The Data Act covers personal and non-personal data, but it does not displace EU or national data-protection and privacy law. Article 1(5) says those laws continue to apply and prevail if they conflict with the Data Act.
For infringements of Chapters II, III, and V, a GDPR supervisory authority may, within its scope of competence, use Article 83 GDPR fines up to the amount in Article 83(5): EUR 20 million or, for an undertaking, 4% of total worldwide annual turnover in the preceding financial year, whichever is higher. That is a specific route, not the cap for every Data Act infringement. The European Data Protection Supervisor has a separate Article 40(5) route for Chapter V infringements within its competence.
Classify the issue before using either route: connected-product access, mandatory business-to-business sharing, public-sector access, cloud switching, trade secrets, or personal-data protection. Questions about legal basis, data-subject rights, and personal-data processing may require the data protection authority.