No regulator publishes a clean percentage of how many online stores meet privacy law, but GDPR's industry and commerce sector, which covers most e-commerce, logged 588 fines totaling nearly EUR 395 million, according to CMS Law's GDPR Enforcement Tracker Report 2026, published May 21, 2026. The single largest of those fines, EUR 150 million against fashion retailer Shein's parent entity, landed in September 2025 alone. California's regulator has been busy too, fining three consumer-facing companies in 2025 for privacy policy and opt-out failures. None of this adds up to a clean compliance rate, but it is the closest measurable answer available.

How many online stores were fined under GDPR in 2025?

GDPR's industry and commerce sector, the classification that covers most retailers and e-commerce operators, has accumulated 588 total fines worth nearly EUR 395 million, according to CMS Law's GDPR Enforcement Tracker Report 2026. New fines added in this tracker edition reached 94, more than double the 40 new fines recorded in the prior edition, a pace CMS attributes partly to one very large single case.

Industry and commerce GDPR fines by lead regulator (count) 2248882194Spain (AEPD)224Romania (ANSPDCP)88Italy (Garante)82All other authorities194

Figure 1: Spain's AEPD alone accounts for more than a third of all industry and commerce fines tracked. Source: CMS Law, GDPR Enforcement Tracker Report 2026 (published May 2026).

Spain's AEPD leads by fine count, not by total euros collected, since it issues a high volume of smaller penalties against local retailers. The average penalty across the sector sits at roughly EUR 671,734, but that average is skewed hard by a handful of nine-figure cases, which the next section covers directly.

What is the largest fine ever issued against an online store?

One online store was fined 150 million euros for cookies EUR 150M fine against a single online storefor unlawful cookie tracking, Sept 2025

France's data protection authority, CNIL, fined Infinite Styles Services Co. Limited, the entity operating fashion retailer Shein, EUR 150 million on September 9, 2025, for placing tracking cookies on the Shein platform without valid user consent. That single case is the largest fine CMS Law's tracker has recorded against any business in the industry and commerce sector, and it alone accounts for roughly 38% of the sector's entire EUR 394,979,927 cumulative total.

A cookie-consent fine of that size is a reminder that GDPR enforcement against online stores rarely centers on data breaches. The Shein case, like most of the largest retail fines in CMS Law's dataset, traces back to consent mechanics: cookies loading before a visitor makes a choice, or a banner that makes "reject" harder to find than "accept."

How is the US enforcing privacy law against online retailers?

Three 2025 CCPA fines targeted consumer-facing companies $1.2M Tractor Supply $632K Honda $345K Todd Snyder

The California Privacy Protection Agency fined three consumer-facing companies in 2025, and the violations line up with what CNIL found in Europe: privacy policy gaps and broken opt-out mechanisms, not breaches. Tractor Supply Company was fined 1.2 million dollars, its largest fine to date, for failing to maintain an adequate privacy policy, failing to notify job applicants of their privacy rights, and failing to provide an effective opt-out mechanism, including through opt-out preference signals. American Honda Motor Co. was fined 632,000 dollars for using dark patterns in its privacy choices and sharing personal information with ad-tech companies without required contracts. Apparel retailer Todd Snyder was fined 345,000 dollars for failing to oversee the technical configuration behind its own opt-out requests.

Online stores closing that specific gap can generate a privacy policy built to disclose opt-out rights and data-sharing practices correctly, which is the exact document category all three 2025 CPPA cases cited as deficient. The same pattern shows up across smaller businesses too, not just national retailers; see our small business privacy statistics for how documentation gaps track with company size.

CalPrivacy's enforcement arm is also getting more tips to act on. The agency's online complaint portal has logged more than 10,000 consumer complaints since it launched in 2023, with volume up roughly 120% year over year, and the Tractor Supply case itself originated from a consumer complaint rather than a proactive sweep.

What does the 2025 enforcement timeline for online stores look like?

Figure 2: Enforcement against online stores and consumer-facing companies clustered heavily in the second half of 2025. Sources: CMS Law, GDPR Enforcement Tracker Report 2026; California Privacy Protection Agency, 2025 Annual Report.

Five separate actions inside seven months is not a coincidence of timing. Regulators on both sides of the Atlantic were running active sweeps for most of that stretch, which means an online store that squeaked by in the first half of 2025 faced a meaningfully higher chance of a letter, a complaint-triggered review, or a joint investigation by the second half.

Which privacy law actually applies to your online store?

Figure 3: Most online stores selling across borders end up bound by more than one branch of this test at once. Source: authors' synthesis of GDPR territorial scope and US state comprehensive privacy law thresholds, current as of 2026.

A single storefront selling internationally rarely lands on just one branch of that test. A US-based store shipping to EU customers answers "yes" at the very first question, which is exactly the scenario that put Shein's cookie banner inside CNIL's jurisdiction despite the company's Asian manufacturing base and Irish and Singaporean holding structure. Our breakdown of what percentage of Shopify stores have a privacy policy walks through why even a platform-level contract requirement does not answer this question cleanly for any single merchant.

How does EU and US enforcement against online stores compare?

RegionRegulator(s)Enforcement scale2025's largest single case
European UnionNational DPAs under GDPR588 industry and commerce fines, nearly EUR 395 million cumulativeEUR 150 million, Shein's operating entity, CNIL
California, USCalifornia Privacy Protection Agency3 fines against consumer-facing companies in 2025, over 2.1 million dollars combined1.2 million dollars, Tractor Supply Company

Source: CMS Law, GDPR Enforcement Tracker Report 2026; California Privacy Protection Agency, 2025 Annual Report.

The euro figures dwarf the dollar figures because GDPR fines scale against global annual revenue, while CCPA fines are calculated per violation with a statutory cap. A retailer the size of Shein can absorb a nine-figure GDPR fine and keep operating; the CCPA's per-violation structure is designed to punish scale differently, by multiplying a smaller base penalty across every affected consumer record instead.

Is there a clean percentage for how many online stores meet privacy law?

No. Neither the enforcement data above nor any published academic audit answers that question with a single number, and the closest available research measures something related but not identical: whether a site publishes any privacy policy at all, not whether that policy actually satisfies GDPR or CCPA. A 2021 Princeton and KU Leuven study of 9.6 million archived homepages, covered in more depth in our full breakdown of how many websites have a privacy policy, found a detectable privacy policy link on 37.2% of top-1,000-ranked sites, falling to just 9.6% for sites ranked below 1 million. That study did not isolate online stores specifically and predates 2025's enforcement wave by four years, so treat it as general context rather than a current e-commerce figure.

The enforcement record is the more current signal, and it points the same direction the presence study does: a large share of the businesses regulators actually investigate turn out to have a policy in place that fails on the details, not one that is missing outright. See our e-commerce privacy statistics for how that pattern plays out alongside checkout trust and retail data breach numbers.

The Bottom Line

The honest answer to "how many online stores meet privacy law" is that nobody has published that number, and the two regulators generating the most current data, GDPR's national authorities and California's CPPA, measure enforcement outcomes rather than a baseline compliance rate. What is fully documented is the direction of travel: 588 fines and nearly EUR 395 million against the industry and commerce sector in Europe, a EUR 150 million single case against one online store, and three separate California fines against consumer-facing companies inside a single year, with opt-out mechanics and cookie consent as the common failure point across every case. An online store does not need a published compliance percentage to act on that pattern. A current privacy policy that correctly discloses data sharing and actually honors opt-out signals addresses the exact gap every 2025 case in this post was fined for.

Frequently Asked Questions

What percentage of online stores meet privacy law requirements? No independent audit publishes that figure. The closest measurable proxy is enforcement volume: GDPR's industry and commerce sector, which covers most e-commerce and retail businesses, has logged 588 fines totaling nearly EUR 395 million, according to CMS Law's GDPR Enforcement Tracker Report 2026, published May 21, 2026.

What is the largest privacy fine ever issued against an online store? EUR 150 million, issued against fashion retailer Shein's parent entity, Infinite Styles Services Co. Limited, by France's data protection authority CNIL on September 9, 2025, for unlawful cookie placement, according to CMS Law's GDPR Enforcement Tracker Report 2026.

How is California enforcing privacy law against online retailers? The California Privacy Protection Agency fined Tractor Supply Company 1.2 million dollars in 2025, its largest fine to date, for failing to maintain an adequate privacy policy and failing to provide an effective opt-out mechanism, according to CalPrivacy's 2025 Annual Report.

How many privacy complaints has California's regulator received about businesses? More than 10,000 complaints since CalPrivacy's online complaint portal launched in 2023, with complaint volume up roughly 120% year over year, according to the California Privacy Protection Agency's 2025 Annual Report.

Where the Numbers Come From

  1. CMS Law. "GDPR Enforcement Tracker Report 2026: Industry and Commerce." Published May 21, 2026. 588 total fines, EUR 394,979,927 cumulative total, 94 new fines in this edition versus 40 in the prior edition, EUR 150 million Shein-entity fine dated September 9, 2025.
  2. California Privacy Protection Agency. "2025 Annual Report." Tractor Supply Company (1.2 million dollars), American Honda Motor Co. (632,000 dollars), and Todd Snyder (345,000 dollars) enforcement actions; over 10,000 complaints received since the complaint portal's 2023 launch, up roughly 120% year over year; September 2025 Global Privacy Control sweep and November 2025 GPEN review of children's websites and apps.
  3. Amos, R., Acar, G., Lucherini, E., Kshirsagar, M., Narayanan, A., and Mayer, J. (2021). "Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset." Proceedings of WWW '21. General web privacy policy detection rates of 37.2% and 9.6% cited for background context, not specific to online stores.

Note: All figures verified as of July 2026. GDPR fine totals reflect CMS Law's publicly available Enforcement Tracker database and are refreshed with each new tracker edition; CalPrivacy's enforcement figures cover the period described in its 2025 Annual Report and will update with the agency's next annual disclosure.