What “up to £17.5m” means

It is a possible statutory maximum for relevant infringements, not a prediction of your fine.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Practical explainer

Maximum penalties explainer; actual enforcement is case-specific.

What happened

The ICO’s fining guidance distinguishes standard and higher maximum amounts. The higher UK GDPR maximum is £17.5 million or, for an undertaking, 4% of total worldwide annual turnover in the preceding financial year, whichever is higher. The EU GDPR uses a different currency amount: its higher tier is €20 million or 4%, whichever is higher.

Source: ICO — original source ↗

What it means for your website

Large numbers get attention, but they should not replace an explanation of the actual problem. A regulator assesses the relevant infringement and circumstances. A scanner finding does not come with an automatic invoice, and a warning is not a legal determination. For a business owner, the useful response is to identify the affected activity, assess its impact and fix supported problems promptly. Ask anyone selling a compliance service to explain the evidence behind the finding and the limits of the proposed work. Be cautious about claims that a cheap plugin or one-off scan removes every possible regulatory risk.

Three useful next steps

  1. Treat maximum figures as ceilings, not forecasts.
  2. Ask which law and finding are relevant to your site.
  3. Agree a practical, evidence-based remediation scope.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

ICO — original sourceEU GDPR Article 83 — official text

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading