Art. 83 GDPR – General conditions for imposing administrative fines
| Art. 83(1) | Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive. | proportionality principle |
| Art. 83(2) | Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on its amount, due regard shall be given to:
| eleven factors |
| Art. 83(3) | If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total fine shall not exceed the amount specified for the gravest infringement. | single gravest infringement |
| Art. 83(4) | Infringements of the following shall be subject to fines of up to €10.000.000, or up to 2% of total worldwide annual turnover of the preceding financial year for an undertaking, whichever is higher:
| lower tier ceiling |
| Art. 83(5) | Infringements of the following shall be subject to fines of up to €20.000.000, or up to 4% of total worldwide annual turnover of the preceding financial year for an undertaking, whichever is higher:
| higher tier ceiling |
| Art. 83(6) | Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to fines of up to €20.000.000, or up to 4% of total worldwide annual turnover, whichever is higher. | non-compliance ceiling |
| Art. 83(7) | Without prejudice to the corrective powers of supervisory authorities under Article 58(2), each Member State may lay down rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. | public authority carve-out |
| Art. 83(8) | The exercise by a supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards under Union and Member State law, including effective judicial remedy and due process. | procedural safeguards |
| Art. 83(9) | Where the legal system of the Member State does not provide for administrative fines, this Article may be applied so that the fine is initiated by the competent supervisory authority and imposed by competent national courts, provided those remedies are effective and equivalent to administrative fines. In any event, the fines imposed shall be effective, proportionate and dissuasive. Those Member States notified the Commission of the relevant provisions of their laws by 25 May 2018 and must notify any subsequent amendment without delay. | non-administrative-fine states |
Article 83 is not an obligation to comply with. It is the rulebook a supervisory authority must follow once an infringement of another article is already established, deciding whether to fine a controller or processor and how much. It sets two fine ceilings depending on which provisions were breached, lists eleven factors authorities must weigh in every case, and requires every fine to be effective, proportionate and dissuasive.
Two CJEU rulings since 2023, Deutsche Wohnen and ILVA, have clarified how far it reaches: a company can be fined without a named, culpable employee being identified, and the fine ceiling is set by the turnover of the whole corporate group the controller belongs to, not just the entity under investigation.
Key Facts
| Chapter | Chapter 8 – Remedies, liability and penalties (Art. 77–84) |
|---|---|
| Applies to | Every supervisory authority deciding whether, and how much, to fine a controller or processor for an infringement established under another GDPR article |
| Maximum fine | Article 83 sets the ceiling itself: up to €20.000.000 or 4% of worldwide annual turnover, whichever is higher, for the most serious categories (Art. 83(5)–(6)) |
| In force since | 25 May 2018 |
| Explained by recitals | 148, 149, 150, 151, 152 |
| Closest UK equivalent | UK GDPR Art. 83, near-identical wording, ceiling expressed in GBP: up to £17.5 million or 4% of global turnover |
The Two Fine Tiers
Which tier applies depends on which underlying article was infringed, not on the size of the company or the number of people affected.
| Tier | Ceiling | Covers infringements of |
|---|---|---|
| Lower tier | €10.000.000 or 2% of global turnover | Child’s-consent verification (Art. 8), processing not requiring identification (Art. 11), Art. 25–39 controller/processor obligations, certification (Art. 42–43) |
| Higher tier | €20.000.000 or 4% of global turnover | Core principles and lawful-basis conditions (Art. 5, 6, 7, 9), data subject rights (Art. 12–22), international transfer rules (Art. 44–49), non-compliance with a supervisory authority order (Art. 58(2)) |
The Eleven Factors Under Article 83(2)
Before setting a fine, an authority must weigh each of the following, in addition to the two-tier ceiling above.
- Nature, gravity and duration of the infringement
- Intentional or negligent character of the infringement
- Mitigating action taken by the controller or processor
- Degree of responsibility, given the technical and organisational measures in place
- Any relevant previous infringements
- Degree of cooperation with the supervisory authority
- Categories of personal data affected
- How the infringement came to the authority’s attention
- Compliance with any earlier order on the same matter
- Adherence to approved codes of conduct or certifications
- Any other aggravating or mitigating circumstance, including financial benefit gained or loss avoided
GDPR Article 83 Cases: How the Conditions for Fines Have Been Tested
Article 83 does not get “infringed” the way a substantive obligation does. It is the mechanism authorities use once an infringement is already established elsewhere. The two cases below are not about a company breaking Article 83. They are the CJEU rulings that fixed how far Article 83’s fining conditions actually reach.
| Organisation | Court / Authority | Date | What Article 83 clarified |
|---|---|---|---|
| Deutsche Wohnen SE | CJEU (referred by Kammergericht Berlin) | 5 Dec 2023 | A company can be fined without identifying a culpable named employee; fault, intent or negligence, is still required |
| ILVA A/S | CJEU (referred by Vestre Landsret, Denmark) | 13 Feb 2025 | The fine ceiling is calculated on the turnover of the whole corporate “undertaking,” not just the fined subsidiary |
All Article 83 conditions-for-fines cases →
Recitals That Explain Article 83
Confirms Member States may impose criminal penalties for GDPR infringements in addition to, or instead of, administrative fines.
Allows Member States to set rules on further penalties for breaches of national provisions adopted under the GDPR.
Sets out the two-tier fine structure and the case-by-case factors authorities must weigh, mirroring Article 83(2).
Recognises that Denmark and Estonia’s legal systems do not provide for administrative fines, so equivalent sanctions run through their national courts instead.
Leaves Member States free to set their own sanctioning rules for infringements not covered by Article 83’s administrative fines.