GDPR Fines Statistics (2026)

Curated statistics on GDPR enforcement, cumulative and record fines, the countries that fine most, and the data protection authority decisions against Google Analytics.

Последен преглед July 2026

The GDPR turned data protection from a paperwork exercise into a financial risk with real numbers attached. Eight years of enforcement have produced thousands of fines, a handful of billion-euro headlines, and a line of decisions aimed directly at web analytics. This page collects the key figures with sources.

Cumulative fines

According to the DLA Piper GDPR Fines and Data Breach Survey published in January 2026, supervisory authorities across Europe have issued approximately 7.1 billion euros in GDPR fines from 25 May 2018 through 10 January 2026. Fines issued during 2025 totaled roughly 1.2 billion euros, about level with 2024.

The CMS GDPR Enforcement Tracker, the other widely cited database, lists more than 3,200 publicly known enforcement actions across the EU and EEA. Both sources note that published fines understate real enforcement, since many authorities do not publish every decision.

The largest fines

The record book is dominated by a small number of big tech cases:

  • Meta, 1.2 billion euros, May 2023. The Irish Data Protection Commission fined Meta over transfers of European Facebook user data to the US. It remains the largest GDPR fine ever issued.
  • Amazon, 746 million euros, July 2021. Luxembourg's CNPD fined Amazon Europe Core over ad targeting without valid consent. A Luxembourg court annulled this fine on procedural grounds in March 2026, per the CMS Enforcement Tracker.
  • TikTok, 530 million euros, April 2025. The Irish DPC's fine over data transfers to China was the largest of 2025, per DLA Piper.
  • Meta and Instagram account for several more of the top ten, including fines of 405 million and 390 million euros issued by the Irish DPC in 2022 and 2023.

Separately from the GDPR, France's CNIL used the ePrivacy rules to fine Google 150 million euros and Facebook 60 million euros in early 2022 because rejecting cookies was harder than accepting them.

Fines by country

Two different league tables exist, and they look nothing alike:

  • By value, Ireland leads with roughly 4.04 billion euros in cumulative fines, around 57 percent of all GDPR fine value, per DLA Piper (2026). That reflects one thing: Meta, Google, TikTok, and other tech firms have their EU headquarters in Dublin. France overtook Luxembourg in 2025 to become the second country past the 1 billion euro mark.
  • By count, Spain leads for the seventh consecutive year, with over a thousand published fines, followed by Italy and Romania, per the CMS Enforcement Tracker Report. Spain's model is many smaller penalties against ordinary businesses rather than a few landmark cases.

The practical takeaway for a normal company: enforcement is not only a big tech story. The volume leaders fine small and mid-sized businesses routinely, just in smaller amounts.

The Google Analytics decisions

For analytics specifically, the most consequential enforcement did not involve fines at all, but findings that a mainstream tool was unlawful to use:

  • Austria, January 2022. The Austrian data protection authority (DSB) ruled that a website's use of Google Analytics unlawfully transferred personal data to the US, the first decision applying the CJEU's Schrems II judgment of July 2020 to an everyday tool.
  • France, February 2022. The CNIL reached the same conclusion and ordered French websites to stop or find alternatives, later publishing guidance that standard configurations could not be fixed with contract clauses alone.
  • Italy, June 2022. The Garante aligned with Austria and France, warning all Italian website operators.
  • Denmark, September 2022. The Datatilsynet declared that Google Analytics could not be used lawfully without supplementary measures, and Finland, Norway, and Sweden took the same line. Sweden's IMY went furthest, issuing the first fines for Google Analytics use in mid 2023, including a penalty of around 1 million euros against a telecom operator.

The reasoning was the same in every case: IP addresses and online identifiers collected by analytics are personal data, and sending them to a US provider subject to US surveillance law breached GDPR transfer rules. The EU-US Data Privacy Framework, adopted in July 2023, restored a legal transfer basis, but the framework is under legal challenge and the underlying finding stands: analytics data is personal data, and regulators will act on it.

The simplest way to stay outside that entire risk surface is analytics that never collects personal data in the first place. Analyse works cookieless, keeps no identifiers, and needs no consent banner, so there is nothing to transfer and nothing to fine. The GDPR-compliant analytics guide covers the details.

Sources

Често задавани въпроси

How much have GDPR fines totaled so far?

Cumulative GDPR fines reached 7.1 billion euros from May 2018 through 10 January 2026, according to the DLA Piper GDPR Fines and Data Breach Survey. Roughly 1.2 billion euros of that was issued in 2025 alone.

What is the largest GDPR fine ever?

The largest fine remains the 1.2 billion euro penalty the Irish Data Protection Commission imposed on Meta in May 2023 over EU-US data transfers. The 746 million euro Amazon fine from Luxembourg in 2021 was the second largest until a Luxembourg court annulled it on procedural grounds in March 2026.

Which country has issued the most GDPR fines?

By total value, Ireland leads with over 4 billion euros in cumulative fines, driven by cases against big tech companies headquartered there. By number of fines, Spain leads, with over a thousand published penalties, followed by Italy and Romania, according to the CMS GDPR Enforcement Tracker.

Is Google Analytics illegal under the GDPR?

Several EU data protection authorities, starting with Austria in January 2022 and followed by France, Italy, and Denmark among others, ruled that the way Google Analytics transferred personal data to the US violated GDPR transfer rules after the Schrems II judgment. The 2023 EU-US Data Privacy Framework eased the transfer issue, but it faces legal challenges and the decisions show analytics data is squarely within GDPR scope.

Have companies been fined over cookies and analytics specifically?

Yes. France's CNIL fined Google 150 million euros and Facebook 60 million euros in early 2022 over cookie refusal mechanisms under the ePrivacy rules, and Sweden's IMY issued the first fines tied directly to Google Analytics use in mid 2023.

Измервайте без загубите от съгласието

Analyse работи без бисквитки, така че продължавате да измервате всеки посетител без банер за съгласие. Анализи, фунии и SEO машина в един таб. Пробвайте безплатно 14 дни.

Безплатен пробен период