual applicable ceiling rather than assuming the highest cap.
When estimating exposure for an undertaking, account for the 'whichever is higher' mechanism and seek advice on how 'undertaking' and worldwide turnover are calculated across corporate groups, as this remains an area of interpretation.
Document mitigating factors aligned to the Article 83 assessment criteria (such as remedial measures, cooperation with the supervisory authority, and the nature and duration of any infringement), since these influence where within a tier a fine may fall.
Distinguish the EU GDPR euro thresholds from the sterling figures under the UK GDPR and any national variations when preparing multi-jurisdiction compliance materials, and verify current amounts against official sources.
Treat published tier caps as maxima only, and avoid representing worst-case figures as expected outcomes in internal risk communications.
Verify article references, covered provisions, and monetary or turnover figures against the current official text of the Regulation and applicable regulatory guidance before relying on them in a compliance program.