Really? There is a
long list of criteria to consider on that exact page you link, and those
will be checked by courts if the DPAs appear unreasonable. I didn't say a 20 million fine is impossible, but it'll need a very good basis.
Yes, the maxima are high, but it's crazy to believe the DPAs will be able (both legally and politically) to hand fines even close to that out left and right, even if you assumed they over night suddenly turn into organizations hell-bent to do maximum damage.
It's weird how people see that maximum amount and somehow believe those will be the norm, throwing all experience with both the DPAs and other regulations out of the window. How many undeserving businesses have been fined to death in other areas (financial regulation, environmental protection, ...) and why should this suddenly start with privacy law? No government has an interest in its enforcement arm ruining business, of course they care about downsides. Regulation and its enforcement doesn't exist in a vacuum, as much as the revenge-boner some "privacy advocates" (ideally selling some GDPR advice on the side...) get right now wishes it were otherwise.
(On the other hand, these numbers seem to be the only thing motivating some business owners to care, so even if they're never used they've served a purpose. Really, the amount of conversations you see that go "And they are complaining that suddenly doing X is so much work", "Didn't they have to do X under previous law as well?" "..." is mind-boggling)