Maximum penalties explainer; actual enforcement is case-specific.
What happened
The ICO’s fining guidance distinguishes standard and higher maximum amounts. The higher UK GDPR maximum is £17.5 million or, for an undertaking, 4% of total worldwide annual turnover in the preceding financial year, whichever is higher. The EU GDPR uses a different currency amount: its higher tier is €20 million or 4%, whichever is higher.
Source: ICO — original source ↗
What it means for your website
Large numbers get attention, but they should not replace an explanation of the actual problem. A regulator assesses the relevant infringement and circumstances. A scanner finding does not come with an automatic invoice, and a warning is not a legal determination. For a business owner, the useful response is to identify the affected activity, assess its impact and fix supported problems promptly. Ask anyone selling a compliance service to explain the evidence behind the finding and the limits of the proposed work. Be cautious about claims that a cheap plugin or one-off scan removes every possible regulatory risk.
Three useful next steps
- Treat maximum figures as ceilings, not forecasts.
- Ask which law and finding are relevant to your site.
- Agree a practical, evidence-based remediation scope.
Sources & context
Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.
ICO — original sourceEU GDPR Article 83 — official textOur practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.