Two-Tier Fine Structure
The GDPR generally organises the maximum administrative fines a regulator can impose into two levels, depending on which type of obligation has been breached. Less severe breaches typically fall into a lower tier, while breaches of core data protection principles and individuals' rights typically fall into a higher tier with larger maximum amounts. The actual fine in any case is decided by the relevant supervisory authority based on the circumstances, so the tiers set ceilings rather than fixed penalties.
The two-tier fine structure refers to the framework in Article 83 GDPR under which administrative fines are capped at two different maximum levels according to the nature of the infringement. The lower tier applies to certain infringements set out in Article 83(4) and is generally subject to a maximum expressed as the higher of a fixed monetary ceiling or a percentage of total worldwide annual turnover of the preceding financial year; the higher tier applies to infringements set out in Article 83(5) (and, in respect of non-compliance with a supervisory authority order, Article 83(6)) and is subject to a larger maximum on the same higher-of basis. The precise monetary ceilings and turnover percentages, and the allocation of specific obligations to each tier, are stated in the Regulation text and should be verified against the current official version, as thresholds and their application in practice are set by law and informed by regulator guidance. Each individual fine is assessed against the factors in Article 83(2), and member state implementing law and derogations (for example concerning public authorities) may affect how fines apply; equivalent provisions exist under the UK GDPR and Data Protection Act with amounts expressed in sterling. Note that the evidence packet supplied does not contain any regulatory source on this term, so no source citation can be made here and readers should consult the GDPR text directly.
Why it matters
The two-tier fine structure is the mechanism that gives the GDPR much of its practical weight, because it links the seriousness of an infringement to the size of the maximum penalty a supervisory authority may impose. For organisations, understanding which obligations sit in the lower tier and which sit in the higher tier is central to assessing legal exposure, prioritising compliance work, and briefing senior management and boards on risk. Breaches touching core data protection principles, the legal bases for processing, and individuals' rights generally attract the higher ceiling, which signals that these areas warrant the most rigorous controls.
Because the tiers set maximum amounts rather than fixed penalties, the actual fine in any given case is decided by the relevant supervisory authority in light of the circumstances. This means the tier alone does not tell an organisation what it will pay; it defines the outer boundary within which a regulator exercises its discretion. Compliance programmes should therefore treat the tier as an indicator of the potential ceiling and the seriousness the legislature has attached to a category of obligation, not as a scheduled fee.
The framework also matters because its application is not uniform across every jurisdiction that has adopted a GDPR-style regime. Member state implementing law and derogations can affect how fines apply, for example in relation to public authorities, and the UK GDPR and Data Protection Act express equivalent provisions in sterling. Readers assessing exposure across multiple jurisdictions should verify the controlling text and any national variations rather than assuming a single set of figures applies everywhere.
Who it's relevant to
Inside Two-Tier Fine Structure
Common questions
Answers to the questions practitioners most commonly ask about Two-Tier Fine Structure.