CompTIA Security+ (SY0-701)Security Program Management and OversightMedium

A U.S.-based company with $60 million in annual global revenue suffers a data breach affecting EU residents' personal data and is found to have violated GDPR. Regulators state the maximum applicable fine tier is 4% of annual global revenue. What is the maximum potential fine under this tier?

  1. A$2,400,000
  2. B$6,000,000
  3. C$24,000,000
  4. D$600,000
Show answer & explanation

Correct answer: A. $2,400,000

4% of $60,000,000 = $60,000,000 x 0.04 = $2,400,000.

Why the other options are wrong

  • B. This equals 10% of revenue, not the applicable rate.
  • C. This equals 40% of revenue, far exceeding the stated tier.
  • D. This equals 1% of revenue, not the 4% tier specified.

GDPR Fine Tiers

GDPR authorizes fines up to the greater of a fixed amount or a percentage of a company's annual global revenue, depending on the severity of the violation.

  • Higher tier: up to 4% of global annual revenue or €20 million, whichever is greater
  • Lower tier: up to 2% of global annual revenue or €10 million
  • Applies regardless of company location if EU residents' data is involved

Memory trick: GDPR bites 4% for the big violations, 2% for the smaller ones.

More Security Program Management and Oversight questions