A guide for businesses to the enforcement architecture of the GDPR, the principal legal bases for administrative fines, the dominant themes in enforcement since the Regulation entered into application, and a summary of the twenty largest fines on record.

I. Introduction: Seven Years of Enforcement

The General Data Protection Regulation entered into application on 25 May 2018, introducing what was at the time the most demanding personal data protection framework in the world. The GDPR introduced a new penalty architecture that represented a fundamental departure from the modest fines that had characterised enforcement under its predecessor: supervisory authorities were authorised to impose fines of up to €20 million, or 4% of total worldwide annual turnover, whichever was higher.

In the years since May 2018, GDPR enforcement has moved through distinct phases. The first phase was characterised by a relatively limited number of fines as supervisory authorities built their capacity. The second phase, from 2021 onwards, saw a dramatic escalation in both the number and the scale of fines. By March 2025, the CMS GDPR Enforcement Tracker had recorded over 2,500 fines totalling more than €6 billion.

II. The Enforcement Framework — Articles 58 and 83

The GDPR’s enforcement framework is principally governed by two provisions: Article 58, which sets out the investigative and corrective powers available to each national supervisory authority, and Article 83, which establishes the conditions under which administrative fines may be imposed.

Under Article 58, supervisory authorities possess a broad toolkit for addressing non-compliance. The corrective powers in Article 58(2) escalate from the relatively mild to the potentially existential: authorities may issue warnings, reprimands, orders to comply, temporary or permanent bans on processing, requirements to erase data, and administrative fines under Article 83.

III. The Two-Tier Fine Structure Under Article 83

Article 83 of the GDPR establishes two distinct fine tiers.

Article 83(4) — Lower Tier (up to €10m or 2% of global annual turnover): Applies to infringements of controller and processor obligations including conditions for consent (Article 7), data protection by design and default (Article 25), processing under the controller-processor relationship (Article 28), records of processing (Article 30), security of processing (Article 32), data breach notification (Articles 33-34), and DPO obligations (Articles 37-39).

Article 83(5) — Upper Tier (up to €20m or 4% of global annual turnover): Applies to infringements of the most fundamental GDPR obligations including the basic principles of processing (Articles 5-7), data subjects’ rights (Articles 12-22), international data transfers (Articles 44-49), and non-compliance with a supervisory authority order under Article 58(2).

In practice, the 4% turnover calculation is the decisive figure for large multinational organisations. For global technology platforms with tens of billions of euros in annual revenue, the 4% exposure runs into hundreds of millions or billions of euros — explaining why the largest GDPR fines are concentrated among a small number of very large US-headquartered organisations.

IV. Dominant Enforcement Themes

Seven years of GDPR enforcement have produced clear patterns in the types of conduct supervisory authorities prioritise.

International Data Transfers: Chapter V compliance — particularly transfers to the United States — has generated the single largest fine in GDPR history. The Schrems II judgment invalidated Privacy Shield in July 2020, creating years of legal uncertainty and enforcement exposure.

Lawful Basis for Behavioral Advertising: Multiple large fines against social media platforms have centred on which legal basis may lawfully underpin the use of personal data for targeted advertising. The EDPB has consistently rejected attempts by platforms to classify behavioral advertising as “necessary for the performance of a contract.”

Children’s Data and Age Verification: Several of the largest fines involve the processing of personal data relating to minors, including default public account settings, failure to implement age-appropriate design safeguards, and inadequate age verification systems.

Transparency and Cookie Consent: Failures to provide clear, accurate, and accessible information — and cookie consent mechanisms that make refusal difficult — have resulted in substantial fines from the French CNIL and other authorities.

Security and Data Breach Failures: Inadequate technical and organisational security measures, failure to notify breaches within the 72-hour window, and inadequate notifications have all produced significant fines.

Facial Recognition and Biometric Data: The unlawful processing of biometric data has attracted fines from multiple national supervisory authorities and is gaining further momentum with the EU AI Act.

V. Summaries of the Twenty Largest Fines

1. Meta Platforms Ireland — €1.2 Billion (Irish DPC, May 2023): The largest fine in GDPR history arose from Meta’s practice of transferring personal data of Facebook’s European users to servers in the United States. The DPC found that Meta had relied on Standard Contractual Clauses without implementing adequate supplementary measures to ensure transferred data received essentially equivalent protection. The DPC ordered Meta to suspend its transfers to the US within five months.

2. Amazon Europe — €746 Million (Luxembourg CNPD, July 2021): The investigation centred on Amazon’s behavioural advertising targeting system and the legal basis Amazon relied upon for processing users’ personal data to serve targeted advertisements. The CNPD concluded that Amazon’s processing did not comply with the GDPR’s general data processing principles.

3. TikTok Technology Ltd — €530 Million (Irish DPC, May 2025): The DPC found that TikTok had transferred personal data to staff in China who could remotely access EEA user data without adequate protection. TikTok also failed to specify in its Privacy Policy the third countries to which data was transferred. Compounding the case, TikTok disclosed that limited EEA user data had actually been stored on Chinese servers contrary to its representations.

4. Meta/Instagram (Children’s Data) — €405 Million (Irish DPC, September 2022): Instagram’s business account feature automatically published children’s phone numbers and email addresses, and children’s personal accounts defaulted to public. This was the first binding EU-wide decision on the protection of children’s data rights under the GDPR.

5. TikTok (Children’s Data) — €345 Million (Irish DPC, September 2023): TikTok had set children’s accounts to public by default, its Family Pairing feature did not verify adult-child relationships, and push notifications could make children’s activity visible to third parties.

6. LinkedIn Ireland — €310 Million (Irish DPC, October 2024): The DPC found that LinkedIn’s reliance on consent, legitimate interests, and contract necessity for behavioral advertising was invalid in each case — addressing and rejecting all three of the most commonly relied upon legal bases for targeted advertising in a single enforcement action.

7. Uber — €290 Million (Dutch DPA, August 2024): For over two years following the Schrems II judgment, Uber continued to transfer European drivers’ highly sensitive personal data (including location, payments, identity documents, and criminal records) to the US without any valid Chapter V mechanism.

8. Meta/Facebook (533 Million User Scrape) — €265 Million (Irish DPC, November 2022): Meta failed to implement adequate technical measures to prevent systematic exploitation of its contact importer functionality, which enabled harvesting of 533 million users’ phone numbers and profile data. The fine was based on data protection by design and default failures under Article 25.

9. Meta/Facebook (2018 Data Breach) — €251 Million (Irish DPC, December 2024): A vulnerability in the “View As” feature enabled attackers to steal access tokens for approximately 29 million global Facebook accounts including 3 million EEA accounts. The DPC found deficiencies in both security requirements under Article 32 and data protection by design under Article 25.

10. WhatsApp Ireland — €225 Million (Irish DPC, September 2021): WhatsApp failed to provide adequate transparency information to users and non-users about how their personal data was processed, including data shared with other Meta group companies. The EDPB required the DPC to find additional infringements and increase the fine from its initial proposal.

11 & 12. Meta/Facebook and Meta/Instagram (Behavioral Advertising) — €210 Million and €180 Million (Irish DPC, January 2023): Meta’s attempt to use “contract necessity” to justify targeted advertising was rejected. By framing its terms of service as a contract necessarily including behavioral advertising, Meta sought to avoid requiring explicit consent. The EDPB and DPC found behavioral advertising is not objectively necessary for social media.

13 & 14. Google (Cookie Consent) — €150 Million and €100 Million (French CNIL, 2022 and 2020): The CNIL found Google’s cookie consent mechanisms made accepting cookies a single-click action while rejecting cookies required multiple steps — an asymmetry making refusal disproportionately burdensome.

15. Enel Energia — €79.1 Million (Italian Garante, 2024): Systematic violations in telemarketing operations including processing without valid legal basis, unverified third-party consent lists, failure to respect objection rights, and excessive retention. The fine escalated from a prior €26.5 million fine demonstrating continued non-compliance.

17. Criteo — €40 Million (French CNIL, June 2023): Criteo could not demonstrate valid consent for retargeting cookie processing and failed to honour data subject access and erasure rights. The decision applied the GDPR consent framework to the retargeting supply chain, holding a data processor directly responsible for verifying consent.

18. H&M — €35.3 Million (Hamburg DPA, October 2020): Managers systematically recorded employees’ health conditions, religious beliefs, and family circumstances through informal conversations, constituting a severe violation of employees’ fundamental privacy rights involving special category data under Article 9 without any lawful basis.

19. Clearview AI — €30.5 Million (Dutch DPA, September 2024): Building an illegal biometric database of billions of facial images scraped from public websites without any lawful basis. The special category nature of biometric data and the complete absence of transparency or data subject rights made this a fundamental violation.

20. Enel Energia — €26.5 Million (Italian Garante, July 2022): Unlawful telemarketing processing using third-party lists lacking valid consent, disregarding prior objections, and failing to maintain adequate processing records.

VII. Geographic and Sectoral Patterns

A disproportionate share of the largest penalties by value has been imposed by the Irish Data Protection Commission, reflecting the fact that many of the world’s largest technology platforms have established their EU principal establishments in Ireland. Of the twenty largest fines listed above, eleven were issued by the Irish DPC.

The organisations subject to the largest fines are overwhelmingly large US-headquartered technology platforms. Of the total value of GDPR fines issued since May 2018, consistently over 60% by value has been imposed on US-based companies. Spanish supervisory authorities, while rarely issuing the largest individual fines, have issued the greatest number of enforcement decisions of any EU supervisory authority — predominantly against companies in financial services and telecommunications for direct marketing and consent violations.

VIII. Emerging Enforcement Trends

Several enforcement trends are visible in the GDPR’s seventh year. The first is the intersection of GDPR enforcement with the EU AI Act, which entered into force in August 2024. Many AI systems — including those used for credit scoring, recruitment, biometric identification, and content recommendation — engage both GDPR obligations and the new AI Act framework.

The second trend is the growing focus on accountability and governance failures rather than isolated technical breaches. More recent enforcement actions have found violations reflecting structural failures: inadequate data protection by design, persistent legal basis mischaracterisation, failure to maintain records adequate to demonstrate compliance.

The EDPB’s coordinated enforcement forum (CEF) mechanism has proven increasingly consequential, producing enforcement decisions across multiple jurisdictions simultaneously and creating more consistent jurisprudence across the EU.

IX. Lessons for Businesses

Seven years of GDPR enforcement deliver clear lessons relevant to any organisation processing the personal data of individuals in the EU.

The first lesson is that the legal basis question is not a formality. The majority of the largest fines involved findings that the controller had no valid legal basis for its processing. Organisations should invest in careful, documented, and legally defensible lawful basis assessments for every significant category of processing before that processing begins.

The second lesson is that international data transfers remain one of the highest-risk compliance areas. Organisations that rely on Standard Contractual Clauses must conduct and document transfer impact assessments; those relying on the EU-US Data Privacy Framework should have contingency planning in place.

The third lesson is that children’s data requires a heightened and specifically designed compliance approach. Organisations whose platforms, products, or services may be accessed by children should implement age verification mechanisms, age-appropriate design principles, and default protective settings.

The fourth lesson is that accountability documentation is not a bureaucratic overhead but a legal shield. Organisations best positioned to avoid or mitigate enforcement action are those that can produce, on demand, records of processing activities, lawful basis assessments, transfer impact assessments, DPIAs, and audit trails documenting how compliance decisions were reached.

Legal Disclaimer: This article is provided for informational and educational purposes only and does not constitute legal advice. Fine amounts, dates, and procedural statuses are based on publicly available information as of April 2026 and are subject to change as a result of ongoing appeal proceedings. Businesses assessing their own GDPR compliance exposure should seek advice from qualified legal counsel.

See Also