Corporations treat fines as cost of doing business. In order to actually be effective, there need to be mandatory minimum prison terms for C-level staff who greenlit a particular program.
I'm also all for throwing C levels in jail ALONG WITH the board as well. They want to benefit and sign off on choices of the company? They can also hold said responsibility on illegal stuff.
Fines may deter small and medium-sized corporations, but not large ones. Therefore something else might. Like prison.
[1] https://www.privacyaffairs.com/gdpr-fines/
[2] https://www.statista.com/statistics/507742/alphabet-annual-g...
So, for a one-person startup, €20M means game over.
The combined amount of fines across all companies over the GDPR's entire 4-year lifespan is just 1Bn.
If the lower don't suffice, we will get closer & closer to the maximum.