Logo Logo
  • Platform
    • Products
      • Why Core dna
        See how Core dna transforms your digital business.
      • eCommerce
        Power your eCommerce ambition
      • CMS
        For marketers with vision, not code
      • Automations
        Automate your way to success
      • DXP
        Build, manage, and scale your digital properties in one place.
      By Role
      • Developers
        Modernize your web presence without ripping or replacing anything.
      • Executives
        Empower marketers, free up IT team and slash costs at the same time.
      • Marketers
        Total control, without the development team.
      Company
      • Customers
        Helping power the digital presence of hundreds of customers
      • Features
        Content and commerce features.
      • Services
        From digital transformation strategy to scaling your digital business.
      • Admin login
        Access to Core dna DXP 1 admin
  • Solutions
    • Use Cases
      • B2B
        Go directly to customers with an all-in-one B2B platform.
      • B2C
        Connect to shoppers anytime, anywhere with our B2C eCommerce solution
      • Marketplace
        Multi-vendor eCommerce marketplace platform.
      • Content
        Craft content with ease, then deliver it anywhere.
      • Headless
        A hybrid headless platform loved by marketers and developers.
      • Infrastructure
        Advanced cloud infrastructure built for scale and security.
      By Industry
      • Direct to Consumers / Manufacturing
        Get the tools and experience to thrive in the new direct-to-consumer world.
      • Education
        Create a powerful online presence with your school website.
      • Franchises
        Seamlessly push brand-approved marketing to all locations or specific locations - easily.
      • Retail
        Sell with excellence in-store and online.
      • Media
        Don’t just break news, break news everywhere.
      • Travel & Tourism
        Give travellers the speed and reliability they demand.
      • Membership Organizations
        Empower Your Membership Management with Smart Technology
  • Resources
    • Insights
      • Blog
      • Guides
      • FAQ
      Developers
      • Getting started
      • Documentation
      • API
  • Pricing
  • Partners
    • Why Partner?
    • Program Overview
    • Become a partner
Get started
 
  1. Home
  2. Core dna insights

Are GDPR Fines Out of Control? Let’s Find Out

Are GDPR Fines Out of Control? Let’s Find Out
Sam Saltis
March 29, 2021 - (7 min read)

Web Development | Security

With record-breaking GDPR fines hitting headlines, it’s fair to ask—has enforcement gone too far? We dig into the data and trends to uncover what’s really driving the spike in penalties.

Key takeaways

  • GDPR applies globally: Any company handling EU citizen data must comply, regardless of where it's based.
  • Fines are severe: Violations can cost up to €20 million or 4% of annual global revenue, whichever is higher.
  • Fines depend on several factors: Including the severity of the breach, response actions, and past history.
  • Compliance builds trust: Meeting GDPR standards not only avoids fines but also strengthens customer confidence.
In a hurry? Get Headless CMS

On this page:

    What is GDPR?

    GDPR stands for General Data Protection Regulation. It’s a long, winding set of laws that essentially tighten data protection protocols for any business dealing with EU-citizen data. Plus, it gives those same citizens a whole bunch of new powers over their data, even if it’s on a faraway company’s server.

    The GDPR was primarily designed for two purposes: to offer users more control over their data, and to provide more transparency in the data collection process. According to the European Union, the new set of laws “regulates the processing by an individual, a company or an organization of personal data relating to individuals in the EU.” The data protection requirements apply to any individual or company that uses another party's data “outside the personal sphere, (such as) for socio-cultural or financial activities”.

    Our very own blog post, GDPR explained in five minutes, will guide you through the rest of the legislation.

    How to Choose a CMS: The Ultimate Guide

    The need for GDPR compliance

    The impetus behind the call for GDPR compliance comes down to the one idea that, without it, no business transaction could ever take place: Trust. The GDPR seeks to ensure that customers can trust businesses to protect their sensitive data, maintain transparency about what they do with that data, and, in the event of a security breach, that the customers are informed of the breach in a timely manner.

    Read this next: Website Security: What You Need to Know Before It's Too Late

    GDPR fines: How much are we talking here?

    Companies can be fined for GDPR violations on one of two levels.

    Lower-level violations can merit a fine of €10 million or two percent of the violator's worldwide annual revenue, whichever is higher. That's revenue, as in income before expenses. A more serious violation can result in a fine of €20 million, or four percent of the violator's annual revenue — again, whichever is higher. Individuals can also face fines for GDPR violations if they use other parties' personal data for anything other than personal purposes.

    The fines for GDPR violations promise to be among the harshest levied against any industry for any breach of the public trust. Here’s why:

    Image. GDPR fines: How much are we talking here?

    How GDPR fines are calculated

    Article 83 of the GDPR outlines how the fines will be calculated prior to assessing the penalties to violators. The ten major criteria that authorities will use to determine fines will include:

    1. Did the offender meet the standards for data protection certifications?
    2. Did the offender cooperate with authorities investigating the data breach?
    3. What type of personal data was accessed due to the breach?
    4. Did the offender have a history of allowing such data breaches?
    5. Was the data breach due to the offender's negligence or intentional action?
    6. What actions did the offender take to mitigate the damage?
    7. What was the nature and extent of the damage caused by the data breach?
    8. When did the offender notify the regulatory authorities and the affected parties about the data breach?
    9. What preventative measures did the offender take prior to the data breach?
    10. What other mitigating circumstances were involved in the data breach?

    The true impact of GDPR fines

    The impact that a significant GDPR fine can have on a firm's bottom line can be devastating, even for some of the world's biggest companies. In the case of a firm that commits the most egregious violations, as listed above, the effect of a fine totaling up to four percent of annual revenue can cause the company's profit numbers to go from black to red in an instant.

    Gavin Millard, EMEA technical director of the data security firm Tenable, told InfoSecurity Magazine that the firms with the highest revenues face the possibility of the highest fines, as “the larger the revenue, the larger the risk, and the larger the fines”.

    Image. The true impact of GDPR fines

    As an example of what these firms could face, an article in Digital Guardian examined what the impact would have been if GDPR had been in effect during the 2025 data breach of Hilton Hotels. In November 2017, the New York Attorney General's Office fined Hilton $700,000 for a breach involving data from 350,000 customers, an average of $2 per record. Under GDPR, the fine could have been as high as $420 million.

    Preparing for GDPR compliance

    With just a few months to go before these rules go into effect, companies that handle EU-based clients are scrambling to meet GDPR standards. The key to ensuring GDPR compliance lies in asking the right questions, such as:

    • Do third parties have access to our customer data?
    • If so, what preventative measures are they taking to protect that data?
    • What protections do we have against data breaches?
    • If a data breach occurs, can we detect it?
    • What data protection training do we have for our employees?
    • Can we process data deletion requests?
    • How can we manage user consent in ways that are GDPR-compliant?

    GDPR: Prevention is better (and cheaper) than cure

    The prospect of facing stiff fines for failing to comply with such strict rules may cause companies to fear the new regulations. While the fines can have a serious impact of a firm's bottom line, many companies are looking at the new rules as an opportunity, rather than a threat. These companies see the chance to step up their data security methods as a means to protect both themselves and their customers.

    Companies who comply with the new GDPR rules can earn higher levels of trust from their customers, their investors, and the market at large. While the efforts to remain in compliance can be stressful and expensive, the investment of time and effort into maintaining compliance will save companies from the damage of fines, lawsuits, and damage to their reputations.

    Have questions? Speak with our experts to find your ideal content solution
    Sam Saltis
    Sam Saltis

    Sam Saltis is the founder and CEO of Core dna, a digital experience platform (DXP) that helps digital teams build and optimize complex, dynamic websites with less code than ever before. Sam has more than 30 years’ experience building technology solutions for various industries and sectors, such as government, business and tourism. 

    He leads a team of technology experts who share his vision of empowering clients to harness the Internet to scale their businesses and enhance their relationships.

    Previous PostHow to Improve eCommerce Conversions by Creating Urgency in Sales
    Back
    Next PostIs Drupal CMS Still the Best Choice for Commerce?

    Related guides

    • What is GraphQL: Your Secret Weapon
    • Progressive Web App (PWA): The Ultimate Guide
    • How to design the Perfect eCommerce Website
    See all guides

    Related posts

    How to Choose the Right eCommerce Web Development Approach

    Web Development

    How to Choose the Right eCommerce Web Development Approach
    March 01, 2025 ( 11 min read )
    Webhook vs API? Choose The Right Tool for Your Integrations

    eCommerce Business

    Webhook vs API? Choose The Right Tool for Your Integrations
    February 19, 2025 ( 4 min read )
    Web Development Trends 2025: 27 Trends Shaping the Future of Development

    Web Development

    Web Development Trends 2025: 27 Trends Shaping the Future of Development
    January 17, 2025 ( 10 min read )
    The Truth About SAP Commerce Cloud: Pros, Cons & More

    Web Development

    The Truth About SAP Commerce Cloud: Pros, Cons & More
    January 10, 2025 ( 9 min read )
    Website Replatforming: Smart Move or Hidden Risk?

    Web Development

    Website Replatforming: Smart Move or Hidden Risk?
    January 02, 2025 ( 22 min read )
    No code, big wins! How to built an LMS in weeks

    About Core dna

    No code, big wins! How to built an LMS in weeks
    December 22, 2024 ( 6 min read )
    CMS Migration Checklist: A Comprehensive Step-by-Step Guide

    Web Development

    CMS Migration Checklist: A Comprehensive Step-by-Step Guide
    December 04, 2024 ( 7 min read )
    eCommerce Website Requirements: The Essential Checklist

    Web Development

    eCommerce Website Requirements: The Essential Checklist
    November 06, 2024 ( 13 min read )
    Franchise Website Development Essentials

    Web Development

    Franchise Website Development Essentials
    October 30, 2024 ( 5 min read )
    4 Tips for Managing a High Traffic Website

    Web Development

    4 Tips for Managing a High Traffic Website
    August 08, 2024 ( 10 min read )
    Open Source vs Closed Source: What You Need to Know

    Web Development

    Open Source vs Closed Source: What You Need to Know
    July 11, 2024 ( 17 min read )
    December 2023 - Release 6: Customizable admin menus and OAuth 2.0

    Web Development

    December 2023 - Release 6: Customizable admin menus and OAuth 2.0
    December 16, 2023 ( 5 min read )
    Solutions by Role
    • Partners
    • Developers
    • Executives
    • Marketers
    Solutions by Need
    • Intranet
    • Event Management
    • Content Management
    • B2b eCommerce
    • B2c eCommerce
    • Headless
    • Marketing
    Solutions by Industry
    • Community
    • Healthcare
    • Finance
    • Technology
    • Hospitality
    • Franchise
    • Education
    • Travel & Tourism
    Company
    • About Us
    • Why Core dna
    • Partner Ecosystem
    • Customers
    • Careers
    • Contact Us
    • G2Crowd Reviews
    Resources
    • Blog
    • Guides
    • Admin login
    • RSS Feed
    • Documentation
    Support
    • Help
    • Videos
    • Network Status
    • GDPR
    • Privacy Policy
    • Terms & Conditions
    • Fair Use Policy
    Get our latest articles
    Success! You've been added to our email list.
    Melbourne

    348 High Street

    Prahran, VIC 3181

    Australia

    +61 3 85639100

    Boston

    55 Court St, Level 2

    Boston, MA 02108

    USA

    +1 617 274 6660

    Berlin

    Belziger Str. 71

    Berlin 10823

    Germany

    +1 617 274 6660

    Go wow them! ™ | Core dna copyright ©  2025.