The largest GDPR fine ever issued is EUR 1.2 billion, imposed on Meta Platforms Ireland Limited by Ireland's Data Protection Commission on 22 May 2023 for transferring EU users' Facebook data to the United States without an adequate legal safeguard. As of 2026, per enforcementtracker.com's live database and the CMS Enforcement Tracker Report 2026, no later decision has come close to it.

What makes the record unusual is not just its size. Ireland's own regulator did not want to impose a fine at all, and the record has moved only twice in GDPR's entire history. Below is the full story: how the fine came to exist over the regulator's objection, which fines held the "largest ever" title before it, and how close EUR 1.2 billion actually sits to what the law could have allowed.

The largest GDPR fine ever issued is EUR 1.2 billion EUR1.2B still the record GDPRfine as of 2026

How did Meta end up with the largest GDPR fine ever?

The fine closed a decade-long case. Max Schrems' privacy advocacy group noyb first complained about Facebook's EU-to-US data transfers back in 2013, and the dispute ran through two separate Court of Justice of the EU rulings that struck down the legal frameworks Meta relied on, first Safe Harbor in 2015, then Privacy Shield in 2020. By the time Ireland's DPC issued a draft decision in 2022, Meta had been operating under a legally uncertain transfer mechanism, Standard Contractual Clauses, for years, with no adequate protection against US government surveillance access under Section 702 of the Foreign Intelligence Surveillance Act.

The DPC's draft decision ordered Meta to suspend the transfers but did not include a fine, on the reasoning that a suspension order alone would already be "effective, proportionate and dissuasive." Under GDPR's one-stop-shop mechanism, that draft went to every other EU data protection authority for consensus, and objections from other regulators sent the case to the European Data Protection Board for a binding decision under Article 65. The EDPB "largely overturned" the DPC's position, per European Digital Rights' reporting on the case, and directed Ireland to add a fine, which the EDPB itself set at the record-breaking EUR 1.2 billion figure. Ireland's DPC, bound to adopt whatever the EDPB decided even where it disagreed, announced the fine on 22 May 2023.

One-line takeaway: the largest GDPR fine in history exists because a European board overruled the one regulator that did not want to impose it.

Figure 1: How Ireland's DPC ended up issuing a fine it originally opposed. Source: European Digital Rights (2023) and ByrneWallaceShields legal analysis of the DPC decision.

If your site moves EU user data across borders, including through analytics, ad tools, or cloud storage hosted outside the EU, this case is the clearest signal yet that regulators expect the transfer mechanism named in your privacy policy to be currently valid, not just filled in once and forgotten. You can generate a GDPR-ready privacy policy that documents your legal basis and transfer safeguards in the format regulators check first.

Which fines held the "largest ever" title before Meta's?

The record has changed hands only twice in GDPR's history. France's CNIL set the first widely recognized benchmark, fining Google EUR 50 million on 21 January 2019 for insufficient transparency and consent around behavioral advertising, the first fine large enough to draw global attention to GDPR's enforcement teeth. That figure held the "largest GDPR fine ever" title for roughly two and a half years.

Luxembourg's CNPD took the record in July 2021, fining Amazon Europe EUR 746 million over ad-personalization consent practices, a figure nearly 15 times larger than Google's. Amazon held the record for about 22 months until Ireland's Meta decision in May 2023 more than doubled it again. No fine issued since, including TikTok's EUR 530 million Irish penalty in 2025, has come within striking distance of Meta's figure.

One-line takeaway: each time the record has changed hands, the new fine has been at least 15 times larger than the one it replaced.

Figure 2: The three fines that have held the "largest GDPR fine ever" title since 2018. Source: Wikipedia's summary of the CNIL decision, MLex, and Ireland's Data Protection Commission.

Record GDPR fine at each handover (EUR millions) 04008001,2001,600M50Google 2019746Amazon 20211,200Meta 2023

Figure 3: Each new record has dwarfed the one before it. Source: France's CNIL (2019), Luxembourg's CNPD (2021), Ireland's DPC (2023).

Worth noting: Amazon's EUR 746 million fine, the record for nearly two years, was annulled by a Luxembourg appeals court on procedural grounds in March 2026 and sent back to the CNPD for reconsideration. The underlying violation was not overturned, only the fine amount and process, but it means the runner-up spot on this list is currently unsettled while Meta's record sits undisturbed at the top.

How big is EUR 1.2 billion next to what GDPR allows?

Large as it is, the Meta fine landed well short of the legal ceiling. GDPR's Article 83 caps its higher tier of fines at the greater of EUR 20 million or 4% of a company's total global annual revenue. Applied to Meta's USD 116.6 billion in full-year 2022 revenue, the figure GDPR uses as the base year for a 2023 decision, the 4% ceiling works out to roughly USD 4.7 billion. The actual EUR 1.2 billion penalty is roughly 26% of that maximum.

Meta's fine as a share of the statutory maximum 26%of the 4% statutory maximum0100

Figure 4: Meta's fine as a share of the statutory maximum GDPR allowed, based on 2022 global revenue. Source: Meta's Q4 and full-year 2022 earnings release; GDPR Article 83.

That gap matters for how the fine should be read. Regulators did not reach for the largest number the law technically permitted; they set a figure large enough to be the record while still leaving headroom below the cap. A company with a more severe or more prolonged violation, or one that failed to cooperate with the investigation, could in theory face a proportionally larger fine relative to its revenue than Meta did.

One-line takeaway: the record fine used only about a quarter of the maximum penalty GDPR actually allows against a company Meta's size.

How does the record fine compare to Meta's other GDPR penalties?

Meta itself holds three of the fines large enough to appear among GDPR's biggest ever, all from Ireland's DPC: the EUR 1.2 billion transfer fine, a EUR 390 million fine from January 2023 over the legal basis for behavioral advertising, and a EUR 265 million fine from 2022 following a data-scraping breach. Combined, Meta's three fines total roughly EUR 1.86 billion, and the record-setting May 2023 decision alone makes up about 65% of everything Meta has paid under GDPR.

FineAmountDateRegulatorReason
Meta (transfers)EUR 1.2 billionMay 2023Ireland DPCUnlawful EU-US data transfers
Meta (ad consent)EUR 390 millionJanuary 2023Ireland DPCLegal basis for behavioral ads
Meta (data scraping)EUR 265 million2022Ireland DPCBreach affecting scraped user data

Table: Meta's three largest GDPR fines, all from Ireland's DPC. Source: Data Protection Commission Ireland press releases, compiled via the CMS Enforcement Tracker Report 2026.

Meta combined EUR 1.86B in GDPR fines, by decision 1,200M390M265MTransfers (record fine, 2023)1,200MAd consent (2023)390MData scraping breach (2022)265M

Figure 5: The record fine accounts for about two-thirds of everything Meta has paid under GDPR to date. Source: Data Protection Commission Ireland, compiled via the CMS Enforcement Tracker Report 2026.

One-line takeaway: no other company appears twice among GDPR's largest fines; Meta appears three times, and its record decision alone is worth more than its other two fines combined.

This record fine is only one entry in a much larger enforcement picture. For the full ranked list beyond just the single largest decision, see our biggest GDPR fines of all time roundup of the top 50, or our broader GDPR fines totals and averages for how this record fits into cumulative enforcement since 2018. We also track the average GDPR fine and a full year-by-year fines timeline as separate deep dives in this cluster, for readers who want the trend line rather than the record holder alone.

The Bottom Line

EUR 1.2 billion has been the largest GDPR fine ever issued since 22 May 2023, and the record has moved only twice across GDPR's entire history, each time by a company at least an order of magnitude larger than the one that held the title before it. The most citable detail is not the size of the number but how it came to exist: Ireland's own regulator drafted a decision with no fine attached, and the European Data Protection Board overruled that position to set the record anyway, a reminder that GDPR's most consequential decisions increasingly come from EU-level dispute resolution rather than any single national authority. For most sites, the practical lesson sits below the headline figure: the violation was a stale legal basis for a cross-border data transfer, exactly the kind of disclosure that goes out of date quietly until a regulator asks to see it.

Frequently Asked Questions

What is the largest GDPR fine ever issued? EUR 1.2 billion, imposed on Meta Platforms Ireland Limited by Ireland's Data Protection Commission on 22 May 2023 over unlawful transfers of EU user data to the United States. It remains the record as of 2026, per enforcementtracker.com's live database and the CMS Enforcement Tracker Report 2026.

Did Ireland's regulator actually want to fine Meta 1.2 billion euros? No. Ireland's DPC drafted a decision that opposed adding any fine to its order suspending the data transfers, arguing a fine would not be effective, proportionate, or dissuasive on top of the suspension. The European Data Protection Board overruled that position through Article 65 binding dispute resolution and imposed the EUR 1.2 billion fine anyway.

How many times has the record for largest GDPR fine changed hands? Twice since GDPR took effect in May 2018. France's CNIL held the record with a EUR 50 million fine against Google from January 2019 until July 2021, when Luxembourg's CNPD fined Amazon EUR 746 million. That stood until Ireland's Meta decision in May 2023, which has now held the record for more than three years.

How big is the Meta fine compared to what GDPR could have imposed? EUR 1.2 billion works out to roughly a quarter of the statutory maximum. GDPR's Article 83 caps the largest tier of fines at 4 percent of a company's global annual revenue, and 4 percent of Meta's USD 116.6 billion in 2022 revenue is roughly USD 4.7 billion, meaning regulators fined Meta at well under half of what the law allowed.

Where the Numbers Come From

  1. IAPP. (2023). "Meta Fined GDPR-Record 1.2 Billion Euros in Data Transfer Case." EUR 1.2 billion fine, announced 22 May 2023, Ireland's Data Protection Commission.
  2. European Digital Rights (EDRi). (2023). "EUR 1.2 Billion GDPR Fine for Meta." Decade-long case, 2013 to 2023, EDPB overturned DPC's position.
  3. ByrneWallaceShields. (2023). "Not All Fine: Meta Fined EUR 1.2 Billion." DPC's draft decision opposed a fine; EDPB decision dated 12 May 2023 under Article 65.
  4. enforcementtracker.com. Live GDPR fines database, 3,202 recorded actions, EUR 6.31 billion cumulative, checked 2026.
  5. Data Protection Commission Ireland. (2023). "Data Protection Commission Announces Conclusion of Two Inquiries into Meta Ireland." EUR 210 million and EUR 180 million fines (EUR 390 million combined), 4 January 2023.
  6. CMS Law. (2026). "GDPR Enforcement Tracker Report 2026, Numbers and Figures." 2,685 fines, EUR 6.11 billion cumulative total.
  7. MLex. (2026). "Amazon Sees Luxembourg Appeals Court Annul EUR746 Million GDPR Fine." Fine annulled and remanded for reconsideration, 12 March 2026.
  8. Meta Platforms. (2023). "Meta Reports Fourth Quarter and Full Year 2022 Results." Full-year 2022 revenue of USD 116.609 billion.

Note: All figures verified as of 2026. The EUR 746 million Amazon fine referenced for historical comparison is under active reconsideration following a March 2026 Luxembourg appeals court ruling. Figures are refreshed at least twice a year as new enforcement decisions and tracker editions are published.