Around €1.2 billion (£996m) in General Data Protection Regulation (GDPR) fines were issued across Europe in 2024, according to the latest edition of DLA Piper’s GDPR Fines and Data Breach Survey.
The global law firm’s seventh annual data privacy report shows that in the year from 28th January 2024, €1.2 billion fines were imposed, a 33% decrease compared to fines in the previous year, bucking the seven-year trend of increasing enforcement.
DLA Piper said that this does not represent a shift in focus from personal data enforcement, however, with the year-on-year trend continuing upwards and this year’s reduction almost entirely due to the €1.2 billion fine against Meta falling in 2023 which skewed the 2023 figures.
That record breaking penalty was issued by the Irish DPC against Meta Platforms Ireland Limited, and according to the latest report, Ireland remains the preeminent GDPR enforcer, issuing €3.5 billion (£2.91bn) in fines since May 2018, more than four times the value of fines issued by second placed Luxembourg Data Protection Authority, with €746.38 million (£619m) in fines over the same period.
In 2024, big tech companies and social media giants continued to be the primary targets for record fines, with the Irish Data Protection Commission issuing fines of €310 million (£257m) against LinkedIn and €251 million (£208m) against Meta.
The report also notes that there have been a number of decisions this year signalling the intent of data protection authorities to scrutinise the operation of AI technologies and their alignment with privacy and data protection laws.
For example, in Ireland, the Irish DPC and X entered an agreement last year to suspend the platform’s processing of certain personal data for the purpose of training its AI chatbot, Grok, following proceedings against X in the Irish High Court, while in December the Italian Garante took action against OpenAI in relation to the management of the ChatGPT service.
Last year also saw enforcement action in other sectors, including financial services.
The Spanish Data Protection Authority issued two fines totalling €6.2 million (£5.1m) against a major bank for inadequate security measures, while Poland’s Personal Data Protection Office imposed administrative fines on some international banks, including a fine of €870,000 (£722,100) for failing to notify customers of a data breach.
The UK was an outlier in 2024, issuing very few fines, with the UK Information Commissioner, John Edwards, quoted as saying that he does not agree that fines are likely to have the greatest impact, resulting in the ICO maintaining its current reprimand regime rather than expand punishments to fines for data protection errors.
DLA Piper said that, in general, the renewed focus on governance and oversight has led to a number of enforcement decisions after failings in these areas, with regulators calling out the failings of management bodies specifically.
Perhaps most significantly, the Dutch Data Protection Commission announced it is investigating whether it can hold the directors of Clearview AI personally liable for breaches of GDPR, following a €30.5 million (£25.32m) against the company.
Recommended reading
- EU Commission Fined For Breaching its Own Data Protection Rules
- Meta Delays AI Training in Europe Following Regulatory Concern
- X’s Default Data Harvesting for AI Model Under Regulatory Scrutiny
“European regulators have signalled a more assertive approach to enforcement during 2024 to ensure that AI training, deployment and use remains within the guard rails of the GDPR,” said Ross McKean, DLA Piper partner and chair of the UK Data, Privacy and Cybersecurity practice.
“As the Dutch DPA champions personal liability for the management of Clearview AI, 2025 may well be the year that regulators pivot more to naming and shaming and personal liability to drive data compliance.”





