Sure, and I know it's mostly scaremongering, but "4% of zero, or 'up to 20 million euros'" is up to 20 million euros.
A better motivator, in my opinion, is that disclosing up front what data you're going to capture, and what you're going to do with it, and obtaining consent for that from users - is "the right thing to do". Unless your business model is "fucking over the users", those are not scary things to do, and will likely lead you to make better decisions about what you collect and how you store it, and reduce your and your users exposure in the worst case.