What are the landmark GDPR enforcement decisions, and what doctrine did each build?
The tier-one decisions and their holdings. Meta transfers (Irish DPC, May 2023, 1.2 billion EUR plus a suspension order): continued EU-US transfers on SCCs after Schrems II without adequate supplementary measures, the largest GDPR fine ever and the enforcement floor under every transfer program, resolved prospectively only by the Data Privacy Framework adequacy decision two months later. The forced-consent pair (Irish DPC per EDPB binding decisions, January 2023, 390 million EUR combined): Meta could not rely on contract necessity (Article 6(1)(b)) to run behavioral advertising, recharacterizing the consent-or-contract question for the entire ad-funded economy, extended by the CJEU's Bundeskartellamt judgment (July 2023) and the EDPB's consent-or-pay opinion (2024). The children's cases: Instagram (405 million EUR, 2022, public-by-default child accounts and published contact details) and TikTok (345 million EUR, 2023, defaults plus dark patterns steering children public), establishing that Article 25 defaults are enforceable product requirements. Amazon (Luxembourg CNPD, 2021, 746 million EUR, the advertising-consent decision litigated for years afterward) proving lead authorities outside Dublin could reach nine figures. Google's twin French decisions (CNIL: 50 million EUR GDPR consent transparency, 2019, upheld; plus the separate ePrivacy cookie fines below) building consent-quality doctrine. The security-failure line: British Airways (20 million GBP) and Marriott (18.4 million GBP) from the ICO (2020), H&M's employee-surveillance fine (35.3 million EUR, Hamburg, 2020), and the Irish DPC's Meta password-storage and breach decisions (including 251 million EUR in December 2024 for the 2018 token breach), pricing Article 32. Uber's driver-data transfer fine (Dutch DPA, 290 million EUR, 2024) extending transfer enforcement beyond Meta. And the ADM frontier: Clearview AI fined by Italy, Greece, France, and the UK (multi-million each, plus escalating CNIL non-compliance penalties) for scraping faces, and the Dutch DPA's 30.5 million EUR Clearview decision (2024) with director-liability warnings, establishing that extraterritorial scrapers are reachable. The meta-lesson: doctrine now comes from decisions, not just guidelines, and the EDPB's binding-decision mechanism means the strictest DPA's theory can become everyone's law.
What has US federal and state enforcement established?
The FTC record, built on Section 5 plus its rules: Epic Games (2022, $520 million total: $275M COPPA penalties for children's data collection, $245M refunds for dark-pattern purchases) fusing children's privacy and manipulation doctrine; the health-data campaign, GoodRx (2023, first Health Breach Notification Rule action, $1.5M, over prescription data shared with ad platforms), BetterHelp (2023, $7.8M, therapy-intake data to advertisers), Premom, Cerebral, establishing that consumer-health-to-adtech flows are actionable without HIPAA; Amazon/Alexa and Ring (2023, children's voice data retention and employee access to camera feeds); the data-broker line (X-Mode/InMarket orders restricting sensitive-location sales, the Kochava litigation surviving dismissal) making precise location near sensitive venues an unfairness theory; and the remedy evolution that matters most operationally, FTC orders now routinely require deletion of ill-gotten data and the models trained on it (Everalbum, Cambridge Analytica-adjacent matters), 20-year assessed compliance programs, and executive-level certifications. The state record: California's AG opened with Sephora (2022, $1.2M) establishing that ignored GPC signals and unclassified adtech sales violate the CCPA, followed by the DoorDash and Honda matters (the CPPA's 2025 Honda action targeting burdensome opt-out flows and dark patterns) and the CPPA's enforcement sweeps (streaming, location data); Texas built the biggest book, its Meta biometric settlement ($1.4 billion, 2024, under CUBI) is the largest state privacy recovery ever, followed by its data-broker registrations and its 2024-2025 suits against General Motors (driving-data sales) and Allstate/Arity, plus a 2025 Google settlement reported at $1.375 billion covering location and biometric claims; New York's AG runs steady security-failure settlements; and multistate coalitions (the Google location-history settlement, $391.5 million, 2022) scale the model. The structural takeaways: dark patterns are enforceable in both systems; health and location data draw priority everywhere; deletion remedies mean violations cannot be monetized then kept; and the state AGs plus CPPA now constitute a parallel enforcement network with its own sweep capacity.
What did the cookie and dark-pattern enforcement campaigns change?
They converted interface design into a regulated, audited surface. The French campaign, the spine of it: CNIL's December 2020 decisions (Google 100 million EUR, Amazon 35 million EUR, cookies dropped before consent with defective information, under ePrivacy, deliberately sidestepping the one-stop-shop) then December 2021 (Google 150 million EUR, Facebook 60 million EUR, one-click accept versus multi-click reject, the asymmetry theory) then Microsoft/Bing (60 million EUR, 2022) and TikTok (5M) and Yahoo (10M, 2023), backed by sweep letters against hundreds of sites and public compliance-deadline campaigns that moved the whole French market to first-layer reject buttons; the doctrine exported through the EDPB's cookie-banner taskforce report (2023), harmonizing positions on pre-ticked boxes, deceptive button contrast, and legitimate-interest-based tracking, and through national sweeps (the ICO's 2023-2024 warnings to top UK sites, Spain's and Italy's steady fine practice). The dark-pattern doctrine formalized in parallel: the EDPB's social-media dark-pattern guidelines (2022-2023) taxonomizing manipulation (overloading, skipping, stirring, obstructing), the OECD and FTC dark-pattern reports (the FTC's 2022 staff report cataloging the patterns its Epic and Amazon Prime cases then punished), the CPRA's statutory rule that consent obtained through dark patterns is not consent, echoed in Colorado's rules, and the EU's reinforcement through the DSA (Article 25's dark-pattern ban for platforms) and the Digital Fairness agenda. The TCF earthquake beneath the adtech version: the Belgian DPA's IAB Europe decision (2022, upheld in relevant part by the CJEU 2024 on the consent string as personal data and IAB's joint-controller exposure) put the consent-plumbing standard itself under enforcement, forcing TCF redesigns. What changed for practitioners: banner UX, button symmetry, purpose granularity, and withdrawal mechanics are now testable violations with published rubrics; sweeps are automated and scale to hundreds of sites; and the same asymmetry doctrine now runs on both continents, CNIL's reject-parity and the CPPA's 'symmetry in choice' rules describe the same test.
What does the private-litigation overlay add to regulatory enforcement?
A parallel pricing system, faster and often costlier than regulators. The BIPA engine: Illinois' private right of action with $1,000/$5,000 statutory damages, no-harm-required standing (Rosenbach, 2019), and per-scan accrual (Cothron v. White Castle, 2023, moderated by the 2024 amendment) produced the defining settlements, Facebook $650 million (face-tagging), Google $100 million (Photos), Clearview's injunctive settlement restricting its faceprint database, and a persistent stream of employer fingerprint-timeclock class actions, making Illinois the de facto national regulator of biometric product decisions (features get built BIPA-first or not at all). The wiretapping wave: California's CIPA (and its two-party-consent siblings) repurposed against session-replay tools, chatbots, and tracking pixels, with the Meta-pixel healthcare litigation (hundreds of hospital-system suits over patient-portal and appointment-page pixels, following the 2022 reporting that exposed the flows) as its most consequential branch, producing nine-figure aggregate settlements and hospital pixel-removal campaigns; the VPPA revival (video-page pixels transmitting viewing data with identifiers) running alongside, with circuit courts split on definitions and the suits continuing regardless. The breach class-action baseline: standing doctrine post-TransUnion v. Ramirez (2021) constrains no-injury federal suits, but large breaches settle anyway (Equifax's $700M-plus global resolution remains the benchmark; T-Mobile's $350M, and the steady mid-eight-figure cadence since), with plaintiff theories increasingly citing the retention and minimization failures regulators also cite, hoarded legacy data enlarging every class. The new statutory PRAs to watch: Washington My Health My Data's private right of action (via the state CPA) opened consumer-health litigation in 2024-2025, and the state-law trend of attaching PRAs to sensitive categories continues. The planning consequence: private litigation keys on technically provable, per-user violations, pixels firing, scans collected, sessions recorded, exactly the class of facts a network-level audit surfaces, so the litigation defense and the compliance audit are the same exercise performed by different parties, and the cheaper party to have perform it is yourself.
How should a compliance program actually use the enforcement record?
As a test suite: every major case names a control that failed, and the failures compose a finite, testable list. The controls the record indicts, in rough frequency order: consent and choice mechanics (tags firing pre-consent or despite refusal, asymmetric flows, ignored GPC, dark patterns: the CNIL campaign, Sephora, Honda, Epic), tested by loading your properties in a clean browser per jurisdiction and reading the network log against the recorded choice; sensitive-data flows to adtech (health pages, symptom checkers, patient portals, cycle trackers, precise location: GoodRx, BetterHelp, the pixel litigation, Kochava), tested by auditing what fires on sensitive surfaces and what SDKs ship in sensitive apps; children's defaults and flows (public-by-default, nudging, under-13 collection: Instagram, TikTok, Epic, YouTube), tested against the design-code standards wherever minors plausibly appear; transfer paper versus transfer fact (Meta 1.2B, Uber 290M), tested by reconciling the transfer inventory against actual vendor data locations and TIA currency; security fundamentals and hoarded data (BA, Marriott, the breach settlements, Optus/Medibank's legacy-data lesson), tested by patch/access/MFA audits plus retention-schedule execution sampling; lawful-basis architecture (Meta's contract-necessity collapse), tested by checking that each processing purpose's claimed basis survives its jurisprudence; and rights machinery under load (deadline misses and verification failures recur as counts in composite fines), tested by mystery-shopping your own DSAR channel. The programmatic disciplines this implies: a quarterly enforcement review feeding a living control-test calendar (new theories arrive by decision, the consent-or-pay and pay-or-okay line being current); sweep-simulation as routine QA, since regulators' own methods (clean-browser crawls, GPC probes, banner audits) are replicable internally at trivial cost; a watch on your own sector's cases specifically, because enforcement clusters (hospitals after the pixel wave, apps after GoodRx, automakers after the GM suit); and honest translation upward, enforcement data is the strongest budget argument privacy teams possess, the record above prices each control failure in eight to ten figures, and the controls cost less than any single case.