GDPR fines 2026: sanctions and compliance checklist
An updated overview of GDPR fine levels, current Datatilsynet trends and a practical compliance checklist for SMEs that want to avoid sanctions.
Karoline, Dokumentkonsulent
The GDPR is not a law for the big players. Datatilsynet handles complaints against businesses of all sizes, and fines are not reserved for tech giants with billion-kroner turnover. With rising enforcement activity, it is more important than ever that your business has the basic requirements in order.
This article gives you an overview of the fine levels, the most frequent breaches and a concrete checklist to bring your business into compliance.
The fine levels: two tiers
Article 83 of the GDPR divides sanctions into two tiers depending on which rule has been breached:
Tier 1: up to EUR 10 million or 2% of global turnover
This tier applies to breaches of, among other things:
- The requirements for data processing agreements (Article 28)
- The requirements for technical and organisational security measures (Article 32)
- Notification of a data breach to Datatilsynet within 72 hours (Article 33)
- Notification of the people affected in the case of serious breaches (Article 34)
- The appointment of a DPO where required (Article 37)
Tier 2: up to EUR 20 million or 4% of global turnover
The highest tier applies to, among other things:
- Processing of personal data without a legal basis (Articles 6 and 9)
- Breach of the basic principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and integrity (Article 5)
- Transfer of personal data to third countries without an adequate level of protection (Articles 44 to 49)
- Infringement of data subjects' rights: access, erasure, data portability (Articles 12 to 22)
The Danish model: criminal fines
In Denmark, Datatilsynet, unlike in many other EU countries, is not empowered to issue administrative fines directly. Instead it files a police report, and the fine is imposed by the courts as a criminal sanction. This means:
- The case goes through the court system, which gives the business the chance to present its defence
- Fines are in practice lower than the maximum limits in Article 83
- But the process is slow and resource-intensive for the business involved
Current trends
In recent years Datatilsynet has sharpened its focus on issues that are especially relevant for SMEs:
Cookies and marketing
Unlawful tracking via cookies, including the use of marketing cookies without valid consent, has been one of the most frequent categories of breach. Many businesses use cookie banners designed to get the user to accept, rather than to give a genuinely free choice.
A valid consent requires, among other things:
- Clear and plain language
- The option to refuse as easily as to accept
- No pre-ticked boxes
- Easy access to withdraw consent
Missing data processing agreements
In inspections, Datatilsynet has found that many SMEs lack written data processing agreements with suppliers such as cloud services, HR systems and newsletter platforms. It is one of the most frequently breached rules and one of the easiest to become compliant on.
Excessive storage of personal data
Businesses that keep CVs, job applications and customer data for years without a purpose breach the principle of storage limitation. Datatilsynet expects documented deletion procedures.
Health data and special categories
Processing health data (for example sick leave in HR systems) requires a special legal basis in addition to the usual one. Many employers today process this data without sufficient documentation of the basis.
Compliance checklist for SMEs
Use this checklist to assess your business's GDPR maturity:
The foundation: records and documentation
- Record of processing activities: do you have an overview of which personal data you collect, for which purposes and on what basis?
- A legal basis for each processing activity: is it consent, contract, a legal obligation or a legitimate interest?
- Privacy policy: is it updated, clear and available to users?
Suppliers and third parties
- Data processing agreements: do you have written agreements with all suppliers that process personal data on your business's behalf?
- Third-country transfers: do you use services that store data outside the EU and EEA? Are there appropriate safeguards (for example EU standard contractual clauses)?
Cookies and digital marketing
- Cookie banner: is valid consent obtained before non-essential cookies are set?
- Consent records: can you document when and what users have consented to?
- Unsubscribing from newsletters: is it easy to opt out of marketing?
Data subjects' rights
- Right of access: can you answer an access request within one month?
- Deletion procedure: do you have a concrete plan for what happens to data when the purpose is fulfilled?
- Data portability: can you provide a person's data in a machine-readable format if they ask?
Security and data breaches
- Technical security measures: is access to personal data limited to those with a work-related need?
- Encryption: is personal data encrypted during storage and transfer where relevant?
- Data-breach procedure: do you have a clear plan for a data breach, and do you know when it must be notified to Datatilsynet (within 72 hours)?
Employee data
- Employment and HR data: do you process employees' personal data on a correct basis and with correct storage?
- Health data: do you have a special basis for processing sick leave and other health data?
- Video surveillance: if you use surveillance cameras, is there visible signage, and is the purpose lawful?
What do GDPR breaches cost in practice?
Danish fines for GDPR breaches have historically been lower than in countries such as Ireland, Luxembourg and Spain, but there has been a rising trend in the size of fines.
Smaller businesses have typically received fines at the lower end, and the size depends, among other things, on:
- The seriousness and duration of the breach
- The size and turnover of the business
- Whether the business cooperated with Datatilsynet during the investigation
- Whether it was intentional or negligent
Added to this are the indirect costs: legal assistance, IT review, communication to affected customers and damage to the business's reputation.
Frequently asked questions about GDPR fines
What are the maximum GDPR fines?
The GDPR operates with two fine levels: up to EUR 10 million (or 2% of global turnover) for the more technical breaches, and up to EUR 20 million (or 4% of global turnover) for fundamental breaches. In Denmark the fines are imposed by the courts after a police report from Datatilsynet.
Can a small business be hit by GDPR fines?
Yes. Datatilsynet handles complaints against businesses of all sizes. SMEs are not protected from fines, but the size is typically scaled to the business's circumstances and the seriousness of the breach.
What should a small business have in order as a minimum?
As a minimum: a privacy policy, data processing agreements with suppliers that process personal data, deletion procedures and a plan for handling data breaches within the 72-hour deadline.
When must a business have a DPO?
A DPO is mandatory for public authorities, for businesses that process special categories of personal data (for example health data) on a large scale, and for businesses that systematically monitor people on a large scale. Most SMEs are not required to have a DPO.
What is a data processing agreement, and when should I use one?
A data processing agreement is a contract with suppliers that process personal data on your behalf, for example your IT supplier, your HR system or your newsletter service. Article 28 of the GDPR always requires a written agreement in these situations.
What happens if I do not notify a data breach?
A data breach must be notified to Datatilsynet within 72 hours if it entails a risk to the affected people's rights. Failure to notify is a separate breach and can lead to further sanctions.
The content of this article is for guidance only and does not constitute legal advice. The GDPR rules are complex, and the specific assessment depends on your business's specific processing activities. Contact a lawyer or data protection officer if you need specific guidance.
This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.