The Guidelines aim to standardize how supervisory authorities calculate fines under GDPR, complementing previous guidelines that focused on when to impose fines. The new guidelines outline a five-step methodology for determining fines, taking into account factors like the nature and seriousness of the infringement, the offending entity's behavior and turnover, and legal maximum limits, while ensuring the fines are effective, proportionate, and dissuasive. The guidelines emphasize that fine calculation is not a strict mathematical process but depends on the specifics of each case..
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2023-05-24
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Official guidance