Earlier quoted context omitted.
Here's the law. Notice that there's a bunch of stuff taken into account before setting the fines. https://gdpr-info.eu/art-83-gdpr/ Here are some cases. The first is a company that was processing sensitive data (health data) who had to register with the ICO in the UK. They didn't register. They were not fined at all, because they were asked to register and did so. (Last paragraph). https://www.bloomberg.com/news/arti…
There is no caselaw on the GDPR and no way to predict how fines will be levied. You can speculate how it will be enforced (as you have), but businesses tend to avoid speculation when assessing risk.
Since the GDPR will be enforced in the UK by ICO, there's very little speculation in the parent post.