What penalties or fines apply for privacy law violations?

How the answer differs across 7 jurisdictions

The Short Answer

GDPR violations in Germany can lead to criminal penalties (up to 3 years imprisonment) under BDSG § 42 or administrative fines up to €20 million or 4% of global annual turnover under EU GDPR — plus up to €50,000 for specific BDSG breaches.

Up to €20M
Max GDPR fine
4% turnover
Alternative GDPR cap
3 years
Max prison term
€50,000
Max BDSG fine
SingaporeFull article
The Short Answer

The maximum fine for a PDPA violation in Singapore is S$1 million.

S$1 million
Max fine per breach
s. 29
PDPA section
Act 26 of 2012
Statute number
2012
Enactment year
European UnionFull article
The Short Answer

A company can be fined up to €20 million or 4% of its global annual turnover — whichever is higher — for a serious GDPR violation.

€20 million
Max fine (absol. amount)
4% turnover
Max fine (relative)
Whichever highe
Fine calculation rule
Art. 83(5)
GDPR penalty tier
The Short Answer

The ICO can fine a company up to £17.5 million or 4% of its global annual turnover — whichever is higher — for the most serious GDPR breaches.

£17.5 million
Maximum fine
4%
Of global turnover
2 tiers
Fine categories
s. 157
DPA 2018 section
South KoreaFull article
The Short Answer

Fines for violating South Korea’s Personal Information Protection Act (PIPA) range from ₩10 million to ₩100 million, depending on the violation type and severity.

₩10M
Min fine
₩100M
Max fine
7 years
Max imprisonment
3 years
Statute of limitations
The Short Answer

Penalties for violations of the Digital Personal Data Protection Act, 2023 (DPDPA) range from ₹50 crore to ₹250 crore, depending on the nature and severity of the breach.

₹250 crore
Max penalty
₹50 crore
Min penalty
DPDP Authority
Enforcing body
2023
Act year
The Short Answer

Violations of Japan's Act on the Protection of Personal Information (APPI) can result in criminal penalties including imprisonment up to 1 year or fines up to ¥500,000 — or both — for unauthorized disclosure or improper acquisition of personal information.

¥500,000
Max fine
1 year
Max imprisonment
5 years
Statute of limitations
APPI s. 83
Criminal penalty

Read Full Articles

Not legal advice. This article is general information based on publicly available sources, written for educational purposes. Laws change and individual situations vary. Consult a licensed attorney in your jurisdiction before acting on anything you read here. Last reviewed: June 2026.