GDPR fines cost businesses €4.5 billion (£3.83bn) over the last six years, new research from Nordlayer has shown, with the biggest fines coming from Spain, Italy, and Germany.
Individual data protection authorities across Europe have issued 2,072 GDPR violation decisions since the legislation was introduced six years ago.
Businesses in Spain had the worst record, with 842 GDPR fines, paying out a total of €80m (£68.16m) in fines since 2018.
Italy came in second overall. The country had less than half the number of violations as Spain, at 358, but paid even more in total fines, which amassed to €229m (£195bn).
German companies had 186 total violations, paying €55m (£46.8bn) in fines since 2018. Romania was close behind with 179 violations, but this only amassed to €1.1m (£940,000).
At number five is Poland, with 73 violations and €4m (£3.4m) in total fines.
While these countries had the most amount of individual fines, Ireland had the most prolific violations and fines since GDPR was introduced. This is largely because Ireland is where most major global tech companies – including Amazon, Meta, Apple, TikTok, and Google, have their European headquarters.
The Irish Data Protection Authority (DPA) issued €2.8 billion (£2.4bn) fines since 2018, and made rulings on some of the most transformative GDPR cases seen.
Meta was charged with six of Europe’s ten biggest fines, the biggest amounting to €1.2bn (£1bn) for a lack of sufficient legal basis for data processing in 2023, which caused Meta to transform much of its business plan for its flagship platform, Facebook. Meta faced a number of fines regarding data processing and sharing among its various platforms including Facebook, Instagram, and WhatsApp.
Still, the Irish DPA has often been lambasted for not being harsh enough on some of its rulings on Meta. The EU data protection board (EUDPB) has had to takeover and review a number of cases made against the tech giant. The 2023 case caused Meta to change its data processing completely, which ushered in its controversial pay or consent advertising model.
TikTok paid €345m (£294bn) for GPR violations, and Google faced two different fines, one for €90m and one for €60m.
In Luxembourg, Amazon was fined €746m (£635m) for GDPR violations.
Recommended
- Meta Bends to EU GDPR: Personalised Ads Will Require Consent
- ICO Fines TikTok £12.7M for Misuse of Children’s Data
- Top 10 GDPR Fines of 2023
The most common reason for a fine was insufficient legal basis for data processing – essentially, companies did not have a legal reason for processing the person data that they did. These fines cost a total of €1.6bn (£1.3bn) since 2018. General data processing non-compliance costs over €2bn (£1.7bn) across 578 fines.
“We’ve witnessed businesses across industries change their data handling practices and invest in security measures to achieve compliance,” said Carlos Salas, cybersecurity expert at NordLayer.
“While full compliance has been challenging for many companies, the GDPR’s impact in empowering individuals and holding organizations accountable for data mishandling cannot be overstated. It has reshaped the digital landscape, forcing a much-needed prioritization of privacy rights.”
“Achieving and maintaining GDPR compliance is an ongoing journey, not a one-time destination,” Salas said.
“Data protection regulations evolve, and cyber threats become more sophisticated, so businesses must remain proactive in their data privacy and security approach.”





