> Having a lower bound
This is exactly the opposite of what GDPR says. If I am Satan himself and I do terrible things with the data of millions of people the maximum possible fine available is €20m or 4% of turnover, whichever is higher.
There is no lower bound. When a penalty is applied they're likely to be about €1000. But often penalties won't be applied, the regulator will ask the company to come back into compliance and give advice on how to do so.
> of €10M in penalties with no respect to how much data the company holds is what makes this taxing for startups.
...and GDPR is full of caveats about how much data is held, and how it's held, and how the company responds after a leak.
https://gdpr-info.eu/art-83-gdpr/
> When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
> the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
> the intentional or negligent character of the infringement;
> any action taken by the controller or processor to mitigate the damage suffered by data subjects;
> the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
> any relevant previous infringements by the controller or processor;
> the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
> the categories of personal data affected by the infringement;
> the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;
> where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
> adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and
> any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.