At least 3,202 GDPR fines have been issued since the regulation took effect on 25 May 2018, according to enforcementtracker.com's live enforcement database, checked in July 2026. A stricter count that only includes cases with a publicly confirmed amount and authority, the CMS Enforcement Tracker Report 2026, puts the number at 2,685 as of its 1 March 2026 cutoff.
Both trackers agree on the direction even though they disagree on the exact tally: the recorded count of GDPR fines has grown every year since 2018 and shows no sign of leveling off in 2026. This page tracks the running total, where the two main trackers diverge and why, which countries fine the most often by count, and how fast the tally is still climbing.
How many GDPR fines have been issued in total?
The most-cited running total is 3,202 recorded cases, per enforcementtracker.com's live, continuously updated database, checked in July 2026. The CMS Enforcement Tracker Report 2026, a stricter annual snapshot with a fixed 1 March 2026 cutoff, counts 2,685 fines with a fully confirmed amount and issuing authority, or 3,062 including cases where some detail is still incomplete.
| Source | Fine count | Cutoff / checked date |
|---|---|---|
| enforcementtracker.com (live) | 3,202 | Live, checked July 2026 |
| CMS Enforcement Tracker Report 2026 (confirmed detail) | 2,685 | 1 March 2026 |
| CMS Enforcement Tracker Report 2026 (incl. incomplete) | 3,062 | 1 March 2026 |
Figure 1: Three ways of counting the same underlying enforcement activity. Source: enforcementtracker.com (checked July 2026), CMS Enforcement Tracker Report 2026 (cutoff 1 March 2026).
The gap is not a data error. enforcementtracker.com counts a case the moment a regulator's action is publicly reported, even before every field (amount, authority, closing status) is confirmed, while the CMS Enforcement Tracker Report only adds a case to its headline count once the amount and issuing authority are both verifiable. Both counts sit well above the average GDPR fine of EUR 2,277,122 (about EUR 2.28 million), per the CMS Enforcement Tracker Report 2026, a figure pulled down by thousands of smaller penalties against local businesses even as a handful of billion-euro fines against large platforms dominate the headlines. For the euro side of this picture, including how the cumulative total is climbing, see our breakdown of GDPR fine totals and averages.
How has the number of GDPR fines grown since 2018?
The confirmed fine count has more than doubled in three years. CMS's own report editions, each anchored to a fixed 1 March cutoff, show over 1,500 confirmed cases at the five-year mark in 2023, 2,225 cases at the six-year mark in 2024, and 2,685 cases by the 2026 edition.
| Report edition | Cutoff date | Confirmed fine count |
|---|---|---|
| CMS Enforcement Tracker Report, 5-year edition | 1 March 2023 | Over 1,500 |
| CMS Enforcement Tracker Report, 6-year edition | 1 March 2024 | 2,225 |
| CMS Enforcement Tracker Report 2026 | 1 March 2026 | 2,685 |
Figure 2: Confirmed GDPR fine count at each CMS Enforcement Tracker Report cutoff. Source: CMS Enforcement Tracker Report, 2023, 2024, and 2026 editions.
CMS's own methodology notes put a precise number on one leg of that growth: 510 new fines were added in the twelve months before the 1 March 2024 cutoff alone, of which 2,086 carried complete detail at the time. The pace has not slowed heading into 2026 either. enforcementtracker.com recorded 156 new fines already in 2026 and 141 in the trailing six months, checked in July 2026, which means new fines are still landing at roughly one every two to three days across the EU/EEA. If your site handles EU user data and has not reviewed its legal basis and consent flow recently, you can generate a GDPR-ready privacy policy that documents the disclosures regulators check first, including legal basis, retention, and international transfers.
Which countries have issued the most GDPR fines?
Spain has issued more individual GDPR fines than any other country by a wide margin, with 1,048 recorded cases per the CMS Enforcement Tracker Report 2026, or 1,078 per enforcementtracker.com's live count. That single country accounts for roughly two out of every five confirmed fines in the CMS dataset.
| Country / grouping | Recorded fine count | Source |
|---|---|---|
| Spain | 1,048 | CMS Enforcement Tracker Report 2026 |
| Spain (live count) | 1,078 | enforcementtracker.com, checked July 2026 |
| Italy, Romania, and Poland (next most active, combined range) | 106 to 490 each | CMS Enforcement Tracker Report 2026 |
Figure 3: Spain's share of the CMS Enforcement Tracker Report's 2,685 confirmed fines. Source: CMS Enforcement Tracker Report 2026.
Spain's lead by count does not translate into the largest total value: its data protection authority, the AEPD, issues a high volume of smaller fines against local businesses and public bodies, while Ireland's Data Protection Commission issues far fewer fines by count but holds the largest cumulative euro value because it regulates Meta, TikTok, and LinkedIn under GDPR's one-stop-shop mechanism. The two rankings, most fines by count and most euros by value, measure different things and should not be conflated; our ranked list of the biggest GDPR fines of all time covers the value side in full.
Why do GDPR fine counts differ between trackers?
Every public count of GDPR fines depends on a disclosure pipeline that does not run the same way in every EU/EEA country, which is why no two trackers land on exactly the same number.
Figure 4: Why the same underlying enforcement activity produces different published counts. Source: CMS Enforcement Tracker Report 2026 methodology notes, enforcementtracker.com database rules.
Some national authorities publish a fine with a confirmed amount immediately; others confirm the case first and disclose the exact amount only after an appeal period closes, which is why enforcementtracker.com's live total of 3,202 runs ahead of CMS's confirmed 2,685. Even inside a single tracker's own database, not every case is treated as fully documented.
Figure 5: Share of the CMS Enforcement Tracker Report's tracked cases that carry a fully confirmed amount and authority versus those still missing a field. Source: CMS Enforcement Tracker Report 2026, numbers and figures section.
Treat any single published count as a floor, not a ceiling. DLA Piper's GDPR Fines and Data Breach Survey, published January 2026, does not publish an independent fine count at all, reporting only a cumulative euro total (EUR 7.1 billion) built from its own network of European data protection lawyers, which is a reminder that the count you cite should always name which tracker and which cutoff it came from.
What GDPR violations trigger the most fines?
The CMS Enforcement Tracker Report 2026 classifies every confirmed case by violation type, and three categories account for the bulk of all recorded fines: insufficient legal basis for processing, non-compliance with general data-processing principles, and insufficient technical and organizational security measures, in that order by case count. The report does not publish an exact percentage split for these three categories in its public summary, but it identifies insufficient legal basis as the single most common trigger by number of cases, even though the largest individual fines by value have concentrated on unlawful international data transfers and children's data handling instead.
That pattern matters for any site owner reading a fine-count tracker rather than a fine-amount ranking: the categories that generate the most recorded cases are exactly the disclosures a standard privacy policy and consent flow are built to cover, not just the multibillion-euro violations that make headlines.
The Bottom Line
No matter which tracker you use, GDPR enforcement is not slowing down. Whether you use enforcementtracker.com's live total of 3,202, the CMS Enforcement Tracker Report's stricter confirmed count of 2,685, or the 3,062 figure that includes still-incomplete cases, every credible tracker shows the same trend: more than 1,000 new fines recorded since the five-year mark alone, with 156 more already added in 2026. Spain's volume lead shows that fines are not reserved for Big Tech; the categories driving most of the recorded cases, weak legal basis, unclear processing principles, and thin security measures, apply to sites and businesses of any size.
Frequently Asked Questions
How many GDPR fines have been issued since 2018? At least 3,202, according to enforcementtracker.com's live database, checked in July 2026. A stricter count that only includes cases with full public detail, the CMS Enforcement Tracker Report 2026, puts the confirmed total at 2,685, or 3,062 including cases with incomplete records.
Is the number of GDPR fines still growing in 2026? Yes. enforcementtracker.com recorded 156 new fines in 2026 alone and 141 in the trailing six months, checked in July 2026, showing enforcement has not slowed even as year-over-year totals plateau.
Which country has issued the most GDPR fines? Spain, with 1,048 recorded fines per the CMS Enforcement Tracker Report 2026 (1,078 per enforcementtracker.com's live count), more than double the next most active country.
Why do different GDPR fine trackers report different totals? Because each one uses a different disclosure bar. The CMS Enforcement Tracker Report only counts cases with a publicly confirmed amount and authority, reaching 2,685 fines by its 1 March 2026 cutoff, while enforcementtracker.com's continuously updated database reaches 3,202 by including additional publicly reported actions as they surface.
Where the Numbers Come From
- enforcementtracker.com. Live GDPR fines database, 3,202 recorded cases across 32 countries, EUR 6.31 billion cumulative, Spain 1,078 cases, 156 new cases in 2026, checked July 2026.
- CMS Law. (2026). "GDPR Enforcement Tracker Report 2026, Numbers and Figures." 2,685 confirmed fines (3,062 incl. incomplete), average fine EUR 2,277,122, Spain 1,048 cases, cutoff 1 March 2026.
- CMS Law. (2024). "Six Years of GDPR: Fines Totalling EUR 4.5 Billion." 2,225 cases documented (2,086 with complete detail), 510 fines added in the preceding year, cutoff 1 March 2024.
- CMS Law. (2023). "Fifth Anniversary of the GDPR: Fines Totalling EUR 2.7 Billion." Over 1,500 cases, cutoff 1 March 2023.
- DLA Piper. (2026). "GDPR Fines and Data Breach Survey: January 2026." EUR 7.1 billion cumulative fines since 25 May 2018, no independent fine count published, data through 10 January 2026.
Note: All figures verified as of July 2026. enforcementtracker.com's count updates continuously and may already be higher by the time you read this; the CMS Enforcement Tracker Report's confirmed count is refreshed at its next 1 March cutoff. This page is refreshed at least twice a year to track both.