Other articles

  • What is the difference between a Privacy Policy and a Cookie Policy?
  • Do I need a cookie policy on my website?
  • What is a Cookie Policy?
  • What is a Privacy Policy generator?
  • How to write a privacy policy?
  • What is a privacy policy?

Knowledge base

Menu

  • Pricing
  • Features
    • Regulation compliance
    • GDPR (EU)
    • CCPA (California)
    • PIPEDA (Canada)
    • LGPD (Brasil)
    • KVKK (Turkey)
    • POPIA (South Africa)
    • The basics
    • 42 languages
    • User consents recording
    • Third-party cookie blocking
    • Geo targeting
    • Self-hosted code
    • Google Consent Mode v2
    • Automation
    • Automatic monthly scans
    • Automatic script blocking
    • Advanced reporting
    • Cookie Banner sharing
    • IAB TCF 2.2 integration
    • Google-certified CMP
  • Resources
    • Cookie Scanner
    • Privacy Policy Generator
    • System status
    • Roadmap
    • Changelog
  • Blog
    • Guides
    • News
    • GDPR & CCPA
    • Privacy laws
    • Compare
    • Knowledge base
  • Support
    • Help Center
    • Integrations
    • Contact us
    • Feature request
  • For partners
    • Agencies
    • Affiliates
  • separator
  • Language switcher
    • Profile
    • Billing
    • My plan
  • Sign in
  • Try now
Details

Does not complying with GDPR always lead to penalties?

There are two levels of GDPR fines: for severe violations and for lower-level violations.

The lower-level violations could result in an administrative fine of up to €10 million, or 2% of the annual global turnover of the company of the preceding financial year, whichever is higher.

The severe violations could result in an administrative fine of up to €20 million, or 4% of the annual global turnover of the company of the preceding financial year, whichever is higher.

However, not all GDPR violation cases lead to penalties. The GDPR supervisory authority has the power to decide the action that needs to be taken against the violating company. Depending on the severity of the GDPR violation, the GDPR supervisory authority may take the following measures, with or without fine:

  • Issue warning;
  • Temporarily or permanently ban the activity of the company;
  • Request user's personal data deletion;
  • Request to restrict the user's personal data transfer to a third party.
 
  • About CookieScript
  • Terms of Service
  • Privacy Policy
  • Pricing
  • Resources
  • Cookie Scanner
  • Privacy Policy Generator
  • System status
  • Sitemap
  • Changelog
  • Alternatives
  • CookieBot
  • Termly
  • OneTrust
  • Iubenda
  • Cookie Information
  • CookieFirst
  • Illow
  • Blog
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Knowledge base
  • Support
  • Help center
  • Contact us
  • Integrations
  • Request a feature
  • Roadmap
  • For Partners
  • For agencies
  • For Affiliates

Copyright ©2025 CookieScript


main version