EU Privacy Law EU/EEA

GDPR Enforcement Tracker: Largest Fines, Trends, and Lessons for Compliance Teams

The biggest GDPR fines on record, what each was actually for, and the enforcement patterns that predict where regulators look next.

Regulation

GDPR, Article 83

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Cumulative GDPR fines have run into the billions of euros since 2018, with the ten largest all issued against major technology companies.
  • The record is EUR 1.2 billion (Meta, May 2023) over EU-US data transfers; the top tier also includes Amazon (EUR 746M), Instagram (EUR 405M), TikTok (EUR 345M), and LinkedIn (EUR 310M).
  • The dominant enforcement themes are lawful basis for advertising, children's defaults, international transfers, and cookie consent.
  • Most fines are small and complaint-driven: the typical enforcement event is a four-to-six-figure penalty against an ordinary company, triggered by one individual.
  • The EDPB's cross-border cooperation mechanism means a single lead authority decision can bind a company across all member states.

GDPR enforcement is measured in more than headlines. Since May 2018, European authorities have issued thousands of fines totaling billions of euros, and the pattern of what gets fined is the closest thing compliance teams have to a regulator’s priority list. This page tracks the largest penalties and the trends behind them.

RegulationGDPR, Article 83
Max penaltyEUR 20M or 4% of global annual turnover
Record fineEUR 1.2 billion (Meta, 2023)
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

The largest fines on record

FineCompanyYearAuthorityWhat it was for
EUR 1.2BMeta2023Ireland (DPC)EU-US transfers without valid safeguards after Schrems II
EUR 746MAmazon2021Luxembourg (CNPD)Advertising processing without valid consent
EUR 405MMeta (Instagram)2022Ireland (DPC)Children’s contact data public by default
EUR 345MTikTok2023Ireland (DPC)Children’s accounts public by default, weak family pairing
EUR 310MLinkedIn2024Ireland (DPC)Lawful basis failures in behavioral advertising
EUR 290MUber2024Netherlands (AP)Driver data transfers to the US without safeguards
EUR 265MMeta2022Ireland (DPC)Data scraping enabled by platform design
EUR 251MMeta2024Ireland (DPC)2018 breach affecting 29 million accounts
EUR 225MWhatsApp2021Ireland (DPC)Transparency failures in privacy notices
EUR 201MMeta2023Ireland (DPC)Forcing consent via terms of service (with the EUR 390M January decisions)

The four themes that drive enforcement

Advertising lawful basis. Amazon, LinkedIn, and the Meta decisions all turn on the same question: what legal basis supports behavioral advertising? Regulators have rejected contract and are skeptical of legitimate interests, pushing the industry toward consent.

Children’s defaults. Instagram and TikTok were fined for design choices, not breaches. Public-by-default settings for minors are treated as violations in themselves.

International transfers. Meta’s record fine and Uber’s EUR 290 million show that Chapter V is enforced at the highest tier. Transfer paperwork is not optional documentation; it is the difference between the largest fine ever and none.

Cookies and trackers. Alongside GDPR cases, ePrivacy enforcement produced the CNIL’s EUR 150 million Google and EUR 60 million Facebook decisions over reject-button asymmetry. Website consent is the most automatable check regulators and complainants have.

What this means for your program

Enforcement risk concentrates where evidence is easy to gather. Anyone can inspect your website’s trackers, read your privacy notice, and file a complaint; nobody outside can see your internal ROPA. Start hardening where the evidence is public: run a free scan to see your site the way a complainant would, then work inward using our GDPR compliance roadmap.

Frequently Asked Questions

What is the largest GDPR fine ever issued?

EUR 1.2 billion, issued by the Irish Data Protection Commission against Meta in May 2023, for continuing to transfer EU Facebook user data to the US without valid safeguards after Schrems II.

Who issues GDPR fines?

The national supervisory authority of each member state, such as France's CNIL or Ireland's DPC. For cross-border cases the lead authority for the company's EU headquarters runs the case, with other authorities and the EDPB able to force changes through the Article 65 dispute mechanism.

How are GDPR fine amounts calculated?

Article 83(2) lists the factors: nature and duration of the violation, intent or negligence, mitigation, prior violations, cooperation, and data categories affected. The EDPB's 2023 fining guidelines add a structured method that starts from the seriousness and the company's turnover.

Do small companies actually get fined?

Yes, constantly. Large fines make headlines, but most enforcement is four-to-six-figure penalties against ordinary businesses over CCTV, marketing consent, ignored access requests, and website trackers. These cases typically start with a single complaint.

Can GDPR fines be appealed?

Yes, through national courts, and companies regularly do. Some fines get reduced; the structural findings usually survive. Appeals do not suspend the reputational cost, and remediation orders often bind during the appeal.

Regulatory Crosswalk

UK GDPRePrivacy DirectiveDSA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.