GDPREU General Data Protection Regulation
European UnionAll Industries
Up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher
Article 83(5) sets the upper tier for breaches of the basic principles, data subject rights, and transfer rules. A lower tier of EUR 10 million or 2% applies to controller and processor obligations, including the Article 32 security duty. Separately, Article 82 gives any person who suffers damage a direct right to compensation from the controller or processor, which is pursued in the national courts rather than through the regulator.
Covers. Any information relating to an identified or identifiable natural person.
Beyond money. Supervisory authorities can order processing to stop, suspend data transfers to a third country, and impose a temporary or definitive ban.
Enforced by National supervisory authorities, led by the lead authority for the main establishment.
GDPR itself creates no criminal offence. Article 84 leaves criminal penalties to each Member State, and several have legislated them separately.
CCPA/CPRACalifornia Consumer Privacy Act / California Privacy Rights Act
California, USAAll Industries
USD 2,663 per violation, or USD 7,988 per intentional violation or one involving a minor
No ceiling — scales with the breach
Administrative penalties are assessed per violation, and a violation is usually counted per affected consumer, so a single practice can compound quickly. Separately, Section 1798.150 gives consumers a private right of action after a breach of unencrypted personal information caused by a failure to maintain reasonable security, with statutory damages of USD 100 to USD 750 per consumer per incident and no need to prove harm.
Covers. Information that identifies, relates to, or could reasonably be linked with a consumer or household — the household limb is broader than most privacy laws.
Enforced by The California Privacy Protection Agency and the Attorney General — and, for breaches, consumers themselves.
Both the administrative penalties and the Section 1798.150 damages range are adjusted for inflation in odd-numbered years, so published figures drift.
LGPDLei Geral de Proteção de Dados
BrazilAll Industries
Up to 2% of revenue in Brazil, capped at BRL 50 million per violation
Article 52 sets a simple fine of up to 2% of the group revenue in Brazil for the last financial year, excluding taxes, with a hard per-violation cap. A daily fine may run alongside it, subject to the same cap.
Covers. Information relating to an identified or identifiable natural person.
Beyond money. ANPD can publicise the infringement, block or delete the personal data concerned, and partially or wholly suspend the processing activity.
Enforced by ANPD, the Brazilian national data protection authority.
Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.
PIPEDAPersonal Information Protection and Electronic Documents Act
CanadaAll Industries
Up to CAD 100,000 per violation
PIPEDA is deliberately weak on money next to the instruments beside it in this list. The Commissioner cannot levy administrative fines at all; the offence provisions cover obstructing an investigation and destroying records that are the subject of a request, and are prosecuted rather than assessed. Federal reform to change this died with Bill C-27 in January 2025.
Covers. Information about an identifiable individual, held in the course of commercial activity.
Enforced by The Office of the Privacy Commissioner of Canada, with prosecution by the Crown.
The Commissioner has recommendation and reporting powers, not order-making powers. The practical exposure is reputational and, increasingly, a provincial one.
PDPASingapore Personal Data Protection Act
SingaporeAll Industries
Up to SGD 1 million, or 10% of annual turnover in Singapore for larger organisations, whichever is higher
The turnover-linked ceiling was introduced by the 2020 amendments and applies where annual Singapore turnover exceeds SGD 10 million. Alongside the organisational penalty, Part 9B creates personal criminal offences for individuals who mishandle personal data held by their own employer.
Covers. Data about an individual who can be identified from that data, or from that data and other information the organisation has or is likely to have access to.
Personally. Any individual who knowingly or recklessly discloses, uses, or re-identifies personal data held by their organisation without authorisation — A fine of up to SGD 5,000, imprisonment for up to 2 years, or both.
Enforced by The Personal Data Protection Commission of Singapore.
Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.
PIPLPersonal Information Protection Law of China
ChinaAll Industries
Up to CNY 50 million or 5% of the previous year turnover, for serious violations
Article 66 sets a two-step scheme: an order to rectify and a fine of up to CNY 1 million for ordinary breaches, escalating to the CNY 50 million or 5% ceiling where the circumstances are serious. The same article reaches the people who ran the processing, not only the company.
Covers. Information recorded electronically or otherwise relating to identified or identifiable natural persons within China.
Beyond money. Authorities can order the suspension of the relevant business, order a full suspension for rectification, and refer the revocation of business permits or licences.
Personally. The directly liable person in charge, and other directly liable staff — A personal fine of CNY 100,000 to CNY 1 million, and a bar on serving as a director, supervisor, senior manager, or person in charge of a relevant company for a set period.
Enforced by The Cyberspace Administration of China and provincial-level authorities.
Separate criminal liability for infringing personal information exists under PRC Criminal Law and is prosecuted independently of Art. 66; it is not claimed here.
United StatesPublic Companies
USD 5 million and up to 20 years imprisonment for a wilful false certification
SOX is the clearest case on this page of an instrument that reaches a person rather than a balance sheet. Section 906 attaches criminal liability to the certification the CEO and CFO sign personally. Section 802 and the obstruction provisions add a separate 20-year exposure for destroying or altering records, which reaches anyone, not only officers.
Covers. Regulates the reliability of the financial reporting PROCESS, not a class of data. What comes into scope is whatever feeds a financial statement assertion, which is decided by the control narrative rather than by a definition. 18 U.S.C. Sec. 1520 separately reaches audit workpapers as records.
Personally. The CEO and the CFO, by name, on their own certification — and, separately, anyone who alters, destroys, or conceals a record to impair an official proceeding — Certification: up to USD 1 million and 10 years for a knowing false certification, rising to USD 5 million and 20 years where it is wilful. Records: up to 20 years.
Enforced by The SEC civilly; the Department of Justice criminally.
The certification offences turn on state of mind. Knowing and wilful are different thresholds carrying different maximums.
GLBAGramm-Leach-Bliley Act
United StatesFinancial Services
Up to USD 100,000 per violation for the institution
The Safeguards Rule obliges financial institutions to maintain a written information security programme with named accountability. Enforcement is by the functional regulator, and the statute reaches the officers and directors as well as the institution.
Covers. Nonpublic personal information about a customer of a financial institution, in any form the institution handles.
Personally. Any person who obtains customer information from a financial institution under false pretences, including officers and employees who do so — Imprisonment for up to 5 years, rising to 10 years where the offence is aggravated. The officer-level fine of USD 10,000 per violation is widely cited but sits in the general enforcement provisions rather than in the criminal section.
Enforced by The FTC, the SEC, and the federal banking regulators, depending on the institution.
Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.
DORAEU Digital Operational Resilience Act
European UnionFinancial Services
For designated critical ICT providers, 1% of average daily worldwide turnover, charged every day
Article 35 lets the Lead Overseer impose a periodic penalty payment of 1% of the average daily worldwide turnover of the preceding business year, levied daily until the provider complies, for up to six months. For financial entities themselves, penalties are set by each Member State rather than by the Regulation.
Covers. Regulates ICT risk management and operational resilience at the level of the ENTITY. Scope follows the financial entity and its critical functions, not any category of data.
Enforced by National financial regulators; the ESAs directly, for designated critical ICT providers.
The daily mechanism is designed to compel compliance rather than to punish, so it stops the moment the deficiency is remedied.
HIPAAHealth Insurance Portability and Accountability Act
United StatesHealthcare
USD 145 to USD 73,011 per violation, to a calendar-year cap of USD 2,190,294 per identical provision
Civil penalties run in four tiers keyed to culpability, from no knowledge through wilful neglect that was never corrected. The figures are adjusted for inflation annually; the amounts here took effect on 28 January 2026. Criminal referrals go to the Department of Justice and target people, not the covered entity.
Covers. Protected health information — individually identifiable health information held or transmitted by a covered entity or business associate.
Personally. Any person who knowingly obtains or discloses protected health information — employees, executives, and contractors alike. Prosecuted by the Department of Justice, not by OCR — Up to USD 50,000 and 1 year. Up to USD 100,000 and 5 years where the offence is committed under false pretences. Up to USD 250,000 and 10 years where there is intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm.
Enforced by HHS Office for Civil Rights civilly; the Department of Justice criminally.
OCR continues to apply a 2019 enforcement discretion policy that lowers the annual caps for the first three tiers below the published figure.
CMMCCybersecurity Maturity Model Certification
United StatesDefense Industrial Base
Treble damages plus per-claim civil penalties under the False Claims Act, and loss of contract eligibility
The exposure here is not a compliance fine but a fraud claim. The DOJ Civil Cyber-Fraud Initiative treats an inaccurate security assessment score or a false affirmation as a misrepresentation, and liability can arise with no breach and no harm to the government at all. One contractor settled for USD 4.6 million after reporting a positive score when the true score was negative 142.
Covers. Two borrowed classes. Federal contract information is the lower tier; controlled unclassified information is the higher one.
Beyond money. Suspension and debarment remove the ability to hold federal contracts.
Enforced by The Department of Defense contractually; the Department of Justice under the False Claims Act.
Phase II of the CMMC rollout was suspended in July 2026. During the interim, the Department enforces against NIST SP 800-171 self-assessment rather than requiring third-party certification — which moves the exposure onto the accuracy of your own assessment.
NIS2EU Network and Information Security Directive 2
European UnionEssential & Important Entities
Essential entities: EUR 10 million or 2% of worldwide turnover. Important entities: EUR 7 million or 1.4%
Both ceilings take the higher of the fixed sum and the percentage. The more consequential provision is not the money: Article 20 places the approval and oversight of cybersecurity risk-management measures on the management body itself, and Article 32(6) lets an authority ask a court to bar a named executive from running the business.
Covers. Regulates the security of network and information SYSTEMS. Art. 21 lists measures rather than data classes, and an entity is in scope for its sector and size, not for what it stores.
Beyond money. Authorities can also suspend a certification or authorisation covering the services concerned.
Personally. Any natural person discharging managerial responsibilities at chief executive or legal representative level in an essential entity — A temporary prohibition on exercising managerial functions in that entity, lasting until the deficiencies are remedied. Article 20 separately makes the management body accountable for approving and overseeing the measures.
Enforced by The national competent authority designated by each Member State.
Article 34 sets a floor, not a ceiling. Member States may and do set higher maximums when transposing, so the national figure is the one that governs.
European UnionHealthcare / Research
Up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher
The European Health Data Space carries a GDPR-shaped penalty structure of its own, with a lower tier of EUR 10 million or 2% for less serious infringements. Health data access bodies can also act against a data user directly, independently of the supervisory authority.
Covers. Electronic health data — personal or non-personal data relating to health, in electronic form.
Beyond money. A health data access body can exclude a data user from access to the Space for up to five years.
Enforced by National health data access bodies and market surveillance authorities.
Obligations phase in over several years from entry into force, so which provisions are live depends on the date.
UK DPAUK Data Protection Act 2018
United KingdomAll Industries
Up to GBP 17.5 million or 4% of total annual worldwide turnover, whichever is higher
The standard maximum for the UK GDPR is GBP 8.7 million or 2%; the higher maximum applies to the more serious infringements. The Act adds criminal offences that the Commissioner prosecutes in her own name, and those reach individuals who act outside their employer instructions.
Covers. Personal data as under UK GDPR, with a second heightened class the EU instrument does not have.
Personally. Any person who knowingly or recklessly obtains or discloses personal data without the consent of the controller — and, separately, a controller or their staff who alter records to defeat a subject access request — An unlimited fine on conviction. There is no custodial sentence for either offence.
Enforced by The Information Commissioner, who also prosecutes the criminal offences.
Individual prosecutions under s.170 and s.173 have resulted in convictions of employees and of company directors, but never in a prison sentence, because the sentence is not available.
SEC 17a-4SEC Rule 17a-4 - Records to be Preserved
United StatesSecurities / Broker-Dealers
No statutory cap. Roughly USD 2.7 billion assessed across around 60 firms since 2021
No ceiling — scales with the breach
The recordkeeping rules carry no ceiling, and the off-channel communications sweep shows what that means in practice: business conducted on personal devices and unapproved messaging apps was not captured, and the penalties were sized to the firm rather than to a schedule. This is an enforcement pattern, not a published maximum.
Covers. Defined by record TYPE rather than by data class — the books and records a broker-dealer must make and then preserve.
Personally. Any person who wilfully violates the Exchange Act or a rule made under it, including supervisors and compliance officers charged individually — Up to USD 5 million and 20 years imprisonment for a wilful violation.
Enforced by The SEC and FINRA civilly; the Department of Justice for wilful violations.
The USD 2.7 billion figure describes what has been assessed to date. It is not a ceiling and should not be read as one.
United States (State)Insurance
A model law. It binds only where a state has enacted its own version.
Set by each state. The model suggests USD 500 per violation to a USD 10,000 cap
Model Law 668 deliberately does not fix a national penalty. Section 10 defers to each state general insurance code, so the answer to what it costs is genuinely which state. The suggested figures rise to USD 10,000 per violation, capped at USD 50,000, where a commissioner cease-and-desist order is breached.
Covers. A three-part definition: business information whose disclosure would harm the licensee, plus consumer information by identifier, plus health information.
Beyond money. A commissioner can suspend or revoke the licence to write business in the state.
Enforced by The insurance commissioner of each state that has enacted a version of the model.
Around 28 jurisdictions have enacted some version, and the enacted texts differ. Only the version adopted in your states of licensure binds you.
MiCAEU Markets in Crypto-Assets Regulation
European UnionCrypto / Web3 / Digital Assets
Set in national transposition. Published ceilings range from EUR 5 million or 3% of turnover upwards
MiCA sets minimum maximums and requires Member States to legislate the rest, so the tiers differ by infringement type and by country. Published summaries disagree with each other for exactly that reason. The reliable statement is that the ceilings are turnover-linked, that they reach the management body as well as the firm, and that the authorising national regulator is the one to ask.
Covers. Regulates crypto-asset SERVICES and the entities providing them. The regulated object is the activity and the authorisation, not a data class.
Beyond money. Withdrawal of the crypto-asset service provider authorisation removes the ability to operate in the Union at all.
Enforced by National competent authorities, with EBA and ESMA supervision for significant issuers.
Because the tiers are set nationally, a single headline figure would be wrong somewhere. Check the transposition in your authorising Member State.
DPDP ActIndia Digital Personal Data Protection Act 2023
IndiaAll Industries
Up to INR 250 crore for failing to maintain reasonable security safeguards
The Schedule to the Act sets a distinct maximum per obligation: INR 250 crore for security safeguards, INR 200 crore for failing to notify a breach, INR 200 crore for the children provisions, and INR 150 crore for the additional obligations on significant data fiduciaries. Notably, the Act carries no imprisonment at all — the design is civil penalties only.
Covers. Digital personal data — data about an identifiable individual, in digital form or digitised afterwards.
Enforced by The Data Protection Board of India, with appeal to the Appellate Tribunal.
The Rules were notified in November 2025, but the substantive compliance obligations take effect on 13 May 2027, and enforcement begins then with no grace period.
APPIJapan Act on Protection of Personal Information
JapanAll Industries
Up to JPY 100 million for a corporate offender
The Commission works through guidance and orders first. The penalty attaches to breaching an order or to providing a false report, rather than to the underlying handling failure, and the corporate ceiling was raised substantially by the 2020 amendments.
Covers. Information about a living individual which identifies them, including by an individual identification code.
Enforced by The Personal Information Protection Commission of Japan.
The enforcement culture is corrective rather than punitive; orders and published guidance are far more common than fines.
Quebec Law 25Quebec Law 25 - An Act to Modernize Legislative Provisions Respecting Personal Information
Quebec, CanadaAll Industries
Penal fines to CAD 25 million or 4% of worldwide turnover; administrative penalties to CAD 10 million or 2%
No ceiling — scales with the breach
Quebec runs two parallel tracks. Administrative monetary penalties are imposed by the Commission; penal fines are prosecuted and can be doubled for a repeat offence. Section 93.1 adds a private right of action, and an infringement that is intentional or results from gross fault carries a minimum award of CAD 1,000 in punitive damages per person, which is what makes class proceedings viable.
Covers. Any information which relates to a natural person and directly or indirectly allows that person to be identified.
Enforced by The Commission d’accès à l’information, and individuals directly.
The punitive damages minimum is per individual and does not require proof of pecuniary loss, so the aggregate in a class action is driven by headcount.
SOCI ActAustralia Security of Critical Infrastructure Act 2018
AustraliaCritical Infrastructure
Civil penalties set per provision — 200 penalty units for a risk management programme failure, 750 units per day for annual reporting
The Act prices each obligation separately rather than setting one ceiling. Failing to adopt and maintain a critical infrastructure risk management programme attracts up to 200 penalty units; missing the annual report attracts 750 units per day of contravention for a company. Where the contravener is a body corporate a court may order up to five times the maximum.
Covers. Data that, if compromised, would prejudice the socio-economic stability, defence or national security of Australia — defined partly by a headcount threshold.
Beyond money. Government assistance powers allow direct intervention in the operation of a critical asset during a serious incident.
Enforced by The Cyber and Infrastructure Security Centre, within the Department of Home Affairs.
The value of a penalty unit is indexed periodically, so the dollar equivalent of each figure moves.
NERC CIP-007-6NERC Critical Infrastructure Protection - Systems Security Management
North AmericaPower / Utilities
Up to USD 1.54 million per day per violation, indexed from the statutory USD 1 million
The Energy Policy Act of 2005 set the original ceiling at USD 1 million per day per violation and it is adjusted for inflation. Because the exposure accrues daily and per violation, a control gap that persisted across an audit period compounds. Penalties are public once filed with FERC.
Covers. Information about a BES Cyber System that could be used to gain unauthorised access to it, or to compromise its operation.
Beyond money. Findings require a mitigation plan with milestones, and can bring a public letter of reprimand, placement on a reliability watch list, and additional spot checks.
Enforced by NERC and the Regional Entities, with penalties approved by FERC.
Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.
United StatesRail / Transit
Civil penalties assessed per violation under 49 CFR Part 1503, with no schedule published for these directives
Security Directives are issued and amended without notice-and-comment, and they bind the designated owner-operators directly. TSA opens an action by serving a Notice of Proposed Civil Penalty setting out the provision, the facts, and the proposed amount, which is drawn from its published sanction guidance rather than from the directive itself.
Covers. Information whose disclosure would be detrimental to transportation security. The directives themselves are SSI.
Enforced by The Transportation Security Administration.
The directives are reissued periodically with new numbers and amended requirements, so the obligations in force change more often than a statute would.
European UnionWater / Waste / Energy
Penalties are set by each Member State in transposition — the Directive itself fixes no amount
Article 22 requires Member States to lay down penalties that are effective, proportionate and dissuasive, and leaves the figures to them. The obligations themselves — resilience measures, incident notification, background checks on sensitive roles — are harmonised even though the sanction is not.
Covers. Regulates the physical and organisational resilience of critical ENTITIES. It is the non-cyber sibling of NIS2 and defines no data category at all.
Enforced by The national competent authority designated by each Member State.
Because CER and NIS2 were adopted together and often transposed together, the national penalty regime for the two is frequently the same instrument.
European Union / GlobalAI Systems / All Industries
Up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher
Article 99 sets three tiers. The top tier applies to the prohibited practices in Article 5. Breaching the provider, deployer, and other operator obligations attracts EUR 15 million or 3%; supplying incorrect or misleading information to a notified body or an authority attracts EUR 7.5 million or 1%.
Covers. The data sets used to build a high-risk AI system, plus the input data it consumes in operation.
Beyond money. Market surveillance authorities can require a system to be withdrawn from the market or recalled.
Enforced by National market surveillance authorities, and the AI Office for general-purpose models.
For SMEs and start-ups the rule inverts: the fine is the lower of the fixed sum and the percentage, not the higher.
DSAEU Digital Services Act
European UnionDigital Platforms / Social Media
Up to 6% of annual worldwide turnover
The 6% ceiling covers infringements of the obligations, failure to comply with interim measures, and breach of binding commitments. Separately, periodic penalty payments of up to 5% of average daily worldwide turnover accrue for each day of delay in complying with an order.
Covers. Regulates intermediary SERVICES and the handling of illegal content. Obligations attach to the service and its size, not to a defined category of data.
Beyond money. For persistent and serious infringements the Commission can ask for temporary restriction of access to the service.
Enforced by The European Commission for very large platforms; national Digital Services Coordinators otherwise.
Very large online platforms and search engines carry additional obligations that smaller services do not, so the applicable duties depend on designation.
HMS OHIPHealth Management System Billing (OHIP/Alberta)
CanadaHealthcare Billing
Recovery of amounts paid, plus provincial health privacy penalties for the information itself
Billing integrity and health information privacy are two different exposures that arrive together. The ministry can audit, recover payments, and refer billing conduct for prosecution; the personal health information in the same systems is governed by provincial health privacy legislation with its own offence provisions and prosecutions.
Covers. Identifying information about an individual relating to their physical or mental health, or to the provision of health care.
Beyond money. Billing privileges can be suspended.
Enforced by The provincial health ministry and, for personal health information, the Information and Privacy Commissioner of Ontario.
The applicable statute is provincial, so Ontario and Alberta differ in both the obligations and the amounts.