Skip to main content
Back to knowledge base
Overview

GDPR fines: overview, amounts and lessons

Since the GDPR took effect in May 2018, supervisory authorities across Europe have imposed billions of euros in fines. This overview covers the most significant fines at EU level, in the Netherlands (Dutch DPA) and Belgium (Belgian DPA), with the violation, amount and practical lesson per fine.

28 March 20269 min read

Fine framework: how are GDPR fines calculated?

The GDPR has two tiers of fines (Art. 83):

  • Tier 1 (Art. 83(4)): up to EUR 10 million or 2% of global annual turnover — for violations of Art. 25 (privacy by design), Art. 30 (processing register), Art. 32 (security) and Art. 33-34 (breach notification)
  • Tier 2 (Art. 83(5)): up to EUR 20 million or 4% of global annual turnover — for violations of processing principles (Art. 5), legal basis (Art. 6), consent (Art. 7), data subject rights (Art. 12-22) and transfers (Art. 44-49)

Largest European fines

Unlawful transfer for advertising — EUR 1.2 billion (2023)

A major technology company was fined for transferring European users' personal data to the US without adequate safeguards. The largest GDPR fine to date.

Lesson: Non-EEA transfers without a valid basis are among the most heavily fined violations.

Insufficient legal basis for personalised ads — EUR 390 million (2023)

A social media platform was fined for using contractual necessity as a legal basis for personalised advertising.

Lack of transparency and consent — EUR 746 million (2021)

A major e-commerce company was fined for placing cookies without valid consent and insufficient transparency.

Unlawful profiling of minors — EUR 345 million (2023)

A social media platform was fined for defaulting accounts of minors (13-17) to public and insufficient child protection measures.

Dutch fines (Autoriteit Persoonsgegevens)

Inadequate security — EUR 440,000 (2022)

A healthcare institution was fined for inadequate security of medical records. Staff had unnecessary access and there was no access logging.

No DPA — EUR 525,000 (2022)

An organisation was fined for systematically failing to conclude DPAs with processors accessing client data.

Lesson: A DPA is not optional — it is mandatory for any processing by third parties.

Late breach notification — EUR 290,000 (2023)

A company reported a data breach after three months instead of within 72 hours.

Unlawful processing of national ID numbers — EUR 3.7 million (2021)

A government body processed national identification numbers without a legal basis for purposes outside its mandate.

Belgian fines (Gegevensbeschermingsautoriteit)

Cookies without valid consent — EUR 250,000 (2022)

A website operator was fined for placing tracking cookies before obtaining consent. The cookie banner presented choices unequally.

Inadequate security after breach — EUR 100,000 (2023)

After a breach, the organisation had no encryption and no regular security audits. Art. 32 is an ongoing obligation.

Denial of right to erasure — EUR 50,000 (2023)

An organisation refused an erasure request without demonstrating a valid Art. 17(3) exception.

Incomplete privacy notice — EUR 75,000 (2022)

A company's privacy notice was incomplete: recipients were not specifically named, retention periods were missing and legal bases were unclear.

How to prevent a GDPR fine

  • Conclude DPAs with all parties processing personal data on your behalf (Art. 28)
  • Maintain a current processing register with all processing activities, legal bases and retention periods (Art. 30)
  • Implement adequate security and review regularly: encryption, access control, logging (Art. 32)
  • Report breaches within 72 hours and document every incident (Art. 33-34)
  • Document non-EEA transfers with SCCs, TIAs and supplementary measures (Art. 44-49)
  • Respect data subject rights: access, rectification, erasure, portability (Art. 12-22)
  • Conduct DPIAs for high-risk processing (Art. 35)
  • Train staff on privacy awareness and your organisation's procedures

Prevent GDPR fines?

DPAkit helps you keep DPAs, security and documentation in order so you are prepared for any audit.

Start for free