Meta and its Facebook, Instagram, and WhatsApp subsidiaries have paid roughly EUR 2.83 billion in finalized GDPR fines since September 2021, across seven decisions issued by Ireland's Data Protection Commission (DPC), the lead EU regulator for Meta under GDPR's one-stop-shop rule. That running total, current as of July 2026, includes the record EUR 1.2 billion fine from May 2023 and does not yet count a further EUR 360 to 430 million case still awaiting final orders.
No other company has accumulated anything close to that figure under GDPR. Below is every finalized fine that makes up the total, the timeline they landed on, how Meta's share compares to global GDPR enforcement, and what is still working its way through the Irish courts.
How much has Meta paid in GDPR fines in total?
Seven separate DPC decisions make up Meta's EUR 2.83 billion running total. Each one is a finalized, publicly confirmed penalty against a Meta-family entity, drawn directly from the DPC's own press releases rather than a secondary aggregator.
| Date | Entity fined | Amount | Reason |
|---|---|---|---|
| 2 Sept 2021 | WhatsApp Ireland Ltd | EUR 225M | Transparency obligations toward users and non-users |
| 15 Sept 2022 | Meta Platforms Ireland (Instagram) | EUR 405M | Children's data exposed through business accounts |
| 28 Nov 2022 | Meta Platforms Ireland (Facebook) | EUR 265M | Data protection by design and default failures behind a scraping incident |
| 4 Jan 2023 | Meta Platforms Ireland (Facebook and Instagram) | EUR 390M | No valid legal basis for personalized advertising |
| 22 May 2023 | Meta Platforms Ireland | EUR 1,200M | Unlawful EU-to-US data transfers |
| 27 Sept 2024 | Meta Platforms Ireland | EUR 91M | Plaintext storage of user passwords |
| 17 Dec 2024 | Meta Platforms Ireland | EUR 251M | 2018 breach exposing roughly 29 million accounts |
Add the seven figures and the total comes to EUR 2.827 billion, which this post rounds to EUR 2.83 billion throughout. Every entry traces back to a DPC press release naming the exact euro amount, the decision date, and the GDPR articles found to have been breached, so the total is a sum of confirmed penalties rather than an estimate.
What is the timeline of Meta's GDPR fines?
Meta's GDPR enforcement history runs in clusters rather than a steady drip: no fines for the first three years GDPR was in force, then seven finalized decisions in roughly three and a half years, with a further case now pending.
Figure 1: Every finalized and pending Meta GDPR case by year. Source: Irish Data Protection Commission press releases, 2021 to 2026.
The gap between January 2023 and September 2024 is the longest stretch without a new finalized fine, but it was not a quiet period at the DPC: both the EUR 1.2 billion transfer fine and the 2018 breach inquiry were working through the DPC's decision-making and, in the transfer case, the Article 65 dispute-resolution process at the European Data Protection Board during that window.
Which single Meta GDPR fine is the largest?
The EUR 1.2 billion fine issued against Meta Platforms Ireland Limited in May 2023, over transferring EU users' Facebook data to the United States without an adequate legal transfer mechanism, is both Meta's largest individual fine and the largest GDPR fine ever issued against any company. It is nearly three times the size of Meta's second-largest fine.
Figure 2: Meta's seven finalized fines ranked by amount. Source: Irish Data Protection Commission decisions, 2021 to 2024.
The size gap matters for how the fine was set. GDPR's Article 83 caps the higher tier of violations at EUR 20 million or 4% of global annual turnover, whichever is greater. Meta's global revenue put the percentage-based cap far above EUR 20 million, and the European Data Protection Board's binding Article 65 decision instructed the DPC to raise its own draft fine specifically to reflect the scale and duration of the unlawful transfers, which had continued for years after the underlying legal mechanism (Privacy Shield) was struck down by the Court of Justice of the EU in 2020.
How does Meta's total compare to all GDPR fines combined?
Meta's EUR 2.83 billion accounts for a large share of every GDPR fine ever issued, though the exact percentage depends on which tracker you use as the denominator. Against the CMS Enforcement Tracker Report's stricter, confirmed-case total of EUR 6.11 billion (cutoff 1 March 2026), Meta's share is roughly 46%. Against DLA Piper's broader EUR 7.1 billion estimate, which also folds in fines reported through the firm's own network of European data protection lawyers, Meta's share is closer to 40%. Either way, one company accounts for close to half of all documented GDPR enforcement value since the regulation took effect in May 2018, a concentration explored in more detail in our full GDPR fines total breakdown.
Figure 3: Meta's share of the CMS Enforcement Tracker Report's EUR 6.11 billion confirmed total. Source: CMS Enforcement Tracker Report 2026, Irish DPC decisions.
That concentration is a direct result of Meta's size and its regulatory home base, not evidence that Meta is uniquely non-compliant compared to other large platforms. TikTok, Amazon, and LinkedIn have all received fines above EUR 250 million from the same Irish regulator, but none has accumulated a running total anywhere near Meta's.
Why does Ireland handle almost all of Meta's GDPR fines?
Every one of Meta's seven finalized fines was issued or led by Ireland's Data Protection Commission, because Meta's main EU establishment is in Dublin. GDPR's one-stop-shop mechanism assigns lead-authority status to the regulator where a company's main EU establishment sits, so complaints and breach inquiries touching Meta's EU operations route through the DPC by default.
Figure 4: How a Meta GDPR case reaches a finalized fine. Source: GDPR Articles 56, 60, and 65, as applied in the Irish DPC's Meta decisions.
The mechanism is also why some of Meta's fines ended up larger than the DPC's own initial draft. In both the 2021 WhatsApp case and the 2023 EU-to-US transfer case, other national regulators objected to the DPC's proposed penalty as too low, and the European Data Protection Board's binding decision instructed the DPC to raise the final amount.
How has Meta's total grown year over year?
Meta's cumulative GDPR total went from zero to nearly EUR 900 million by the end of 2022, then jumped past EUR 2.4 billion in a single year once the record transfer fine landed in 2023.
Figure 5: Meta's cumulative GDPR fine total at each year end. Source: Irish Data Protection Commission decision dates, 2021 to 2024.
Roughly 85% of Meta's entire running total landed in a single 12-month stretch: the EUR 390 million legal-basis fine in January 2023 and the EUR 1.2 billion transfer fine in May 2023 together account for more than EUR 1.5 billion of the EUR 2.83 billion total. If you handle EU user data and have not reviewed how your own privacy policy states its legal basis for processing and any international transfers since before 2023, that concentration of enforcement activity is a reason to check: you can generate a GDPR-ready privacy policy covering legal basis, transfer mechanisms, and retention in the same categories the DPC's Meta decisions turned on.
Is Meta facing any pending GDPR fines?
Yes. A case over how Meta's Hive system handled data subject access requests, first filed as a complaint in July 2018, is still awaiting final orders as of May 2026. The DPC issued a draft decision in October 2025 proposing a fine in the EUR 360 to 430 million range, Meta challenged the DPC's authority to address the issue on a systemic, company-wide basis rather than case by case, and the Irish High Court dismissed Meta's challenge on 21 May 2026. Final orders on the amount had not been issued as of this post's last data check in July 2026, so this figure is not included in the EUR 2.83 billion confirmed total above. Treat the EUR 360 to 430 million range as a pending estimate, not a finalized penalty, until the DPC publishes its final decision.
The Bottom Line
Meta's EUR 2.83 billion in finalized GDPR fines is not a single catastrophic penalty. It is seven separate decisions, each targeting a distinct compliance failure, from unclear legal basis for advertising to unlawful international transfers to inadequate breach documentation. The categories that produced Meta's fines, legal basis, transparency, security by design, and breach notification, are the same categories every privacy policy is supposed to address regardless of company size. A small business will never face a percentage-of-global-turnover fine the way Meta has, but the underlying compliance gaps that triggered each of Meta's seven decisions are the same gaps regulators check first in any GDPR investigation. With a further EUR 360 to 430 million case still pending final orders, this running total is very likely to move again before its next scheduled refresh.
Frequently Asked Questions
How much has Meta paid in GDPR fines in total? Roughly EUR 2.83 billion across seven finalized decisions from Ireland's Data Protection Commission between September 2021 and December 2024. This does not include a separate EUR 360 to 430 million case still awaiting final orders as of May 2026.
What is Meta's biggest GDPR fine? EUR 1.2 billion, issued by Ireland's Data Protection Commission in May 2023 over unlawful EU-to-US data transfers. It remains the largest GDPR fine ever issued against any company as of July 2026.
Why does Ireland issue almost all of Meta's GDPR fines? Meta's main EU establishment is in Dublin, which makes Ireland's Data Protection Commission the lead supervisory authority under GDPR's one-stop-shop mechanism (Article 56). All seven of Meta's finalized fines were issued or led by the Irish DPC, sometimes after other EU regulators forced a higher penalty through the Article 65 dispute process.
What percentage of all GDPR fines has Meta paid? Roughly 46 percent of the EUR 6.11 billion the CMS Enforcement Tracker Report counts in confirmed, publicly documented GDPR cases as of its March 2026 cutoff, or about 40 percent of DLA Piper's broader EUR 7.1 billion estimate.
Where the Numbers Come From
- Data Protection Commission Ireland. (2021). "Data Protection Commission Announces Decision in WhatsApp Inquiry." EUR 225 million fine, 2 September 2021.
- Data Protection Commission Ireland. (2022). "Data Protection Commission Announces Decision in Instagram Inquiry." EUR 405 million fine, 15 September 2022.
- Data Protection Commission Ireland. (2022). "Data Protection Commission Announces Decision in Facebook Data Scraping Inquiry." EUR 265 million fine, 28 November 2022.
- DLA Piper. (2023). "EU and Ireland: Meta's Legal Basis for Targeted Ads Found to Breach GDPR." EUR 390 million combined fine across Facebook and Instagram decisions, 4 January 2023.
- Data Protection Commission Ireland. (2023). "Data Protection Commission Announces Conclusion of Inquiry into Meta Ireland." EUR 1.2 billion fine over EU-US data transfers, decision 12 May 2023, announced 22 May 2023.
- Data Protection Commission Ireland. (2024). "Irish Data Protection Commission Fines Meta Ireland EUR91 Million." Plaintext password storage, 27 September 2024.
- Data Protection Commission Ireland. (2024). "Irish Data Protection Commission Fines Meta EUR251 Million." 2018 breach affecting roughly 29 million accounts, 17 December 2024.
- The Irish Times. (2026). "Meta Loses Challenge to Possible EUR430m Fine Over Personal Data Processing Complaint." High Court judgment, 21 May 2026, final orders pending.
- CMS Law. (2026). "GDPR Enforcement Tracker Report 2026, Numbers and Figures." EUR 6.11 billion cumulative total across all companies, cutoff 1 March 2026.
Note: All figures verified as of July 2026. The EUR 360 to 430 million pending case is not included in the EUR 2.83 billion confirmed total and remains subject to a final DPC decision following the 21 May 2026 High Court ruling. This total is refreshed at least twice a year to track new DPC decisions and CMS Enforcement Tracker Report editions.