🇪🇺 GDPR⚖️ Penalties🚀 Phase 5 · Advanced

GDPR Penalties Explained — Real Cases and How Companies Failed

The headline numbers grab attention. The patterns behind them are the useful part — because the same handful of failures produced almost every record fine.

GK
Gauri Khatate
🔐 Cybersecurity Expert & Technical Writer·📖 5 min read
📅 June 2026·🏢 SecComply
GDPR penalties resolve into four repeatable failure patterns

Five billion euros in GDPR fines resolve, on inspection, into four repeatable failures — transfers, lawful basis, rights, and security.

More than five billion euros in GDPR fines have been handed down since 2018, and the biggest numbers make the news for a day. The number is not the lesson. Strip the cases down and the same few failures appear again and again — not exotic ones, but foundational: moving data where it shouldn’t go, processing without a basis that holds, ignoring people’s rights, and leaving data exposed. The record fines aren’t a catalogue of bad luck. They’re a catalogue of the same predictable gaps, at scale, in companies that could easily have afforded to close them.

€1.2B
The record fine — for moving European data to the US
€746M
For using customer data to target ads without a valid basis
€5.88B+
Total GDPR fines since the regulation took effect in 2018
4 patterns
Transfers, legal basis, rights, and security cover most of it

The Tiers, Briefly

GDPR fines come in two tiers. The lower one — up to €10 million or 2% of global turnover — covers procedural failures like inadequate records, weak privacy-by-design, or no data protection officer. The higher one — up to €20 million or 4% of global turnover — covers the serious stuff: no lawful basis, ignoring individual rights, breaching the core principles, and unlawful transfers. Because the ceiling is a share of worldwide turnover, the same violation that costs a small firm a modest sum costs a global platform a headline. The percentages are the reason the biggest numbers all belong to the biggest companies.

Pattern One: Transfers

The single most expensive category of GDPR failure is moving European data outside the EU without adequate protection — and it produced the largest fine in the regulation’s history.

THE RECORD — META, €1.2 BILLION (IRELAND, 2023)

In May 2023 Ireland’s regulator fined Meta €1.2 billion, the largest GDPR penalty ever issued, for transferring European users’ data to the United States without adequate protection — relying on contractual clauses the courts had already found insufficient after the Schrems II ruling. The fine wasn’t about a leak or weak security; Meta’s defences are formidable. It was about a structural decision — where data lived and how it flowed — that the company kept making after the legal ground beneath it had shifted. Transfers are the costliest fault line in the whole regime: TikTok’s €530 million fine in 2025 (data sent to China) and Uber’s €290 million in 2024 (driver data to the US) sit on the same line. And it scales all the way down: any company routing EU data through non-EU cloud services is making the same category of decision, where the only question is whether anyone checked it was lawful.

Pattern Two: No Lawful Basis

The second pattern is processing personal data with no legal footing that holds. Amazon’s €746 million fine — the second-largest ever — turned on how it used customer data to target advertising; Meta drew a €390 million penalty over the basis it claimed for behavioural ads; CaixaBank’s €6 million was a bank that couldn’t justify the basis for its processing. Each was a failure not of security or honesty but of the prior question: was the company allowed to do this at all? When the basis is missing or wrong, everything built on it is unlawful, however well it’s secured.

PatternWhat went wrongWhere it showed up
TransfersEU data sent abroad without protectionMeta €1.2B; TikTok €530M; Uber €290M
No lawful basisProcessing with no valid legal footingAmazon €746M; CaixaBank €6M
Rights & transparencyVague notices; requests unmet or incompleteWhatsApp €225M; Google €50M; Spotify
Weak securityData left exposed; breachesBritish Airways £20M; Marriott £18.4M

Pattern Three: Rights and Transparency

The third cluster is about people not being able to understand or control what’s done with their data. WhatsApp’s €225 million fine was for opaque privacy information; Google’s €50 million — the first major GDPR penalty, back in 2019 — was for failing to give users a clear, informed choice over ad personalisation; Spotify was penalised for access requests answered partially and vaguely. None involved a breach. They involved the regulation’s insistence that processing be transparent and individual rights be real, not theoretical.

Pattern Four: Security and Children

The fourth covers data left exposed and the special protection owed to minors. British Airways (£20 million) and Marriott (£18.4 million) were fined for security failings that allowed major breaches. And a striking share of recent fines concern children: TikTok’s €345 million penalty in 2023 turned on default-public child accounts and weak age verification, part of a wider pattern of regulators treating minors’ data as the highest-priority category. Both sub-patterns share a theme — the most vulnerable data and the most vulnerable people draw the closest scrutiny.

How the Fined Failed vs. How the Compliant Operate

Pattern-matching across the record fines — the gap between the penalised and the prepared tends to follow the same shape:

How companies got finedHow compliant companies operate
✗ Kept transferring data on invalid grounds✓ A valid transfer mechanism, reviewed as the law shifts
✗ Processed with no basis that holds✓ A documented lawful basis per purpose
✗ Vague notices, requests ignored✓ Clear notices, rights answered on the clock
✗ Treated existing security as good enough✓ Security benchmarked to a recognised standard
✗ Default-public settings for children✓ Privacy by default, strongest for minors
✗ Reacted only after the regulator called✓ Closed the foundational gaps in advance
✗ Assumed scale was a defence✓ Knew turnover makes the percentage hurt more

Why the Money Was Avoidable

The uncomfortable thread through every record fine is that the failures were ordinary and the decisions were early. A transfer not re-papered when the law changed. A lawful basis never properly established. A consent flow that assumed agreement. A right that was never built into the product. None of these required a sophisticated attacker or a stroke of bad luck — they required someone to make, or dodge, a foundational decision, often years before the fine arrived. The penalties are large because the companies are large. The mistakes behind them are within reach of almost any organisation, which is exactly why they’re worth studying.

Final Thought

GDPR penalties read like a wall of intimidating numbers and resolve, on inspection, into a short list of repeatable lessons: know where your data goes, have a basis that holds, make rights real, and protect what you keep. The companies in the headlines didn’t fail in novel ways. They failed in the same four ways, at a scale that turned ordinary gaps into record fines — and every one of those gaps is closable before a regulator ever calls.

The test: take the four patterns — transfers, basis, rights, security — and ask, honestly, which one the organisation would be fined for if a regulator looked this week. Most companies can name it immediately. That answer is the work, and it’s cheaper to do now than to read about later.

Which of the Four Failure Patterns Would You Be Fined For Today?

SecComply runs the same analysis the record fines came out of — transfers, lawful basis, rights and transparency, and security — against your actual processing, and tells you where the exposure really sits.

Frequently Asked Questions

How big can a GDPR fine be?

There are two tiers. The lower is up to 10 million euro or 2% of global annual turnover for procedural failures; the higher is up to 20 million euro or 4% of global turnover for serious breaches like no lawful basis, ignoring rights, or unlawful transfers. Because the ceiling is a share of worldwide turnover, the biggest numbers belong to the biggest companies.

What is the most expensive type of GDPR failure?

International transfers — moving European data outside the EU without adequate protection. It produced the largest fine ever, Meta’s 1.2 billion euro penalty in 2023, and recurs in TikTok’s 530M and Uber’s 290M fines.

Do GDPR fines require a data breach?

No. Many of the largest fines involved no breach at all — they were about lawful basis (Amazon 746M), transparency (WhatsApp 225M, Google 50M), or retention (Deutsche Wohnen 14.5M). Security is only one of the four patterns.

Were these fines avoidable?

Almost always. The failures were ordinary and the decisions were early — a transfer not re-papered when the law changed, a basis never properly established, a right never built into the product. Every one of those gaps is closable before a regulator calls.