Enforcement
GDPR Fines: The Biggest Penalties and What They Mean for You
Since 2018, European data protection authorities have issued more than €7.1 billion in GDPR fines. Enforcement is accelerating every year, with €1.2 billion in penalties issued in 2025 alone. No business is too big or too small to be targeted. Here is a complete breakdown of the largest fines, the most recent enforcement actions, and what they mean for anyone who runs a website.
The big picture
GDPR Enforcement at a Glance
Seven years of the General Data Protection Regulation have transformed data privacy enforcement across Europe and beyond. The numbers tell the story.
The General Data Protection Regulation, which took effect on May 25, 2018, gave European data protection authorities the power to issue substantial financial penalties for violations. Under GDPR, fines can reach up to €20 million or 4% of a company’s global annual turnover, whichever is higher. For less severe violations, the cap is €10 million or 2% of global annual turnover.
In the first two years, enforcement was relatively cautious as regulators established precedents and companies adapted to the new framework. Since 2021, however, fines have increased dramatically in both frequency and scale. More than 60% of all GDPR fines — over €3.8 billion — have been imposed since January 2023, reflecting a decisive shift toward aggressive enforcement.
Eight of the ten largest GDPR fines ever imposed have been levied against US-based companies, including Meta, Amazon, Google, and TikTok’s parent company ByteDance. Together, these fines total approximately €3.9 billion, representing nearly 63% of the entire fine total. However, European companies, SMBs, and public-sector organizations are increasingly in the crosshairs as well. Spain’s Data Protection Authority alone has issued more than 930 individual fines, many targeting small and medium-sized businesses.
For the first time since GDPR came into force, data protection authorities recorded an average of more than 400 personal data breach notifications per day between late January 2025 and January 2026 — a 22% year-on-year increase. This surge reflects both the growing scale of data processing and the increasing willingness of organizations to report breaches under GDPR’s mandatory 72-hour notification requirement.
All-time record
Top 10 Largest GDPR Fines Ever
The ten biggest financial penalties imposed under the GDPR since its inception. Data current through February 2026, sourced from the EDPB, GDPR Enforcement Tracker, and individual DPA decisions.
| Rank | Company | Fine Amount | Country / DPA | Year | Reason |
|---|---|---|---|---|---|
| 1 | Meta (Facebook) | €1.2 billion | Ireland — DPC | 2023 | Unlawful transfer of EU user data to the United States using Standard Contractual Clauses without adequate safeguards against US government surveillance. |
| 2 | Amazon Europe | €746 million | Luxembourg — CNPD | 2021 | Processing personal data for targeted advertising without valid consent. Users were not given adequate means to opt out of behavioral tracking. |
| 3 | TikTok (ByteDance) | €530 million | Ireland — DPC | 2025 | Transferring EU user data to servers in China despite assurances that no European data was stored there. Chinese law deemed insufficient to protect EU data. |
| 4 | Meta (Spain ruling) | €479 million | Spain — Commercial Court of Madrid | 2025 | Unlawful data processing gave Meta unfair competitive advantage in the advertising market. Damages awarded to 87 Spanish media publishers. |
| 5 | Meta (Instagram) | €405 million | Ireland — DPC | 2022 | Wrongfully processing children’s personal data, including publicly exposing email addresses and phone numbers of minors using business accounts. |
| 6 | Meta (Facebook & Instagram) | €390 million | Ireland — DPC | 2023 | Using “contract necessity” as a false legal basis for behavioral advertising data processing. Facebook fined €210M, Instagram €180M. |
| 7 | Google LLC (Gmail) | €200 million | France — CNIL | 2025 | Inserting advertisements disguised as emails into Gmail inboxes without user consent. Dark patterns made refusing advertising cookies harder than accepting them. |
| 8 | WhatsApp Ireland | €225 million | Ireland — DPC | 2021 | Failure to meet transparency obligations under GDPR. Users were not adequately informed about how their data was shared with other Meta companies. |
| 9 | SHEIN (Infinite Styles) | €150 million | France — CNIL | 2025 | Placing advertising cookies on user devices before consent was obtained. Non-functional opt-out mechanisms and misleading cookie banners on shein.com. |
| 10 | Google (Cookie Consent) | €150 million | France — CNIL | 2021 | Failing to provide users an easy way to refuse cookies. Accepting cookies required one click; rejecting them required multiple clicks across several screens. |
2025 enforcement
Notable GDPR Fines and Actions in 2025
2025 saw regulators across Europe issue more than €1.2 billion in GDPR penalties. Here are the most significant enforcement actions of the year and what made each case important.
TikTok — Illegal Data Transfers to China
Ireland’s Data Protection Commission fined TikTok’s parent company ByteDance €530 million in May 2025 for transferring EU user data to servers in China. TikTok had assured the DPC that no European users’ data was stored in China, but the regulator found this to be incorrect. An assessment of Chinese data protection law determined it does not provide an equivalent level of protection to GDPR. This is the third-largest GDPR fine ever issued and the largest of 2025. TikTok has lodged a full appeal against the decision.
Meta — Unfair Competition via GDPR Violations
In November 2025, the Commercial Court of Madrid ordered Meta to pay €479 million in damages to 87 Spanish digital publishers. The court found that between May 2018 and August 2023, Meta processed Facebook and Instagram user data under an improper legal basis — claiming “contract necessity” rather than obtaining user consent. This gave Meta an unfair competitive advantage in the online advertising market, drawing ad revenue away from publishers who could not access equivalent personal data. This landmark ruling establishes a precedent for competitors to claim financial damages resulting from GDPR violations.
Google — Gmail Ads and Cookie Dark Patterns
In September 2025, France’s CNIL imposed a combined €325 million fine on Google: €200 million on Google LLC and €125 million on Google Ireland. The investigation, triggered by a complaint from the advocacy group NOYB, found that Google inserted advertisements between emails in Gmail users’ inbox tabs without consent — a practice the CNIL classified as unsolicited direct marketing. Additionally, the Google account creation process used dark patterns that required six clicks to refuse advertising cookies but only two clicks to accept them, affecting over 74 million French accounts. The CNIL cited Google’s prior fines in 2020 and 2021 as aggravating factors.
SHEIN — Cookies Before Consent
Also in September 2025, the CNIL fined SHEIN’s Irish subsidiary €150 million for placing advertising cookies on users’ devices before any consent was obtained on shein.com. The investigation found that SHEIN provided incomplete and misleading information in its cookie banners, failed to clearly identify third-party cookies, and made it difficult for users to refuse or withdraw consent. The CNIL treated each user visit where cookies were placed without consent as a separate violation, significantly amplifying the scale of the penalty. This case reinforced that e-commerce companies face the same scrutiny as big tech platforms.
Poczta Polska — Election Data Processing
Poland’s data protection authority UODO fined the state-run postal service Poczta Polska 27 million PLN (approximately €7.4 million) for unlawfully processing personal data during the 2020 pandemic elections. The Ministry of Digital Affairs had provided personally identifiable information on all eligible voters to the postal service without a valid legal basis. This case demonstrates that public-sector organizations are subject to the same GDPR enforcement as private companies, and that data processing decisions made during emergencies do not receive automatic exemptions from privacy law.
Luka Inc. — AI Company Privacy Violations
Italy’s Garante demanded a €5 million fine from US-based AI company Luka for collecting and processing personal and behavioral information without obtaining proper consent. The Garante also found that Luka’s privacy notices were too opaque for users to understand what data was being collected and how it was used. This fine signals that AI companies face growing GDPR scrutiny, and that the collection of behavioral data for AI training purposes requires the same level of transparency and consent as any other form of data processing.
ING Bank — Unlawful Identity Scanning
Poland’s UODO imposed a €4.375 million fine on ING Bank for unlawfully processing personal data collected from identity document scans. Between April 2019 and September 2020, the bank scanned customers’ and potential customers’ identity documents without verifying whether the scans were justified under Anti-Money Laundering regulations. The case underscores that financial institutions cannot rely on AML compliance as a blanket justification for collecting and retaining sensitive identity data. The purpose limitation principle still applies, and each processing activity must be individually assessed.
McDonald’s Polska — Employee Data Breach
Poland’s UODO fined McDonald’s Polska approximately €3.9 million after a misconfigured server exposed sensitive employee data, including PESEL numbers (national identification numbers), passport numbers, and work shift details. The fine was imposed for inadequate technical and organizational measures to prevent the breach, as required under GDPR Article 32. This case is a reminder that GDPR does not only apply to customer-facing data collection. Employee data processing carries the same obligations, and data security failures affecting internal systems are subject to the same enforcement standards.
Trends
Five Enforcement Trends Shaping GDPR in 2025 and Beyond
GDPR enforcement is not just getting bigger — it is getting more targeted, more sophisticated, and harder to avoid. Here are the five key trends every website owner should understand.
Cookie consent enforcement is accelerating
The era of token cookie banners is over. France’s CNIL has been at the forefront of cookie enforcement, issuing €325 million to Google and €150 million to SHEIN in September 2025 alone. Both fines targeted the same core violation: placing cookies or running tracking scripts before obtaining valid user consent. The CNIL’s approach of treating each non-consented user session as a separate violation means that high-traffic websites face exponentially larger penalties. Other European DPAs are following suit. The message is clear: if your website sets any non-essential cookies before a user actively consents, you are violating the law, and regulators are actively looking for you. Consent must be obtained before tracking begins, not after, and not assumed by continued browsing.
Dark patterns in cookie banners are drawing fines
Regulators have moved beyond checking whether a cookie banner exists and are now evaluating how it is designed. The CNIL’s investigation into Google’s account creation process found that refusing personalized advertising cookies required six clicks, while accepting required only two. This asymmetry in the user journey was deemed a dark pattern that compromised the “freely given” requirement of GDPR consent. Similarly, SHEIN’s cookie banner was found to provide incomplete information and make it difficult for users to withdraw consent. Enforcement now focuses on the practical experience of the consent mechanism, not just its existence. If your reject button is smaller, less visible, or harder to reach than your accept button, you have a compliance problem. If you use pre-checked boxes, confusing language, or require more steps to decline than to accept, you are engaging in a dark pattern that regulators are trained to identify.
Big tech companies are repeat offenders
Meta alone has accumulated over €2.5 billion in GDPR fines across multiple enforcement actions, including the record €1.2 billion fine in 2023, the €405 million Instagram children’s data fine in 2022, the €390 million legal basis fine in 2023, and the €479 million Spanish court ruling in 2025. Google has been fined by France’s CNIL three separate times for cookie-related violations, with the CNIL explicitly citing prior fines as an aggravating factor when calculating the 2025 penalty. Regulatory history is now a penalty multiplier. Companies that have been fined before face larger penalties the next time, and regulators expect that previous enforcement should have prompted changes in behavior. For website owners, this means that ignoring a compliance warning or a minor enforcement action today makes the next one significantly more expensive.
Small and medium-sized businesses are not immune
While the headline fines target global technology companies, the vast majority of GDPR enforcement actions are aimed at small and medium-sized businesses. Spain’s AEPD has issued more than 930 individual fines, many in the range of €1,000 to €100,000, targeting local businesses for violations like sending marketing emails without consent, failing to honor data deletion requests, or installing CCTV without proper notice. Poland’s UODO has fined schools, municipalities, and healthcare providers. Italy’s Garante has penalized small online retailers and app developers. The average GDPR fine across all countries and all enforcement actions is approximately €2.36 million, but the median is far lower, reflecting a long tail of smaller penalties imposed on ordinary businesses. If you operate a website that collects personal data from EU residents, you are subject to GDPR regardless of your company’s size, location, or revenue.
Cross-border enforcement is getting smoother
One of the earliest criticisms of GDPR enforcement was the “one-stop-shop” mechanism, which allowed companies to be regulated primarily by the DPA in the EU country where they had their main establishment. This led to bottlenecks, particularly at Ireland’s DPC, which oversees most US tech companies with European headquarters in Dublin. In 2025, cross-border enforcement has become notably more efficient. The Irish DPC issued the €530 million TikTok fine within a structured timeframe, and France’s CNIL bypassed the one-stop-shop entirely for Google’s cookie violations by enforcing under national ePrivacy rules rather than GDPR. Meanwhile, the Spanish court ruling against Meta demonstrates that civil courts can impose GDPR-related damages independently of DPA enforcement, opening up a parallel enforcement path through private litigation. The practical implication is that regulatory arbitrage — choosing a lenient jurisdiction for your EU headquarters — is becoming less effective. Multiple enforcement pathways now exist, and they are all active.
Practical takeaways
What This Means for Website Owners
You do not need a €1 billion budget or a team of lawyers to comply with GDPR. But you do need to get the basics right. Here are the concrete steps every website owner should take based on current enforcement priorities.
Your cookie banner must offer real choice
The Google and SHEIN fines prove that having a cookie banner is not enough. It must provide equally prominent accept and reject options, without dark patterns. Users must be able to refuse all non-essential cookies in the same number of clicks it takes to accept them. Pre-checked boxes, hidden reject buttons, confusing language, and “legitimate interest” workarounds for advertising cookies are all enforcement targets. Test your banner from the perspective of a first-time visitor who wants to decline everything. If that process is harder than accepting, you have a compliance gap.
Your privacy policy must be accurate and complete
GDPR Articles 13 and 14 require specific disclosures in your privacy policy: the identity of the data controller, purposes and legal bases for processing, categories of data collected, retention periods, third-party sharing, international transfers, and data subject rights. Missing sections are a common finding in enforcement actions, and “opaque” privacy notices were explicitly cited in the Luka Inc. fine. Your privacy policy must reflect what your website actually does with data, not what a template says. If you add a new analytics tool or change a third-party provider, your privacy policy must be updated to match.
Consent must come before tracking
This is the single most important compliance requirement and the one most frequently violated. No analytics cookies, advertising pixels, social media widgets, or third-party tracking scripts should fire on your website before a user has actively given consent. This is what the SHEIN fine was about: cookies placed before the consent banner even appeared. It is what the Google fine was about: advertising delivered without user permission. If your website loads Google Analytics, Meta Pixel, TikTok Pixel, or any similar tool on page load without waiting for consent, you are committing the same violation that led to hundreds of millions in fines.
International data transfers need a valid mechanism
The two largest GDPR fines ever — Meta’s €1.2 billion and TikTok’s €530 million — both concerned unlawful transfers of EU personal data to countries outside the European Economic Area. If your website sends user data to servers in the United States, China, or any other country without an EU adequacy decision, you need a valid transfer mechanism in place, such as Standard Contractual Clauses or Binding Corporate Rules, supplemented by a Transfer Impact Assessment. Simply using a US-based analytics provider or cloud hosting service can trigger this requirement. The EU-US Data Privacy Framework provides a pathway for US companies that have self-certified, but you must verify that your specific providers are covered.
Even small websites can face enforcement
The €1 billion headline fines make it easy to assume that GDPR enforcement only targets major corporations. That assumption is dangerous. Spain’s AEPD issues fines to small businesses almost daily, with penalties in the thousands to tens of thousands of euros for violations like sending emails without consent, failing to respond to data access requests, or operating CCTV cameras without proper signage. Poland has fined schools and municipal offices. If your website processes personal data from EU residents — and virtually every website does, through cookies, contact forms, analytics, or email signups — you are within scope. Compliance is not optional regardless of how small your audience or revenue might be.
Compliance is ongoing, not one-time
GDPR compliance is not a box you check once and forget about. Websites change constantly — new plugins are added, third-party scripts are updated, marketing tools are integrated, and staff changes affect data handling practices. The Google fine explicitly referenced the company’s failure to fix issues that had been identified in previous enforcement actions. Regulators expect continuous compliance, not point-in-time fixes. Set up regular compliance scans, monitor your cookie behavior after every site update, and review your privacy policy at least quarterly. Automated monitoring tools can catch regressions before a regulator does.
Take action
Don’t risk a fine — check your compliance
Scan your website in 30 seconds to see exactly where you stand on GDPR compliance. Find out if your cookies, consent banner, and privacy policy meet current enforcement standards.
Related Resources
Learn more about GDPR compliance.
A practical, step-by-step checklist for making your website GDPR compliant, covering cookies, consent, privacy policies, data subject rights, and more.
How manipulative design in cookie banners and consent flows violates GDPR, with real enforcement examples and guidance on compliant design.
Everything you need to know about implementing cookie consent that meets GDPR and ePrivacy requirements, including banner design and consent storage.
A plain-language explanation of the General Data Protection Regulation, who it applies to, what it requires, and why it matters for website owners everywhere.