The Most Common Privacy Violations
Tracking Before Consent
Loading analytics, advertising pixels, or session-recording scripts before the visitor consents. This is the single most common finding in cookie-consent enforcement across the EU, and the basis of many ePrivacy fines.
Invalid or Coerced Consent
Pre-ticked boxes, "accept" buttons with no equally easy "reject" option, cookie walls, and dark patterns. GDPR requires consent to be freely given, specific, informed, and as easy to withdraw as to give.
Unlawful International Transfers
Sending EU personal data to jurisdictions without adequate safeguards. Post-Schrems II, transfers relying on invalidated mechanisms have driven some of the largest fines ever issued.
Missing or Misleading Disclosures
Privacy policies that omit third-party data sharing, fail to name processors, or bury key information. Transparency failures under GDPR Articles 12–14 frequently compound other violations.
Inadequate Security & Breach Response
Weak technical safeguards, unencrypted data, and late breach notification (GDPR requires notification within 72 hours). Regulators penalize both the breach and the response.
Children's Data Failures
Processing minors' data without age verification or parental consent, and defaulting children's accounts to public. Enforcement under both GDPR and COPPA has accelerated sharply.
Landmark Enforcement Actions
| Company | Fine | Regulator / Year | Violation |
|---|---|---|---|
| Meta (Facebook) | €1.2 billion | Irish DPC, 2023 | Unlawful EU–US data transfers after Schrems II |
| Amazon | €746 million | Luxembourg CNPD, 2021 | Advertising targeting without valid consent |
| TikTok | €345 million | Irish DPC, 2023 | Children's account settings defaulted to public |
| €225 million | Irish DPC, 2021 | Transparency failures in privacy disclosures | |
| €90 million | French CNIL, 2021 | Cookie refusal harder than acceptance | |
| H&M | €35 million | Hamburg DPA, 2020 | Excessive covert monitoring of employees |
| British Airways | £20 million | UK ICO, 2020 | Security failures enabling a breach of 400k+ customers |
GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher. US state laws such as the CCPA/CPRA add per-violation penalties on top.
How to Avoid These Violations
- 1. Audit your trackers. Know every cookie, pixel, and third-party script on your site — and confirm none fire before consent.
- 2. Fix your consent banner. Reject must be as easy as accept, with no pre-ticked boxes or dark patterns.
- 3. Map your data flows. Document where personal data goes, including international transfers, and put valid safeguards in place.
- 4. Keep disclosures current. Your privacy policy must accurately name the third parties you share data with and the purposes of processing.
- 5. Prepare for breaches. Have an incident-response plan that meets the 72-hour GDPR notification window.
Find Out Where You're Exposed
Run a free privacy scan to detect undisclosed trackers, consent problems, and disclosure gaps on your own website — the same issues behind the fines above.