Here's a venture capital funded organisation who was handled sensitive personal data of many people. They had a legal requirement to register with the English Information Commisioner under existing DPA law. They didn't register.
What fine do you think they got?
(penultimate para) https://www.bloomberg.com/news/articles/2018-04-26/u-k-healt...
Big fines are reserved for the worst incompetent or deliberate repeated failure.