Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Articles 83-84 (Sanctions)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Legal Reference⚖️ GDPR Regulatory Text⚖️ Binding Legal Force

Articles 83 & 84 GDPR : Criteria and Statutory Ceilings for Administrative Fines

Official EU Regulation (EU) 2016/679 legal analysis · Controlled official sources

⚡ In 30 seconds:

Article 83 GDPR and EDPB Guidelines 04/2022 govern administrative fines across two statutory ceilings (€10M/2% worldwide turnover or €20M/4% worldwide turnover), applying a harmonised multi-step calculation method ensuring effectiveness, proportionality, and dissuasiveness.

The Two Tiers of Administrative Fines (Arts. 83(4) & 83(5) GDPR)

Article 83 establishes two tiers of maximum administrative financial penalties calculated on the total worldwide annual turnover of the preceding financial year of the undertaking (economic concept of an undertaking under Articles 101 and 102 TFEU):

  • Tier 1 (Art. 83(4)) — Up to €10,000,000 or 2% of total worldwide annual turnover: Infringements of governance and security obligations (Privacy by Design Art. 25, processor contracts Art. 28, records Art. 30, security Art. 32, breach notification Arts. 33-34, DPIA Arts. 35-36, DPO appointment Arts. 37-39);
  • Tier 2 (Art. 83(5)) — Up to €20,000,000 or 4% of total worldwide annual turnover: Infringements of core principles (Art. 5), legal grounds (Art. 6), sensitive data (Art. 9), data subjects' rights (Arts. 12 to 22), or international transfer rules (Arts. 44 to 49).

Harmonised Methodology for Calculating Fines (EDPB Guidelines 04/2022)

In accordance with EDPB Guidelines 04/2022, supervisory authorities apply a harmonised five-step methodology to determine the final amount of the administrative fine:

  • Step 1: Identifying the processing operations and classifying the established infringements;
  • Step 2: Determining the starting amount based on the gravity of the infringement (low, medium, high) and the turnover/economic size of the undertaking;
  • Step 3: Evaluating aggravating and mitigating circumstances (Art. 83(2));
  • Step 4: Verifying compliance with statutory legal maximum ceilings (Arts. 83(4) and 83(5));
  • Step 5: Final assessment of whether the total fine is effective, proportionate and dissuasive.

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
⚖️ Binding Source
Meta Platforms / Bundeskartellamt (4 juil. 2023) · ECLI: ECLI:EU:C:2023:537

Publicité personnalisée : rejet de l'exécution contractuelle et de l'intérêt légitime pour le traitement massif croisé sans consentement libre

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Lignes Directrices 04/2022 sur le calcul des amendes · 2022-05-24

Méthodologie d'harmonisation du calcul des amendes administratives financières sous l'Article 83

Consult official source →

See Also in the Legal Framework

Article 5 GDPR Official Text

Article 5 GDPR: Cardinal Processing Principles & Accountability

Legal analysis of the cardinal principles in Article 5 GDPR: lawfulness, fairness, transparency, purpose limitation, dat...

View document
Article 6 GDPR Official Text

Article 6 GDPR: The Six Lawful Grounds for Lawful Processing

Legal analysis of Article 6 GDPR: the six alternative legal bases for lawfulness of processing, valid consent criteria, ...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-23 Last modified: 2026-08-23

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice