Enforcement & Risk Intelligence

Privacy Violations Guide

Regulators have issued billions in privacy fines. Understand the most common violations, learn from the largest real-world enforcement actions, and find out how to avoid making the same mistakes.

Scan Your Site for Violations

The Most Common Privacy Violations

Tracking Before Consent

Loading analytics, advertising pixels, or session-recording scripts before the visitor consents. This is the single most common finding in cookie-consent enforcement across the EU, and the basis of many ePrivacy fines.

Invalid or Coerced Consent

Pre-ticked boxes, "accept" buttons with no equally easy "reject" option, cookie walls, and dark patterns. GDPR requires consent to be freely given, specific, informed, and as easy to withdraw as to give.

Unlawful International Transfers

Sending EU personal data to jurisdictions without adequate safeguards. Post-Schrems II, transfers relying on invalidated mechanisms have driven some of the largest fines ever issued.

Missing or Misleading Disclosures

Privacy policies that omit third-party data sharing, fail to name processors, or bury key information. Transparency failures under GDPR Articles 12–14 frequently compound other violations.

Inadequate Security & Breach Response

Weak technical safeguards, unencrypted data, and late breach notification (GDPR requires notification within 72 hours). Regulators penalize both the breach and the response.

Children's Data Failures

Processing minors' data without age verification or parental consent, and defaulting children's accounts to public. Enforcement under both GDPR and COPPA has accelerated sharply.

Landmark Enforcement Actions

Company Fine Regulator / Year Violation
Meta (Facebook) €1.2 billion Irish DPC, 2023 Unlawful EU–US data transfers after Schrems II
Amazon €746 million Luxembourg CNPD, 2021 Advertising targeting without valid consent
TikTok €345 million Irish DPC, 2023 Children's account settings defaulted to public
WhatsApp €225 million Irish DPC, 2021 Transparency failures in privacy disclosures
Google €90 million French CNIL, 2021 Cookie refusal harder than acceptance
H&M €35 million Hamburg DPA, 2020 Excessive covert monitoring of employees
British Airways £20 million UK ICO, 2020 Security failures enabling a breach of 400k+ customers

GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher. US state laws such as the CCPA/CPRA add per-violation penalties on top.

How to Avoid These Violations

  1. 1. Audit your trackers. Know every cookie, pixel, and third-party script on your site — and confirm none fire before consent.
  2. 2. Fix your consent banner. Reject must be as easy as accept, with no pre-ticked boxes or dark patterns.
  3. 3. Map your data flows. Document where personal data goes, including international transfers, and put valid safeguards in place.
  4. 4. Keep disclosures current. Your privacy policy must accurately name the third parties you share data with and the purposes of processing.
  5. 5. Prepare for breaches. Have an incident-response plan that meets the 72-hour GDPR notification window.

Find Out Where You're Exposed

Run a free privacy scan to detect undisclosed trackers, consent problems, and disclosure gaps on your own website — the same issues behind the fines above.

Related Guides