The year 2023 witnessed a groundbreaking GDPR fine surpassing €1.2 billion to Meta (formerly known as Facebook), marking a significant moment in data protection enforcement.
Meta continues to dominate, with several of its subsidiaries among the recipients of the top GDPR fines.
However, the trend is not exclusive to big tech companies. Over 2024, European regulators demonstrated increasing confidence in issuing fines across various sectors, not limited to technology and social media.
By January 2025, the cumulative total of GDPR fines has reached approximately €5.88 billion, highlighting the continuous enforcement of data protection laws and the rising financial repercussions for non-compliance.
While big tech continues to be the primary target the regulatory landscape has expanded. Authorities are now increasingly focusing on other industries, including finance, healthcare, and energy, underscoring the broadening scope of GDPR enforcement.
We will explore the details of the top 20 GDPR fines, examining the monumental penalties and the evolving trends in data protection and enforcement that are shaping 2025.
20 biggest GDPR fines so far
1. Meta GDPR fine- €1.2 billion 
In May 2023, in a groundbreaking decision in the past five years of GDPR enforcement, the Irish Data Protection Commission (DPC) imposed a historic fine of €1.2 billion on US tech giant Meta.
This record-breaking fine was issued for transferring personal data of European users to the United States without adequate data protection mechanisms and serves as a significant milestone in data protection regulation.
Meta, the parent company of popular platforms like Instagram and WhatsApp, has been penalized for failing to comply with the European Union’s General Data Protection Regulation (GDPR). Still, this fine highly surpasses all other fines.
As Meta plans to appeal the decision, the outcome of this legal battle will have far-reaching implications, shaping the future of data transfers and privacy rights in the digital age.
This fine serves as a clear warning to other companies that the GDPR’s requirements must be taken seriously, and non-compliance can result in severe financial consequences
Read the entire article: Meta Hit with Record €1.2B GDPR Fine
2. Amazon GDPR fine – €746 million 
On July 16, 2021, the Luxembourg National Commission for Data Protection (CNDP) issued a fine in the amount of €746 million ($888 million) to Amazon.com Inc.
The fine was issued due to a complaint filed by 10,000 people against Amazon in May 2018 through a French privacy rights group that promotes and defends fundamental freedoms in the digital world- La Quadrature du Net.
The CNPD opened an investigation into how Amazon processes personal data of its customers and found infringements regarding Amazon’s advertising targeting system that was carried out without proper consent.
Read the entire article: Luxembourg DPA Issues €746 Million GDPR Fine to Amazon
3. Meta GDPR fine – €405 million 
On September 5, 2022, Ireland’s Data Protection Commission (DPC) issued a €405 million GDPR fine to Meta Ireland concerning the lawfulness of processing children’s personal data following the legal bases of performance of a contract and legitimate interest.
The DPCs’ investigation focused on teenagers between the ages of 13 and 17, the operation of Instagram business accounts, and how such accounts automatically displayed children’s contact information (email addresses and/or phone numbers) publicly.
According to DPC, Meta failed to take measures to provide child users with information using clear and plain language, lacked appropriate technical and organizational measures, and failed to conduct a Data Protection Impact Assessment where processing was likely to result in a high risk to the rights and freedoms of child users.
Read the entire article: Meta Fined €405 Million for Mishandling Teenagers’ Data on Instagram
4. Meta GDPR fine – €390 million 
On 4 January, Ireland’s Data Protection Commission (DPC) announced the conclusion of two inquiries against Meta Ireland and the decision to issue a €390 million fine in connection to its Facebook and Instagram services.
Meta changed the Terms of Service for its Facebook and Instagram users right before the GDPR was enforced, changing the legal basis from consent to contract for most of its processing activities.
Users were asked to accept new updated Terms of Services to access their Facebook and Instagram accounts; otherwise, the services would not be available.
Meta considered that, by accepting Terms of Services, users would enter into a contract with Meta, claiming that processing of personal data was necessary for the delivery of Facebook and Instagram services and performance of the contract, so any personalized and behavioral advertising would be considered in line with the GDPR.
However, two complainants contended that, by making the accessibility of its services conditional on users accepting the updated Terms of Service, Meta was, in fact, “forcing” them to consent.
Read the entire article: DPC fines META €390 million for violation of the GDPR
5. TikTok GDPR fine- €345 million 
TikTok is facing a substantial fine of €345 million due to violations of GDPR, with a specific focus on its handling of children’s accounts.
The Irish Data Protection Commission (DPC) concluded its investigation in September 2023, examining TikTok’s data practices between July 31 and December 31, 2020, particularly concerning young users.
The inquiry assessed various aspects, including platform settings, age verification, and communication with child users. The DPC’s decision revealed multiple GDPR breaches related to data processing, transparency, and fairness.
To address these violations, the DPC issued a reprimand, instructed TikTok to rectify its data processing practices within three months, and imposed a significant administrative fine of €345 million.
Read the entire article: TikTok fined €345m for violation of GDPR
6. Linkedin GDPR fine – €310 million 
On October 30, 2024, the Irish Data Protection Commission (DPC) fined LinkedIn Ireland €310 million for GDPR violations.
The investigation, initiated by a complaint from French nonprofit La Quadrature Du Net, revealed LinkedIn’s misuse of user data for behavioral analysis and targeted advertising.
Alongside the fine, the DPC issued a reprimand and ordered LinkedIn to revise its data practices. This case highlights the importance of transparency, fairness, and lawful data processing under the GDPR.
Read the entire article: Irish DPC Imposes €310 Million GDPR Fine on LinkedIn Ireland
7. Uber GDPR fine – €290 million 
8. Meta GDPR fine – €265 million 
On November 25, 2022, the Irish DPA fined Meta €265 million. The DPA had previously launched an investigation against Meta back in 2021 after several media reports indicated that Facebook’s dataset with personal information was made available on a public hacking platform.
This data leak affected up to 533 million users, disclosing their personal data (phone numbers and email addresses) to third parties without authorization.
The DPA reviewed and analyzed the Facebook Search, Messenger Contact Importer, and Instagram Contact Importer Tools. The DPA’s main goal was to assess the implementation of organizational and technical measures that would protect personal data, and they found a breach of Art. 25 GDPR.
Read the entire article: DPC imposes €265 million fine on Meta
9. META GDPR fine- €251 million 
The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited €251 million following an investigation into a major data breach that occurred in 2018.
The breach affected 29 million Facebook users globally, including 3 million in the EU/EEA, and involved unauthorized access to personal data such as names, contact information, and sensitive details like religion and political beliefs.
The DPC identified several GDPR violations, including inadequate breach notification, failure to document the breach, and lapses in data protection in system design and processing.
Meta was fined €8 million for improper notification, €3 million for inadequate documentation, €130 million for poor system design, and €110 million for not processing only necessary data by default.
This fine adds to Meta’s growing list of penalties, with the company facing a record €1.2 billion fine last year. Meta has announced plans to appeal the decision.
Read the entire article: Irish Data Protection Commission Fines Meta €251 Million
10. WhatsApp GDPR fine – €225 million 
On 2 September 2021, Ireland’s data protection authority, the Data Privacy Commission (DPC), announced their decision to issue a GDPR fine to a Facebook-owned instant messaging and voice-over-IP service, WhatsApp Ireland €225 million (or $267 million) after a three-year investigation.
The binding decision was issued after the European Data Protection Board (EDPB) intervened and required the DPC (lead supervisory authority for WhatsApp Ireland Ltd.), to reassess the initially proposed fine regarding infringements of transparency in the calculation of the fine as well as the timeframe for WhatsApp to comply.
Read the entire article: WhatsApp faces €225 million for transparency violation
11. Meta fine – €91 Million 
The Irish Data Protection Commission (DPC) fined Meta Platforms Ireland €91 million for a 2019 data breach where user passwords were stored in plaintext without proper encryption.
The breach, which affected sensitive user information, resulted in multiple GDPR violations, including failures in breach notification and security measures.
The fine emphasizes the importance of robust data protection practices to prevent unauthorized access to personal data.
Read the entire article: Irish DPC Fines Meta €91 Million for Inadequate Password Security
12. Google LLC fine- €90 million 
On December 31, 2021, CNIL issued a €90 million fine to GOOGLE LLC over the inability to allow YouTube users in France to refuse cookies as easily as they could accept them.
The CNIL concluded that making refusal mechanisms more complex than they should be, discourages users from refusing cookies and benefits a company that bases its main revenue streams on advertising and targeting based on cookies.
The CNIL ordered the companies to provide users located in France with a means of refusing cookies as simple as the existing means of accepting them within three months or pay the penalty of €100.000 euros per day of delay.
Cookie regulation, or the ePrivacy Directive, does not directly fall under the GDPR, but GDPR defines how data controllers can obtain consent and therefore counts as the GDPR fine.
Read the entire article: CNIL fines Google and Facebook a total of €210 million over cookies
13. Enel Energia SpA fine – €79 million 
On February 8, 2024, the Italian data protection authority (Garante) fined Enel Energia SpA €79.10 million for GDPR violations following an investigation by the Guardia di Finanza.
The investigation revealed that Enel had unlawfully acquired 978 contracts from four companies using illicit customer lists, failing to implement adequate security measures in its customer management system.
The Garante deemed the violations serious, considering the number of affected individuals and Enel’s role in technology. Enel must also inform 595 impacted parties and enhance its security measures to ensure compliance.
14. Google Ireland fine- €60 million 
The €60 million fine to Google Ireland was issued by the CNIL on the same day as the abovementioned fine to Google LLC.
The smaller fine of 60 million euros was issued for the exact same reasons as the €90 million fine. However, this fine was issued concerning the google.fr search website.
15. Facebook Ireland- €60 million 
Facebook failed to provide mechanisms allowing its users to refuse cookies as easily as they can accept them.
The investigation, which started in April, uncovered that, as opposed to a single button to accept cookies, Facebook requires several clicks to refuse cookies.
In addition, the button to refuse cookies is located at the bottom of the second page and was labeled “Accept cookies,” which was confusing and misleading.
16. Google France GDPR fine – €50 million 
On January 21, 2019, the French National Commission on Informatics and Liberty (CNIL) fined Google a €50 million fine for lack of transparency, inadequate information, and valid consent regarding the ads personalization.
Google failed to provide enough information to users about consent policies and did not give them enough control over how their personal data is processed.
17. CRITEO fine -€40 million 
On June 15, 2023, (CNIL) levied a substantial fine of €40 million against CRITEO, an online advertising company renowned for its expertise in behavioral retargeting. CRITEO failed to obtain proper consent, provide clear information, and enable user rights.
CNIL found multiple violations, including trackers without user consent, lack of transparency in privacy policy, incomplete access to personal data, inadequate consent withdrawal and data erasure procedures, and absence of joint controller agreements.
Read the entire article: CRITEO Fined €40 Million Over Targeted Advertising
18. H&M GDPR fine- €35.25 million 
The Hamburg Commissioner for Data Protection and Freedom of Information (BfDI) issued a €35,3 million fine to Swedish retail conglomerate Hennes & Mauritz – H&M for violating the GDPR.
After a technical error, the data on the company’s network drive was accessible to everyone for a few hours. The press picked up the news making the Commissioner aware of the violation.
The case is pretty interesting since the company collected sensitive personal data of their employees through whispering campaigns, gossip, and other sources to create profiles of employees and used that data in the employment process.
The personal data included medical records, diagnoses and symptoms of the illness, and private details about vacation and family affairs.
Read the entire article: H&M fined €35,3 Million for violation of the GDPR
19. Amazon France Logistique- €32 Million GDPR Fine 
Amazon France Logistique, responsible for managing Amazon’s warehouses in France, incurred a €32 million GDPR fine from the CNIL for implementing an intrusive employee monitoring system.
This system utilized scanners to track employee activity, leading to data retention and statistical indicators that the CNIL deemed disproportionate and excessive.
The investigation stemmed from employee complaints and media coverage, revealing violations such as unlawful data retention, excessive monitoring, failure to ensure lawful processing, and lack of transparency and security measures.
The CNIL criticized indicators like tracking scanner inactivity and fast scanning, considering them invasive and unnecessary.
Despite acknowledging Amazon’s business challenges, CNIL penalized the company due to the extensive monitoring’s impact on employees’ privacy and its contribution to Amazon’s competitive advantage.
Read the entire article: €32 Million GDPR Fine for Amazon France Logistique
20. Clearview AI- €30.5 Million 
On September 3, 2024, the Dutch Data Protection Authority (AP) fined Clearview AI €30.5 million for illegal data collection practices.
The American company scraped facial images from the internet without consent, creating a biometric database that violated GDPR regulations.
Clearview’s use of this data for intelligence purposes raised significant privacy concerns. In addition to the fine, Clearview faces penalty payments if violations continue.
The AP is also considering holding the company’s directors personally accountable. This action underscores efforts to regulate facial recognition technology and protect individual privacy in the EU.
Read the entire article: Dutch DPA Fines Clearview AI €30.5 Million for Illegal Data Collection
Conclusion
This is the up-to-date list of the biggest GDPR fines so far, but the list is constantly changing, indicating a lot of activities from data protection authorities. As the DLA Piper report states:
“Supervisory authorities across Europe have been staffing up their enforcement teams and getting to grips with the new regime.”
2025 is likely to give rise to more data privacy laws and could prove to be a year of increased enforcement and greater penalties for violations of GDPR.
How to start your compliance journey
Data Privacy Manager consists of four products and 11 modules that tackle real day-to-day challenges and can help you with:
- PERSONAL DATA DISCOVERY – AI-based solution designed to automate personal data discovery and classification across your systems in any language and script from structured and unstructured sources through machine learning and database connectivity, eliminating false positives and providing accurate insight into personal data.
- PRIVACY PROGRAM AUTOMATION – Six modules (Data Processing Inventory (ROPA), Data Subject Requests, Third Party Management, Assessment Automation, Risk Management, and Incident Management) designed to automate privacy processes, support cross-departmental cooperation and minimize privacy-related risks.
- CONSENT AND PREFERENCE MANAGEMENT – Manage consents in real-time and provide customers with easy and secure access to their data. It gives a clear overview of activities and enables you to keep records of consent in one central place. Real-time insight into the complete personal data lifecycle from the moment of opt-in to the data removal
- DATA REMOVAL ORCHESTRATION– A clear and automated way to delete personal data that is no longer needed or is requested to be removed. Data Privacy Manager has paired up with filerskeepers to provide a privacy platform with instant access to data retention information across hundreds of countries worldwide.

