A GDPR fine can reach €20 million or 4% of a company's global annual turnover, whichever is higher, but that ceiling only applies to the most serious violations, and most enforcement actions land well below it. Cumulative fines since GDPR took effect now exceed €7.1 billion, spread across more than 3,200 individual cases ranging from a few hundred euros to over a billion. Below: the actual two-tier fine structure, what regulators weigh before setting a number, a wider set of real fines at every scale, and answers to who can actually be fined and how the process works.
Key Takeaways
- GDPR fines run on two tiers: up to €10 million or 2% of global annual turnover for less severe violations, and up to €20 million or 4% for the most serious ones, whichever figure is higher in each tier.
- Cumulative GDPR fines have passed €7.1 billion, though the exact total depends on which tracker you check, since no single official EU-wide register exists.
- Uber holds the second-largest GDPR fine on record: €824.99 million from the Dutch DPA in August 2026, over fully automated driver-deactivation decisions. Amazon's €746 million fine, which held that position for years, was annulled by a Luxembourg court in March 2026 on procedural grounds, not because the underlying violation was found to be lawful.
- Fines aren't reserved for household names or billion-dollar companies. Regulators have issued penalties from a few hundred euros up to national retailers, telecoms, and banks in the tens of millions, well before you reach Meta or Amazon's scale.
- Any organization processing EU residents' data can be fined, regardless of where it's headquartered; individuals face a separate, much smaller penalty regime under national law, not GDPR's corporate fine structure.
- Getting fined is a multi-step process, not a single event: investigation, draft decision, a chance to respond, final decision, and then appeal to national courts, which is exactly the path that got Amazon's fine annulled.
Secure Privacy is a cookie and consent management platform built to keep the compliance gaps that trigger these fines, unlawful cookie tracking, inadequate consent records, missing legal basis, from happening in the first place.
What Are the Two Tiers of GDPR Fines?
GDPR Article 83 sets two fine tiers, and which one applies depends on which provision was violated, not how large the company is. The lower tier, up to €10 million or 2% of global annual turnover, whichever is higher, covers violations like inadequate record-keeping, failing to appoint a required Data Protection Officer, or not reporting a data breach on time. The upper tier, up to €20 million or 4% of global annual turnover, whichever is higher, covers the core principles: unlawful processing, ignoring a valid consent withdrawal, or violating a data subject's fundamental rights.
"Whichever is higher" is the detail most summaries get backwards or drop entirely. For a small company, the flat euro figure is usually the binding number. For a large multinational, 2% or 4% of global turnover can dwarf the flat cap, which is why Meta's €1.2 billion fine and Amazon's now-annulled €746 million figure were both calculated as a percentage of revenue, not the flat ceiling.
Article 83(2) lists ten factors a data protection authority has to weigh before setting the actual number within that ceiling, not just default to the maximum:
| Factor | What it covers |
|---|---|
| Nature, gravity, and duration | How severe the violation was and how long it went on |
| Intentional or negligent | Whether it was a deliberate choice or an oversight |
| Mitigating action | Steps taken to reduce harm to affected people |
| Technical and organizational measures | Whether reasonable safeguards existed beforehand |
| Prior violations | Whether the organization has been sanctioned before |
| Cooperation with the authority | Whether the organization cooperated during the investigation |
| Categories of data affected | Whether special-category or children's data was involved |
| How the authority learned of it | Self-reported versus discovered independently |
| Compliance with prior orders | Whether earlier corrective orders were followed |
| Other aggravating or mitigating factors | Financial benefit gained, or any other relevant circumstance |
This is why two violations that look similar on paper can result in very different fines. A company that self-reports, cooperates fully, and had reasonable safeguards in place going in gets weighed differently than one that didn't, even under the same Article.
Why the Penalty Scale Changed: A Before-and-After Example
GDPR's turnover-based ceiling is easiest to understand next to a real pre-GDPR case. In 2015, Hilton Hotels suffered two data breaches that exposed roughly 350,000 customers' payment card details. New York's Attorney General settled the resulting investigation in 2017 for $700,000 total, split between New York and Vermont, working out to about $2 per affected record. That penalty predates GDPR entirely; it was calculated under US state consumer-protection and breach-notification law, not anything resembling a turnover-based cap.
Run the same breach through GDPR's structure today and the number changes by orders of magnitude. A company the size of Hilton facing a serious breach and transparency failure would be assessed against its global annual turnover, not a per-record formula, putting a comparable violation in the hundreds of millions rather than hundreds of thousands. This is an illustrative estimate, not a fine any regulator has actually issued against Hilton under GDPR, but it's a useful way to see why "whichever is higher" matters: a penalty regime built around a percentage of global revenue scales with company size in a way flat per-incident fines never did.
How Much Have GDPR Fines Totaled So Far?
There's no single official EU-wide register, so the honest answer depends on which tracker you check and when. CMS's Enforcement Tracker, continuously updated and independently checkable, put the running total at €7.14 billion across 3,248 cases as of this writing. DLA Piper's January 2026 GDPR Fines and Data Breach Survey, which surveys data protection authorities directly rather than compiling published decisions, put the figure at roughly €7.1 billion as of its own January 2026 snapshot, with about €1.2 billion issued in 2025 alone.
The two figures have converged since earlier in 2026, when CMS's running total sat closer to €6.3 billion and the gap between the two trackers was wider. The remaining difference isn't a contradiction to resolve, it's a methodology difference: one counts individually documented and verified fines, the other captures some enforcement activity that authorities report but that never gets a dedicated public case file. Treat both as directionally accurate rather than reconciling them to one exact figure, and check the live tracker link below rather than trusting any hard-coded number you read elsewhere, since this total moves every month.
Where GDPR Fines Are Concentrated
Enforcement isn't spread evenly across the EU or across industries. Ireland's Data Protection Commission accounts for roughly €4.04 billion of cumulative fine value, about 57% of the EU-wide total, largely because it's the lead authority for Meta, WhatsApp, and other major US tech companies with their European headquarters there; 8 of the 10 largest GDPR fines in history were issued by Ireland's DPC. Spain's AEPD has led by case volume for seven consecutive years, issuing far more individual fines than any other authority, though typically at a much smaller scale than Ireland's or Luxembourg's.
By sector, media, telecommunications, and broadcasting, a category covering social platforms, streaming services, ISPs, and ad infrastructure, accounts for roughly €4.97 billion, close to 70% of all corporate fine value to date. That concentration reflects where the highest-value violations tend to happen: large-scale ad targeting, cross-border data transfers, and consent management at a scale where a small percentage-of-turnover fine still runs into hundreds of millions.
The pace of enforcement hasn't slowed. Around €1.2 billion in GDPR fines were issued in the most recent 12-month period, roughly level with the year before it, indicating that high-value enforcement is now a stable pattern rather than a one-time surge.
What Are the Biggest GDPR Fines Issued So Far?
Meta holds the record by a wide margin: a €1.2 billion fine from Ireland's Data Protection Commission in May 2023 over unlawful EU-to-US data transfers, separate from Meta's earlier €390 million fine over its ad-personalization consent basis. TikTok has drawn two major fines from two different authorities: €530 million from Ireland's DPC over international data transfers, and a separate €14.5 million from the UK's ICO specifically over children's data handling.
Uber now holds the second-largest GDPR fine ever issued: €824.99 million from the Dutch data protection authority (Autoriteit Persoonsgegevens) on August 21, 2026. The case centered on Uber's use of fully automated decisions, without meaningful human review, to deactivate drivers over suspected fraud or low customer ratings between 2018 and 2022. The Dutch DPA found this violated GDPR's Article 22 restriction on purely automated decisions with significant effects, and separately found Uber hadn't adequately informed drivers that the decisions were automated. The investigation reached the Dutch authority because Uber's European headquarters are in the Netherlands, putting it in the one-stop-shop mechanism's lead role after 171 French drivers first complained to a French human rights organization. Uber has said it disagrees with the fine and plans to appeal.
Amazon's case is the one worth getting right rather than repeating the old headline number. Luxembourg's CNPD fined Amazon €746 million in 2021, long cited as the second-largest GDPR fine ever issued until Uber's fine surpassed it, but Luxembourg's Administrative Court annulled Amazon's fine in March 2026. The court didn't clear Amazon of wrongdoing; it found the CNPD had skipped a required fault-analysis step before issuing the fine and sent the case back rather than upholding it as issued. The underlying finding that Amazon's legitimate-interest basis for behavioral advertising was invalid, and that its transparency notices fell short, still stands. Smaller but still significant fines have landed on Criteo (€40 million), Marriott ($125 million under the UK's post-Brexit regime), and Germany's 1&1 Telecom ($10.6 million), each covered in more depth in its own case study.
Other Major Fines Worth Knowing
A handful of other fines round out the picture of how far enforcement reaches beyond the single largest cases:
- Meta, €405 million (Ireland, September 2022). Ireland's DPC fined Meta over Instagram's handling of children's personal data, after finding the platform let under-13s create business accounts, made it easy for adults to contact children, and failed to give children adequate information about how their data was used.
- Meta, €265 million (Ireland, November 2022). A separate DPC fine over a data breach that exposed the personal information of roughly 533 million Facebook users worldwide. The DPC found Meta had both failed to implement adequate technical safeguards and failed to notify affected users of the breach in a timely way.
- WhatsApp, €225 million (Ireland, September 2021). Issued after the European Data Protection Board intervened and required Ireland's DPC to reassess an initially lower proposed fine, over transparency failures in how WhatsApp shared user data with other Meta companies without valid consent.
- British Airways, €204.6 million proposed, later reduced (UK, 2019-2020). The UK's ICO announced its intent to fine British Airways this amount after a 2018 breach exposed roughly 500,000 customers' names, addresses, login details, and full payment card information, including CVV codes. The ICO found the airline failed to secure the data adequately, failed to detect the breach for over two months, and failed to notify customers promptly. The final fine, issued in 2020 after the ICO's standard consultation process, was reduced to about £20 million, a pattern worth noting: initial proposed figures and final issued fines are often different numbers.
Smaller and Mid-Size GDPR Fines Worth Knowing
Headline billion-euro cases make the news, but most GDPR enforcement lands well below that scale, against companies of every size. This is a representative sample, not an exhaustive list:
| Company or case | Authority | Amount | What happened |
|---|---|---|---|
| Roularta Media Group | Belgian DPA | €50,000 | Using cookies without consent and no retention policy |
| Unnamed website operator | Belgian DPA | €15,000 | Cookie-consent software installed but non-functional |
| Unnamed data broker | Belgian DPA | €50,000 | Collected pregnant mothers' data without valid consent, then sold it to third parties |
| Dating website (unnamed) | Danish Datalysnet | Compliance order | Bundled consent and Terms and Conditions under one checkbox |
| Individual website owner | Romanian DPA | €150 | Published another person's personal data without a legal basis |
| Unnamed company | French CNIL | €300,000 | Failed to respond to data subject access requests |
| Unnamed company | Italian Garante | €5,000 | Unsolicited marketing calls with no legal basis, ignored access/deletion requests |
| Unnamed company | Spanish AEPD | €24,000 | Relied on implied rather than explicit consent |
| Conseguridad | Spanish AEPD | €50,000 | Failed to appoint a required Data Protection Officer |
| CaixaBank | Spanish AEPD | €2 million (final, reduced from an original €6 million) | Insufficient legal basis and inadequate transparency around data processing; the fine was cut by Spain's National Court on further appeal |
| Klarna | Swedish IMY | $733,000 (SEK 7.5 million) | Failed to give customers clear, accessible information about how personal data would be processed and shared |
| Austrian Postal Service | Austrian DPA | €13 million (final, reduced from an original €18 million) | Sold inferred political-affinity profiles on roughly 2.2 million people without consent; the fine was cut twice on appeal while the core violation was upheld |
| Vodafone Spain | Spanish AEPD | €8.15 million | Marketing calls and messages sent without consent, including to customers who had opted out |
| TikTok | Dutch DPA | €750,000 | Children's privacy policy only available in English, not Dutch, for young Dutch users |
| Glovo | Spanish AEPD | €550,000 | Inadequate handling of data subject access, rectification, and deletion requests |
| Fastweb | Italian DPA | €5.3 million | Unsolicited marketing communications and inadequate response to data rights requests |
| REWE International | Austrian DPA | €8 million | Loyalty program (jö Bonus Club) collected and used member data for marketing without valid consent |
| Free Mobile | French CNIL | €27 million | Inadequate security measures (weak VPN authentication, poor anomaly detection) that enabled a 2024 breach exposing 24 million subscriber records |
| Free (fixed-line) | French CNIL | €15 million | Same 2024 breach investigation; kept former subscribers' personal data, including IBANs, far longer than necessary |
What Actually Causes Most GDPR Fines?
Fines cluster around a handful of recurring failure types rather than being evenly spread across every possible violation:
| Violation type | What it looks like | Example |
|---|---|---|
| No valid legal basis | Processing or sharing data without consent, contract, or another Article 6 basis | Meta's €1.2 billion fine, over transferring EU user data to the US without a valid transfer mechanism |
| Inadequate security (Article 32) | Missing encryption, plaintext password storage, weak access controls | Knuddels, fined €20,000 after storing passwords in plain text |
| Transparency failures | Vague or missing privacy notices, unclear cookie disclosures | Common basis for smaller DPA enforcement actions across the EU |
| Ignoring data subject rights | Failing to honor access, deletion, or objection requests within the required timeframe | A frequent secondary finding alongside larger enforcement actions |
| Unlawful cross-border transfer | Moving EU data outside the EU without an adequate mechanism | TikTok's €530 million fine over EEA-to-China transfers |
| Children's data mishandling | Processing minors' data without appropriate safeguards or age verification | TikTok's separate €14.5 million UK ICO fine |
A GDPR fine doesn't require a headline-scale breach to land. Knuddels, a small German chat app, was fined just €20,000 in 2018 for storing user passwords in plain text after a breach, well below what its underlying security failure could have drawn under the full tier structure. The DPA cited the company's prompt breach notification and cooperation with the investigation, exactly the Article 83(2) factors covered above, as the reason the fine landed far below the maximum. It's a useful data point against the assumption that only billion-euro companies actually get fined.
Who Can Actually Be Fined Under GDPR?
Any organization that processes personal data belonging to people in the EU can be fined, regardless of where that organization is headquartered. GDPR's territorial scope reaches beyond the EU's borders whenever a company offers goods or services to EU residents or monitors their behavior, so "we're not based in Europe" isn't itself a defense.
Individuals aren't fined under GDPR's corporate penalty structure at all. A company's employees, executives, or a Data Protection Officer can face personal liability in some member states, but that comes from national implementing law or separate criminal statutes, not GDPR's own Article 83 fine mechanism, which is aimed at the organization as a data controller or processor.
There's no fixed minimum fine either. Enforcement actions have landed in the low hundreds of euros for narrow, low-impact violations, all the way up to the billion-euro figures above. The ten-factor weighing process in Article 83(2) applies at every scale, not just to headline-making cases.
What Does the Fining Process Actually Look Like?
A GDPR fine doesn't happen in a single step, and understanding the sequence matters as much as knowing the ceiling.
It typically starts with an investigation, triggered by a complaint, a data breach notification, or a data protection authority's own audit activity. One detail organizations underestimate: an investigation that starts from a single complaint about a single practice often doesn't stay narrow. Authorities investigating one reported issue commonly review an organization's broader data processing along the way, which means one complaint can surface violations well beyond what was originally reported.
If the violation can still be fixed at this stage, it sometimes can be. At least one national authority's own guidance (Austria's DPA, in a documented decision) has treated bringing practices into compliance before the process concludes as a mitigating step, though this isn't a guaranteed escape route and depends heavily on the specifics of the case and the authority involved.
If the authority finds a violation, it issues a draft decision, which under the GDPR's cooperation mechanism can involve other EU authorities if the case crosses borders. The organization can respond and contest findings before a final decision and fine amount are issued. After that, the organization can appeal to national courts, which is exactly the path that led to Amazon's fine being annulled rather than the CNPD's underlying findings being reinstated automatically, and the same path that cut the Austrian Postal Service's and CaixaBank's fines described above. In rare cases, affected individuals can also pursue separate civil claims for damages, independent of the regulatory fine itself, if they suffered concrete harm from the violation.
Building compliance in ahead of an investigation is the only point in that timeline where the outcome is still fully in an organization's control. A consent management platform that keeps a verifiable, timestamped record of what consent was actually given, and blocks tracking until it is, addresses the single most common trigger across the enforcement actions cited above: processing that outran its actual legal basis. Secure Privacy logs every consent decision with a timestamp specifically so that record exists before a regulator ever asks for one, not after.
For a broader, forward-looking view of where enforcement is trending by sector and authority, this site's own quarterly enforcement heat map tracks that separately from the historical fines covered here.
FAQ
What are the two tiers of GDPR fines?
The lower tier reaches €10 million or 2% of global annual turnover, whichever is higher, for violations like inadequate records or late breach reporting. The upper tier reaches €20 million or 4%, whichever is higher, for violations of GDPR's core principles like unlawful processing or ignoring data subject rights.
How much have GDPR fines totaled in total?
Around €7.1 billion across roughly 3,250 documented cases as of this writing, per CMS's continuously updated Enforcement Tracker. DLA Piper's independent, survey-based January 2026 estimate lands at a similar figure; the two trackers use different counting methods, not different facts.
What is the biggest GDPR fine ever issued?
Meta's €1.2 billion fine from Ireland's Data Protection Commission in May 2023, over unlawful EU-to-US data transfers. It remains the largest GDPR fine on record.
Is Amazon's €746 million fine still valid?
No, not as originally issued. Luxembourg's Administrative Court annulled it in March 2026 over a procedural error in how the fine was calculated, though the underlying finding of a GDPR violation wasn't overturned. The case was sent back rather than resolved outright.
What's the second-largest GDPR fine ever issued?
Uber's €824.99 million fine from the Dutch DPA in August 2026, over fully automated decisions that deactivated drivers without meaningful human review. It took the position previously held by Amazon's now-annulled €746 million fine.
Can a business outside the EU be fined under GDPR?
Yes. GDPR applies to any organization that offers goods or services to people in the EU or monitors their behavior, regardless of where that organization is based.
Can a small business actually get fined under GDPR?
Yes. Knuddels, a small German chat app, was fined €20,000 in 2018 for storing passwords in plain text after a breach, well below the billion-euro figures that dominate headlines. Fine size scales with the violation and the company's response, not just company size.
What's the most common cause of a GDPR fine?
Missing legal basis for processing (including unlawful cross-border transfers) and inadequate security measures under Article 32 account for most major enforcement actions, from Meta's transfer-basis fine to Knuddels' plaintext-password fine.
Is there a minimum GDPR fine?
No fixed minimum exists. Fines have ranged from a few hundred euros for narrow violations, like the Romanian DPA's €150 penalty against an individual, to over a billion euros for the most serious cases, with the actual number set case by case under Article 83(2)'s ten weighing factors.
Sources
- Article 83 GDPR, General conditions for imposing administrative fines
- CMS Enforcement Tracker, live cumulative fines and case count
- DLA Piper GDPR Fines and Data Breach Survey, January 2026
- Knuddels GDPR fine, LfDI Baden-Württemberg, 2018
- New York Attorney General, 2017 Hilton data breach settlement announcement
- Luxembourg Administrative Court, Amazon CNPD case annulment, March 2026
- Ireland Data Protection Commission decisions, Meta and WhatsApp fines
- UK Information Commissioner's Office, British Airways fine
- Dutch Data Protection Authority, TikTok children's privacy decision
- Austrian Data Protection Authority and Federal Administrative Court, Austrian Postal Service case
- Spanish AEPD and National Court, CaixaBank case



