Missing or inadequate privacy notices fall under a specific, named GDPR violation category, and it is not a rare one: "insufficient fulfilment of information obligations" ranks 5th of the 9 violation types tracked in CMS Law's GDPR Enforcement Tracker Report 2026, which recorded 2,685 fines worth EUR 6.11 billion through its 1 March 2026 cutoff. The single largest fine built on transparency failures remains WhatsApp Ireland's EUR 225 million penalty from 2021.
That category covers exactly what its name suggests: a controller that never publishes a privacy notice, and a controller that publishes one missing a required disclosure, are assessed under the same rule. Below is where this violation type ranks against the other eight CMS tracks, what a compliant notice has to say under Articles 13 and 14, the two confirmed enforcement cases that anchor this category, and how total GDPR enforcement has grown across three consecutive report editions.
Where do missing privacy policy fines rank among GDPR violations?
CMS Law's GDPR Enforcement Tracker Report 2026 groups every recorded fine into one of nine violation categories. Its own report language states outright that "insufficient legal basis for data processing" is the most common category and that "insufficient fulfilment of information obligations," the category covering missing, incomplete, or misleading privacy notices under Articles 12 through 14, ranks fifth. CMS does not publish an exact percentage or case count for each individual category in its public summary, so treat the ranking below as a relative frequency order, not a set of measured shares.
| Rank | Violation category (CMS Enforcement Tracker Report 2026) |
|---|---|
| 1 | Insufficient legal basis for data processing |
| 2 | Insufficient technical and organisational security measures |
| 3 | Non-compliance with general data processing principles |
| 4 | Insufficient fulfilment of data subjects' rights |
| 5 | Insufficient fulfilment of information obligations (missing or inadequate privacy notices) |
| 6 | Insufficient cooperation with the supervisory authority |
| 7 | Insufficient fulfilment of data breach notification obligations |
| 8 | Lack of appointment of a data protection officer |
| 9 | Insufficient data processing agreement |
Ranking fifth of nine still means information-obligation failures are a mainstream enforcement target, ahead of four other categories including missed breach-notification deadlines and missing DPO appointments. A site owner who assumes regulators only chase security breaches or unlawful ad tracking is missing a category that applies to nearly every site that collects any personal data at all, from a contact form to an ecommerce checkout. You can generate a privacy policy built to cover these disclosures, including the controller identity, legal basis, and retention statements Article 13 requires.
What counts as a missing or inadequate privacy policy under GDPR?
Article 13 lists what a controller must tell people at the point personal data is collected: the controller's identity and contact details, the purposes and legal basis for processing, who the data is shared with, how long it is kept, and the data subject's rights, including the right to complain to a supervisory authority. Article 14 sets the same requirements for data collected from a source other than the individual. A privacy policy that omits any of these, or states them so vaguely that a reader cannot act on them, is treated as a violation even if a policy technically exists on the page.
Figure 1: The compliance test regulators effectively apply before citing Article 13 or 14. Source: GDPR Articles 12 to 14, as categorized in CMS Law's GDPR Enforcement Tracker Report 2026.
Italy's data protection authority, the Garante, applied close to this exact test to Deliveroo Italy in a 22 July 2021 enforcement order. The decision found the company's rider-facing privacy policy breached Article 13(2)(a) because it described data retention with an unspecific formula rather than a stated period, and breached Article 13(2)(f) because it did not give riders meaningful information about the automated logic used to prioritize shift allocation. Both failures sit inside the same information-obligations category this post is built around, and both were about content the policy got wrong, not a complete absence of any privacy notice.
What is the biggest fine for a privacy policy or transparency failure?
The largest confirmed GDPR fine built specifically on transparency failures is EUR 225 million, issued against WhatsApp Ireland Limited by Ireland's Data Protection Commission on 2 September 2021. The DPC's own announcement describes the inquiry as having examined "whether WhatsApp has discharged its GDPR transparency obligations with regard to the provision of information and the transparency of that information to both users and non-users" of its service. The European Data Protection Board directed the DPC to raise the fine from its original, much lower proposal before the final figure was issued.
WhatsApp's case shows the ceiling on this category is not small. Article 83's statutory caps apply the same way to an information-obligations violation as to any other GDPR breach: up to EUR 20 million or 4% of global annual turnover, whichever is higher, once a violation is confirmed. A EUR 225 million fine sits well inside that percentage-of-turnover cap for a company the size of Meta, WhatsApp's parent; a small business with a materially deficient privacy policy faces the same legal category of violation, just against a far smaller revenue base for the percentage calculation to apply to.
How has overall GDPR enforcement grown, and where does this category sit within it?
Total recorded GDPR fine cases have climbed with every CMS Law report edition: 1,576 cases at the 2023 five-year mark, 2,225 at the 2024 six-year mark, and 2,685 by the 2026 report's 1 March cutoff, a 70% increase across three editions. Cumulative fine value has grown even faster over the same period, and our companion post on total GDPR fines and enforcement trends breaks down that euro-value growth and the biggest individual fines across every violation category, not just information obligations.
Figure 2: Total recorded GDPR fine cases at each CMS Enforcement Tracker Report cutoff. Source: CMS Law GDPR Enforcement Tracker Report, 2023, 2024, and 2026 editions.
Figure 3: Milestone enforcement events and report cutoffs behind this category's ranking. Source: Data Protection Commission Ireland, Garante per la protezione dei dati personali, CMS Law GDPR Enforcement Tracker Report editions.
Figure 4: Cumulative GDPR fine value in euros at the same three report cutoffs, for comparison against the case-count growth in Figure 2. Source: CMS Law GDPR Enforcement Tracker Report, 2023, 2024, and 2026 editions.
Country-level enforcement is concentrated, though CMS's public summary only confirms an exact case count for the top country.
| Country | GDPR fine-count standing |
|---|---|
| Spain | Most fines of any country, 1,048 recorded cases, its 5th consecutive year at the top (CMS Enforcement Tracker Report 2026) |
| Italy | Second-most fines by count (CMS's 2024 report; exact 2026 count not published in the public summary) |
| Romania | Third-most fines by count (CMS's 2024 report; exact 2026 count not published in the public summary) |
| Ireland | Highest cumulative fine value overall, roughly EUR 4.04 billion, despite far fewer individual cases |
Spain's volume comes largely from smaller, high-frequency cases, including many information-obligation and consent-related complaints against individual businesses. Ireland's value comes from a handful of very large platform fines, mostly outside the information-obligations category, because it is the lead regulator for Meta, TikTok, and LinkedIn under GDPR's one-stop-shop mechanism.
The Bottom Line
Missing or inadequate privacy notices are not a niche GDPR risk. CMS Law's 2026 report puts this category 5th of 9 by frequency, ahead of missed breach-notification deadlines and missing DPO appointments, and the WhatsApp case shows the ceiling on a transparency-specific fine reaches nine figures once a large platform is involved. For most sites the practical exposure looks like Deliveroo Italy's case rather than WhatsApp's: a policy that exists but omits a required element, such as a concrete retention period or a clear statement of legal basis. Two related angles worth tracking as this cluster grows are how these fines land specifically on small businesses with limited compliance budgets, and how information-obligation fines compare with the far larger fines tied to data breach notification failures; both are separate report categories from the one covered here. Reviewing a privacy policy against the Article 13 checklist above, or generating one built to include every required disclosure, addresses the exact category this post is about.
Frequently Asked Questions
Can a business be fined under GDPR just for not having a privacy policy? Yes. GDPR Articles 12 through 14 require organizations to give data subjects specified information about their data processing, and failing to provide that information at all is treated the same as providing it inadequately. CMS Law's GDPR Enforcement Tracker Report 2026 tracks this as "insufficient fulfilment of information obligations," the fifth most common of nine violation categories among 2,685 recorded fines through 1 March 2026.
What is the biggest GDPR fine for a privacy policy or transparency violation? EUR 225 million, issued against WhatsApp Ireland Limited by Ireland's Data Protection Commission on 2 September 2021, after the European Data Protection Board directed the DPC to raise its original proposed fine. The case examined whether WhatsApp met its GDPR transparency obligations toward both users and non-users of its service.
How common are fines tied to missing or inadequate privacy notices compared with other GDPR violations? They rank 5th of the 9 violation categories CMS Law tracks in its GDPR Enforcement Tracker Report 2026, behind insufficient legal basis, inadequate security measures, non-compliance with general processing principles, and failures to fulfill data subjects' rights, across 2,685 recorded fines worth EUR 6.11 billion as of 1 March 2026.
What does a GDPR-compliant privacy policy need to disclose? At minimum, Articles 13 and 14 require the identity of the data controller, the purposes and legal basis for processing, who receives the data, how long it is kept, and the data subject's rights, including the right to lodge a complaint with a supervisory authority. Italy's Garante cited Deliveroo Italy's privacy policy in a 22 July 2021 enforcement order in part because it used vague retention language instead of a stated time period.
Where the Numbers Come From
- CMS Law. (2026). "GDPR Enforcement Tracker Report 2026, Numbers and Figures." 2,685 fines, EUR 6.11 billion cumulative, nine violation categories including "insufficient fulfilment of information obligations" ranked fifth, cutoff 1 March 2026.
- Data Protection Commission Ireland. "Data Protection Commission Announces Decision in WhatsApp Inquiry." EUR 225 million fine over GDPR transparency obligations, 2 September 2021.
- Garante per la protezione dei dati personali. Ordinanza ingiunzione n. 285 concerning Deliveroo Italy s.r.l., finding breaches of Article 13(2)(a) and 13(2)(f) GDPR, 22 July 2021.
- DLA Piper. (2026). "GDPR Fines and Data Breach Survey: January 2026." Cumulative total EUR 7.1 billion since 25 May 2018, EUR 1.2 billion issued in 2025, data through 10 January 2026.
- enforcementtracker.com. Live GDPR fines database, 3,202 recorded actions, EUR 6.31 billion cumulative, checked July 2026.
- CMS Law. (2023). "Fifth Anniversary of the GDPR: Fines Totalling EUR 2.7 Billion." 1,576 cases, cutoff 1 March 2023.
- CMS Law. (2024). "Six Years of GDPR: Fines Totalling EUR 4.5 Billion." 2,225 cases (2,086 with complete details), Spain, Italy, and Romania as the top three countries by case count, cutoff 1 March 2024.
Note: All figures verified as of July 2026. The Deliveroo Italy decision's Article 13 findings are confirmed directly from the Garante's published order; this post does not state the case's fine amount because it could not be independently confirmed at the time of writing. Case counts and the CMS violation-category ranking are refreshed at least twice a year to track new CMS Enforcement Tracker Report editions.