GDPR enforcement is measured in more than headlines. Since May 2018, European authorities have issued thousands of fines totaling billions of euros, and the pattern of what gets fined is the closest thing compliance teams have to a regulator’s priority list. This page tracks the largest penalties and the trends behind them.
| Regulation | GDPR, Article 83 |
|---|---|
| Max penalty | EUR 20M or 4% of global annual turnover |
| Record fine | EUR 1.2 billion (Meta, 2023) |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
The largest fines on record
| Fine | Company | Year | Authority | What it was for |
|---|---|---|---|---|
| EUR 1.2B | Meta | 2023 | Ireland (DPC) | EU-US transfers without valid safeguards after Schrems II |
| EUR 746M | Amazon | 2021 | Luxembourg (CNPD) | Advertising processing without valid consent |
| EUR 405M | Meta (Instagram) | 2022 | Ireland (DPC) | Children’s contact data public by default |
| EUR 345M | TikTok | 2023 | Ireland (DPC) | Children’s accounts public by default, weak family pairing |
| EUR 310M | 2024 | Ireland (DPC) | Lawful basis failures in behavioral advertising | |
| EUR 290M | Uber | 2024 | Netherlands (AP) | Driver data transfers to the US without safeguards |
| EUR 265M | Meta | 2022 | Ireland (DPC) | Data scraping enabled by platform design |
| EUR 251M | Meta | 2024 | Ireland (DPC) | 2018 breach affecting 29 million accounts |
| EUR 225M | 2021 | Ireland (DPC) | Transparency failures in privacy notices | |
| EUR 201M | Meta | 2023 | Ireland (DPC) | Forcing consent via terms of service (with the EUR 390M January decisions) |
The four themes that drive enforcement
Advertising lawful basis. Amazon, LinkedIn, and the Meta decisions all turn on the same question: what legal basis supports behavioral advertising? Regulators have rejected contract and are skeptical of legitimate interests, pushing the industry toward consent.
Children’s defaults. Instagram and TikTok were fined for design choices, not breaches. Public-by-default settings for minors are treated as violations in themselves.
International transfers. Meta’s record fine and Uber’s EUR 290 million show that Chapter V is enforced at the highest tier. Transfer paperwork is not optional documentation; it is the difference between the largest fine ever and none.
Cookies and trackers. Alongside GDPR cases, ePrivacy enforcement produced the CNIL’s EUR 150 million Google and EUR 60 million Facebook decisions over reject-button asymmetry. Website consent is the most automatable check regulators and complainants have.
What this means for your program
Enforcement risk concentrates where evidence is easy to gather. Anyone can inspect your website’s trackers, read your privacy notice, and file a complaint; nobody outside can see your internal ROPA. Start hardening where the evidence is public: run a free scan to see your site the way a complainant would, then work inward using our GDPR compliance roadmap.