Everytime a new EU regulation is discussed on HN people are up in arms about the "maximum fines" and some replace the "maximum" with "mandatory".
Fines need to be reasonable and proportional and that is not optional if they should survive a court case.
The big fines are tool used to bring global conglomerates into compliance.
From https://gdpr.eu/fines/:
> The more serious infringements go against the very principles of the right to privacy and the right to be forgotten that are at the heart of the GDPR. These types of infringements could result in a fine of up to €20 million, or 4% of the firm’s worldwide annual revenue from the preceding financial year, whichever amount is higher. (emphasis theirs, well, bold not italics, but yeah.)
Meta/Facebook/WhatsApp was fined about 2.4 billion (6 out of top 10 fines), but still nowhere near close to the maximum (which would be about 54 billion).
OTOH this might just be a case of "temporarily inconvenienced billionaire" logic or the same fear mongering as "if we raise minimum wage you won't be able to afford rent".
I'm actually surprised the ICO can fine the UK government. This can't happen in France, for instance.
That was an error with potentially very grave consequences, but it seems the MoD handled it well once they were aware of it (“Soon after the data breach, the MoD contacted the people affected asking them to delete the email, change their email address, and inform the ARAP team of their new contact details via a secure form. The MoD also conducted an internal investigation, made a statement in Parliament about the data breach, and updated the ARAP’s email policies and processes, including implementing a ‘second pair of eyes’ policy for the ARAP team when sending emails to multiple external recipients”)
I don’t think a larger fine would have made them do better, so why make it higher?