Spain, the EU country with the most GDPR enforcement activity, has issued an average fine of roughly EUR 76,985 per case across 1,284 recorded fines from 2021 through 2024, according to CMS Law's GDPR Enforcement Tracker Report 2026. That is about 30 times smaller than the same report's EU-wide average of EUR 2,277,122, a gap driven almost entirely by a small number of billion-euro fines against household-name platforms.

Regulators do not publish an official breakdown of GDPR fines by company size, so no tracker can say precisely how many fines land on small businesses specifically. What the year-by-year enforcement data does show is the scale of the typical fine, and that scale looks nothing like the headlines. Below is what Spain's own numbers say, how they compare to the mega-fines skewing the EU-wide mean, and what the most common violation triggers actually are.

Spain's average GDPR fine is a fraction of the EU-wide average EUR 76,985 average GDPR fine in Spain,2021 through 2024 (CMS 2026)

How big is the average GDPR fine, really?

The EU-wide average across every recorded GDPR fine is EUR 2,277,122, per CMS Law's GDPR Enforcement Tracker Report 2026, which tracked 2,685 confirmed fines totaling EUR 6.11 billion through its 1 March 2026 cutoff. That average is not a typical case; it is pulled sharply upward by a handful of enormous penalties against a handful of large platforms.

Spain tells a different story. As the country with the most confirmed enforcement actions, its year-by-year totals give the clearest picture of what a fine actually looks like on the ground: 258 fines worth EUR 35.07 million in 2021, 378 fines worth EUR 20.78 million in 2022, 367 fines worth EUR 29.82 million in 2023, and 281 fines worth EUR 13.18 million in 2024.

YearFines issuedTotal fine value (EUR)Average per fine (EUR)
202125835,074,800135,948
202237820,775,36154,961
202336729,817,41081,248
202428113,180,80046,908
2021 to 2024 combined1,28498,848,37176,985
GDPR fines issued in Spain per year (CMS Law 2026) 01002003004002582021378202236720232812024

Figure 1: Spain issues hundreds of confirmed GDPR fines every year. Source: CMS Law, GDPR Enforcement Tracker Report 2026, Spain country data.

Every single year in that table lands closer to five or six figures than to seven or eight. A small business that gets fined does not usually see a headline; it sees a bill in the tens of thousands of euros. A working privacy policy generator that keeps disclosures current is a low-cost way to stay out of that column entirely.

Why does the EU-wide average look so much bigger?

The EU-wide average is skewed because a tiny number of fines are enormous. The 10 largest confirmed GDPR fines on record, all against Meta, TikTok, LinkedIn, Uber and WhatsApp, add up to EUR 4.21 billion, about 69% of the report's entire EUR 6.11 billion cumulative total, according to CMS Law's GDPR Enforcement Tracker Report 2026. Those 10 cases are less than 0.4% of the 2,685 fines the report counted.

That leaves the other 2,675 recorded fines, more than 99.6% of all cases, sharing the remaining 31% of total value. For a fuller breakdown of how the EUR 2.28 million average fine is calculated and why it keeps climbing, see our companion post on the average GDPR fine; for the full list of the record-setting cases pulling that average up, see our post on the biggest GDPR fines on record.

Share of EUR 6.11 billion in confirmed GDPR fines (2018-2026) 69%31%Top 10 largest fines69%All other 2,675 fines31%

Figure 2: A small handful of mega-fines account for most of the money, but almost none of the case count. Source: CMS Law, GDPR Enforcement Tracker Report 2026.

Ten cases moving 69% of the total value means the other side of that split, the vast majority of GDPR enforcement by count, is made up of fines far closer to Spain's scale than to Meta's.

Which country fines the most, and is that typical?

Spain has issued more confirmed GDPR fines than any other country, 1,048 recorded cases as of CMS Law's 1 March 2026 cutoff, per the GDPR Enforcement Tracker Report 2026. Ireland, by contrast, has issued far fewer individual fines but holds the largest cumulative value at roughly EUR 4.04 billion, according to DLA Piper's GDPR Fines and Data Breach Survey published January 2026, because Ireland's Data Protection Commission regulates Meta, TikTok and LinkedIn under GDPR's one-stop-shop rule. For the full multi-tracker breakdown of how these cumulative totals are counted, see our post on total GDPR fines since 2018.

ScopeFines countedTotal fine valueAverage fine
Spain, 2021 to 20241,284EUR 98.85 millionEUR 76,985
EU-wide, cutoff 1 March 20262,685EUR 6.11 billionEUR 2,277,122
Total GDPR fine value in Spain per year, EUR millions (CMS Law 2026) 010203040M202120222023202413.2M

Figure 3: Spain's total yearly fine value has trended down since 2021 even as case counts stayed high. Source: CMS Law, GDPR Enforcement Tracker Report 2026, Spain country data.

More cases and a shrinking total value points to the same conclusion as the average-fine math: Spain's regulator is issuing a high volume of comparatively modest fines, not a smaller number of large ones.

What actually triggers a GDPR fine a small business could face?

Insufficient legal basis for processing personal data is the single most common violation category behind a GDPR fine, according to CMS Law's GDPR Enforcement Tracker Report 2026, followed by non-compliance with general data processing principles and insufficient technical or organizational security measures. None of the three most common triggers require the scale of a global platform to happen; a small business that processes customer data without a documented legal basis or with weak account security can trip the same rule Meta did.

Figure 4: The three most common violation categories behind a GDPR fine, ranked by case volume. Source: CMS Law, GDPR Enforcement Tracker Report 2026.

Warning

What this data cannot tell you: regulators publish fine amounts and violation categories, not the fined organization's employee count or revenue. Every figure in this post about "small-scale" fines refers to the size of the penalty, not confirmed evidence that the recipient was a small business. Treat the comparison as a scale proxy, not a literal SME breakdown.

How has enforcement scaled since GDPR took effect?

Figure 5: The largest fines make headlines, but the case count behind them has grown every year. Source: CMS Law, GDPR Enforcement Tracker Report 2026; Irish Data Protection Commission press releases.

The mega-fines above are real and they are rising, but so is the quieter enforcement volume underneath them. Our post on how small businesses handle privacy compliance covers the documentation and training gap that leaves smaller firms more exposed to exactly the kind of legal-basis and security violations behind most of Spain's case volume.

The Bottom Line

The average GDPR fine a small business is realistically likely to encounter looks nothing like the EUR 1.2 billion Meta case or the EUR 530 million TikTok case. It looks like Spain's own numbers: somewhere in the tens of thousands of euros, triggered most often by a missing legal basis for processing personal data rather than a headline-grabbing data transfer dispute. That EUR 76,985 average across 1,284 Spanish cases from 2021 through 2024 is roughly 30 times smaller than the EU-wide average of EUR 2,277,122, and it is a far more useful benchmark for a small business owner than the billion-euro cases dominating the news cycle. Keeping a privacy policy generated and current directly addresses the single most common trigger, insufficient legal basis, before it ever becomes a case number in next year's report.

Frequently Asked Questions

What is the average GDPR fine a small business might face? Regulators do not publish GDPR fines broken down by company size, but the closest real-world proxy is Spain, the country with the most enforcement activity: its average fine works out to about EUR 76,985 across 1,284 cases from 2021 through 2024, according to CMS Law's GDPR Enforcement Tracker Report 2026, a scale far closer to what a small business could plausibly pay than the billion-euro fines against Meta or TikTok.

How many GDPR fines are issued in a typical year? Spain alone issued 281 confirmed fines in 2024, and 367 in 2023, according to CMS Law's GDPR Enforcement Tracker Report 2026. Across every country the tracker covers, the report counted 2,685 cumulative confirmed fines through its 1 March 2026 cutoff.

Do most GDPR fines go to big tech companies? No, not by count. The 10 largest confirmed GDPR fines, issued against Meta, TikTok, LinkedIn, Uber and WhatsApp, total EUR 4.21 billion, about 69% of the report's EUR 6.11 billion cumulative value, but they represent only 10 of 2,685 recorded cases, less than half a percent of all enforcement activity.

Which country issues the most GDPR fines? Spain, with 1,048 recorded cases as of CMS Law's 1 March 2026 cutoff, more than any other country tracked in the GDPR Enforcement Tracker Report 2026, even though its average fine is far smaller than the report's overall average.

Where the Numbers Come From

  1. CMS Law. (2026). "GDPR Enforcement Tracker Report 2026, Numbers and Figures." 2,685 confirmed fines, EUR 6.11 billion cumulative, average EUR 2,277,122, Spain 1,048 cases, cutoff 1 March 2026, published 21 May 2026.
  2. CMS Law. (2026). "GDPR Enforcement Tracker Report 2026, Spain." Year-by-year fine counts and totals: 258 fines/EUR 35,074,800 (2021), 378 fines/EUR 20,775,361 (2022), 367 fines/EUR 29,817,410 (2023), 281 fines/EUR 13,180,800 (2024), over EUR 40 million reported for 2025.
  3. enforcementtracker.com. Live GDPR fines database, 3,202 recorded actions, EUR 6.31 billion cumulative, checked July 2026.
  4. DLA Piper. (2026). "GDPR Fines and Data Breach Survey: January 2026." Cumulative total EUR 7.1 billion since 25 May 2018, Ireland cumulative EUR 4.04 billion, data through 10 January 2026.

Note: All figures verified as of July 2026. Spain's 2025 total was still preliminary at last check and will be revised once CMS Law publishes a full-year figure.