Legal Q&A · Compliance, Registers & Licences

How does the authority calculate a fine for a GDPR breach?

Law as at 10 September 2026

Short answer

The EDPB methodology in Guidelines 04/2022 uses five steps: identify the processing operations, set a starting amount based on the infringement category, severity and the undertaking's turnover, adjust for aggravating and mitigating factors, check the statutory ceiling, and assess effectiveness and proportionality. Ceilings are EUR 10 or 20 million, or 2% or 4% of worldwide turnover for undertakings. Turnover means the whole group, rather than only the company at fault. Arguments can address severity, remediation and enhanced cooperation; mandatory notification itself is neutral. Inability to pay is considered only exceptionally.

Data protection fines are not guessed. Supervisory authorities across the Union, including Slovakia’s Office for Personal Data Protection, use the European Data Protection Board’s methodology, Guidelines 04/2022 on calculating administrative fines, to build the amount in five steps. Knowing those steps helps identify which arguments carry weight and when to present them.

Five calculation steps

  1. The authority identifies the processing operations under review and assesses concurrent infringements. If several infringements arise from the same or linked operations, the total fine cannot exceed the ceiling for the most serious one (Article 83(3) GDPR).
  2. It sets the starting amount by infringement category (Article 83(4) to (6)), severity in the specific case, including nature, scope, duration, intention or negligence and data categories, and the undertaking’s turnover.
  3. It adjusts the amount for aggravating and mitigating factors under Article 83(2).
  4. It checks that the result stays within the statutory maximum.
  5. It assesses whether the fine is effective, proportionate and dissuasive (Article 83(1)). The amount can still move either way at this stage.

The ceilings and why group turnover matters

The Regulation provides two bands. Breaches of controller and processor duties, such as processing security, records or incident reporting, carry a ceiling of EUR 10 million or 2% of total worldwide annual turnover, whichever is higher (Article 83(4)). Breaches of processing principles, legal basis, data subject rights and transfer rules carry a ceiling of EUR 20 million or 4% (Article 83(5) and (6)). Slovak law adopts these bands:

The Office may impose a fine of up to EUR 20,000,000 or, for an undertaking, up to 4% of total worldwide annual turnover for the preceding financial year, whichever is higher, on a person who: a) failed to comply with or breached a basic principle of personal data processing, including the conditions for consent […].

Section 104(2) of Act No. 18/2018 Coll. (unofficial English translation)

The undertaking is not just the company that breached the duty. The methodology adopts competition law’s single-economic-unit concept, so a subsidiary in a large group is assessed using group turnover. It also works the other way: for low turnover, the authority substantially reduces the starting amount using the methodology’s tables to reflect business size. A microenterprise and a multinational group therefore do not receive the same amount for the same infringement.

Where arguments can make a difference

The main opportunities are steps two, three and five. Severity includes the nature and scope of processing, number of people affected, data categories and degree of fault. A limited negligent breach starts from a different position than a deliberate, systemic one. Steps to mitigate harm and enhanced cooperation that genuinely limits adverse consequences may be mitigating factors. Previous infringements may be aggravating; their absence is neutral. Compliance with the duty to notify an incident under Article 33 and ordinary cooperation required by law are likewise neutral. Voluntary notification beyond what is required and assistance exceeding the statutory standard are different. Compliance with approved codes of conduct is also considered (EDPB Guidelines 04/2022, version 2.1, paragraphs 94–99). Exceptionally, the methodology permits a reduction for inability to pay, but requires objective evidence that the fine would irreversibly threaten the company’s economic viability. The authority will not construct these arguments for you. Document remedial steps, cooperation and impacts during the proceedings, rather than waiting for an administrative appeal.

We summarise common underlying breaches in your duties when processing data. A typical operational risk is illustrated in cameras at the workplace and in shops.

How we can help

We put processing and documentation in place to withstand inspection through GDPR and personal data protection. A data protection officer can provide ongoing oversight. We represent you before the authority and in judicial review through court representation.

If you have received notice of proceedings, contact us before your first response. The first submission already influences the authority’s assessment of severity and cooperation.

This answer provides general information on the law as at 10 September 2026. It does not constitute legal services or replace an assessment of an individual case. The details of your situation may differ. Book a consultation to discuss them.

More legal questions

All questions and answers
  1. We drive a van with a trailer abroad. Do we need a tachograph from 1 July 2026? Very probably yes. If the vehicle's maximum permissible mass, including any trailer, exceeds 2.5 tonnes and you carry goods across borders, it must have a second-generation smart tachograph from 1 July 2026. The driver must observe driving times, breaks and rest periods as truck drivers do. The new extension for combinations over 2.5 and up to 3.5 tonnes applies to international transport and cabotage. Above 3.5 tonnes, domestic journeys may also be covered; statutory exemptions must always be assessed. At an inspection, the relevant records for the inspection day and the preceding 56 days must be produced.
  2. Do we need an internal whistleblowing system? Yes, if you employ at least 50 people; public authorities are covered from five employees, and employers in financial services, transport safety or environmental services regardless of size. The system requires a designated responsible person, published reporting channels, an internal policy and a register of reports. Receipt must be acknowledged within seven days and investigation results communicated within 90 days. The Whistleblower Protection Office may impose a fine of up to EUR 50,000, or EUR 100,000 for employers with at least 250 employees.
  3. We want to change the authorised person in the Register of Public Sector Partners. How does it work? The change is always a replacement, because the register allows only one authorised person. You sign a written agreement with the new person, who verifies the beneficial owners afresh, prepares a verification document and electronically applies to register the change; the law does not require cooperation from the former person. However, if the former person requested their own removal, you must secure a replacement within 30 days of removal. After that period the other contracting party may withhold payments and, if the delay exceeds 30 days, withdraw from the contract.
  4. When is a certified signature enough, and when do we need lawyer authorisation? These are different legal procedures. Official signature certification by a notary, municipality or district office confirms only that a particular person signed the document; its content is not reviewed. In authorisation, a lawyer drafts the contract, establishes the parties' identities, checks legality and bears liability for damage. The cadastre does not require certified signatures on such contracts. Since 17 August 2026, incorporation documents and business interest transfers require lawyer authorisation or a notarial deed. A qualified electronic signature with a timestamp replaces a handwritten signature and its certification, but not authorisation or a notarial deed.

Cannot find your question? Ask your own question

Facing this situation?

Tell us what you need help with.

Describe your situation. We will review it and tell you within 24 hours whether and how we can help, including an indicative fee.

  1. 1Send your enquiry via this form
  2. 2Within 24 h you get a price confirmation and plan
  3. 3We start work only after your approval
Mgr. Patrik Tulinský, LL.M. Czech and Slovak attorney · SAK 300422 · ČAK 19654

Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.

PDF, Word, images, ZIP… max 10 MB per file, 30 MB total.

Submitting this form does not create an engagement or attorney-client relationship. Before taking on a matter we run a conflict-of-interest check, so please do not send sensitive originals until we confirm the matter together.