GDPR authorities logged an average of 443 data breach notifications a day between 28 January 2025 and 27 January 2026, according to DLA Piper's GDPR Fines and Data Breach Survey, published in January 2026. That is a 22% jump from the prior year's 363 a day, and the first time the daily average has passed 400 since GDPR took effect on 25 May 2018. Every one of those notifications is a potential entry point into the fine-setting process this post walks through.

Most breach notifications never turn into a fine at all. The ones that do go through a specific legal test set out in GDPR Article 83, and the size of the eventual penalty depends less on how many records were exposed than on how the company behaved before, during, and after the breach became known.

How many GDPR data breach notifications are reported each day?

GDPR authorities logged 443 data breach notifications a day in 2026 443/day average GDPR breach notifications,DLA Piper survey, Jan 2025 to Jan 2026

The 443-a-day figure comes from DLA Piper's survey of breach notifications logged with supervisory authorities across the EU and EEA, covering the twelve months from 28 January 2025 to 27 January 2026. The prior twelve-month period averaged 363 a day, so the increase works out to roughly 80 more notifications a day, or a 22% rise. DLA Piper's report frames this as a genuine acceleration rather than a reporting-methodology change, since the survey has used a consistent counting approach across its annual editions.

A rising notification count is not the same thing as a rising fine count. Most notified breaches are resolved with no penalty, a corrective order, or a fine too small to make any public tracker. The volume matters because it sets the pool of cases a regulator could act on, and because Article 83(2)(h) explicitly lets a regulator weigh how a breach became known to it, whether the company self-reported promptly or the authority found out some other way, when deciding how hard to come down. For a fuller look at how many breaches happen worldwide, not just how many get reported to a GDPR authority, see our breakdown of daily data breach counts.

PeriodDaily notification averageYear-over-year change
28 Jan 2024 to 27 Jan 2025363Baseline
28 Jan 2025 to 27 Jan 2026443+22%

Source: DLA Piper, GDPR Fines and Data Breach Survey, January 2026.

How does a regulator actually calculate a fine for a data breach?

GDPR does not have a separate fine schedule for breaches. A breach-related violation, most often a failure to secure data under Article 32 or a failure to notify it properly under Article 33 or 34, falls into GDPR's lower statutory tier under Article 83(4): a cap of EUR 10 million or 2% of the company's global annual turnover, whichever is higher. Regulators start from that cap, then move up or down inside it using the eleven factors listed in Article 83(2).

Figure 1: The Article 83(2) factors a regulator weighs once a breach-related violation is confirmed. Source: GDPR Articles 83(2) and 83(4), as summarized by gdpr-info.eu.

Because the higher-tier percentage cap scales with global turnover, a small business and a multinational platform can commit an identical Article 32 security failure and land on very different fine amounts, even inside the same lower tier. A EUR 10 million business with a lower-tier violation is effectively capped near the flat EUR 10 million figure, while 2% of a platform the size of Meta's global revenue runs into the hundreds of millions. Keeping a privacy policy current, with an accurate description of the technical and organizational measures in place, is itself evidence under Article 83(2)(d) and can reduce the "degree of responsibility" a regulator assigns. You can generate a GDPR-ready privacy policy that documents those measures alongside legal basis and retention periods, the same disclosures regulators check first.

For how this two-tier structure plays out across GDPR fines generally, not just breach cases, see our companion piece on the average GDPR fine.

What is the biggest fine ever tied to a confirmed data breach?

The largest confirmed GDPR fine directly tied to a single data breach is EUR 265 million, issued by Ireland's Data Protection Commission (DPC) against Meta Platforms Ireland Limited on 25 November 2022. The inquiry, covering the period 25 May 2018 to September 2019, concerned Facebook Search, Facebook Messenger's contact importer, and Instagram's contact importer tools, and it followed the April 2021 discovery that a dataset covering 533 million Facebook users had been posted for free on a hacking forum. The DPC found Meta had violated Article 25(1) and 25(2), the data-protection-by-design-and-default requirements, rather than the security or notification articles directly.

A second Meta decision, announced 17 December 2024, fined the company EUR 251 million over a breach reported by Meta itself in September 2018: attackers exploited a flaw in the video-upload feature combined with the "View As" tool to generate access tokens for roughly 29 million accounts worldwide, about 3 million of them in the EU/EEA. That decision is the clearest public example of a regulator pricing out each violated article separately.

How Meta's EUR 251 million breach fine breaks down by article 130M110M8M3MArt. 25(1), design defaults130MArt. 25(2), minimization defaults110MArt. 33(3), breach notification gaps8MArt. 33(5), documentation failures3MEUR 251Mtotal fine

Figure 2: How the EUR 251 million Meta fine splits across four GDPR articles. Source: Data Protection Commission Ireland, 17 December 2024 decision.

Of the EUR 251 million total, EUR 130 million was assigned to Article 25(1) and EUR 110 million to Article 25(2), the same design-and-default provisions as the 2022 case, while the breach-notification articles, 33(3) and 33(5), accounted for a combined EUR 11 million. That split is instructive: even in a case explicitly about a breach, most of the fine value came from how the underlying system was designed, not from how the notification paperwork was handled.

Why did British Airways' proposed GBP 183 million fine drop to GBP 20 million?

The UK's Information Commissioner's Office (ICO) gives the clearest public example of Article 83's factors actually reshaping a fine after the fact. In July 2019, the ICO issued a notice of intent to fine British Airways GBP 183.39 million over a 2018 breach in which attackers injected card-skimming code (a Magecart-style attack) into BA's website, compromising the personal and payment data of about 400,000 customers. That figure was calculated as 1.5% of BA's 2017 annual revenue, an early methodology the ICO later abandoned.

British Airways: proposed fine vs final fine British Airways, 2018 breach (GBP millions)20Mbar = actual, tick = target

Figure 3: The ICO's proposed fine against the amount British Airways actually paid. Source: ICO enforcement notice, 16 October 2020.

The final penalty, issued 16 October 2020, was GBP 20 million, a reduction of about 89%. The ICO's published reasoning set a new starting figure of GBP 30 million under its revised methodology, then cut GBP 6 million for mitigating security steps BA had taken after the breach, and a further GBP 4 million under its policy on financial hardship during the COVID-19 pandemic. The underlying Article 32 security failure was not in dispute; only the amount changed, and only after the case moved through the same aggravating-and-mitigating framework described above.

Marriott International's breach fine followed a similar shape. The ICO fined Marriott roughly GBP 18.4 million in October 2020 over a Starwood guest-reservation database that had been compromised since 2014, discovered after Marriott's 2016 acquisition of Starwood and disclosed in November 2018. As with BA, the Article 32 finding centered on inadequate security due diligence rather than a novel legal theory.

What happens if a company reports a breach late?

A fine can follow a paperwork failure even when the underlying breach itself is small. Ireland's DPC fined Twitter International Company EUR 450,000 on 15 December 2020, the first cross-border GDPR fine coordinated through the one-stop-shop mechanism, for violating Article 33(1) and 33(5): a bug that had exposed some users' protected tweets was reported internally in December 2018 but not properly notified to the DPC or adequately documented until weeks later. No user data was confirmed to have been misused; the fine was for the notification failure itself.

Figure 4: When each landmark breach-tied GDPR fine was issued. Source: ICO enforcement notices; Data Protection Commission Ireland press releases, 2020 to 2024.

Article 33's 72-hour notification clock starts when a controller becomes "aware" of a breach, not when the investigation concludes, and Article 33(5) separately requires documenting every breach, even ones judged low-risk enough not to require notification at all. The Twitter case shows that documentation gap can be fined on its own, independent of anything the breach actually exposed.

How do breach-tied fines compare to each other?

CompanyFineYearRegulatorPrimary article
Meta Platforms IrelandEUR 265 million2022Ireland DPCArt. 25(1), 25(2)
Meta Platforms IrelandEUR 251 million2024Ireland DPCArt. 25(1), 25(2), 33(3), 33(5)
British AirwaysGBP 20 million2020ICO (UK)Art. 32
Marriott InternationalGBP 18.4 million2020ICO (UK)Art. 32
Twitter InternationalEUR 450,0002020Ireland DPCArt. 33(1), 33(5)

Source: Data Protection Commission Ireland; UK Information Commissioner's Office.

Meta's two breach-related fines add up to roughly EUR 516 million, which works out to about 8.4% of the CMS Enforcement Tracker Report's EUR 6.11 billion cumulative GDPR total as of its 2026 edition, a meaningful share for just two decisions out of more than 2,685 documented cases. That concentration mirrors the pattern our biggest GDPR fines post found across GDPR enforcement generally: a handful of platform-scale decisions account for a disproportionate share of every euro ever collected.

The Bottom Line

The 443-a-day notification pace shows the raw pipeline into GDPR breach enforcement is busier than at any point since 2018, but the fines this post traced show volume is not what drives the final number. British Airways and Marriott were fined for the same underlying failure, inadequate security under Article 32, and both saw their proposed penalties cut sharply once mitigating factors were weighed. Meta's two fines show that even in decisions explicitly about a breach, the biggest dollar amounts traced back to how systems were designed under Article 25, not to the notification articles most people associate with breach law. Twitter's case is the counterpoint: a EUR 450,000 fine for a notification delay, with no confirmed data misuse at all. The practical read for any site handling personal data is that Article 32's security measures and Article 33's 72-hour clock are two separate compliance obligations, and a regulator will fine a gap in either one on its own terms. For the full picture of how GDPR fines total up across every violation type, not just breaches, see our GDPR fines overview.

Frequently Asked Questions

How many GDPR data breach notifications are reported each day? An average of 443 notifications a day between 28 January 2025 and 27 January 2026, a 22% increase on the prior year's 363 a day, according to DLA Piper's GDPR Fines and Data Breach Survey published in January 2026. It is the first time the daily average has passed 400 since GDPR took effect in May 2018.

What GDPR articles apply to a data breach? Article 32 requires appropriate technical and organizational security measures, Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a breach, and Article 34 requires notifying affected individuals when the breach creates a high risk to their rights. All three sit in GDPR's lower fine tier under Article 83(4): up to EUR 10 million or 2% of global annual turnover, whichever is higher.

What is the biggest fine ever tied to a confirmed data breach? The EUR 265 million fine against Meta Platforms Ireland Limited, issued by Ireland's Data Protection Commission on 25 November 2022 over a 2019 to 2021 data-scraping incident that exposed 533 million users' data, is the largest confirmed GDPR fine tied to a specific breach as of 2026. Meta's second breach fine, EUR 251 million in December 2024 over a 2018 breach, ranks close behind.

Why did British Airways' fine drop from GBP 183 million to GBP 20 million? The ICO's original 2019 notice proposed GBP 183.39 million, calculated as 1.5% of British Airways' 2017 revenue under an early draft methodology. The final October 2020 penalty of GBP 20 million reflected a recalculated starting figure, a GBP 6 million reduction for mitigating security steps BA had taken, and a further GBP 4 million reduction tied to the airline's COVID-19 financial hardship, a cut of about 89%.

Where the Numbers Come From

  1. DLA Piper. (2026). "GDPR Fines and Data Breach Survey: January 2026." Average of 443 breach notifications a day for the period 28 January 2025 to 27 January 2026, up 22% from 363 a day the prior year; cumulative fines EUR 7.1 billion since 25 May 2018.
  2. Data Protection Commission Ireland. (2022). "Data Protection Commission Announces Decision in Facebook 'Data Scraping' Inquiry." EUR 265 million fine, decision dated 25 November 2022, covering the period 25 May 2018 to September 2019.
  3. Data Protection Commission Ireland. (2024). "Irish Data Protection Commission Fines Meta EUR251 Million." Decision dated 17 December 2024, over a breach reported by Meta in September 2018 affecting roughly 29 million accounts globally.
  4. Data Protection Commission Ireland. (2020). "Data Protection Commission Fines Twitter International Company EUR450,000." Decision dated 15 December 2020, for breaching Article 33(1) and 33(5).
  5. Information Commissioner's Office (UK). (2020). "British Airways Enforcement Notice." Final penalty GBP 20 million issued 16 October 2020, reduced from a GBP 183.39 million notice of intent issued in July 2019.
  6. Information Commissioner's Office (UK). (2020). "Marriott International Inc Enforcement Notice." Penalty of roughly GBP 18.4 million issued 30 October 2020, over a Starwood guest-database breach disclosed in November 2018.
  7. gdpr-info.eu. "Art. 83 GDPR, General Conditions for Imposing Administrative Fines." Eleven-factor list under Article 83(2); two-tier caps under Article 83(4) and 83(5).
  8. CMS Law. (2026). "GDPR Enforcement Tracker Report 2025/2026, Numbers and Figures." 2,685 documented fines, EUR 6.11 billion cumulative, cutoff 1 March 2026.

Note: All figures verified as of September 2026. The Marriott penalty amount is drawn from consistent public reporting of the ICO's 30 October 2020 decision rather than a directly scraped ICO page; breach-notification volumes and cumulative fine totals are refreshed at least twice a year to track new DLA Piper and CMS report editions.