Privacy

Violation of privacy laws: do you really have to fear heavy fines?

High GDPR fines of up to 20 million euros are possible, but as an ordinary SME, you almost never need to fear those maximum amounts. When determining a fine, the Dutch Data Protection Authority (AP) takes into account the severity of...

Published on March 25, 2019 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

High GDPR fines of up to 20 million euros are possible, but as an ordinary SME, you almost never need to fear those maximum amounts. When determining a fine, the Dutch Data Protection Authority (AP) takes into account the severity of the violation and the size of your company. As a result, for a smaller enterprise, any potential fine usually turns out to be much lower than the high-profile millions mentioned in the news. Nevertheless, the risk is real enough to warrant seriously getting your privacy affairs in order: even a “lower” fine can still be costly, and the AP is also increasingly focusing on remedial measures and penalty payments.

What is a GDPR fine?

The General Data Protection Regulation (GDPR) determines how organizations must handle personal data. In the Netherlands, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is the supervisory body that enforces this. If an organization fails to comply with its obligations, the DPA can take various measures:

  • A warning or reprimand – a formal exhortation to rectify the violation.
  • An order subject to a penalty payment – ​​you must make an adjustment within a certain period, otherwise a penalty payment will accrue.
  • An administrative fine – a monetary fine as a sanction for the violation.

A fine is therefore not the only instrument, and often not the first either. In practice, the AP frequently opts for remedial action first: you are given the opportunity to cease the violation before a fine comes into play. Nevertheless, it pays to know how the fine system works so that you can realistically assess the financial risk.

How high can a GDPR fine be?

The GDPR provides for two statutory maximum fines. Which one applies depends on the type of violation. In each case, the highest of the percentage and the fixed amount applies:

  • Up to 10 million euros or 2% of global annual turnover for violations of additional administrative obligations, such as the absence of a processing register or a processor agreement.
  • Up to 20 million euros or 4% of global annual turnover for more serious infringements, such as violating the fundamental principles of the GDPR or the rights of data subjects.

Important to understand: these are maximums. They are ceilings, not standard amounts. The multi-million euro fines that make the news almost always concern large (often international) enterprises with enormous turnovers and serious, large-scale violations. For the average SME, these amounts are completely out of reach.

How does the Dutch Data Protection Authority calculate a fine?

The Dutch Data Protection Authority (AP) has been working with updated fine policy rules since 2023. For enterprises, the AP aligns with the European guidelines for calculating fines. An important difference compared to the old system is that the size of your enterprise is now taken into account at the outset of the calculation. As a result, the fine aligns better with your actual financial capacity. Broadly speaking, the system works as follows:

  1. The statutory maximum is determined. The AP first examines whether the violation falls under the lighter (2% / 10 million) or the heavier (4% / 20 million) regime.
  2. The severity of the violation is classified. The AP categorizes violations according to severity. The more serious the violation, the larger the portion of the maximum fine that serves as the starting point. Minor violations result in a much lower starting point than serious ones.
  3. Company size determines the starting amount. An enterprise with modest turnover applies only a small fraction of the starting amount that would apply to a large enterprise. This significantly reduces the fine, particularly for SMEs.
  4. Aggravating and mitigating factors. Next, the AP examines the specific circumstances: the duration of the violation, the number of parties involved, whether you acted intentionally or were negligent, and whether you cooperated and limited the damage. The fine is higher in the case of repeated violations.

The result: there is no fixed price tag per violation. Two companies that formally violate the same rule can receive widely differing fines, depending on their size and the circumstances.

The fine amounts from older articles and policy rules (with fixed base fines per category) are outdated. Therefore, do not miscalculate based on outdated tables; the current system explicitly takes your company size into account.

When do you, as an entrepreneur, run the risk of a fine?

The AP can take action for various violations. Common risk areas for SME entrepreneurs are:

  • No or an incomplete processing register. Many organizations are required to keep records of which personal data they process and why.
  • Missing data processing agreements. If you engage an external party that processes personal data on your behalf (for example, a cloud service or accounting package), you must make written agreements regarding this.
  • No or an inadequate privacy statement. You must clearly inform visitors and customers about what you do with their data.
  • Cookies without valid consent. Placing tracking and marketing cookies without prior consent is a common mistake.
  • Failure to respond, or responding too late, to the rights of data subjects, such as a request for access or deletion.
  • Failure to report a data breach (in a timely manner) when required to do so.

Far from every violation leads directly to a fine. However, they do increase your risk and, during an inspection or a complaint, can make the difference between a friendly encouragement and an enforcement process.

A complaint from a (former) customer or employee is often the trigger for an investigation. A dissatisfied data subject who reports to the AP can set the ball rolling – even at a small company. Therefore, ensure that you handle requests for access or removal seriously and on time.

How do you avoid a GDPR fine?

The cheapest fine is the fine you never get. With a number of concrete steps, you can get your privacy management in order:

  1. Create a processing register and keep it up to date. This is often the starting point of every privacy audit. View the GDPR processing register.
  2. Enter into data processing agreements with all your suppliers who process personal data for you, with a comprehensive data processing agreement.
  3. Publish a clear privacy statement on your website and keep it up to date.
  4. Manage your cookies correctly, with a valid cookie banner and a clear explanation.
  5. Establish a procedure for data breaches and data subject requests so that you can respond within the time limits.
  6. Evaluate periodically. Laws, regulations, and your own processes change; a recurring check keeps you compliant.

Unsure where you stand? A quick privacy check quickly exposes the biggest risks. Our legal experts are happy to assist you with privacy and data protection.

What do you do in the event of an inspection or fine from the Dutch Data Protection Authority?

Are you facing an investigation, a request for information, or a (proposed) fine from the AP? Then take timely action:

  • Do not ignore correspondence. Respond promptly and completely; cooperating can work to your advantage.
  • Limit the damage. End the violation as soon as possible and document the remedial measures you take.
  • Check the procedure. A notice of intent to impose a fine is not yet a final decision. You can submit a statement of views and lodge an objection later.
  • Seek legal assistance. A well-substantiated response can prevent a fine, reduce it, or convert it into a less severe measure.

Our specialists are familiar with enforcement practices regarding the Dutch Data Protection Authority and assist you throughout such a process.

Frequently asked questions about GDPR fines

How high is a GDPR fine for an SME?

There is no fixed amount for this. The AP takes into account the severity of the violation as well as the size of your company. As a result, for a smaller company, a fine is usually much lower than the statutory maximums of 10 or 20 million euros. In practice, those maximums apply primarily to large enterprises involved in serious, large-scale violations.

Will I receive an immediate fine for violating the GDPR?

Not necessarily. The AP has multiple instruments and regularly opts for remedial action or an order subject to a penalty payment first. Whether a fine follows depends on the severity of the violation, the circumstances, and your cooperation.

Does the GDPR also apply to freelancers and small businesses?

Yes. The GDPR applies to every organization that processes personal data, regardless of size – so this includes freelancers and small businesses. The size of your company plays no role in the obligation to comply with the GDPR, but it does weigh in on the amount of any potential fine.

What is the difference between the two GDPR fine limits?

The lower maximum (up to 2% of global annual turnover or €10 million) applies to more administrative violations, such as a missing processing register. The higher maximum (up to 4% or €20 million) applies to more serious violations, such as violating the fundamental principles of the GDPR or the rights of data subjects. In each case, the highest of the percentage and the fixed amount applies.

Does my turnover count towards the amount of the fine?

Yes. Since the updated penalty policy rules, the size of your company is given primary weight in the calculation. Companies with lower turnover are subject to a smaller starting amount, meaning the fine aligns better with your financial capacity.

Can I object to a GDPR fine?

Yes. A notice of intent to impose a fine is not yet a final decision; you can first submit a statement of views. An objection and subsequently an appeal are possible against a final fine decision. Seek good advice in this regard, as strong substantiation can make all the difference.

Prevent problems: manage your privacy properly

The fines for violating privacy legislation are substantial, but as an SME entrepreneur, you rarely need to fear the high-profile millions. Much more important is having your basics in order: an up-to-date processing register, watertight data processing agreements, and a clear privacy statement. By doing so, you not only limit your risk of fines but also prevent reputational damage and hassle with customers and regulators.

Do you want to be sure your GDPR matters are in order, or are you facing an investigation or fine from the Dutch Data Protection Authority? Our privacy lawyers are happy to advise you. Schedule an intake meeting and get your privacy in order worry-free.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 24, 2026

Having a non-compete clause drafted: costs and process

Having a non-compete clause drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom draft over a template.

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

July 24, 2026

Having general terms and conditions drafted for contractors: costs and process

Having general terms and conditions for contractors drafted by a lawyer: what does it cost, how does the process work, and when do you choose custom work over...

July 23, 2026

Having general terms and conditions drafted: costs and process

Having general terms and conditions drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom-made version over a template.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation