Cumulative GDPR fines have reached roughly EUR 7.1 billion since the regulation took effect on 25 May 2018, according to DLA Piper's GDPR Fines and Data Breach Survey, published in January 2026 and covering activity through 10 January 2026. That headline number sits above the two dedicated fine-tracking databases, which report lower directly-documented totals because they count only publicly confirmed cases with a disclosed amount and date.
The gap between trackers is not a data error. It reflects a real disclosure problem in GDPR enforcement: some national authorities issue fines that never appear in a public register with a confirmed amount, so any tracker built from public case records will undercount the true total. Below is what the two most-cited public trackers show, side by side, followed by the biggest individual fines, the year-over-year trend, and the countries doing most of the enforcing.
Why do GDPR fine totals differ between trackers?
Three credible sources currently report three different cumulative totals, and all three are defensible once you know what each one counts.
| Source | Cumulative total | Cases counted | Cutoff date |
|---|---|---|---|
| DLA Piper GDPR Fines and Data Breach Survey | EUR 7.1 billion | Aggregated from regulator disclosures and law firm network reporting | 10 January 2026 |
| CMS Enforcement Tracker Report | EUR 6.11 billion | 2,685 fines | 1 March 2026 |
| enforcementtracker.com (CMS-affiliated public database) | EUR 6.31 billion | 3,202 actions | Live, checked July 2026 |
DLA Piper's figure is the highest because it draws on the firm's own network of European data protection lawyers across dozens of jurisdictions, including fines that were reported to regulators or disclosed in local proceedings but never entered a structured public database with a confirmed euro amount. The CMS Enforcement Tracker Report and its companion live database, enforcementtracker.com, are stricter: both require a publicly documented case with an amount before they add it to the count, and the two differ from each other slightly because enforcementtracker.com updates continuously while the CMS Report is a fixed-cutoff annual snapshot. Treat the EUR 7.1 billion figure as the most complete estimate and the EUR 6.11 to 6.31 billion range as the most conservative, verifiable floor.
Figure 1: Three trackers, three totals, same underlying enforcement activity. Sources: DLA Piper (Jan 2026), enforcementtracker.com (Jul 2026), CMS Enforcement Tracker Report (Mar 2026 cutoff).
What is the biggest GDPR fine ever issued?
The largest confirmed GDPR fine is EUR 1.2 billion, issued by Ireland's Data Protection Commission against Meta Platforms Ireland Limited in May 2023 over transferring EU user data to the United States without an adequate legal basis, following a binding decision from the European Data Protection Board. It remains the record as of July 2026 and is more than double the next-largest confirmed fine.
A EUR 746 million fine against Amazon Europe, issued by Luxembourg's CNPD in July 2021 over ad-personalization consent practices, was widely reported for years as the second-largest GDPR fine. That status is now unsettled: Luxembourg's administrative court upheld the fine in March 2025, but a higher Luxembourg appeals court annulled the EUR 746 million penalty in 2026, confirming that Amazon breached GDPR while sending the case back to the CNPD to reassess whether a fine is warranted and at what amount. Treat the EUR 746 million figure as under active reconsideration rather than a settled historical fine.
Figure 2: Top 5 confirmed GDPR fines by amount, excluding the disputed Amazon fine. Source: CMS Enforcement Tracker Report 2026, DPC Ireland decisions.
Figure 3: Milestone fines by year. Source: CMS Enforcement Tracker Report 2026, DPC Ireland press releases.
How have total GDPR fines grown year over year?
Cumulative fines have climbed from roughly EUR 2.77 billion at the five-year mark to roughly EUR 6.11 to 7.1 billion by the start of 2026, depending on which tracker you use. The CMS Enforcement Tracker Report's own year-over-year snapshots give the clearest consistent trend line, since each edition uses the same counting methodology against a fixed March cutoff.
Figure 4: Cumulative GDPR fines at each CMS Enforcement Tracker Report cutoff. Source: CMS Enforcement Tracker Report, 2023, 2024, and 2026 editions.
Annual enforcement has held at a high plateau rather than continuing to accelerate. DLA Piper's January 2026 survey puts 2025's total at roughly EUR 1.2 billion, broadly matching 2024's figure, and notes that more than 60% of the entire EUR 7.1 billion cumulative total has landed since January 2023. If you handle EU user data and have not reviewed your consent flows since before 2023, that statistic alone is a reason to check now: you can generate a GDPR-ready privacy policy covering the disclosures regulators check first, including legal basis, data transfers, and retention periods.
How is a GDPR fine actually calculated?
GDPR fines are not flat penalties. Article 83 sets two statutory ceilings, and regulators choose the higher one, then adjust downward or upward based on the severity, duration, and intent behind the violation.
Figure 5: The two-tier cap structure regulators apply before setting a final fine. Source: GDPR Article 83, as summarized in CMS Enforcement Tracker Report methodology notes.
Because the higher cap uses a percentage of global annual turnover, the largest possible fines apply almost exclusively to large multinational platforms. A small business with EUR 500,000 in annual revenue and a lower-tier violation faces a cap far closer to the flat EUR 10 million figure than to any percentage-based number, but regulators still scale the fine to the severity of the specific violation rather than defaulting to the cap.
Which countries and violation types drive the most fines?
Spain has issued the most individual GDPR fines of any country, with 1,048 recorded cases as of the CMS Enforcement Tracker Report 2026 cutoff. Ireland issues far fewer fines by count but holds the highest cumulative value, at EUR 4.04 billion, because Ireland's Data Protection Commission is the lead regulator for Meta, TikTok, LinkedIn, and other companies headquartered in the EU through Ireland under GDPR's one-stop-shop mechanism.
Figure 6: Ireland's share of the CMS Enforcement Tracker Report's EUR 6.11 billion cumulative total. Source: CMS Enforcement Tracker Report 2026, DLA Piper January 2026 survey.
The most common violation categories, per the CMS Enforcement Tracker Report's classification of all recorded cases, are insufficient legal basis for processing, non-compliance with general data-processing principles, and insufficient technical and organizational security measures. Those three categories account for the bulk of fines by count, though the largest individual fines by value have concentrated on unlawful international data transfers and children's data handling rather than security failures.
The Bottom Line
Every credible tracker agrees on the direction: GDPR enforcement has not slowed down, and the euro totals keep climbing even as year-over-year annual totals plateau around EUR 1.2 billion. Whether you use DLA Piper's EUR 7.1 billion estimate or the more conservative EUR 6.11 to 6.31 billion documented by CMS and enforcementtracker.com, the practical takeaway for any site handling EU user data is the same: the categories driving the most fines, insufficient legal basis, unclear processing principles, and weak security measures, are all things a current, accurate privacy policy and a defensible consent flow address directly. The biggest fines target platforms with hundreds of millions of users, but the violation categories that trigger most of the 2,685-plus recorded cases apply to sites of any size.
Frequently Asked Questions
What is the total amount of GDPR fines issued so far? Roughly EUR 7.1 billion since GDPR took effect on 25 May 2018, according to DLA Piper's GDPR Fines and Data Breach Survey published in January 2026. Two dedicated fine-tracking databases report lower directly-documented totals of EUR 6.11 billion and EUR 6.31 billion because they only count publicly confirmed cases with a disclosed amount.
What is the biggest GDPR fine ever issued? The EUR 1.2 billion fine against Meta Platforms Ireland Limited, issued by Ireland's Data Protection Commission in May 2023 over unlawful EU-to-US data transfers, remains the largest GDPR fine on record as of July 2026.
What is the average GDPR fine? About EUR 2.28 million across all recorded cases since 2018, per the CMS Enforcement Tracker Report 2026. The median fine is far lower than the average because a small number of billion-euro penalties against large tech companies skew the mean upward.
Which country has issued the most GDPR fines? Spain has issued the most individual fines, with 1,048 recorded cases per the CMS Enforcement Tracker Report 2026. Ireland has issued far fewer fines by count but the highest total value, at EUR 4.04 billion cumulative, because it regulates Meta, TikTok, and other large platforms under GDPR's one-stop-shop mechanism.
Where the Numbers Come From
- DLA Piper. (2026). "GDPR Fines and Data Breach Survey: January 2026." Cumulative total EUR 7.1 billion since 25 May 2018, data through 10 January 2026.
- CMS Law. (2026). "GDPR Enforcement Tracker Report 2026, Numbers and Figures." 2,685 fines, EUR 6.11 billion cumulative, cutoff 1 March 2026.
- enforcementtracker.com. Live GDPR fines database, 3,202 recorded actions, EUR 6.31 billion cumulative, checked July 2026.
- Data Protection Commission Ireland. (2022). "Data Protection Commission Announces Decision in Instagram Inquiry." EUR 405 million fine, 15 September 2022.
- Data Protection Commission Ireland. (2025). "Irish Data Protection Commission Fines TikTok EUR530 Million." 2 May 2025.
- Data Protection Commission Ireland. (2023). "DPC Announces EUR345 Million Fine of TikTok." 15 September 2023.
- MLex. (2026). "Amazon Sees Luxembourg Appeals Court Annul EUR746 Million GDPR Fine." Fine annulled and remanded for reconsideration, 2026.
- CMS Law. (2023). "Fifth Anniversary of the GDPR: Fines Totalling EUR 2.7 Billion." Report published 22 May 2023, cutoff 1 March 2023.
- CMS Law. (2024). "Six Years of GDPR: Fines Totalling EUR 4.5 Billion." Report published 15 May 2024, cutoff 1 March 2024.
Note: All figures verified as of July 2026. The Amazon EUR 746 million fine is under active reconsideration following a 2026 appeals court ruling and may change before this post's next refresh. Cumulative totals are refreshed at least twice a year to track new CMS Enforcement Tracker Report editions and DLA Piper survey updates.