Cumulative GDPR fines climbed from EUR 272.5 million in January 2021 to roughly EUR 7.1 billion by January 2026, according to DLA Piper's GDPR Fines and Data Breach Survey series, the law firm's annual snapshot of enforcement across Europe. That growth was not steady. Annual totals swung from under EUR 300 million in the regulation's first two and a half years to a peak year of well over EUR 1.6 billion, then leveled off. Below is the year-by-year trajectory across the two most-cited trackers, what drove the biggest single year, and why competing "totals" published a few months apart never quite agree.
How have cumulative GDPR fines grown since 2018?
Fines stayed modest for years after GDPR took effect on 25 May 2018. By January 2021, DLA Piper's survey put the cumulative total across all surveyed jurisdictions at just EUR 272.5 million, roughly two and a half years into enforcement. Growth accelerated sharply after that: cumulative fines reached EUR 5.88 billion by January 2025 and EUR 7.1 billion by January 2026, an increase of more than 25 times in five years.
Figure 1: Cumulative GDPR fines at each CMS Enforcement Tracker Report annual cutoff. The March 2025 point is implied by the 2026 report's own stated year-over-year change rather than stated directly. Source: CMS Enforcement Tracker Report, 2023-2026 editions.
The CMS Enforcement Tracker Report, which only counts publicly confirmed cases with a disclosed amount, shows the same upward trend on a stricter, fixed March cutoff: EUR 2.7 billion across 1,500-plus cases at the 5-year mark, rising to EUR 6.11 billion across 2,685 cases by the 8-year mark in March 2026. Both trackers agree on the shape of the curve even though their absolute totals differ by roughly EUR 1 billion at any given point.
How much have GDPR fines totaled year by year?
DLA Piper's survey runs on a January-to-January cycle rather than the calendar year, and its published year-over-year figures give the clearest picture of how the annual pace has actually moved. The year to January 2023 alone added EUR 1.64 billion in new fines, a 50% increase over the prior 12-month period, per DLA Piper's January 2023 survey. The following period, the year to January 2024, is not stated as a flat figure in DLA Piper's own report, but its January 2025 survey says fines "were imposed" totaling EUR 1.2 billion "in the year from 28 January 2024," a 33% decrease compared to the aggregate fines imposed in the previous 12 months, which implies a total of roughly EUR 1.8 billion in the year to January 2024, the survey period that contains the record Meta fine described below.
Figure 2: Fines per 12-month DLA Piper survey period. The year-to-Jan-2024 figure is implied by the 33% year-over-year decrease DLA Piper reported the following year; the other three periods are stated directly. Source: DLA Piper GDPR Fines and Data Breach Survey, January 2023, 2025, and 2026 editions.
The pace has since held flat rather than kept climbing. DLA Piper's January 2026 survey puts the year to January 2026 at roughly EUR 1.2 billion, explicitly "matching 2024's figure." After the record year driven by a single mega-fine, annual totals settled at less than three-quarters of that peak and have stayed there for two consecutive survey periods.
Why was the year to January 2024 the biggest on record?
A single fine explains most of that period's total. Ireland's Data Protection Commission fined Meta Platforms Ireland Limited EUR 1.2 billion in May 2023 over unlawful EU-to-US data transfers, a decision that fell inside DLA Piper's year-to-January-2024 survey window and remains the largest GDPR fine ever issued as of July 2026. See our full ranking of the biggest GDPR fines for how the rest of the top 10 compares.
Figure 3: Milestone points across the GDPR fines timeline. Source: DLA Piper GDPR Fines and Data Breach Survey (2021, 2023, 2025, 2026 editions), CMS Enforcement Tracker Report 2026.
A single record fine skewing one year's total is not unusual in this dataset. It is also why year-over-year percentage changes in GDPR fine totals should be read with the underlying case list in mind, not treated as a pure enforcement-intensity signal on their own. Regulators are not fining more companies more often every single year; sometimes one very large platform fine moves the whole annual number.
Why do different trackers report different year-by-year totals?
Three credible sources currently track GDPR fines, and each uses a different period boundary and a different counting rule, which is why their numbers never line up exactly even when checked in the same month.
Figure 4: A quick test for why two "GDPR fines" totals disagree. Source: methodology notes from DLA Piper's survey series and the CMS Enforcement Tracker Report.
DLA Piper's survey draws on the firm's own network of European data protection lawyers and runs January to January, which is why its cumulative total (EUR 7.1 billion by January 2026) sits well above the CMS Enforcement Tracker Report's stricter, publicly-documented-only total (EUR 6.11 billion at its March 2026 cutoff). enforcementtracker.com, the CMS-affiliated live database, sits in between at EUR 6.31 billion because it updates continuously rather than snapshotting once a year. None of the three is wrong; they are measuring slightly different things over slightly different windows. If your business handles EU user data, the practical response to any of these totals is the same: keep the disclosures regulators check first current, starting with a privacy policy built for GDPR's legal-basis and data-transfer requirements.
How is the EUR 6.11 billion CMS cumulative total split across reporting years?
Splitting the CMS Enforcement Tracker Report's cumulative total by the period each euro was added shows the same plateau pattern from a different angle.
Figure 5: Composition of the CMS Enforcement Tracker Report's EUR 6.11 billion cumulative total by the period each slice was added. The Year 7 slice is implied by subtracting the report's own stated figures; Year 8 matches the EUR 487.6 million increase CMS reported directly between its 2025 and 2026 editions. Source: CMS Enforcement Tracker Report, 2023-2026 editions.
Year 6 alone, which contains the Meta fine, added more to the cumulative total (EUR 1.8 billion) than the first five years combined added in any single 12-month stretch. Year 8, the most recent period, added less than a third of that, which is the same leveling-off pattern DLA Piper's survey shows independently.
Year-by-year totals, side by side
| Snapshot date | DLA Piper cumulative | DLA Piper 12-month total | CMS cumulative (cutoff) |
|---|---|---|---|
| Jan 2021 | EUR 272.5 million | Not separately published | Not available |
| Jan 2023 | Not separately published | EUR 1.64 billion | EUR 2.7 billion (Mar 2023, 1,500+ cases) |
| Jan 2024 (implied) | ~EUR 4.68 billion | ~EUR 1.8 billion (implied) | EUR 4.5 billion (Mar 2024) |
| Jan 2025 | EUR 5.88 billion | EUR 1.2 billion | EUR 5.62 billion (Mar 2025, implied, 2,245 cases) |
| Jan 2026 | EUR 7.1 billion | EUR 1.2 billion | EUR 6.11 billion (Mar 2026, 2,685 cases) |
Source: DLA Piper GDPR Fines and Data Breach Survey (2021, 2023, 2025, 2026 editions), CMS Enforcement Tracker Report (2023-2026 editions). Rows marked "implied" are computed from figures each source stated directly, not published as a standalone total by that source.
For context on the full cumulative picture and how it breaks down by country and violation type, see our GDPR fines totals and averages for 2026. A running tally of what Meta specifically has paid under GDPR, separate from the year-by-year totals here, is a natural next addition to this cluster once that data is compiled.
The Bottom Line
The GDPR fines timeline is not a smooth upward line. It is a slow start through 2021, a sharp acceleration driven by a handful of mega-fines against large platforms in 2023, and a plateau at roughly EUR 1.2 billion a year since. Whichever tracker you use, the direction is the same: enforcement has not slowed down in aggregate case count, but the annual euro total now depends heavily on whether a single billion-euro-class fine lands inside the 12-month window being measured. A small or mid-sized business is far more likely to be affected by the steady base rate of enforcement, insufficient legal basis, unclear processing principles, and weak security measures, than by the mega-fines that swing the year-over-year headline number.
Frequently Asked Questions
How much have cumulative GDPR fines grown since 2018? Cumulative GDPR fines rose from EUR 272.5 million in January 2021 to roughly EUR 7.1 billion by January 2026, according to DLA Piper's GDPR Fines and Data Breach Survey series, an increase of more than 25 times over five years.
What was the biggest year for GDPR fines? The 12 months to January 2024 were the largest on record, with a total implied at roughly EUR 1.8 billion by DLA Piper's own reported 33% year-over-year decrease the following year, dominated by the EUR 1.2 billion fine against Meta Platforms Ireland Limited in May 2023.
Are GDPR fines increasing or leveling off? They have leveled off. DLA Piper recorded roughly EUR 1.2 billion in fines in both the year to January 2025 and the year to January 2026, and the CMS Enforcement Tracker Report's most recent 12 months added just EUR 487.6 million, its smallest year-over-year increase in the data available.
Why do different GDPR fine trackers show different year-by-year totals? DLA Piper's survey runs on a January-to-January cycle and includes cases reported through its own network of European lawyers, the CMS Enforcement Tracker Report uses a fixed March cutoff and counts only publicly confirmed cases, and enforcementtracker.com updates continuously, so any two totals measured a few months apart will not match exactly.
Where the Numbers Come From
- DLA Piper. (2026). "GDPR Fines and Data Breach Survey: January 2026." Cumulative EUR 7.1 billion since 25 May 2018, through 10 January 2026; year to January 2026 totaled roughly EUR 1.2 billion, matching 2024's figure.
- DLA Piper. (2025). "GDPR Fines and Data Breach Survey: January 2025." Cumulative EUR 5.88 billion; year to January 2025 totaled EUR 1.2 billion, a 33% decrease versus the prior 12-month period.
- DLA Piper. (2023). "GDPR Fines and Data Breach Survey: January 2023." Year to January 2023 totaled EUR 1.64 billion, a 50% year-over-year increase.
- DLA Piper. (2021). "GDPR Fines and Data Breach Survey: January 2021." Cumulative EUR 272.5 million since 25 May 2018.
- CMS Law. (2026). "GDPR Enforcement Tracker Report 2026, Numbers and Figures." 2,685 fines totaling EUR 6.11 billion, cutoff 1 March 2026, up EUR 487.6 million and 440 cases from the 2025 edition.
- CMS Law. (2023). "Fifth Anniversary of the GDPR: Fines Totalling EUR 2.7 Billion." Report published 22 May 2023, cutoff 1 March 2023, 1,500-plus cases.
- CMS Law. (2024). "Six Years of GDPR: Fines Totalling EUR 4.5 Billion." Report published 15 May 2024, cutoff 1 March 2024.
- enforcementtracker.com. Live GDPR fines database, 3,202 recorded actions, EUR 6.31 billion cumulative, checked 30 July 2026.
Note: All figures verified as of July 2026. DLA Piper's survey uses a January-to-January cutoff and the CMS Enforcement Tracker Report uses a fixed 1 March cutoff, so figures dated a few months apart are not directly comparable; rows and figures marked "implied" are computed from percentages or deltas each source stated directly rather than published as a standalone total. This timeline is refreshed at least twice a year alongside new DLA Piper survey and CMS Enforcement Tracker Report editions.