Analysis

The Biggest GDPR Fines Ever and What Caused Them

The largest GDPR fines on record share a common pattern: international data transfers and consent for advertising, more often than data breaches. Here's what actually caused the biggest ones.

Published July 6, 2026·Last updated August 18, 2026

When people picture a huge GDPR fine, they usually picture a hacked database. In practice, the largest fines on record have overwhelmingly been about something else: unlawful international data transfers and invalid consent for advertising, not security breaches. That pattern is worth understanding, because it tells you where the real enforcement risk has concentrated.

Meta, €1.2 billion (2023)

The largest GDPR fine issued to date. Ireland’s Data Protection Commission fined Meta over its continued transfer of European users’ data to the US following the Schrems II ruling, which found the previous transfer mechanism inadequate. We cover the underlying legal mechanism in our piece on Schrems II and the SCC problem. Meta has appealed the decision.

Amazon, €746 million (2021)

For years the largest fine on record before Meta’s, issued by Luxembourg’s regulator over Amazon’s advertising practices, centered on processing personal data for targeted advertising without a valid legal basis. The case has been the subject of ongoing appeals and legal challenges since it was issued, a reminder that headline fine amounts aren’t always the final, settled figure.

TikTok, fines in both 2023 and 2025

TikTok has faced more than one major GDPR enforcement action: a fine in 2023 centered on how it handled children’s data and international transfers, and a separate, larger fine in 2025 tied specifically to transfers of European user data to China. Both were reported as under appeal. The pattern, a platform with a large European user base facing repeated fines over the same underlying transfer and consent issues, illustrates how these aren’t necessarily one-time corrections but recurring enforcement risk when the underlying practice doesn’t change.

Our recommendation

CookieYes

Nearly every fine on this list traces back to consent or transfer failures that were, at the mechanical level, fixable, CookieYes exists specifically to close the consent-gating gap before it becomes an enforcement problem.

Try CookieYes

Meta, two more fines in 2022 and 2023

Beyond the €1.2 billion transfer fine, Meta was separately fined roughly €405 million in 2022 over how Instagram handled children’s data, and roughly €390 million in early 2023 over the legal basis it used for personalized advertising on Facebook and Instagram, both also reported as under appeal. Three separate nine-figure-plus fines against one company, all rooted in consent and legal basis, not a security incident.

Google, €50 million (2019)

One of the earlier landmark fines, issued by France’s CNIL, centered on Google’s lack of transparency and invalid consent for personalized advertising. Notable for coming from a national regulator directly (rather than the “lead supervisory authority” mechanism used for later cross-border cases) and for signaling early that ad-tech consent flows specifically were a regulatory priority.

H&M, €35 million (2020)

A useful contrast to the transfer/advertising pattern: this one was about excessive employee monitoring. A German H&M service center was found to have recorded detailed personal information about employees, health details, family issues, and more, well beyond what was necessary, violating the data minimization principle covered in our overview of GDPR’s core principles. A reminder that GDPR enforcement isn’t only about customer-facing websites.

What the pattern actually tells you

Three consistent themes across the largest fines:

  1. International data transfers, especially to the US, have been the single largest source of fine value. This is a mechanical, closable gap for most businesses, see our piece on how the 2023 Data Privacy Framework changed this specifically for US transfers.
  2. Invalid consent for advertising is the second major theme, and it scales with how much of your business model depends on targeted advertising, the more central it is, the more scrutiny it draws.
  3. Fine amounts change significantly on appeal, sometimes years after the original decision. Headline numbers reported at the time of a fine are a starting point, not a final outcome.

Why this matters for a much smaller business

You’re extremely unlikely to face a nine-figure fine, those are reserved for the largest platforms with the most severe, sustained violations. But the underlying mechanics that caused these fines, transferring data without a valid mechanism, relying on consent that wasn’t actually freely given, are exactly the same mechanics that show up in far smaller enforcement actions and complaints against much smaller businesses. The dollar amount scales with your size and revenue; the underlying mistake doesn’t.

This is an educational overview of publicly reported enforcement actions, not a comprehensive or fully current list, and not legal advice. Fine amounts and appeal outcomes change over time, verify current status before relying on any specific figure. Consult a privacy attorney for guidance on your own compliance posture.