The two main UK GDPR ceilings are £8.7 million or 2% of worldwide annual turnover and £17.5 million or 4%, using the higher figure for an undertaking.
Those statutory maximums do not set automatic tariffs. The ICO decides whether to issue a penalty notice and sets the amount from the infringement, seriousness, turnover where relevant, and aggravating or mitigating factors.
ICO enforcement can include warnings about intended processing, reprimands for infringements, orders, processing restrictions, fines, or a combination permitted by law. The and are ceilings; they do not set default penalties. The ICO must assess the individual case, and the turnover percentage applies to an only when it produces a higher ceiling than the fixed sterling amount.
1
Section 1
What should teams understand about UK GDPR penalties and fines?
Article 83 and section 157 DPA 2018 create two main ceilings. The standard band is £8.7 million or, for an , the higher of £8.7 million and 2% of total worldwide annual turnover in the preceding financial year. The higher band is £17.5 million or, for an undertaking, the higher of £17.5 million and 4% of that turnover.
The percentage does not automatically apply to every business. It produces the statutory ceiling only when it exceeds the fixed amount. The ICO gives the crossover figures as worldwide turnover above £435 million for the 2% band and above £437.5 million for the 4% band.
For example, an with £300 million in preceding-year worldwide turnover still has an £8.7 million standard ceiling because 2% is £6 million. At £500 million, the standard ceiling is £10 million and the higher ceiling is £20 million. These calculations identify only the maximum; they do not estimate the fine.
A statutory maximum does not predict the fine. The Commissioner must ensure that a fine is effective, proportionate, and dissuasive, and must consider the Article 83(2) factors that are relevant to the case. Article 83 and the DPA 2018 are binding law. The ICO's fining guidance explains its current evaluative approach but does not replace the statutory test or make the five steps a tariff.
Standard band: specified controller and processor duties in Articles 8, 11, 25 to 39, 42, and 43, plus specified certification-body and code-monitoring duties.
Higher band: processing principles and consent in Articles 5, 6, 7, and 9; rights in Articles 12 to 21; specified automated-decision safeguards in Articles 22B and 22C; international-transfer duties; specified DPA 2018 obligations; and non-compliance with certain ICO orders or access powers.
Separate DPA 2018 powers also cover failures involving information notices, assessment notices, enforcement notices, and data-protection charges; the applicable provision determines the penalty route and maximum.
Controllers, processors, certification providers, monitoring bodies, and other persons can face fines where the cited provisions apply. Identify the legal role before selecting a band.
A fine is one possible corrective measure. The ICO may also use warnings, reprimands, orders to comply, rectification or erasure orders, processing restrictions, or suspension of data flows where its powers and the case permit.
Which facts can increase or reduce a UK GDPR fine?
Article 83(2) directs the Commissioner to consider the nature, gravity, and duration of the infringement; the processing purpose and scope; the number of people affected and their damage; whether conduct was intentional or negligent; mitigation; responsibility for technical and organisational measures; previous infringements; cooperation; data categories; how the ICO learned of the issue; compliance with earlier measures; approved codes or certification; and other aggravating or mitigating factors such as financial benefit or avoided loss.
Prompt remediation and cooperation can matter, but they do not erase the infringement or guarantee a reduced fine. Evidence should show what the organisation knew, what control failed, how quickly it contained and corrected the issue, how it protected people, and whether it complied with notification and ICO requests.
Scope and impact: affected processing, duration, data categories, number and types of people affected, and evidence of actual or potential damage.
State of mind and responsibility: decision records, risk assessments, warnings, budgets, control ownership, training, testing, and whether conduct was intentional or negligent.
Response: containment, mitigation for people, correction, regulator and individual notifications, preservation of evidence, and recurrence prevention.
Regulatory history: previous infringements, earlier ICO measures, compliance with those measures, and the completeness and timing of cooperation.
Financial context: benefit gained or loss avoided, the legal-entity and group structure, economic activity, autonomy, and the preceding financial year's worldwide turnover.
The ICO's fining guidance uses five steps: assess seriousness; account for turnover where the controller or processor is part of an ; calculate a starting point from seriousness and, where relevant, turnover; adjust for aggravating and mitigating factors; and check that the result is effective, proportionate, and dissuasive. The ICO says this is an evaluative process, not a mechanical formula.
Where the same or linked processing operations intentionally or negligently infringe several UK GDPR provisions, Article 83(3) caps the total at the maximum for the gravest infringement. That rule does not combine genuinely separate conduct into one ceiling. The ICO assesses whether operations are linked from the circumstances, including their purpose, affected people, and timing.
For example, the ICO guidance treats an Article 8 children's-consent failure and an Article 13 transparency failure arising from the same or linked processing as subject to the single gravest-infringement ceiling, even if separate amounts are identified. By contrast, a security failure involving employee salary and bank details and an unrelated transparency failure in direct marketing can be separate conduct, so each infringement has its own applicable maximum.
Financial hardship is not assumed from the size of a proposed fine. The ICO guidance says a reduction for inability to pay is available only in exceptional circumstances after the appropriate amount has been calculated.
Map each alleged infringement to the exact UK GDPR or DPA 2018 provision and its maximum band.
Separate the infringement decision from the seriousness assessment and the later calculation of amount.
Determine whether the controller or processor forms part of a wider before using turnover.
Identify whether multiple findings arise from the same or linked processing operations or from separate conduct.
Retain the source financial statements, group and control analysis, factual chronology, mitigation record, and submissions relied on.
What should an organisation do when an infringement or ICO investigation is possible?
Contain continuing harm, preserve evidence, and identify the controller, processor, and before estimating exposure. Meet any separate breach-notification or rights-request deadline; responding to an investigation does not pause those duties.
Build a provision-by-provision record instead of multiplying turnover by a percentage. Include the alleged conduct, affected processing, dates, people and data, applicable maximum, Article 83 factors, remediation, regulatory correspondence, financial evidence, and unresolved factual or legal issues. Separate verified facts, the organisation's position, and assumptions. Obtain case-specific legal advice where liability, privilege, appeals, or representations on a proposed penalty are in issue.
Is the maximum UK GDPR fine always 4% of turnover?
No. The infringement determines the band. The standard ceiling is £8.7 million or, for an , the higher of £8.7 million and 2% of worldwide annual turnover in the preceding financial year. The higher ceiling is £17.5 million or, for an undertaking, the higher of £17.5 million and 4%. The final fine can be lower, and the ICO assesses each case.
Does a data breach automatically lead to a fine?
No. A security incident must first be assessed against the UK GDPR duties that apply, including security, processor escalation, ICO notification, affected-person communication, and recordkeeping. The ICO then decides which infringements, if any, are established and whether a is appropriate. Other corrective measures can be used instead of or alongside a fine where the law permits.
Is the turnover calculation based only on the UK company that committed the infringement?
Not necessarily. If the controller or processor is part of an , the ICO can calculate the statutory maximum from the undertaking's worldwide turnover as a whole. An undertaking can include a parent and subsidiary that form one economic unit. The result depends on autonomy, decisive influence, and the economic, organisational, and legal links in the specific group.
Can remediation prevent a UK GDPR fine?
Remediation can be relevant mitigation, but it does not erase an infringement or guarantee that the ICO will avoid or reduce a fine. The Commissioner considers mitigation alongside seriousness, intent or negligence, responsibility, prior infringements, cooperation, affected data, notification, compliance with earlier measures, and other aggravating or mitigating factors.
Stop or reduce continuing risk and keep a dated record of each containment and mitigation step.
Preserve logs, notices, policies, DPIAs, contracts, decisions, tickets, complaints, communications, and financial records without altering the originals.
Map each fact to the exact obligation, responsible role, maximum band, seriousness evidence, and aggravating or mitigating factor.
Coordinate accurate, timely responses to ICO information, assessment, or enforcement notices and track every stated deadline.
Keep public, customer, employee, insurer, board, and regulator communications consistent with the verified facts.
Record the outcome separately for each alleged infringement: not established, established without a , included in a penalty notice with the applicable maximum and amount, or addressed through another corrective measure.
Current ICO guidance confirms the £8.7 million or 2% and £17.5 million or 4% ceilings and explains when turnover produces the higher statutory maximum.