France's data protection authority, the CNIL, fined Google EUR 325 million in September 2025 for displaying advertising between Gmail users' emails without their consent, according to CNIL's own enforcement decision published that month. It is the largest confirmed fine tied to marketing communications since GDPR took effect in May 2018, more than four times Italy's EUR 79.1 million telemarketing fine against Enel Energia, the next-largest case on record.

Most of the biggest marketing and spam-related penalties do not come from a single, uniform "GDPR marketing fine" category. They come from a patchwork of national direct-marketing and ePrivacy laws that regulators enforce alongside GDPR's consent principles, in decisions that frequently bundle email, SMS, and phone marketing together. Below is what the largest confirmed cases actually show, followed by an honest look at which law is doing the real work in each one.

CNIL fined Google EUR 325 million over unconsented Gmail advertising emails and cookies, September 2025 EUR 325M CNIL fine tied to unconsentedGmail ad emails, September 2025

How much was Google fined for marketing emails?

Google was fined EUR 325 million by the CNIL on 1 September 2025, split between EUR 200 million against Google LLC and EUR 125 million against Google Ireland Limited. The decision covered two things at once: displaying promotional emails inside Gmail's "Promotions" and "Social" tabs without the prior consent required for direct marketing under French law, and inadequate cookie consent during account creation. CNIL did not itemize how much of the EUR 325 million relates to each violation, so the figure should be read as covering both, not as a pure email-spam penalty.

The regulator said roughly 74 million Gmail accounts tied to French users were affected, with about 53 million of them exposed to the unconsented ad emails specifically. Google has six months from the decision to fix its consent flow, with a penalty of EUR 100,000 per day for continued non-compliance after that window. The same CNIL decision also cited cookie-consent failures alongside the email issue; see our GDPR cookie fines case data for 2025 for how that EUR 325 million splits against the EUR 150 million SHEIN cookie fine issued the same day.

CaseFine amountYearPrimary channel
Google (CNIL, France)EUR 325 million2025Gmail promotional emails, plus cookies
Enel Energia (Garante, Italy)EUR 79.1 million2024Telemarketing calls, security failure
Enel Energia (Garante, Italy)EUR 26.5 million2022Telemarketing calls without consent
Wind Tre (Garante, Italy)EUR 16.7 million2020SMS, email, and phone marketing

If your site sends any marketing email to EU users, the consent standard the CNIL applied here, a clear opt-in before the first promotional message, not a pre-ticked box or a buried opt-out, is the one worth checking your own flow against. A privacy policy generator built for GDPR can keep marketing-consent disclosures aligned with that standard as the rules keep tightening.

Which telemarketing fines are largest in the EU?

Outside the Google case, Italy's Garante has issued the largest telemarketing-specific fines in the EU, all against energy and telecom companies. Enel Energia was fined EUR 79.1 million on 29 February 2024, the Garante's largest fine to date, after unauthorized sales agents exploited security shortcomings in Enel's customer database to activate at least 9,300 contracts through unwanted calls. Two years earlier, in January 2022, the same authority fined Enel Energia EUR 26.5 million for a separate pattern of promotional calls made without consent to numbers on Italy's opt-out registry, some using pre-recorded messages.

Largest marketing and telemarketing privacy fines by amount 0100200300400M325Google (2025)79.1Enel Energia (2024)26.5Enel Energia (2022)16.7Wind Tre (2020)11.5Eni Gas e Luce(2019-20)

Figure 1: The five largest confirmed marketing and telemarketing-related privacy fines, by amount. Sources: CNIL (2025), Garante per la protezione dei dati personali (2022, 2024), enforcementtracker.com.

Wind Tre received a EUR 16.7 million fine in July 2020 after hundreds of people reported unwanted SMS messages, emails, phone calls, and automated calls sent without prior authorization, on top of failing to let people easily withdraw marketing consent. Eni Gas e Luce was fined twice for unlawfully concluded telemarketing contracts, with the second of the two fines confirmed at EUR 3 million in a decision dated 11 December 2019, contributing to a combined total of roughly EUR 11.5 million across both actions. This mirrors the broader enforcement pattern documented in our GDPR fines totals for 2026, where insufficient legal basis for processing remains the single most-cited violation category across all case types, not just marketing.

Cumulative fine totals rarely stay flat once a regulator starts working through a sector. Enel Energia's second fine, three years after its first, shows that repeat violations in the same company can produce a much larger penalty the second time around.

Is a marketing-email fine really a GDPR fine?

Not always as the sole legal basis, and this is the part most secondhand coverage skips. Direct marketing in the EU is governed by the ePrivacy Directive, which each member state implements through its own national law: France's Postal and Electronic Communications Code (CPCE) Article L.34-5 for commercial prospecting, Italy's Privacy Code for telemarketing consent, and the UK's Privacy and Electronic Communications Regulations (PECR) for marketing calls, texts, and emails. GDPR's Article 83 penalty framework sits alongside these laws rather than replacing them, and a single enforcement decision often cites both at once.

Figure 2: The legal-basis test regulators apply before a marketing-communication fine, and where GDPR does or does not enter the decision. Source: CPCE Art. L.34-5, UK PECR Regulation 21, GDPR Article 6.

The UK's Easylife Limited case shows the split clearly. The ICO issued two separate penalties on 6 October 2022: a GBP 1.35 million fine under UK GDPR for using 145,000 customers' purchase histories to infer health conditions without a lawful basis, later reduced to GBP 250,000 on appeal, and a wholly separate GBP 130,000 fine under PECR for making 1,345,732 unsolicited marketing calls to numbers on the Telephone Preference Service between 1 and 19 August 2020. Only the second penalty was actually about the marketing calls themselves, and it was not appealed.

Easylife's two separate penalties: data protection fine vs marketing-calls fine, GBP thousands Original UK GDPR fine1,350KUK GDPR fine after appeal250KSeparate PECR marketing-calls fine130K

Figure 3: Easylife's data-protection fine and its marketing-calls fine were two different penalties under two different laws. Source: ICO enforcement decision, 6 October 2022.

Calling every one of these a "GDPR fine" is not wrong in the loose journalistic sense many trackers use, since GDPR consent standards usually inform how national marketing laws are applied. But when the legal basis actually matters, for compliance planning or for citing a number precisely, the marketing-specific penalty and the general data-protection penalty are often two different line items.

How have marketing and telemarketing fines grown over time?

The pattern across every confirmed case is the same: penalties have gotten larger, not smaller, as regulators have worked through repeat offenders and bigger platforms.

Figure 4: Confirmed marketing and telemarketing fine milestones, largest cases only. Sources: Garante, CNIL, ICO, enforcementtracker.com.

Share of five largest marketing-fine euros, by case 325M79.1M26.5M16.7M11.5MGoogle, 2025325MEnel Energia, 202479.1MEnel Energia, 202226.5MWind Tre, 202016.7MEni Gas e Luce, 2019-2011.5M459Mcombined, 5 cases

Figure 5: How the five largest confirmed cases split the combined EUR 458.8 million total. Sources: as above.

The 2025 Google decision alone accounts for more than 70% of the combined value of these five cases, which says less about email marketing specifically and more about the scale difference between a global platform and a national energy retailer. Regulators are not slowing down on either type of target.

The Bottom Line

The single largest confirmed penalty tied to marketing communications is CNIL's EUR 325 million fine against Google in September 2025, and it did not stand alone: Italy's Garante has now fined one company, Enel Energia, twice for telemarketing violations totaling more than EUR 105 million across two decisions, and the UK's Easylife case shows regulators are willing to fine the same company under two separate laws for two separate failures in one investigation. None of these fines are purely about "spam" in the informal sense; they are about consent records that did not hold up, whether the channel was email, SMS, or a phone call. A privacy policy and consent flow that documents opt-in marketing consent clearly, with an easy way to withdraw it, is the practical answer to every case in this post.

Frequently Asked Questions

What is the largest GDPR-related fine for marketing emails? EUR 325 million, imposed by France's CNIL against Google in September 2025 for displaying unconsented advertising emails to Gmail users, alongside cookie-consent violations found in the same decision.

Are marketing-email fines actually issued under the GDPR? Not always as the sole legal basis. Several of the largest cases, including Google's EUR 325 million CNIL fine and Wind Tre's EUR 16.7 million Garante fine, rest primarily on national direct-marketing and ePrivacy laws, such as France's CPCE Article L.34-5 or the UK's PECR, which regulators apply alongside GDPR consent principles rather than under GDPR's Article 83 penalty framework alone.

What is the largest confirmed telemarketing fine in the EU? EUR 79.1 million, issued by Italy's Garante against Enel Energia in February 2024, the authority's largest fine on record, after unauthorized agents exploited security gaps in Enel's systems to run unlawful telemarketing campaigns.

How many marketing calls triggered the Easylife fine in the UK? 1,345,732 unsolicited marketing calls made to numbers registered with the Telephone Preference Service between August 1 and August 19, 2020, according to the ICO's October 2022 penalty notice, which produced a separate GBP 130,000 PECR fine on top of a GBP 1.35 million data protection fine.

Where the Numbers Come From

  1. CNIL. (2025). "Cookies and Advertisements Inserted Between Emails: GOOGLE Fined 325 Million Euros." Decision dated 1 September 2025, EUR 200M against Google LLC and EUR 125M against Google Ireland Limited.
  2. noyb.eu. (2025). "noyb Win: French DPA Fines Google EUR325 Million for Spam Emails in Gmail." Original complaint and case background.
  3. Garante per la protezione dei dati personali. (2024). "Telemarketing: il Garante privacy sanziona Enel Energia." EUR 79,107,101 fine, decision dated 29 February 2024, the Authority's largest fine to date.
  4. Garante per la protezione dei dati personali. (2022). "Telemarketing aggressivo. Il Garante privacy sanziona Enel Energia." EUR 26,513,977 fine, decision dated 16 December 2021.
  5. enforcementtracker.com. "ETid-336: GDPR Fine Against Wind Tre S.p.A." EUR 16.7 million, decision dated 13 July 2020.
  6. enforcementtracker.com. "ETid-187: GDPR Fine Against Eni Gas e Luce." EUR 3 million, decision dated 11 December 2019, second of two fines totaling roughly EUR 11.5 million.
  7. iubenda. (2022). Summary of the ICO's Easylife Limited enforcement decision, GBP 1.35 million UK GDPR fine plus GBP 130,000 PECR fine for 1,345,732 marketing calls, decision dated 6 October 2022, corroborated by freevacy.com's coverage of the March 2023 appeal that reduced the GDPR portion to GBP 250,000.

Note: All figures verified as of July 2026. The Easylife GDPR fine amount reflects the reduced GBP 250,000 figure confirmed on appeal in March 2023; the PECR marketing-calls fine of GBP 130,000 was not appealed and stands as issued. This post is refreshed at least twice a year as new DPA decisions are published.