Flat fines punish scale backwards. A $50 million penalty can close a small company and barely register at a platform earning tens of billions. The GDPR tracker records about €6.11 billion across 2,685 fines through March 2026, including Meta's €1.2 billion penalty. Revenue is not a perfect proxy for harm, but it makes the maximum credible. Courts can still weigh intent and damage within that range.
Should privacy fines be tied to a technology company’s global revenue?
The GDPR can set its most serious penalties as a percentage of worldwide turnover, so the same violation costs a global platform more than a small firm. That approach has produced billion-euro penalties, but it also raises questions about proportionality, deterrence, and whether fines become just another cost passed to customers.
The cases
For (2)
The point is to change decisions before a violation happens. If the ceiling is fixed, a finance team can price it into the launch. A percentage of worldwide turnover tells every board that privacy risk scales with the business benefiting from the data. U.S. proposals have also considered a 4% of revenue cap, which suggests this is not uniquely European thinking.
Against (2)
A huge headline fine can look tough while doing little for the people whose data was used. The €1.2 billion Meta penalty in the enforcement tracker is striking, but a revenue formula alone does not fund restitution or prove practices changed. I would rather require deletion, independent audits, and direct compensation, with fines added when those remedies are ignored.
Turnover tells us how big a company is, not how badly it behaved. A narrow retention mistake and a deliberate sale of sensitive records should not start from the same revenue-based threat. The GDPR data also show a few regulators dominate the largest cases, so legal exposure can depend heavily on venue. Base penalties on people harmed, sensitivity, duration, and repeat conduct instead.