Here are two recent decisions from the UK. The ICO has a maximum £500,000 fine available.
In one a company was handling sensitive personal data (medical data). They're required to register with the ICO. They did not do so. The sceptics would claim they got huge fines. They didn't. THey got a letter asking them to register, with no further action taken. ICO released a statement.
Last para here: https://www.bloomberg.com/news/articles/2018-04-26/u-k-healt...
In another the Crown Prosecution Service lost data in the same way they had previously lost data: they sent unencrypted DVDs through the mail and those DVDs got lost. The DVDs contained victim interviews from children who had been sexually abused. It's hard to think of worse: very sensitive data, transmitted in a stupid easily fixed manner, and a repeat offence. Even this didn't attract the biggest fine. They got a £350,000 fine.
https://ico.org.uk/action-weve-taken/enforcement/crown-prose...
We have over 20 years experience of regulation. We're not making this up.