The EDPB methodology in Guidelines 04/2022 uses five steps: identify the processing operations, set a starting amount based on the infringement category, severity and the undertaking's turnover, adjust for aggravating and mitigating factors, check the statutory ceiling, and assess effectiveness and proportionality. Ceilings are EUR 10 or 20 million, or 2% or 4% of worldwide turnover for undertakings. Turnover means the whole group, rather than only the company at fault. Arguments can address severity, remediation and enhanced cooperation; mandatory notification itself is neutral. Inability to pay is considered only exceptionally.
Data protection fines are not guessed. Supervisory authorities across the Union, including Slovakia’s Office for Personal Data Protection, use the European Data Protection Board’s methodology, Guidelines 04/2022 on calculating administrative fines, to build the amount in five steps. Knowing those steps helps identify which arguments carry weight and when to present them.
Five calculation steps
- The authority identifies the processing operations under review and assesses concurrent infringements. If several infringements arise from the same or linked operations, the total fine cannot exceed the ceiling for the most serious one (Article 83(3) GDPR).
- It sets the starting amount by infringement category (Article 83(4) to (6)), severity in the specific case, including nature, scope, duration, intention or negligence and data categories, and the undertaking’s turnover.
- It adjusts the amount for aggravating and mitigating factors under Article 83(2).
- It checks that the result stays within the statutory maximum.
- It assesses whether the fine is effective, proportionate and dissuasive (Article 83(1)). The amount can still move either way at this stage.
The ceilings and why group turnover matters
The Regulation provides two bands. Breaches of controller and processor duties, such as processing security, records or incident reporting, carry a ceiling of EUR 10 million or 2% of total worldwide annual turnover, whichever is higher (Article 83(4)). Breaches of processing principles, legal basis, data subject rights and transfer rules carry a ceiling of EUR 20 million or 4% (Article 83(5) and (6)). Slovak law adopts these bands:
The Office may impose a fine of up to EUR 20,000,000 or, for an undertaking, up to 4% of total worldwide annual turnover for the preceding financial year, whichever is higher, on a person who: a) failed to comply with or breached a basic principle of personal data processing, including the conditions for consent […].
— Section 104(2) of Act No. 18/2018 Coll. (unofficial English translation)
The undertaking is not just the company that breached the duty. The methodology adopts competition law’s single-economic-unit concept, so a subsidiary in a large group is assessed using group turnover. It also works the other way: for low turnover, the authority substantially reduces the starting amount using the methodology’s tables to reflect business size. A microenterprise and a multinational group therefore do not receive the same amount for the same infringement.
Where arguments can make a difference
The main opportunities are steps two, three and five. Severity includes the nature and scope of processing, number of people affected, data categories and degree of fault. A limited negligent breach starts from a different position than a deliberate, systemic one. Steps to mitigate harm and enhanced cooperation that genuinely limits adverse consequences may be mitigating factors. Previous infringements may be aggravating; their absence is neutral. Compliance with the duty to notify an incident under Article 33 and ordinary cooperation required by law are likewise neutral. Voluntary notification beyond what is required and assistance exceeding the statutory standard are different. Compliance with approved codes of conduct is also considered (EDPB Guidelines 04/2022, version 2.1, paragraphs 94–99). Exceptionally, the methodology permits a reduction for inability to pay, but requires objective evidence that the fine would irreversibly threaten the company’s economic viability. The authority will not construct these arguments for you. Document remedial steps, cooperation and impacts during the proceedings, rather than waiting for an administrative appeal.
We summarise common underlying breaches in your duties when processing data. A typical operational risk is illustrated in cameras at the workplace and in shops.
How we can help
We put processing and documentation in place to withstand inspection through GDPR and personal data protection. A data protection officer can provide ongoing oversight. We represent you before the authority and in judicial review through court representation.
If you have received notice of proceedings, contact us before your first response. The first submission already influences the authority’s assessment of severity and cooperation.
This answer provides general information on the law as at 10 September 2026. It does not constitute legal services or replace an assessment of an individual case. The details of your situation may differ. Book a consultation to discuss them.