GDPR Fines in 2026: Lessons From Recent Enforcement Actions

GDPR Fines in 2026: Lessons From Recent Enforcement Actions

Every “biggest GDPR fines” roundup gives you the same five headline numbers and stops there. What it usually skips is more useful: which regulator actually collected the money, which of those cases are quietly stuck in appeal years later, what the underlying operational failure was, and whether that failure has a direct analogue inside your own stack. This guide works through all four, using the enforcement record through mid-2026.

GDPR Fines

QUICK ANSWER – GDPR fines are issued under Article 83 across two tiers: up to €10 million or 2% of global turnover for procedural failures (missing records, weak DPIAs, poor cooperation), and up to €20 million or 4% for substantive violations (unlawful processing, ignoring data subject rights, unsafe international transfers) — whichever figure is higher. Cumulative fines have passed roughly €7.4 billion since May 2018, over 60% of it issued since January 2023. Enforcement is accelerating, spreading well beyond Big Tech, and starting to overlap with the EU AI Act, which begins enforcing high-risk system rules on 2 August 2026.

GDPR Fines What Each Tier Actually Covers

GDPR Fines Article 83 sets two ceilings, and which one applies depends on what broke — not how big the company is. Regulators classify the violation first, then work down from the applicable ceiling using ten factors set out in Article 83(2): the nature, gravity and duration of the infringement; whether it was intentional or negligent; what mitigating action the company took; the degree of responsibility; any relevant prior infringements; the level of cooperation with the authority; the categories of data involved; how the authority learned of the breach; compliance with any prior corrective orders; and any other aggravating or mitigating circumstance specific to the case.

The EDPB’s Guidelines 04/2022, adopted to harmonize this process across all 27 member states plus the EEA, turn that list into a five-step calculation. Regulators first identify whether the conduct falls into the lower or upper tier — security failures typically land in Tier 1, while unlawful processing or ignoring data-subject rights lands in Tier 2. Second, they set a starting amount based on gravity, using indicative bands of roughly 0–10% of the maximum for low-gravity conduct, 10–20% for medium gravity, and 20–100% for high-gravity conduct. Third, that starting figure is adjusted up or down for the aggravating and mitigating factors above — self-reporting before a regulator discovers the issue, a documented DPIA completed in advance, and active cooperation during the investigation are the three mitigations that show up most often in published decisions as actually moving the number. Fourth, the adjusted figure is checked against the hard statutory ceiling. Fifth, and easy to forget, the authority has to confirm the resulting fine is still effective, proportionate, and dissuasive for that specific organization — the mechanism that keeps a small business from being fined into bankruptcy for the same conduct that costs a multinational a rounding error.

A 2023 EU court ruling — the Volkswagen case, C-807/21 — confirmed that the turnover used for the percentage cap is the whole corporate group’s, not just the fined subsidiary’s. In practice, that means a small SaaS entity owned by a large parent inherits its parent’s exposure: a modest subsidiary sitting inside a €10 billion group faces a 4% cap of €400 million, not 4% of its own comparatively tiny revenue. If your company has been acquired, was spun out of a larger group, or is raising money from a strategic investor, this is worth flagging to whoever owns your compliance budget — the ceiling you’re actually exposed to may have quietly changed.

Article 83(3) adds one piece of relief: when a single course of conduct violates multiple provisions, the total fine is capped at the highest single applicable maximum rather than being stacked article by article. A processing activity that breaches both Article 5 (principles, €20M cap) and Article 32 (security, €10M cap) is capped at €20 million total, not €30 million.

✎ COMMON TRAP – Treating €20M / €10M as “the fine.” They’re statutory ceilings, not typical outcomes. Most published fines across Europe sit well under €100,000 — the mega-fines dominate headlines and skew the average, not the median. A more useful planning number than “the average fine” is a scenario built from your own turnover, your sector’s typical gravity band, and whether your documentation would read as cooperative or evasive to an investigator on day one.

GDPR Fines & 2025–2026 Case Register

The amounts matter less than the pattern behind each one. Every case below has a direct, checkable analogue inside most companies handling EU personal data.

Notable GDPR Enforcement Cases
Case Amount Root Cause Status (mid-2026)
Meta (transfers) €1.2B Unlawful EU–US transfers, Art. 44 Under appeal
Meta (consent→contract) €390M Legal-basis switch w/o re-consent Issued, 2025
TikTok €530M Cross-border transfer safeguards Issued, 2025
LinkedIn €310M "Contract necessity" for ad targeting Issued
Amazon Europe €746M Ad-targeting processing, Art. 6 Annulled on procedure, Mar 2026*
Criteo €40M Pre-ticked / bundled consent Upheld on appeal, Mar 2026
Vodafone Germany €45M Vendor security failures, Art. 32 Issued
IQVIA Operations France €5M Health-data warehouse safeguards Issued, May 2026
Free Mobile €27M Inadequate security controls Issued, 2026
Reddit (UK ICO) £14.5M Age-verification gaps Issued, 2026
Kaspr €200K Profile scraping w/o consent Issued, 2026

Five Cases Worth Reading Past the Headline

Meta — the transfer fine that set the ceiling.

Ireland’s DPC found that Meta kept transferring EU users’ data to the US using Standard Contractual Clauses that no longer offered adequate protection after the Schrems II ruling, without the supplementary safeguards that ruling required. At €1.2 billion, it remains the largest GDPR fine ever issued, and it now functions as the reference point every regulator in Ireland, France, Italy, and Germany cites when calibrating a comparable transfer case. It is also still under appeal, with Meta describing it as unjustified and payment suspended pending the outcome — a reminder that the largest number on any list is often the least final.

LinkedIn and the second Meta case — the legal-basis switch.

Two of the largest 2024–2025 fines share the same root cause: claiming that behavioral advertising was “necessary for the performance of a contract” when the underlying service didn’t actually require it. LinkedIn’s €310 million fine and Meta’s separate €390 million fine for shifting its ad-targeting basis from consent to contract without clearly re-informing users both establish the same principle — you cannot swap the legal basis for existing processing mid-stream without going back for fresh, informed consent. Any product team that has ever quietly changed how a privacy notice describes a data use, without changing the consent flow to match, is running the same risk.

TikTok — transfers, again.

TikTok’s €530 million fine, the single largest issued in 2025, again centers on cross-border transfer safeguards. Combined with Meta and Amazon, transfer violations under Article 44–46 account for a disproportionate share of total euro value across the entire enforcement record — even though, by sheer count, transfer cases are a minority of all published fines. If your organization moves any EU personal data to US-based infrastructure, ad networks, analytics tools, or support platforms, this is the single highest-value category to get right.

Amazon — a fine that shows why appeals matter.

Amazon Europe’s €746 million fine, once the second-largest on record, was annulled by Luxembourg’s Administrative Court in March 2026 — but only on procedural grounds. The court explicitly upheld most of the underlying findings and sent the case back to the CNPD to reissue a corrected decision. The lesson isn’t that the fine “went away”: the compliance failure it documented is still on the record, and a revised penalty is still pending.

Kaspr — the small fine with an outsized message.

At just €200,000, Kaspr’s fine for scraping professional profiles and building contact databases without consent is the smallest figure in this register — and arguably the most relevant one for an ordinary mid-market company. It confirms that “the data was publicly available” is not a defense, and that data-enrichment, lead-generation, and outbound-sales tooling built on scraped profiles now sit squarely inside the enforcement perimeter.

✎ WORTH REMEMBERING – A quick AI-generated summary will give you the Meta and TikTok headlines. It won’t tell you that a €200,000 fine against a small scraping vendor is arguably more predictive of your own risk — because it’s replicable against thousands of ordinary companies running a similar playbook, not just the handful of platforms with EU–US transfer exposure.

Enforcement by Country: Who's Actually Fining

GDPR is one regulation, but it is enforced by 27 national authorities plus the UK’s ICO, and their enforcement styles differ enough to matter for where you should expect scrutiny to come from.

Ireland — low volume, dominant value. The Data Protection Commission is lead supervisory authority for most large US tech platforms with an EU base in Dublin, which is why Ireland accounts for 9 of the top 10 fines by euro value despite issuing relatively few decisions overall. Ireland’s enforcement is concentrated, slow-moving, and heavily litigated — most of its largest fines are still under appeal years after being issued. 

Spain — high volume, modest value. The AEPD has issued more published fines than any other European regulator — over a thousand since 2018 — but the average penalty is small, often in the low thousands of euros, spread across consumer-facing businesses of every size.

Germany — fragmented but consistent. Enforcement is split across 16 state-level authorities plus the federal BfDI, which produces hundreds of smaller decisions alongside a handful of headline cases, such as Hamburg’s €35.3 million fine against H&M for systematic employee-monitoring practices.

Italy — high volume and increasingly high value. The Garante is one of the most active regulators in Europe, with a particular focus on telecoms, employment data, and — new for 2026 — some of the first AI-specific GDPR enforcement actions in the EU, treating model training data and chatbot personalization under the same lawful-basis lens it has long applied to ad tech.

United Kingdom — smaller totals, same logic. Enforcement under UK GDPR through the ICO produces cumulative fines in the tens of millions rather than billions, with British Airways’ £20 million fine (reduced from an initial £183 million threat after mitigation and cooperation) still the largest on record.

How Enforcement Got Here

Three forces are driving the acceleration: regulators built up institutional expertise and staffing after years of learning the ropes, the European Data Protection Board has run Coordinated Enforcement Framework sweeps since 2023 (2026’s focus is transparency and information obligations), and a backlog of long-ignored violations is finally reaching enforcement. None of that is expected to ease before the AI Act’s high-risk provisions add a second penalty layer — up to €35 million or 7% of global turnover — on top of existing GDPR exposure in August 2026.

What's Actually Triggering GDPR Fines

Four categories account for roughly 94% of all enforcement action. Unlawful processing dominates by count; general-principle failures dominate the largest individual fines.

GDPR Fines

The SME Myth

GDPR Fines A persistent assumption inside smaller companies is that GDPR enforcement is a Big Tech problem — that regulators are busy chasing platforms with billions of users and have neither the time nor the incentive to pursue a 40-person SaaS company. The enforcement record doesn’t support that. Spain’s AEPD alone has issued over a thousand fines, the overwhelming majority against organizations with nothing like Meta’s or TikTok’s scale — regional service providers, local retailers, small marketing agencies, even municipal governments and public utilities. Educational institutions and publicly owned bodies are showing up in enforcement data more often than they did in GDPR’s early years, a shift from the private-sector focus of 2018–2021.

The reason this matters practically: proportionality doesn’t mean exemption. Article 83(2)’s proportionality requirement is why a small company’s Article 6 violation results in a fine in the thousands or tens of thousands of euros rather than millions — but that fine is still real, still public, and still shows up in due-diligence checks from enterprise customers and investors. Smaller organizations get proportional severity, not a pass.

The Appeals Reality Most Coverage Skips

A headline GDPR fine and a collected fine are two very different things. Ireland’s DPC has imposed roughly €4.04 billion since 2018 — but only around €20 million, about 0.5%, has actually been paid. The rest sits suspended, under appeal, or moving through years of litigation, and nearly every mega-fine on record is being actively contested. Meta’s €1.2 billion fine remains under appeal, with Meta disputing it publicly as unjustified. Amazon’s €746 million fine was annulled on procedure in March 2026, with the underlying violations sent back for a corrected decision. A March 2026 OpenAI fine of €15 million was also annulled. Criteo’s €40 million fine, by contrast, was upheld on appeal in the same month — a reminder that appeal outcomes are decided case by case, not by a general pattern of leniency.

The practical takeaway isn’t “fines don’t matter” — a fine functions as a public finding of fact and a compliance roadmap for regulators and competitors alike, whether or not a check is ever cashed. The underlying legal finding usually survives even when the number doesn’t, which is why treating an appealed fine as a closed, low-priority matter is the more common mistake than assuming it’s a certainty.

What Changes in the Second Half of 2026

On the calendar – 2 August 2026 — the EU AI Act’s high-risk system obligations become enforceable, with penalties up to €35 million or 7% of global turnover. Regulators, especially Italy’s Garante, are already folding AI processing into existing GDPR lawful-basis enforcement. December 2025 (already in effect) — the European Commission issued its first Digital Services Act fine, €120 million against X, covering deceptive verification design, an inadequate ad repository, and researcher access failures. Ad tech and platform companies now sit inside two enforcement regimes — GDPR and the DSA — that don’t always coordinate with each other, which means a single practice can draw scrutiny, and separate penalties, from two different directions. Ongoing — the EDPB’s 2026 Coordinated Enforcement Framework sweep is examining transparency and information obligations across the EEA. If cookie banners, privacy notices, or consent flows haven’t been tested against dark-pattern criteria recently, this is the sweep that will find it.

None of this is exotic. The cases defining the first half of 2026 — a security lapse at Free Mobile, an age-verification gap at Reddit, unconsented scraping at Kaspr — describe failure modes with a direct analogue inside most organizations that process EU personal data, not edge cases unique to platforms the size of Meta or TikTok.

Where Companies Get This Wrong

  • Treating a legal-basis change as a copy edit. Swapping “consent” for “contractual necessity” in a privacy notice, without re-running consent, is the exact pattern behind the LinkedIn and Meta ad-targeting fines — it looks like a documentation update but is legally a fresh processing decision.
  • Assuming publicly available data is fair game. Kaspr’s fine confirms that scraping public profiles to build a contact database still requires a lawful basis; “it was already public” is not a defense under Article 6.
  • Stopping security review at your own infrastructure. Vodafone Germany’s €45 million fine and several 2026 actions trace back to vendor and subprocessor failures, not the fined company’s own systems — Article 32 liability doesn’t end at your API boundary.
  • Reusing old Standard Contractual Clauses without supplementary measures. Transfer violations remain the single highest-value enforcement trigger; SCCs signed before Schrems II guidance, without a documented transfer impact assessment, are a known gap regulators actively look for.
  • Building one consent flow and hoping it covers every jurisdiction. A single global cookie banner rarely satisfies both GDPR’s opt-in standard and the different disclosure requirements now spreading across other jurisdictions — it tends to either annoy EU users with unnecessary friction or under-protect everyone else.
  • Treating an appealed fine as resolved. As covered above, an annulment on procedural grounds is not the same as a finding that the company did nothing wrong — the compliance gap the case identified is still real and still worth fixing.

Building a Defensible Compliance Program

The organizations that stay out of this register share a few habits that go beyond having a privacy policy on file. Documentation has to be contemporaneous — a lawful-basis assessment or DPIA written after a regulator’s letter arrives reads very differently to an investigator than one dated before processing began, and the EDPB’s own gravity-scoring rewards demonstrable advance planning over after-the-fact justification. Consent and cookie tooling needs periodic, not one-time, testing against current dark-pattern criteria, since the criteria regulators apply have visibly tightened year over year. Vendor and subprocessor security reviews need to be a standing part of procurement, not a one-time checkbox at signature, given how often 2026’s fines trace to a vendor’s failure rather than the fined company’s own systems. And any AI feature that touches personal data — model training, personalization, chatbot memory — now needs a lawful-basis review against both current GDPR enforcement patterns and the AI Act’s incoming high-risk requirements, ideally before the feature ships rather than after the first complaint.

A Practical Checklist

☐  Document the lawful basis for every processing activity before data collection starts, not retroactively.

☐  Test consent flows for dark patterns: pre-ticked boxes, bundled consent, or cookie walls.

☐  Re-verify international transfer mechanisms — outdated SCCs without supplementary measures remain the top enforcement trigger.

☐  Extend Article 32 security review to vendors and subprocessors, not just your own systems.

☐  Map every AI feature touching personal data against GDPR lawful-basis rules and the incoming AI Act.

☐  Keep contemporaneous DPIA and records-of-processing documentation — it can’t be recreated convincingly after the fact.

☐  Don’t assume small size is a shield — group turnover, not just your entity’s, can set your fine cap.

☐  Re-test cookie banners and consent flows against current dark-pattern criteria, not the standard that was acceptable two years ago.

☐  If your company was recently acquired or restructured, confirm which group turnover figure now sets your Article 83 percentage cap.

Official Sources & Further Reading

FAQs

What's the actual maximum GDPR fine?

€20 million or 4% of total worldwide group turnover, whichever is higher, for the most serious violations. A lower tier caps procedural failures at €10 million or 2%. Actual fines are calculated against ten Article 83(2) factors, and most published fines are far smaller.

No. GDPR Fines applies extraterritorially to any organization processing EU residents’ personal data, regardless of where the company is headquartered.

Yes, functionally. The underlying legal finding typically survives appeal even when the amount is reduced, annulled on procedure, or suspended for years.

Both. Spain’s AEPD alone has issued over a thousand fines, most against organizations far smaller than Meta or TikTok. Enforcement scales proportionally but does not exempt smaller organizations.

From 2 August 2026, high-risk AI systems face a separate penalty regime (up to €35M or 7% of turnover) layered on top of GDPR exposure. Regulators are already assessing AI training data and personalization under existing GDPR rules ahead of that date.

Unlawful processing under Article 6 accounts for the largest share of fines by count, and cross-border transfer violations drive the highest individual amounts — so a documented lawful basis for every processing activity, paired with a current review of your transfer mechanisms, addresses the two highest-probability and highest-severity categories at once.

Yes, in coordinated cases. The EDPB coordinates cross-border investigations, and a single practice — particularly in ad tech — can now also trigger a separate Digital Services Act fine on top of a GDPR one, as the €120 million DSA fine against X in December 2025 illustrated.

What do you think?