GDPR fines and enforcement actions continued at an active pace through 2025 and into 2026. Cumulative fines since 2018 have exceeded €7.1 billion, per the DLA Piper GDPR Fines and Data Breach Survey (January 2026). Q1 2026 saw continued enforcement activity from major supervisory authorities including the Irish DPC, the French CNIL, the Italian Garante, and the Dutch Autoriteit Persoonsgegevens.
This page summarizes the GDPR enforcement landscape as of 2026 and what tech companies should learn from it.
Key takeaways
- Cumulative GDPR fines since 2018 have exceeded €7.1 billion per the DLA Piper GDPR Fines and Data Breach Survey (January 2026), with enforcement continuing actively into 2026.
- The largest fines concentrate on big tech behavioral advertising, data transfer compliance, and now automated decision-making, from Meta Ireland’s €1.2 billion fine for unlawful EU-to-US transfers to Uber’s €825 million fine of August 2026.
- Common violation patterns include behavioral advertising lawful basis, international transfers, children’s data, cookie consent dark patterns, DSAR failures, and inadequate security.
- 78 percent of the 3,228 fines in the enforcementtracker.com database, 2,520 of them, fall between €1,000 and €500,000 (queried 11 September 2026); that is the realistic band, plus reputational damage and customer churn, not the multi-million headline figure.
- We help technology companies build privacy programs that address the specific risks regulators are actively pursuing rather than generic compliance boxes.
- Engage Compliance reads enforcement decisions as they land and tells clients which ones change what they should be doing.
The largest GDPR fines to date
Meta Ireland: €1.2 billion (May 2023). The Irish Data Protection Commission’s largest single fine, issued for unlawful transfers of EU user data to the United States in violation of Chapter V requirements.
Uber: €825 million (August 2026). The Dutch Autoriteit Persoonsgegevens fined Uber €824,990,000 on 21 August 2026, the second-largest GDPR fine issued to date. Between 2018 and 2022 Uber’s software tracked driving behavior and passenger ratings and deactivated driver accounts automatically on suspicion of fraud or a rating judged too low, with no human involvement, which breached the prohibition on solely automated decisions with legal or similarly significant effects. Uber was also found to have given drivers too little information about the automated decision-making. The French CNIL worked the case with the Dutch authority under the one-stop-shop mechanism, following a 2020 complaint brought on behalf of more than 170 drivers. Uber has appealed and calls the fine disproportionate, so the penalty is not yet final.
Amazon Europe: €746 million (July 2021), annulled on appeal in March 2026. Issued by the Luxembourg supervisory authority CNPD for advertising practices violations, this was the largest GDPR fine at the time. On 12 March 2026 the Luxembourg administrative court of appeal annulled the fine on procedural grounds, holding that the CNPD had not established the fault or negligence that Article 83 requires following the Court of Justice’s Deutsche Wohnen ruling (C-807/21). The court upheld the underlying GDPR violations, including rejection of Amazon’s legitimate-interest basis, and remanded the matter to the CNPD to redo the fault analysis, so a new fine may still follow. It is therefore no longer a standing penalty.
TikTok: €530 million (May 2025). Irish Data Protection Commission fine for transfers of European user data to China, split as €485 million for failing to meet Chapter V transfer safeguards and €45 million for transparency failures, with a six-month order to bring transfers into compliance or suspend them.
Meta Platforms: €405 million (September 2022). Irish DPC fine for Instagram’s processing of children’s data without adequate protections.
TikTok: €345 million (September 2023). Irish DPC fine for children’s data processing including privacy settings defaulting to public.
Meta Platforms: €390 million (January 2023). Irish DPC fine for behavioral advertising lawful basis violations.
LinkedIn Ireland: €310 million (October 2024). Irish DPC fine for behavioral advertising consent and transparency violations.
Uber Technologies: €290 million (August 2024). The Dutch Autoriteit Persoonsgegevens fined Uber for transferring European driver data to the United States without a valid transfer mechanism after the Privacy Shield was struck down. It was the largest Dutch fine until the same authority’s €825 million automated decision-making penalty in 2026.
Meta Platforms: €265 million (November 2022). Irish DPC fine over the scraping and publication of Facebook user data, where the authority found the platform’s design had not built in the data protection measures Article 25 requires.
Meta Platforms: €251 million (December 2024). Irish DPC fine following the 2018 Facebook token breach that exposed the accounts of around 29 million users worldwide, on findings under Articles 33 and 25.
WhatsApp Ireland: €225 million (September 2021). Irish DPC fine for transparency failures, covering what WhatsApp told users and non-users about how their data was processed and shared with other Meta companies.
Cumulative across the fines listed above, total enforcement exceeds €4 billion, with the largest concentrations on big tech behavioral advertising practices and data transfer compliance.
Common violation patterns
Behavioral advertising lawful basis. Multiple large fines have addressed the use of “contract” as lawful basis for advertising-driven personalization, with regulators requiring consent.
Automated decision-making. Article 22 restricts decisions taken solely by automated means where they carry legal or similarly significant effects for someone, and the Uber fine shows what regulators now do with it. Employment and platform-work decisions are the live area: account deactivation, fraud scoring, and ranking systems that change whether a person can earn.
International data transfers. The Meta 1.2 billion fine and several others have addressed Schrems II compliance, particularly for US transfers under inadequate safeguards.
Children’s data. Multiple platforms have faced enforcement for processing children’s data with insufficient protections including default privacy settings, age verification gaps, and inadequate parental controls.
Cookie consent and dark patterns. Multiple supervisory authorities, particularly the French CNIL, have issued fines for cookie banners that make rejecting cookies harder than accepting them.
DSAR response failures. Smaller but numerous fines for inadequate or untimely responses to data subject access requests.
Inadequate security. Article 32 violations resulting in personal data breaches, particularly involving unencrypted data or weak access controls.
Lack of lawful basis documentation. Companies unable to demonstrate documented Article 6 lawful basis for processing activities.
Q1 2026 enforcement highlights
Multiple supervisory authority actions in Q1 2026 continued the patterns above. The most active jurisdictions remain Ireland (lead supervisory authority for many large tech platforms), France (active on cookie compliance and consumer-facing services), Italy (active on AI and biometric processing), and the Netherlands (active on data broker and adtech).
Enforcement against SMEs and tech startups
Most public attention focuses on multi-million euro fines against large tech platforms, but supervisory authority enforcement against smaller companies is much more common in terms of number of cases. The enforcementtracker.com database does not break its 3,228 tracked fines down by company size, so we cannot say how many of these specifically hit SMEs, but the overall distribution is instructive: 2,520 of the 3,228 fines (78 percent) fall between €1,000 and €500,000, and only 175 (5 percent) exceed €1 million (enforcementtracker.com, queried 11 September 2026, using the Min Fine and Max Fine filters, reproducible by anyone). What enforcement against smaller companies typically looks like:
- Fines in that €1,000 to €500,000 band, sized to the violation and, per Article 83, the company’s turnover.
- Reprimands and warnings without financial penalty (common for first offenses).
- Orders to bring processing into compliance, often with specific deadlines.
- Bans on specific processing activities pending remediation.
- Investigation publication that creates reputational consequences beyond the immediate fine.
For most growing tech companies, the realistic risk is not a 100 million euro fine. The database shows the great majority of enforcement action landing well under €500,000, combined with reputational damage and customer churn, particularly during fundraising or enterprise sales cycles.
What tech companies should learn
The patterns of enforcement create clear priorities for tech companies building privacy programs:
- Document lawful basis for every processing activity. The most common avoidable violation is inability to demonstrate documented lawful basis.
- Build proper consent management for processing requiring consent. Cookie banners with dark patterns, default-on consent, and asymmetric reject/accept buttons are repeatedly fined.
- Address international transfers explicitly. SCCs, Transfer Impact Assessments, and DPF certification where applicable. Vague reliance on “appropriate safeguards” is not enough.
- Build DSAR response capability before you need it. Inadequate DSAR response is a common avoidable violation that often triggers broader investigation.
- Implement appropriate technical and organizational security measures. Personal data breaches resulting from foreseeable security gaps are typically fined.
- Conduct DPIAs for high-risk processing. The DPIA itself often surfaces and addresses violations preemptively.
- Maintain RoPA. Regulators investigating any matter typically request RoPA early. Companies without RoPA start the investigation from a position of weakness.
You can self-check most of these priorities against our GDPR readiness checklist.
How Engage Compliance helps
Privacy compliance work designed around enforcement patterns is our core service. We help technology companies build privacy programs that address the specific risks regulators are actively pursuing, not just check generic compliance boxes.
For clients with active or pending supervisory authority matters, we engage on focused project basis to support investigation response.
Get started
If you are evaluating your enforcement exposure or have an active matter, book a consultation.
This page is general information, not legal advice.