EU Regulation 2016/679 - Decision Register

ANNEX A / DECISION REGISTER / 2018 - 2026

Every Major GDPR Fine,Searchable Decision Register

Each entry is sourced to the published decision of the issuing data protection authority. Filter by company, violation, country, year, or status. Status reflects the latest publicly known stage of any appeal proceeding.

Indexed decisions

64

Total recorded

€5.6B

Average fine

€88.1M

Largest single fine

€1.2B

Most active DPA

AEPD (Spain)

I.Decisions

Sources cited per row. Status checked April 2026.

Showing 25 of 64 fines

Meta Platforms (Facebook)

Under Appeal

Record-breaking fine for transferring EU user data to the United States without adequate safeguards following the Schrems II ruling. The DPC found that Meta's reliance on Standard Contractual Clauses was insufficient to protect EU citizens' data from US surveillance programs.

Data Protection Commission (DPC)2023-05-22Cross-Border Transfer ViolationsArt. 46(1)

€1,200,000,000

Amazon Europe Core

Overturned

Luxembourg's CNPD imposed this fine in July 2021 for Amazon's advertising-targeting system processing personal data without a valid Article 6 lawful basis, following complaints coordinated by the French digital-rights group La Quadrature du Net. The administrative tribunal upheld the decision in March 2025, but on 12 March 2026 the Cour administrative (Luxembourg's appeal court) annulled the fine, finding the CNPD had not properly assessed Amazon's degree of negligence or whether a measure other than a fine was appropriate. The court confirmed the CNPD's core findings (legitimate interest was not a valid basis for the advertising processing) and the case was remitted to the CNPD to reconsider the penalty.

Commission Nationale pour la Protection des Donnees (CNPD)2021-07-16Consent ViolationsArt. 6, Art. 7

€746,000,000

TikTok Technology Limited

Under Appeal

The DPC fined TikTok for transferring European user data to China without adequate protections and for misleading the DPC about data storage practices. The investigation found that TikTok staff in China had access to EEA user data without equivalent protection measures.

Data Protection Commission (DPC)2025-05-02Cross-Border Transfer ViolationsArt. 46(1), Art. 5(1)(a)

€530,000,000

Meta Platforms (Facebook & Instagram)

Final

Two combined fines (Facebook €210M + Instagram €180M) for forcing users to accept personalised advertising as a condition of using the service. The EDPB directed the DPC to investigate the lawful basis for processing, finding that Meta could not rely on 'contractual necessity' for behavioural advertising.

Data Protection Commission (DPC)2023-01-04Consent ViolationsArt. 6(1), Art. 7

€390,000,000

Google (LLC & Ireland)

Final

The CNIL fined Google €325M (€200M against Google LLC and €125M against Google Ireland) for inserting advertising disguised as emails between messages in the 'Promotions' and 'Social' tabs of Gmail without consent, and for placing advertising cookies when users created a Google account without valid consent. The cookie breach concerned more than 74 million French accounts, of which 53 million had been shown the ad-style emails. Like the earlier CNIL cookie fines, the decision rests on Article 82 of the French Data Protection Act (the ePrivacy regime) rather than the GDPR itself.

Commission Nationale de l'Informatique et des Libertes (CNIL)2025-09-01Consent ViolationsArt. 82 Loi Informatique et Libertes

€325,000,000

LinkedIn Ireland

Final

LinkedIn was fined for processing user data for behavioural analysis and targeted advertising without a valid legal basis. The DPC found that LinkedIn's reliance on legitimate interest and consent for behavioural advertising did not meet GDPR requirements, and transparency obligations were not fulfilled.

Data Protection Commission (DPC)2024-10-24Consent ViolationsArt. 5(1)(a), Art. 6, Art. 13, Art. 14

€310,000,000

Uber Technologies

Under Appeal

The Dutch DPA imposed the largest-ever fine by a non-Irish regulator for Uber's transfer of European driver data to the US without adequate protections. French drivers filed the initial complaint through the LQDN rights group, and the Dutch AP acted as lead supervisory authority given Uber's EU headquarters.

Autoriteit Persoonsgegevens (AP)2024-08-26Cross-Border Transfer ViolationsArt. 44

€290,000,000

Meta Platforms (Facebook)

Final

Facebook's personal data of over 533 million users from 106 countries was scraped and leaked online. The DPC found that Facebook failed to implement appropriate technical measures (data protection by design and default) to prevent the mass scraping of user data through its contact importer and search features.

Data Protection Commission (DPC)2022-11-28Data Breach Notification FailuresArt. 25(1), Art. 25(2)

€265,000,000

Meta Platforms (Facebook)

Final

Following two inquiries into the September 2018 Facebook 'View As' token breach (which exposed roughly 29 million accounts globally, about 3 million in the EU/EEA), the DPC fined Meta €251 million. The bulk fell under Article 25 data-protection-by-design and by-default (€130M for Art. 25(1) and €110M for Art. 25(2)), with a further €8M under Article 33(3) for an incomplete breach notification and €3M under Article 33(5) for failing to document the breaches adequately.

Data Protection Commission (DPC)2024-12-17Data Breach Notification FailuresArt. 25(1), Art. 25(2), Art. 33(3), Art. 33(5)

€251,000,000

WhatsApp Ireland

Under Appeal

WhatsApp was fined for failing to meet transparency obligations regarding how it shared user data with other Meta companies. The initial DPC proposed fine was significantly lower, but the European Data Protection Board (EDPB) used its dispute resolution mechanism to increase it.

Data Protection Commission (DPC)2021-09-02Transparency ViolationsArt. 5(1)(a), Art. 12, Art. 13, Art. 14

€225,000,000

SHEIN (Infinite Styles Services)

Final

The CNIL fined Infinite Styles Services Co. Limited, the Irish entity operating shein.com, for placing advertising cookies on visitors' devices before any consent was given and for continuing to read cookies after users clicked 'Refuse all' or withdrew consent. The information banners also failed to describe the advertising purpose of the cookies. The decision followed an inspection of the site that began in August 2023 and, like the parallel Google case, rests on Article 82 of the French Data Protection Act.

Commission Nationale de l'Informatique et des Libertes (CNIL)2025-09-01Consent ViolationsArt. 82 Loi Informatique et Libertes

€150,000,000

Google LLC

Final

CNIL fined Google for making it difficult for users to refuse cookies on google.fr and youtube.com. While accepting all cookies required one click, refusing them required multiple steps across several pages, which the CNIL deemed a violation of free consent principles.

Commission Nationale de l'Informatique et des Libertes (CNIL)2022-01-06Consent ViolationsArt. 82 Loi Informatique et Libertes

€150,000,000

Meta Platforms (Facebook)

Final

Meta was fined after an investigation found that hundreds of millions of Facebook user passwords had been stored in plaintext on internal systems since 2012. The investigation was triggered by Meta's own notification to the DPC in 2019.

Data Protection Commission (DPC)2024-09-26Inadequate Security MeasuresArt. 5(1)(f), Art. 32

€91,000,000

Google Ireland

Final

CNIL fined Google Ireland €90M (alongside Google LLC's €150M) for making it difficult for youtube.com users to refuse cookies compared to accepting them. The restricted formation noted that the refusal mechanism required several clicks while acceptance was a single click.

Commission Nationale de l'Informatique et des Libertes (CNIL)2022-01-06Consent ViolationsArt. 82 Loi Informatique et Libertes

€90,000,000

Microsoft Ireland

Final

CNIL fined Microsoft for depositing advertising cookies on users' computers visiting bing.com without prior consent. The CNIL found that Microsoft placed cookies for advertising purposes before users could express their preferences.

Commission Nationale de l'Informatique et des Libertes (CNIL)2022-12-22Consent ViolationsArt. 82 Loi Informatique et Libertes

€60,000,000

Facebook Ireland

Final

CNIL fined Facebook for making it overly complex for facebook.com users in France to refuse cookies. While a single click accepted all tracking, refusing required navigating through multiple settings pages, violating the requirement for freely given consent.

Commission Nationale de l'Informatique et des Libertes (CNIL)2022-01-06Consent ViolationsArt. 82 Loi Informatique et Libertes

€60,000,000

Google LLC

Final

The first major GDPR fine. CNIL found that Google's consent architecture for personalised advertising lacked transparency and valid consent. Information about data processing was spread across multiple documents, and consent for ad personalisation was pre-checked by default.

Commission Nationale de l'Informatique et des Libertes (CNIL)2019-01-21Transparency ViolationsArt. 13, Art. 14, Art. 6

€50,000,000

Criteo

Final

Criteo, a major advertising technology company, was fined for processing personal data for advertising purposes without valid consent. Users' data was collected via cookies placed by Criteo's partners without proper information or freely given consent.

Commission Nationale de l'Informatique et des Libertes (CNIL)2023-06-15Consent ViolationsArt. 7, Art. 15, Art. 17, Art. 26

€40,000,000

H&M (Hennes & Mauritz)

Final

H&M's Nuremberg service centre recorded extensive personal details about employees including health issues, family problems, and religious beliefs during return-to-work interviews. This data was stored and accessible to managers for profiling employees.

Hamburg Commissioner for Data Protection2020-10-01Unlawful ProcessingArt. 5, Art. 6

€35,258,707

Clearview AI

Final

The Dutch AP imposed a €30.5M fine on Clearview AI, the largest of the European Clearview penalties, for building an illegal database of biometric facial codes by scraping images from the internet without a lawful basis, unlawfully processing special-category biometric data under Article 9, failing to inform data subjects or answer access requests, and not designating an EU representative under Article 27. The AP also warned that using Clearview's services is itself unlawful and attached penalty payments of up to €5.1M for continued non-compliance.

Autoriteit Persoonsgegevens (AP)2024-09-03Unlawful ProcessingArt. 5(1)(a), Art. 6, Art. 9, Art. 12, Art. 14, Art. 15, Art. 27

€30,500,000

TIM (Telecom Italia)

Final

TIM conducted millions of unwanted marketing calls, including to numbers registered on the national opt-out list. The Garante identified systematic failures in consent management, data retention, and a failure to honour data subjects' opt-out requests.

Garante per la Protezione dei Dati Personali2020-01-15Consent ViolationsArt. 5, Art. 6, Art. 7, Art. 17, Art. 21

€27,800,000

Free Mobile

Final

After an October 2024 breach in which an attacker exploited insufficient VPN authentication and ineffective abnormal-behaviour detection to access personal data on some 24 million Free Mobile and Free subscriber contracts (including IBANs for dual customers), the CNIL fined Free Mobile €27M for inadequate security under Article 32. The regulator also found the breach-notification email to affected individuals did not contain all the information required by Article 34, and that data on former subscribers had been retained beyond the period necessary, breaching Article 5(1)(e).

Commission Nationale de l'Informatique et des Libertes (CNIL)2026-01-13Inadequate Security MeasuresArt. 32, Art. 34, Art. 5(1)(e)

€27,000,000

Enel Energia

Final

Enel Energia was fined for aggressive telemarketing using personal data without valid consent. The investigation uncovered a complex chain of data brokers and call centres operating with inadequate consent management, resulting in millions of unsolicited calls.

Garante per la Protezione dei Dati Personali2022-11-24Consent ViolationsArt. 5, Art. 6, Art. 7

€26,500,000

British Airways

Reduced on Appeal

British Airways suffered a data breach in 2018 where attackers exploited vulnerabilities to skim payment card details from the ba.com website and mobile app. The ICO initially proposed a GBP183M fine but reduced it to GBP20M citing COVID-19 economic impacts and BA's cooperation.

Information Commissioner's Office (ICO)2020-10-16Inadequate Security MeasuresArt. 5(1)(f), Art. 32

€22,046,000

Originally €204,000,000

Marriott International

Reduced on Appeal

Marriott's Starwood guest reservation database was breached, exposing approximately 339 million guest records globally, including 30 million EEA residents. The breach originated from a 2014 compromise of Starwood systems that Marriott failed to detect during its 2016 acquisition due diligence.

Information Commissioner's Office (ICO)2020-10-30Inadequate Security MeasuresArt. 5(1)(f), Art. 32

€20,450,000

Originally €110,390,200

Page 1 of 3

SECTION II / TREND ANALYSIS

Where enforcement is heading

GDPR enforcement has hardened year on year. The first sub-billion year was 2018, the first sub-billion month is now uncommon. Meta's Article 46(1) fine in May 2023 (€1.2 billion) signalled that the upper-tier statutory cap is no longer notional, and TikTok's May 2025 €530 million decision shows transatlantic transfer enforcement is now a settled enforcement lane rather than an exceptional one.

Cookie consent and behavioural advertising are the most frequently cited grounds across the register. France's CNIL has driven this workstream under the ePrivacy Directive and Article 82 of the French Data Protection Act, sometimes in coordination with Article 6 GDPR. Ireland's DPC is the lead supervisory authority for several of the largest cases through the one-stop-shop mechanism, with the European Data Protection Board increasingly stepping in under Article 65.

UK enforcement is now governed by the UK GDPR, a separate regime from the EU GDPR post-Brexit, and is handled by the ICO. UK decisions are listed here for reference but are not binding under the EU framework.

RELATED REGISTERS

By supervisory authorityBy violation typeBy industry sectorStatisticsAppeals (Art. 78)Article 83 calculator

REGISTER UPDATED 2026-04-28