The board wants to know our worst-case exposure for this data breach.
The legal maximum is high, but real fines are usually far below it. For security failures the cap is €10 million or 2% of worldwide annual turnover, whichever is higher. Where the regulator also finds a breach of the core security principle, which many breach decisions do, the cap is €20 million or 4%. “Turnover” means the whole group, not only the company that was hacked. On top of any fine come compensation claims from the people affected.
The worst case: the cap
Article 83(4) covers the security and breach-reporting duties. Fines go up to €10 million or
“up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher”
Article 83(5) covers the principles, including security in Article 5(1)(f): up to €20 million or 4%. Many breach decisions cite both, so for the board the realistic ceiling is the higher one.
| A group with €2 billion worldwide turnover | up to €40 million (2%) or €80 million (4%) |
|---|---|
| A company with €50 million turnover | up to €10 million or €20 million, because the fixed amount is higher than the percentage |
The turnover is the group’s. Recital 150 says a company is an “undertaking” as in EU competition law, and the EU Court of Justice confirmed in the Deutsche Wohnen case (C-807/21, 2023) that this is the basis for the fine. Deutsche Wohnen judgment ↗
What decides the real amount
Article 83(2) lists what the regulator weighs: how serious the breach was, how many people it affected and for how long; whether it was deliberate or careless; what you did to limit the harm; past breaches; how well you cooperated; the type of data; and whether you reported it yourself.
The European Data Protection Board’s fining guidelines start from a share of the cap by seriousness (low: 0 to 10%, medium: 10 to 20%, high: 20 to 100%), then adjust for the size of the company. EDPB fining guidelines 04/2022 ↗
Announced figures also come down. The UK regulator first said it intended to fine British Airways £183 million and Marriott £99 million; the final fines were £20 million and £18.4 million.
The three duties after a breach
- Security. Article 32 asks for “a level of security appropriate to the risk”: encryption, access control, regular testing. Most breach fines are for this.
- Tell the regulator. Article 33: “not later than 72 hours after having become aware of it”, and keep a record of every breach, even small ones.
- Tell the people affected when the risk to them is high (Article 34). This is not needed if the data was, for example, properly encrypted.
Compensation claims
Under Article 82, people can claim for material or non-material damage. The EU Court of Justice has said there is no minimum level of seriousness (Österreichische Post, C-300/21), and that fear of misuse after a hack can count as damage (C-340/21). People still have to show that they suffered damage. C-340/21 judgment ↗
What regulators decided
The closest decisions in Fino, biggest fine first. Each line opens the decision with its source.
- Dec 2024Meta Platforms Ireland LimitedA 2018 bug let attackers steal access to about 29 million accounts. Most of the fine was for not building protection in from the start (Article 25); the rest for an incomplete breach report.Data Protection Authority of Ireland · Ireland€251,000,000
- Sep 2024Meta Platforms Ireland LimitedStored users’ passwords in plain text, without encryption.Data Protection Authority of Ireland · Ireland€91,000,000
- Jan 2026FREE MOBILEWeak security let attackers into the systems, and customers were not told enough about the breach.French Data Protection Authority (CNIL) · France€27,000,000
- Oct 2020British AirwaysA 2018 attack on the website and app exposed the details of about 430,000 customers and staff, including card data.Information Commissioner (ICO) · United Kingdom€22,046,000
- Oct 2020Marriott International, IncAn attack on the guest reservation system exposed about 339 million guest records worldwide.Information Commissioner (ICO) · United Kingdom€20,450,000
- Aug 2023Not named in the sourceFaulty web links exposed 650,000 customers’ data for two years.IMY (Sweden) · SwedenSEK 35,000,000≈ €2,940,000
- Aug 2024mBankSent customer data to another bank by mistake, and did not tell the people affected.UODO (Poland) · PolandPLN 4,053,173≈ €950,000
- Mar 2022Bank of IrelandReported breaches to the regulator late, and security was not good enough.DPC (Ireland) · Ireland€463,000
See every decision in Fino and search for “breach”.
What to prepare for the board
- The group’s worldwide turnover for last year: it sets the cap.
- Was the breach reported within 72 hours, with everything Article 33 asks for?
- Were the people affected told, if the risk to them was high?
- Was the data encrypted, and were known weaknesses fixed in time?
- Is this the first incident, or a repeat?
Related explainers
Sources. GDPR text on Fino. Judgments of the EU Court of Justice on EUR-Lex. EDPB Guidelines 04/2022. Decisions from GDPRhub (noyb) and the CMS Enforcement Tracker, CC BY-NC-SA 4.0; descriptions rewritten in plain words by Fino.
Not legal advice. National rules can add to what is described here.