Enforcement

GDPR Fines: The Biggest Penalties and What They Mean for You

Since 2018, European data protection authorities have issued more than €7.1 billion in GDPR fines. Enforcement is accelerating every year, with €1.2 billion in penalties issued in 2025 alone. No business is too big or too small to be targeted. Here is a complete breakdown of the largest fines, the most recent enforcement actions, and what they mean for anyone who runs a website.

The big picture

GDPR Enforcement at a Glance

Seven years of the General Data Protection Regulation have transformed data privacy enforcement across Europe and beyond. The numbers tell the story.

€7.1B+
Total fines issued since May 2018
2,800+
Individual enforcement actions recorded
€1.2B
Fines issued in 2025 alone
400+
Daily breach notifications in 2025

The General Data Protection Regulation, which took effect on May 25, 2018, gave European data protection authorities the power to issue substantial financial penalties for violations. Under GDPR, fines can reach up to €20 million or 4% of a company’s global annual turnover, whichever is higher. For less severe violations, the cap is €10 million or 2% of global annual turnover.

In the first two years, enforcement was relatively cautious as regulators established precedents and companies adapted to the new framework. Since 2021, however, fines have increased dramatically in both frequency and scale. More than 60% of all GDPR fines — over €3.8 billion — have been imposed since January 2023, reflecting a decisive shift toward aggressive enforcement.

Eight of the ten largest GDPR fines ever imposed have been levied against US-based companies, including Meta, Amazon, Google, and TikTok’s parent company ByteDance. Together, these fines total approximately €3.9 billion, representing nearly 63% of the entire fine total. However, European companies, SMBs, and public-sector organizations are increasingly in the crosshairs as well. Spain’s Data Protection Authority alone has issued more than 930 individual fines, many targeting small and medium-sized businesses.

For the first time since GDPR came into force, data protection authorities recorded an average of more than 400 personal data breach notifications per day between late January 2025 and January 2026 — a 22% year-on-year increase. This surge reflects both the growing scale of data processing and the increasing willingness of organizations to report breaches under GDPR’s mandatory 72-hour notification requirement.

All-time record

Top 10 Largest GDPR Fines Ever

The ten biggest financial penalties imposed under the GDPR since its inception. Data current through February 2026, sourced from the EDPB, GDPR Enforcement Tracker, and individual DPA decisions.

Rank Company Fine Amount Country / DPA Year Reason
1 Meta (Facebook) €1.2 billion Ireland — DPC 2023 Unlawful transfer of EU user data to the United States using Standard Contractual Clauses without adequate safeguards against US government surveillance.
2 Amazon Europe €746 million Luxembourg — CNPD 2021 Processing personal data for targeted advertising without valid consent. Users were not given adequate means to opt out of behavioral tracking.
3 TikTok (ByteDance) €530 million Ireland — DPC 2025 Transferring EU user data to servers in China despite assurances that no European data was stored there. Chinese law deemed insufficient to protect EU data.
4 Meta (Spain ruling) €479 million Spain — Commercial Court of Madrid 2025 Unlawful data processing gave Meta unfair competitive advantage in the advertising market. Damages awarded to 87 Spanish media publishers.
5 Meta (Instagram) €405 million Ireland — DPC 2022 Wrongfully processing children’s personal data, including publicly exposing email addresses and phone numbers of minors using business accounts.
6 Meta (Facebook & Instagram) €390 million Ireland — DPC 2023 Using “contract necessity” as a false legal basis for behavioral advertising data processing. Facebook fined €210M, Instagram €180M.
7 Google LLC (Gmail) €200 million France — CNIL 2025 Inserting advertisements disguised as emails into Gmail inboxes without user consent. Dark patterns made refusing advertising cookies harder than accepting them.
8 WhatsApp Ireland €225 million Ireland — DPC 2021 Failure to meet transparency obligations under GDPR. Users were not adequately informed about how their data was shared with other Meta companies.
9 SHEIN (Infinite Styles) €150 million France — CNIL 2025 Placing advertising cookies on user devices before consent was obtained. Non-functional opt-out mechanisms and misleading cookie banners on shein.com.
10 Google (Cookie Consent) €150 million France — CNIL 2021 Failing to provide users an easy way to refuse cookies. Accepting cookies required one click; rejecting them required multiple clicks across several screens.

2025 enforcement

Notable GDPR Fines and Actions in 2025

2025 saw regulators across Europe issue more than €1.2 billion in GDPR penalties. Here are the most significant enforcement actions of the year and what made each case important.

€530M Ireland — DPC

TikTok — Illegal Data Transfers to China

Ireland’s Data Protection Commission fined TikTok’s parent company ByteDance €530 million in May 2025 for transferring EU user data to servers in China. TikTok had assured the DPC that no European users’ data was stored in China, but the regulator found this to be incorrect. An assessment of Chinese data protection law determined it does not provide an equivalent level of protection to GDPR. This is the third-largest GDPR fine ever issued and the largest of 2025. TikTok has lodged a full appeal against the decision.

€479M Spain — Madrid Court

Meta — Unfair Competition via GDPR Violations

In November 2025, the Commercial Court of Madrid ordered Meta to pay €479 million in damages to 87 Spanish digital publishers. The court found that between May 2018 and August 2023, Meta processed Facebook and Instagram user data under an improper legal basis — claiming “contract necessity” rather than obtaining user consent. This gave Meta an unfair competitive advantage in the online advertising market, drawing ad revenue away from publishers who could not access equivalent personal data. This landmark ruling establishes a precedent for competitors to claim financial damages resulting from GDPR violations.

€325M France — CNIL

Google — Gmail Ads and Cookie Dark Patterns

In September 2025, France’s CNIL imposed a combined €325 million fine on Google: €200 million on Google LLC and €125 million on Google Ireland. The investigation, triggered by a complaint from the advocacy group NOYB, found that Google inserted advertisements between emails in Gmail users’ inbox tabs without consent — a practice the CNIL classified as unsolicited direct marketing. Additionally, the Google account creation process used dark patterns that required six clicks to refuse advertising cookies but only two clicks to accept them, affecting over 74 million French accounts. The CNIL cited Google’s prior fines in 2020 and 2021 as aggravating factors.

€150M France — CNIL

SHEIN — Cookies Before Consent

Also in September 2025, the CNIL fined SHEIN’s Irish subsidiary €150 million for placing advertising cookies on users’ devices before any consent was obtained on shein.com. The investigation found that SHEIN provided incomplete and misleading information in its cookie banners, failed to clearly identify third-party cookies, and made it difficult for users to refuse or withdraw consent. The CNIL treated each user visit where cookies were placed without consent as a separate violation, significantly amplifying the scale of the penalty. This case reinforced that e-commerce companies face the same scrutiny as big tech platforms.

€7.4M Poland — UODO

Poczta Polska — Election Data Processing

Poland’s data protection authority UODO fined the state-run postal service Poczta Polska 27 million PLN (approximately €7.4 million) for unlawfully processing personal data during the 2020 pandemic elections. The Ministry of Digital Affairs had provided personally identifiable information on all eligible voters to the postal service without a valid legal basis. This case demonstrates that public-sector organizations are subject to the same GDPR enforcement as private companies, and that data processing decisions made during emergencies do not receive automatic exemptions from privacy law.

€5M Italy — Garante

Luka Inc. — AI Company Privacy Violations

Italy’s Garante demanded a €5 million fine from US-based AI company Luka for collecting and processing personal and behavioral information without obtaining proper consent. The Garante also found that Luka’s privacy notices were too opaque for users to understand what data was being collected and how it was used. This fine signals that AI companies face growing GDPR scrutiny, and that the collection of behavioral data for AI training purposes requires the same level of transparency and consent as any other form of data processing.

€4.4M Poland — UODO

ING Bank — Unlawful Identity Scanning

Poland’s UODO imposed a €4.375 million fine on ING Bank for unlawfully processing personal data collected from identity document scans. Between April 2019 and September 2020, the bank scanned customers’ and potential customers’ identity documents without verifying whether the scans were justified under Anti-Money Laundering regulations. The case underscores that financial institutions cannot rely on AML compliance as a blanket justification for collecting and retaining sensitive identity data. The purpose limitation principle still applies, and each processing activity must be individually assessed.

€3.9M Poland — UODO

McDonald’s Polska — Employee Data Breach

Poland’s UODO fined McDonald’s Polska approximately €3.9 million after a misconfigured server exposed sensitive employee data, including PESEL numbers (national identification numbers), passport numbers, and work shift details. The fine was imposed for inadequate technical and organizational measures to prevent the breach, as required under GDPR Article 32. This case is a reminder that GDPR does not only apply to customer-facing data collection. Employee data processing carries the same obligations, and data security failures affecting internal systems are subject to the same enforcement standards.

Practical takeaways

What This Means for Website Owners

You do not need a €1 billion budget or a team of lawyers to comply with GDPR. But you do need to get the basics right. Here are the concrete steps every website owner should take based on current enforcement priorities.

Your cookie banner must offer real choice

The Google and SHEIN fines prove that having a cookie banner is not enough. It must provide equally prominent accept and reject options, without dark patterns. Users must be able to refuse all non-essential cookies in the same number of clicks it takes to accept them. Pre-checked boxes, hidden reject buttons, confusing language, and “legitimate interest” workarounds for advertising cookies are all enforcement targets. Test your banner from the perspective of a first-time visitor who wants to decline everything. If that process is harder than accepting, you have a compliance gap.

Your privacy policy must be accurate and complete

GDPR Articles 13 and 14 require specific disclosures in your privacy policy: the identity of the data controller, purposes and legal bases for processing, categories of data collected, retention periods, third-party sharing, international transfers, and data subject rights. Missing sections are a common finding in enforcement actions, and “opaque” privacy notices were explicitly cited in the Luka Inc. fine. Your privacy policy must reflect what your website actually does with data, not what a template says. If you add a new analytics tool or change a third-party provider, your privacy policy must be updated to match.

Consent must come before tracking

This is the single most important compliance requirement and the one most frequently violated. No analytics cookies, advertising pixels, social media widgets, or third-party tracking scripts should fire on your website before a user has actively given consent. This is what the SHEIN fine was about: cookies placed before the consent banner even appeared. It is what the Google fine was about: advertising delivered without user permission. If your website loads Google Analytics, Meta Pixel, TikTok Pixel, or any similar tool on page load without waiting for consent, you are committing the same violation that led to hundreds of millions in fines.

International data transfers need a valid mechanism

The two largest GDPR fines ever — Meta’s €1.2 billion and TikTok’s €530 million — both concerned unlawful transfers of EU personal data to countries outside the European Economic Area. If your website sends user data to servers in the United States, China, or any other country without an EU adequacy decision, you need a valid transfer mechanism in place, such as Standard Contractual Clauses or Binding Corporate Rules, supplemented by a Transfer Impact Assessment. Simply using a US-based analytics provider or cloud hosting service can trigger this requirement. The EU-US Data Privacy Framework provides a pathway for US companies that have self-certified, but you must verify that your specific providers are covered.

Even small websites can face enforcement

The €1 billion headline fines make it easy to assume that GDPR enforcement only targets major corporations. That assumption is dangerous. Spain’s AEPD issues fines to small businesses almost daily, with penalties in the thousands to tens of thousands of euros for violations like sending emails without consent, failing to respond to data access requests, or operating CCTV cameras without proper signage. Poland has fined schools and municipal offices. If your website processes personal data from EU residents — and virtually every website does, through cookies, contact forms, analytics, or email signups — you are within scope. Compliance is not optional regardless of how small your audience or revenue might be.

Compliance is ongoing, not one-time

GDPR compliance is not a box you check once and forget about. Websites change constantly — new plugins are added, third-party scripts are updated, marketing tools are integrated, and staff changes affect data handling practices. The Google fine explicitly referenced the company’s failure to fix issues that had been identified in previous enforcement actions. Regulators expect continuous compliance, not point-in-time fixes. Set up regular compliance scans, monitor your cookie behavior after every site update, and review your privacy policy at least quarterly. Automated monitoring tools can catch regressions before a regulator does.

Take action

Don’t risk a fine — check your compliance

Scan your website in 30 seconds to see exactly where you stand on GDPR compliance. Find out if your cookies, consent banner, and privacy policy meet current enforcement standards.

Related Resources

Learn more about GDPR compliance.

GDPR Compliance Checklist

A practical, step-by-step checklist for making your website GDPR compliant, covering cookies, consent, privacy policies, data subject rights, and more.

Dark Patterns and GDPR

How manipulative design in cookie banners and consent flows violates GDPR, with real enforcement examples and guidance on compliant design.

GDPR Cookie Consent Guide

Everything you need to know about implementing cookie consent that meets GDPR and ePrivacy requirements, including banner design and consent storage.

What Is GDPR?

A plain-language explanation of the General Data Protection Regulation, who it applies to, what it requires, and why it matters for website owners everywhere.