Whitepapers & Guides

Penalties and Fines in Data Protection

Since the General Data Protection Regulation came into force in May 2018, the data protection authorities of the EU member states have regularly punished smaller and larger data breaches with substantial fines — and have also penalized massive violations of data protection rules affecting many thousands of people.

4 Years of GDPR: Penalties and Fines in Data Protection

EU countries impose more than 1,000 penalties and 1.6 billion euros in fines in just four years

Since the General Data Protection Regulation came into force in May 2018, the data protection authorities of the EU member states have regularly punished smaller and larger data breaches with substantial fines — and have also penalized massive violations of data protection rules affecting many thousands of people.

In just four years, the responsible national and local data protection authorities uncovered more than 1,000 data protection violations across Europe and, as a result, imposed fines totaling 1.6 billion euros. In addition to multimillion-euro fines against some of the world's highest-revenue corporations, numerous smaller fines were imposed that were nonetheless painful for the companies or private individuals affected.

Even small data breaches can get expensive for small and medium-sized companies. Add to that the damage to reputation and possible claims for damages from those affected. Data protection and full GDPR compliance should therefore not be taken lightly.

Looking Back: Data Protection Violations and Fines Over Time

GDPR violations over time

Source: heyData Embed Download image Created with Datawrapper

Violations doubled in the pandemic years 2020 and 2021

A look at the data shows that European data protection authorities have pursued data protection violations from day one after the GDPR came into force, confirming and penalizing offenses. On average, 24 penalties were imposed per month.

A strikingly high number of data protection violations were reported and punished in the pandemic years 2020 and 2021. From 2019 to 2020, the number of penalized violations rose by 104%, and from 2020 to 2021 by another 40%. For 2022, however, various developments are still possible.

These Industries Violate Data Protection Rules Most Often

GDPR violations by industry

Source: heyData Embed Download image Created with Datawrapper

Even the public sector struggles with GDPR compliance

Countless sensitive personal data come together in every company. Data protection is therefore relevant for every department. A look back at data violations by industry shows which sectors have proven particularly negligent about data protection over the last four years.

With 244 penalized violations, industry and commerce top the list. The sector received fines totaling 796 million euros. However, this sum already includes a single violation that was penalized with a fine of 746 million euros. The record penalty went to retail giant Amazon in 2021. It's followed by the media and telecommunications industry with 178 violations and fines totaling 613 million euros.

Particularly striking is the high number of violations in the public sector and education. 141 violations have been reported since 2018 and punished with a total of 19 million euros in fines. This shows that even government bodies still have considerable difficulties with compliance four years after the GDPR came into force.

The Highest Fines

Record penalties for Amazon, Meta, Google, and H&M

  • Amazon: 746 million euros

In July 2021, the online retailer received the record fine from the data protection authority in Luxembourg. It's the highest fine imposed since the GDPR came into force. The company violated consent requirements in connection with its online targeting.

  • WhatsApp: 225 million euros

After WhatsApp violated transparency requirements under Articles 12-14 of the GDPR, the Irish data protection authority penalized Meta's messenger service in September 2021.

  • Google: 50 million euros, 60 million euros, and 90 million euros

French authorities have already imposed three different multimillion-euro fines on Google. The violations concerned insufficient transparency regarding the personalization of ad formats, the use of cookies for advertising purposes without consent, and user-unfriendly cookie management.

  • Facebook: 60 million euros

In Facebook's case, the French data protection authority also criticized the cumbersome cookie management and imposed a fine of 60 million euros in January 2022.

  • H&M: 35 million euros

After it became known that employees at a site in Nuremberg were extensively questioned about sensitive private information and that this data was stored, German authorities imposed a multimillion-euro fine in October 2020.

Spain Penalizes Data Protection Violations Most Often

The highest fines by country

Source: heyData Embed Download image Created with Datawrapper

In the four years since the introduction of the General Data Protection Regulation at EU level, Spanish data protection authorities have penalized a total of 405 violations and demanded fines of 45 million euros. No other country imposed more penalties in the same period. The record fine of 746 million euros for Amazon, mentioned several times already, was imposed by Luxembourg.

Majority of violations in Germany committed by SMEs and private individuals

Germany has penalized a total of 63 data protection violations over the past four years and imposed fines of 52 million euros. Recipients of fine notices from the German data protection authorities included H&M (35 million euros), Notebooksbilliger (10 million euros), and AOK Baden-Württemberg (1.2 million euros). Most of the notices, however, concerned small and medium-sized companies as well as private individuals and solo self-employed people. Extra guidance on GDPR compliance seems particularly necessary here. The fines may not be as high as those for large corporations with revenues in the millions, but penalties between 100 and 10,000 euros can still hit businesses hard.

10 Criteria Determine the Amount of the Fine

The respective data protection authorities of the EU countries are responsible for investigating and penalizing violations of the General Data Protection Regulation and issuing fine notices. They decide not only whether a violation has occurred but also the amount of the penalty. By the way, every person has the right to report data protection violations to the data protection authorities. The authorities are obliged to investigate every complaint and, if necessary, to issue warnings and penalties. The amount of the penalty, usually in the form of a fine and a request to close the data gaps, is determined by the data protection authorities based on the following criteria:

  • Nature and scope of the violation
  • Intent or negligence
  • Steps taken to mitigate the damage
  • Type of data affected
  • Precautionary measures
  • Data protection certification
  • Track record
  • Cooperation with the authorities
  • Proactive notification to the authority or notification by third parties
  • Other aggravating or mitigating factors
Methodology & Sources

All data on violations, penalties, and fines was taken from the report "GDPR Enforcement tracker, 2nd edition 2021"

Detailed information on violations and fine recipients was researched using the DSGVO-Portal.

Published
30.01.2025
Martin Bastius
Co-Founder & CLO

More studies

View all studies
Data Protection Breaches
8/6/26

Data Protection Breaches: A Critical Year in 2024

Data Protection Breaches: A Critical Year in 2024
Cybercrime
8/6/26

Cybercrime Risk Ranking: Potential Threats in Europe

Cybercrime Risk Ranking: Potential Threats in Europe
Analysis
8/6/26

CCTV Worldwide – Between Safety and Civil Liberties

CCTV Worldwide – Between Safety and Civil Liberties
Discover all stories