BLOG · GDPR ENFORCEMENT

GDPR Fines in 2026:
What the Numbers Actually Mean

€1.2 billion fined last year — but almost none of it hits small agencies. Here is what the enforcement data really says, and where a small agency can still get hurt.

Updated August 2026 · Reading time: 7 minutes

The Real Numbers

Headline figures first, with sources. The CMS Enforcement Tracker (the standard industry reference) recorded roughly €5.9 billion across about 3,200 published enforcement actions by mid-2026; DLA Piper's January 2026 survey, which also counts non-public totals, puts cumulative fines at around €7.1 billion since May 2018. Fines issued in the twelve months to January 2026 were approximately €1.2 billion — broadly flat versus 2024. Average breach notifications now run at 443 per day.

But the distribution matters more than the total. Roughly four out of every five euro ever collected comes from just ten decisions against Big Tech platforms. The largest single fine remains Meta's €1.2 billion (Ireland, 2023, under appeal) for unlawful EU-US data transfers. TikTok's €530 million (Ireland, 2025) is the second-largest standing fine. Amazon's famous €746 million fine was annulled by Luxembourg's Administrative Court in March 2026 on procedural grounds — many older articles still cite it, but it no longer stands.

📊 €1.2B in 2025

Annual fines are stable around €1.2 billion/year. Enforcement volume (2,800+ recorded actions) keeps growing even as headline totals flatten.

🏢 10 Decisions = 80%

Ten decisions — mostly Meta, TikTok, Google, Uber, LinkedIn — account for roughly 80% of all euros collected. The long tail of thousands of fines is much smaller.

⚖️ Fines Get Overturned

Amazon's €746M fine was annulled in March 2026. OpenAI's €15M fine met the same fate. Appeals are real — but do not plan your compliance strategy around them.

What Regulators Actually Fine Companies For

Strip away the Big Tech transfers cases, and the violation types in the long tail are remarkably consistent. Across published actions:

Insufficient legal basis (~34%) — processing personal data without a valid ground under Article 6. This is the single most common violation type, and it covers everything from marketing without consent to keeping old customer records "just in case."

Information obligations (~20%) — failing to tell people what happens to their data. Outdated privacy policies, missing disclosures, buried information.

Website and cookies (~10%) — non-compliant cookie banners, tracking pixels firing before consent, missing cookie policies. This is the category small agencies touch directly.

Note what barely registers at the top of the list: security breaches. Most fines are not about getting hacked — they are about processing data without permission or transparency.

The Two-Tier Penalty System

GDPR Article 83 sets two maximum tiers, and knowing which one applies changes how you think about risk:

Lower tier — up to €10 million or 2% of global annual turnover (whichever is higher): violations of Articles 25, 28, 30-34, and others. This includes not having a Data Processing Agreement with your sub-processors, failing to keep Records of Processing Activities (RoPA), inadequate security measures, and late breach notification.

Upper tier — up to €20 million or 4% of turnover: violations of the core principles (Article 5), lawful basis requirements (Article 6), consent conditions, and data subject rights. This is where the Big Tech fines land.

For a small agency, the lower tier is the relevant one — and every violation in it is a paperwork problem, not a technology problem. A DPA template, a RoPA spreadsheet, and an incident response plan eliminate most of the exposure.

Can a Small Agency Actually Be Fined?

Honest answer: yes, but rarely, and usually for avoidable reasons. Enforcement priorities follow complaints and media attention — that is why Spain leads fine volume (over 1,000 actions) and why most small-entity fines start with a customer complaint.

Where small businesses do get hit:

Video surveillance and doorbells — the classic Spanish/Italian enforcement pattern. Cameras capturing public space or neighbours' property generate steady fines.

Marketing without consent — cold emailing purchased lists, SMS campaigns without opt-in.

Failing to respond to data subject requests — ignoring access or deletion requests within the one-month deadline is an easy, well-documented violation.

And where an agency specifically gets exposed: you process client data without a DPA (an Article 28 violation), or you build client sites with non-compliant cookie banners and tracking — which shifts liability onto both you and your client.

📨 Complaints Drive Enforcement

Most small-business fines begin with a single complaint from a customer, employee, or competitor. Handling data subject requests properly removes your biggest enforcement trigger.

🤝 Agencies = Processors

Without a signed DPA, you are an unlawful processor under Article 28 — a lower-tier violation that is entirely eliminated by having the right contract in place.

🍪 Client Sites Are Your Risk

A site you built with tracking pixels firing before consent creates exposure for your client — and they will remember who built it when the complaint arrives.

A 15-Minute Risk Check for Your Agency

You cannot eliminate regulatory risk entirely, but 15 minutes covers the items that actually produce small-agency fines:

1. DPAs signed? Check you have a signed DPA with every client whose data you process, and with every sub-processor you use (hosting, email, CRM).

2. RoPA exists? One spreadsheet listing what personal data you process, why, on what legal basis, and for how long. Required by Article 30.

3. Cookie banner honest? Test one client site you maintain: does anything beyond strictly necessary cookies load before consent? Browser dev tools, two minutes.

4. Privacy policy current? Does it name your actual tools and actual purposes? A policy last touched in 2019 is itself an information-obligation violation.

5. Request inbox works? Someone must own privacy@youragency.com and answer data subject requests within a month. An unanswered request is the easiest fine a regulator can issue.

Do those five things and you have eliminated nearly every enforcement scenario that realistically reaches a small EU web agency.

Going Deeper

Our GDPR Compliance for Small Web Agencies e-book includes ready-to-use DPA clauses, a RoPA template, an incident response plan, and a 14-day compliance action plan.

Get the Complete GDPR E-Book → →    Cookie Consent Guide → →

Frequently Asked Questions

What is the largest GDPR fine ever issued?

Meta Platforms Ireland received a €1.2 billion fine from the Irish Data Protection Commission in May 2023 for unlawfully transferring EU user data to the US. It remains the largest on record and is under appeal. After Amazon's €746M fine was annulled in March 2026, TikTok's €530 million (Ireland, 2025) is the second-largest standing fine.

What is the maximum GDPR fine?

Two tiers apply: up to €10 million or 2% of annual worldwide turnover for procedural violations (missing DPAs, no RoPA, inadequate security), and up to €20 million or 4% of turnover for core principle violations like unlawful processing or invalid consent. Whichever figure is higher applies.

Can freelancers and sole traders be fined under GDPR?

Yes. GDPR applies to any entity processing personal data, regardless of size. In practice, small-entity fines are typically in the hundreds-to-low-thousands of euros range and usually start from a complaint — most commonly over surveillance cameras, unsolicited marketing, or ignored data subject requests.

Is my agency liable if a client's website we built violates GDPR?

It depends on your role. If you only build and hand over, you are generally not the controller. If you host, maintain, or configured the tracking yourself, you share responsibility — as processor you need a DPA, and knowingly deploying a non-compliant cookie setup exposes you alongside the client.

Has any GDPR fine been overturned?

Yes, notably. Amazon's €746 million fine was annulled by Luxembourg's Administrative Court in March 2026 on procedural grounds, and OpenAI's €15 million Italian fine was annulled the same month. Appeals succeed mainly on procedure — the underlying conduct usually remains regulated.

Get the Complete GDPR E-Book → →    Cookie Consent Guide → →