Blog
sprinto angle right
GDPR
sprinto angle right
GDPR Fines in 2026: Tiers, Calculation and Largest Fines

GDPR Fines in 2026: Tiers, Calculation and Largest Fines

TL;DR
  • GDPR fines have two maximums under Article 83: up to €10 million or 2% of total worldwide annual turnover, or up to €20 million or 4% for the more serious infringements, whichever is higher in each tier.
  • The largest fine so far is €1.2 billion, imposed on Meta by Ireland’s Data Protection Commission (DPC) in May 2023 for sending European Union (EU) users’ data to the United States (US). Second is the nearly €825 million that the Dutch regulator imposed on Uber in August 2026.
  • Regulators arrived at the fine amount using a published five-step method that scales the starting point to the company’s size, so a small company’s serious case starts at a small fraction of a large platform’s.

GDPR fines are penalties that a data protection regulator can impose under Article 83 of the GDPR. They can be up to €20 million or 4% of total worldwide annual turnover for the most serious infringements, and up to €10 million or 2% for the rest, whichever is higher. The largest so far is €1.2 billion against Meta in 2023. The Irish Data Protection Commission fined the company € 1.3 billion for unlawfully transferring data to the United States. However, while massive penalties like these dominate headlines, they represent only a fraction of the overall enforcement activity across Europe. 

However, headline-making penalties represent only a fraction of enforcement across Europe. Since the GDPR took effect in May 2018, regulators have issued thousands of fines for violations ranging from administrative oversights to high-risk failures affecting millions of people.

If you’re concerned about a potential fine, start with the calculation section. The maximums are real, but regulators assess each case individually and consider factors such as the company’s size. This guide explains the penalty tiers, calculation method, largest fines, and the obligations behind them.

What are GDPR fines, and who can be fined?

GDPR fines are administrative penalties imposed on organizations that violate the data protection principles, obligations, and security requirements outlined in the General Data Protection Regulation. These violations can take countless forms, such as in situations where:

  • Personal data is collected without consent
  • Personal data is handled in an insecure manner
  • Individuals are not informed when their data has been compromised
  • A Data Protection Officer is not appointed when required

GDPR primarily categorizes organizations as either Controllers or Processors, depending on their role in collecting and processing data. A detailed view of the GDPR data processor role specifically explains why this distinction matters for enforcement, since processors carry direct obligations under Articles 28 and 32, even though controllers retain primary accountability for how the data is used.

GDPR fines for data controllers

Data controllers are the entities that decide why and how personal data is processed. Because they set the purpose and direction of processing, regulators hold them primarily accountable for ensuring compliance. If a controller fails to establish proper legal bases, ignores data subject rights, or does not implement sufficient safeguards, they can be fined directly.

GDPR fines for data processors (Articles 28 and 32)

Processors are organizations that handle personal data on behalf of a controller and act only on the controller’s instructions. This includes cloud hosting providers, payroll processors, customer support vendors, marketing platforms, and data analytics services. They do not decide the purpose of the processing but carry out essential operational activities involving personal data.

Under the GDPR, processors can also be fined. Regulators are increasingly enforcing against processors, especially when they fail to implement adequate technical and organizational measures. This reflects the growing recognition that processors share real responsibility for protecting personal data, not just controllers.

Who enforces GDPR fines? (Articles 51, 57, and 77)

National supervisory authorities enforce GDPR fines, and each EU member state has at least one. When a company’s main EU establishment is in one country, that country’s authority leads its cross-border cases under the one-stop-shop mechanism (Arts. 56 and 60). That’s why so many large fines come from Ireland, where Meta, TikTok, Google, and LinkedIn have their EU entities.

A case usually starts with a complaint from the person whose data was involved or from a privacy organization acting for their behalf (Art. 80), or with an investigation the regulator opens on its own initiative.

What are the two GDPR fine tiers? (Article 83)

Article 83(4) sets up to €10 million or 2% of total worldwide annual turnover for obligations such as security, records, and breach notification, and Article 83(5) sets up to €20 million or 4% for the principles, lawful basis, data subject rights, and transfers. The higher figure applies in both tiers.

1. Level-one fines (Article 83(4)): Up to €10 million or 2% of global annual revenue

This tier applies to less severe violations, including failure to maintain an inventory of processing activities, failure to appoint a Data Protection Officer, lack of cooperation with supervisory authorities, incomplete or inaccurate records, failure to communicate personal data breaches, and similar administrative shortcomings. And while Tier 1 violations are mostly addressed with warnings initially, they can escalate and result in substantial penalties.

A real fine in this tier: Meta, €251 million in 2024: €240 million for design and default failures, €11 million for breach notification and breach records

2. Level-two fines (Article 83(5)): Up to €20 million or 4% of global annual revenue.

This tier applies to more serious violations, including failure to comply with the fundamental principles of data processing, failure to obtain consent, failure to respect data subject rights, transferring data without proper safeguards, or failing to respond appropriately to breaches. And this is where fines become significant enough to impact even the world’s largest companies.

A real fine in this tier: LinkedIn, €310 million in 2024: lawful basis, fairness and transparency.

The interesting part is where the two figures cross. Two percent of €500 million is €10 million, and 4% of €500 million is €20 million, so for turnover below €500 million, the fixed amount is the maximum.

Turnover here means the whole group’s. In ILVA, the Court of Justice of the EU held that the undertaking in Article 83 has a competition-law meaning, so if your company is part of a group, use the group’s accounts to estimate the maximum.

Security failures under Article 32 are in the lower tier, which many GDPR summaries get wrong. Regulators can also find a breach of the integrity and confidentiality principle in Art. 5(1)(f), which is in the higher tier, as the DPC did in its 2023 TikTok decision.

A fine can come with, or be replaced by, another corrective power under Article 58(2), such as an order to suspend US transfers in Meta’s €1.2 billion case. People who suffer damage can also claim compensation in court, so weigh that against the cost to GDPR compliance.

GDPR Tier 1 vs Tier 2 violations compared

Tier 1 ViolationsTier 2 Violations
– Procedural and administrative compliance failures, such as documentation gaps or missed obligations that do not immediately compromise personal data.
– These issues can sometimes be remedied without immediate financial penalties.
– Regulators may issue warnings or corrective orders before escalating.
– Violations that affect user rights, involve unlawful processing, lead to data breaches, or directly compromise personal data.
– These violations typically trigger immediate fines due to their severity and are more likely to appear in public enforcement registers.

How are GDPR fines calculated?

Regulators weigh the eleven factors in Article 83(2), such as how serious and long-running the infringement was, whether it was intentional or negligent, what you did to limit harm and how you cooperated. The European Data Protection Board (EDPB), the body of EU regulators, turns those factors into a five-step method in its Guidelines 04/2022.

Read each row as a question your records should answer:

Art. 83(2) factorWhat the regulator asks
(a) Nature, gravity and durationHow many people were affected, for how long, and for what purpose?
(b) Intentional or negligentDid you know, or should you have known? A fine needs one or the other (Deutsche Wohnen, C-807/21)
(c) MitigationWhat did you do to limit the harm to people?
(d) Degree of responsibilityWhich measures under Arts. 25 and 32 were in place?
(e) Previous infringementsIs there any relevant history?
(f) CooperationDid you help the investigation and remedy the infringement?
(g) Categories of dataWas special-category data involved?
(h) How it became knownDid you notify, and how fully?
(i) Earlier ordersDid you comply with previous orders on the same subject?
(j) Codes and certificationDid you follow an approved code of conduct (Art. 40) or certification (Art. 42)?
(k) Anything elseDid you gain money or avoid losses through the infringement?

Worth knowing: telling the regulator yourself counts. Factor (h) asks how the regulator found out, including whether you notified it. Reporting a breach yourself, with the details Article 33(3) asks for, is the part of this factor you control.

What is the EDPB’s five-step method for GDPR fines?

edpb-five-step-gdpr-fine-calculation-example-6b

The EDPB’s fining guidelines, finalized in 2023, provide regulators with five steps in a fixed order:

  • Step 1: Identify the processing operations. Where linked operations break several provisions, the total cannot exceed the maximum for the gravest one.
  • Step 2: Find a starting point from the seriousness of the infringement and the company’s turnover.
  • Step 3: Adjust for aggravating and mitigating circumstances in the company’s past or present behavior.
  • Step 4: Apply the legal maximum for each infringement.
  • Step 5: Check that the final figure is effective, dissuasive, and proportionate, as Article 83(1) requires.

In step 2, the regulator first rates the seriousness of the infringement is. For low seriousness, the starting point is between 0 and 10% of the legal maximum; for medium, between 10 and 20%; and for high, between 20 and 100%.

The regulator can then scale that starting point for the size of the company:

Annual turnoverStarting point may be adjusted to
Up to €2 million0.2% to 0.4%
€2 million to €10 million0.3% to 2%
€10 million to €50 million1.5% to 10%
€50 million to €100 million8% to 20%
€100 million to €250 million15% to 50%
€250 million to €500 million40% to 100%
Above €500 millionNo adjustment

The EDPB calls these starting points for further calculation, and not fixed amounts (price tags) for infringements.

How much could a small company be fined under GDPR?

A small company’s GDPR fine starts far below the headline maximum. In the EDPB’s Example 6b, a start-up dating app with €500,000 in turnover sold customers’ sensitive data to data brokers. The high-seriousness starting range of €4 million to €20 million was adjusted down to 0.25% for its size, which works out to €10,000 to €50,000.

The €10,000 to €50,000 is our arithmetic, and the guidelines stop before a final figure: the regulator would still weigh aggravating and mitigating factors (step 3) and check proportionality (step 5).

secure-check-dark

What are the largest GDPR fines issued to date?

The largest GDPR fine is €1.2 billion, imposed on Meta by Ireland’s DPC in May 2023 for transferring EU users’ data to the US. As of September 24, 2026, the ten largest were all imposed on large platforms, eight by the DPC and two by the Dutch regulator, and most concern lawful basis, transfers, transparency or children’s data.

Ranked by amount, with what the regulator found in each case:

#CompanyRegulatorAmountAnnouncedWhat the regulator found
1Meta Platforms IrelandDPC (Ireland)€1.2 billionMay 22, 2023Transfers of EU users’ data to the US without adequate safeguards (Art. 46(1))
2UberDutch Data Protection Authority (AP)Nearly €825 millionAug 21, 2026Drivers’ accounts deactivated by automated systems without meaningful human review (Art. 22), and drivers not told enough about it
3TikTok TechnologyDPC€530 millionMay 2, 2025Staff in China accessing European Economic Area (EEA) users’ data without essentially equivalent protection (Art. 46(1), €485 million); privacy notice didn’t name China (Art. 13(1)(f), €45 million). The Irish High Court upheld the transfer finding in June 2026; the amount is under appeal
4Meta Platforms Ireland (Instagram)DPC€405 millionSep 15, 2022Children’s contact details made public, and children’s accounts public by default
5Google IrelandDPC€403 millionSep 21, 2026Location data in three account features: lawfulness, fairness, transparency, retention and accountability
6Meta Platforms Ireland (Facebook €210 million, Instagram €180 million)DPC€390 million across two decisionsJan 4, 2023Relying on “contract” as the lawful basis for behavioral advertising (ads chosen from tracked activity), and unclear information about it
7TikTokDPC€345 millionSep 15, 2023Children’s accounts public by default, the Family Pairing feature, and transparency to child users
8LinkedIn IrelandDPC€310 millionOct 24, 2024Behavioral analysis and targeted advertising without a valid lawful basis (Arts. 5(1)(a), 6, 13 and 14)
9UberAP€290 millionAug 2024Drivers’ data sent to the US for over two years without a transfer tool
10Meta Platforms IrelandDPC€265 millionNov 28, 2022Data scraped through search and contact-importer tools: data protection by design and by default (Art. 25)

*Sources: each regulator’s announcement, linked from the amount; the AP decided the €290 million Uber fine on July 22, 2024, and announced it in August, per the EDPB’s Uber notice. Some decisions are under appeal, including both Uber fines, so check the regulator’s page for the current status and final amount.

GDPR enforcement at the point of data consumption, not just the point of collection
  • “LinkedIn had a fine data governance program — they properly classified and stored their data — and still got fined 310 million euros under the GDPR. The reason: using that data to infer sensitive characteristics for ad targeting violated consent boundaries nobody was accounting for. The governance question now isn’t whether your program is documented. It’s whether your controls act at the point of consumption. Automated decisions are already starting to overstep legal and societal boundaries, and more enforcement actions will follow.”
  • ~ Kayne McGladrey, Cybersecurity & AI Governance Expert [An excerpt from Sprinto’s webinar on helping brands tackle new-age AI adoption]

Let’s briefly review some of the top cases:

Meta (Facebook): €1.3 billion (2023)

Meta’s penalty was the largest fine ever issued under GDPR. Regulators concluded that Meta routinely transferred EU users’ information to the United States without the agreements and protections required by the regulation. International data transfers have always been subject to strict scrutiny under the GDPR, and this case demonstrates that they require strong legal grounds and equally robust safeguards to support them.

TikTok: €530 million (2025)

TikTok’s infrastructure allowed data collected from EU users to flow back to servers in China with minimal protection. The company also kept users in the dark about how it handled that information and who could access it. This case has become a clear example of broader concerns about data sovereignty, and GDPR makes clear that you need to consider the laws and regulatory standards of any country to which personal data is transferred.

TikTok Limited: €345 million (2023)

Protecting minors is one of GDPR’s most stringent obligations. Yet, TikTok was allowing children’s accounts to be set to public by default, making their personal information visible to anyone on the internet. The company was also processing children’s data without the heightened safeguards that GDPR requires for minors, and regulators took note of this. The case made it evident that platforms must build privacy-by-default protections into their systems, especially when young users are involved.

Meta Platforms: €265 million (2022)

One of the most fundamental obligations under the GDPR is to store data securely and in a manner that ensures its confidentiality, integrity, and availability. However, a breach exposed personal information belonging to over 500 million users, including names, phone numbers, and locations. In this case, Meta had systems that were simply not strong enough to prevent an exposure of this scale. The incident revealed a fundamental failure in a responsibility that GDPR considers non-negotiable.

WhatsApp: €225 million (2021)

In this case, WhatsApp collected extensive personal data and shared it with Meta’s other services, but users had no clear idea what was happening or why. When regulators reviewed WhatsApp’s privacy notices and data practices, they found them vague and incomplete. The company didn’t explain its practices in plain language; it hid behind technical jargon and incomplete disclosures. 

You’ll see these three on most of the biggest GDPR fines lists. But none of them belong there, at least not right now.
  • Meta, €479 million (Spain, 2025): Damages a Madrid commercial court ordered in November 2025 under Spain’s unfair competition law, payable to 87 digital publishers, because the court found Meta gained an unfair advantage by processing data for behavioral ads in breach of the GDPR. No regulator imposed it, and Meta can appeal. (Spain’s General Council of the Judiciary).
  • Google, €325 million (France, 2025): A penalty from France’s regulator, the CNIL, under French cookie and email-marketing rules, which aren’t part of the GDPR. It’s often listed as “Google LLC €200 million” (CNIL).
  • Amazon, €746 million (Luxembourg, 2021): A GDPR fine that Luxembourg’s Administrative Court annulled in March 2026 because the regulator hadn’t assessed intent or negligence. The findings stand, and the regulator has to decide the sanction again (Luxembourg justice portal).
  • As the CNIL and Spanish cases show, cookie consent rules can carry penalties outside Article 83, and competitors or publishers can sue in civil courts.

What drives most GDPR fines?

The most common reason for a GDPR fine is an insufficient legal basis for processing, followed by breaches of the general processing principles and weak security measures, according to the GDPR Enforcement Tracker Report 2026 from the law firm CMS. Security fines often follow a cyber incident.

The CMS report counted 2,685 fines with full details up to March 1, 2026, totaling about €6.11 billion. Its ten largest add up to about €4.2 billion, so the other 2,675 average about €700,000.

The live tracker, which also counts entries with incomplete details, listed 3,275 fines totaling €7.16 billion on 24 September 2026, and national regulators issued €1.15 billion in fines in 2025 alone. Spain has published the most fines for seven years running, followed by Italy, Romania and Poland, though CMS notes that publication practices differ considerably between countries.

Rank by number of fines (CMS 2026)Violation typeWhat it looked like in the cases above
1Insufficient legal basis for data processingContract or legitimate interests used for behavioral advertising (Meta €390 million, LinkedIn)
2Non-compliance with general data processing principlesUnfair or excessive processing of children’s data (Instagram, TikTok €345 million)
3Insufficient technical and organizational measures“A major enforcement trigger, particularly following cyber incidents,” in CMS’s words
4Insufficient fulfillment of data subjects’ rightsAccess or erasure requests handled late or not at all
5Insufficient fulfillment of information obligationsPrivacy notices that leave out a transfer destination (TikTok €530 million) or how data is shared (WhatsApp, €225 million in 2021)

Failures to cooperate with a regulator, to appoint a DPO, or to put a processor contract in place draw very few fines, in the report’s words. So the ranking is also a sensible order for checking your own program.

Face-CTA-3

Tell us where your data goes and which vendors process it, and we’ll show you how Sprinto maps your GDPR controls and keeps the evidence behind them current.

How can you avoid GDPR fines?

Most of the fines on this page trace back to seven practices: a documented lawful basis, current records of processing, a transfer mechanism for every flow outside the EEA, a plain privacy notice, protective design and defaults, rehearsed breach notification, and an Article 28 contract with every processor.

1. Choose and document a lawful basis for each purpose

Article 6(1) gives six bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Explicit consent is the standard for special-category data under Art. 9(2)(a), and it isn’t required for everything else.

How you can prevent it: keep a record of the basis for each processing purpose, including a written balancing test (your interests weighed against the rights of the people whose data it is) when you rely on legitimate interests.

Who may get fined: businesses that run behavioral advertising without a valid lawful basis, as Meta and LinkedIn were.

If you’ve treated consent as the default basis, you’re in good company, and the fix starts with knowing the other five exist.

2. Map your data and keep your records of processing current

Article 30 requires a written record of purposes, data categories, recipients, transfers, retention periods, and security measures, kept internally and shown to the regulator on request.

How you can prevent it: Keep a data map and a record that matches your live systems.

Who may get fined: businesses whose record of processing was built once, often for a customer questionnaire, and never updated.

3. Put a transfer mechanism behind every flow outside the EEA

Use an adequacy decision (a European Commission finding that a country protects data to EU standards), standard contractual clauses (SCCs), or another Article 46 safeguard. With SCCs or another Article 46 safeguard, also assess whether the destination country’s law lets the recipient keep its promises in a transfer impact assessment (TIA).

How you can prevent it: Keep signed SCCs and a TIA for each destination not covered by an adequacy decision.

Who may get fined: businesses that send data outside the EEA without a valid transfer mechanism, as Uber and TikTok were.

4. Say plainly what you do in your privacy notice

Articles 13 and 14 list what people must be told, including purposes, lawful bases, recipients, transfer destinations and any solely automated decisions about them.

How you can prevent it: Have a GDPR privacy policy that matches your record of processing.

Who may get fined: businesses whose notice omits where data goes or how automated decisions are made, as TikTok and Uber did.

5. Build protection into design and defaults

Article 25 asks for protective settings by default, including processing only the data each purpose needs (data minimization). Article 32 asks for security appropriate to the risk, such as encryption.

How you can prevent it: Have a written privacy-by-design policy (start with a privacy-by-design policy template), conduct design reviews for features that expose data, set default settings, and implement access controls.

Who may get fined: businesses that make children’s accounts public by default or leave tools open to scraping, as Instagram, TikTok, and Meta were.

6. Rehearse breach notification before you need it

Article 33 requires notice without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people.

How you can prevent it: Have a breach log covering every breach, reported or not, and a notification template with the Article 33(3) fields: what happened and roughly how many people and records, a contact point, the likely consequences, and the measures taken.

Who may get fined: businesses that send incomplete breach notices or don’t log every breach, as Meta was, for €11 million of its €251 million fine.

Worth doing: time one tabletop exercise (a walk-through of a mock incident) from the first alert to a drafted notification.

7. Sign an Article 28 contract with every processor

A data processing agreement (DPA) sets out what each vendor may do with the data, and Article 28(1) lets you use only processors that give sufficient guarantees.

How you can prevent it: Have signed Article 28 agreements and a current list of sub-processors (the vendors your processors use).

Who may get fined: controllers that pick a processor without checking whether it can protect the data. Few fines so far have been based on the contract itself, per the CMS, but choosing a processor with sufficient guarantees is the controller’s duty.

Work through a GDPR compliance checklist starting where enforcement concentrates: lawful basis, transfers and transparency, then security and breach response.

Continuous monitoring is what separates knowing you’re compliant from hoping you are
  • “The main reason to adopt a compliance tool isn’t the audit — it’s continuous monitoring assurance of controls. You want the CSO to feel comfortable that the controls under their area are operating effectively, constantly. No more twice-a-year internal audit right before the external auditors come in to get that signal. You want that continual assurance.”
  • ~ Alan Luk, Principal TPM, GRC Engineering, Microsoft Azure [An excerpt from a Sprinto interview where he discusses the future of GRC, Automation & Auditor Accountability]

How does Sprinto help with GDPR compliance?

Sprinto is a compliance platform that connects to your systems, turns your GDPR controls into checks, and keeps the evidence behind them current. That matters because Article 83(2) asks what measures you had in place, how you responded, and how you cooperated, and you answer those questions with records: which controls ran, when something drifted, and who fixed it.

block-quote
“We wouldn’t have been able to scale the way we have if we were still on spreadsheets. Right from when we onboard someone new, Sprinto continuously tracks compliance and alerts key tasks to complete, so everyone has a security-first mindset and there’s a clear structure in place.”
Deepak Singla Founder and CEO, Fini AI

Here’s more on how Sprinto helps with GDPR:

  • Evidence from your own systems: Sprinto connects to systems such as Amazon Web Services (AWS), Google Cloud, Azure, GitHub, Okta and Google Workspace and pulls logs, configurations and status checks as evidence.
  • Continuous control monitoring: The security controls you rely on for Article 32 are monitored against your live systems, so drift is flagged when it happens instead of during an investigation.
  • Vendor and DPA evidence: Track evidence that DPAs and transfer mechanisms are in place, as checks in your GDPR program. You upload the DPAs you’ve signed with vendors, and drafting and signing stay outside the platform, with your counsel.
  • Trust Center: You can share your privacy and security posture with buyers under access controls.
~15% Marginal lift to layer GDPR over ISO 27001
6 Additional GDPR checks over ISO 27001
Uncover, a legal-tech SaaS company in the Netherlands, needed to show customers in continental Europe that it met their data security requirements. It already ran ISO 27001 in Sprinto, so GDPR meant adding the privacy pieces, such as a record of processing activities and a process for data subject access requests, and Sprinto’s integrations with its infrastructure keep those checks running continuously.

Frequently asked questions

The legal maximum is €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher (Art. 83(5)). The largest fine imposed is €1.2 billion, imposed by the DPC on Meta in May 2023, and it tops most lists of the biggest GDPR violations and their lessons.

Yes. Article 83(4)(a) names the processor’s own obligations, including the Article 28 contract terms, records under Art. 30(2), security under Article 32, and telling the controller about a breach (Article 33(2)). For compensation claims, a processor is liable only if it breached its duties or acted outside the controller’s lawful instructions (Article 82(2)).

No. The GDPR creates no criminal offenses, even for a personal data breach. Article 84 and Recital 149 leave criminal penalties to member states, and the United Kingdom’s Data Protection Act 2018, which supplements UK GDPR, for example, makes it an offense to knowingly or recklessly obtain or disclose personal data without the controller’s consent (s.170).

Regulators fine the failures behind or after a breach. Weak security (Art. 32) and late or incomplete notification (Article. 33–34) are lower-tier infringements, up to €10 million or 2% (Article 83(4)), and a regulator can also find a breach of the integrity and confidentiality principle (Article 5(1)(f)), which is in the higher tier.

Don’t wait for the full picture. Article 33(1) requires breach notification without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people. Article 33(4) lets you send the details in phases.

A security questionnaire is a structured assessment used to evaluate a vendor’s cybersecurity, privacy, and compliance posture. It typically includes questions on data security, risk management, IT controls, and adherence to frameworks like SOC 2, ISO 27001, HIPAA, PCI, etc. Companies use these questionnaires to determine whether a vendor’s systems and processes meet their security requirements before sharing data or entering into a business relationship.

Yes, if the GDPR applies to it. A US company is in scope when it offers goods or services to people in the EU or monitors their behavior (Article 3(2)). It then usually has to designate an EU representative in writing (Article 27), and failing to do so is itself a lower-tier infringement under Article 83(4).

Srikar Sai
Author

Srikar Sai

As a Senior Content Marketer at Sprinto, Srikar Sai believes good content should be bookmark-worthy by default. He writes about cybersecurity and GRC, aiming to move the needle with every piece. He’s also an ISO 27001-certified Lead Auditor.
Tired of fluff GRC and cybersecurity content? Subscribe to our newsletter and get detailed
research & insights curated to help you earn a seat at the table.
single-blog-footer-img