
The General Data Protection Regulation (GDPR) continues to shape how organizations collect, process, and protect personal data across Europe and beyond. Its influence now extends far beyond compliance teams, affecting cybersecurity strategies, AI governance, digital advertising, healthcare, financial services, and global cross-border business operations. As regulators intensify enforcement and businesses face growing cyber risks, GDPR statistics provide valuable insight into compliance trends, regulatory priorities, and financial exposure. Explore the latest figures to understand how GDPR continues to influence organizations.
Editor’s Choice
- European regulators issued approximately €1.2 billion in GDPR fines during 2025, maintaining one of the highest annual enforcement totals since the regulation took effect.
- The total value of GDPR fines exceeded €7.1 billion between May 2018 and January 2026 across participating European jurisdictions.
- Organizations reported an average of 443 personal data breaches every day during the latest reporting period, representing a 22% year-over-year increase.
- Ireland remained the leading country by cumulative GDPR fines, with enforcement exceeding €4.04 billion since GDPR became applicable.
- The largest GDPR fine on record remains €1.2 billion, imposed against Meta in 2023 for unlawful international data transfers.
- Nine of the ten largest GDPR fines issued since 2018 have targeted major technology companies.
- During 2026, 25 European data protection authorities are participating in a coordinated enforcement action focused on transparency and information obligations under Articles 12–14 of the GDPR.
Recent Developments
- In early 2026, regulators confirmed that GDPR enforcement activity remained consistently high despite stable annual fine totals.
- European supervisory authorities recorded a 22% increase in reported personal data breaches compared with the previous reporting year.
- The latest reporting period marked the first time breach notifications exceeded 400 per day since GDPR entered into force.
- Regulators identified AI-enabled cyberattacks, geopolitical instability, and expanding incident-reporting obligations as major contributors to the increase in breach notifications.
- The EDPB launched its 2026 Coordinated Enforcement Framework, making transparency and information obligations the primary enforcement priority across participating authorities.
- The EDPB also adopted a common data breach notification template during 2026 to improve consistency among European supervisory authorities.
- Regulators continued increasing scrutiny of cross-border data transfers, online tracking, AI systems, and transparency notices throughout 2025 and 2026.
- Ireland issued the largest GDPR fine of 2025, €530 million against TikTok over international data transfer violations.
- Despite stable annual penalties, authorities emphasized that enforcement priorities continue shifting toward accountability, cybersecurity resilience, and AI governance.
GDPR Enforcement Trends Over Time
- GDPR enforcement increased from just 12 cases in 2018 to a cumulative total of 3,179 cases by 2026.
- Annual enforcement activity rose sharply in 2019, when 171 new cases pushed the cumulative count to 183.
- In 2020, regulators added 414 cases, more than doubling the cumulative total to 597 cases.
- Enforcement continued to accelerate in 2021, with 531 new cases and a cumulative total of 1,128 cases.
- The highest annual enforcement level occurred in 2022, when 607 cases were added, bringing the total to 1,735.
- Annual cases declined slightly to 561 in 2023, although the cumulative enforcement count still climbed to 2,296.
- Enforcement slowed significantly in 2024, with only 320 new cases, the lowest annual figure since 2019.
- Regulatory activity rebounded in 2025, as 407 cases were added and cumulative enforcement surpassed 3,000 cases.
- The chart records 156 new cases in 2026, increasing the cumulative total to 3,179 enforcement cases.
- Between 2018 and 2026, the cumulative number of cases expanded by approximately 264 times, highlighting the rapid growth of GDPR enforcement.

GDPR Compliance Statistics
- GDPR applies to organizations worldwide that process the personal data of individuals located in the European Economic Area, regardless of where the organization operates.
- Organizations increasingly integrate GDPR compliance into broader cybersecurity, governance, and enterprise risk management programs rather than treating it as a standalone legal requirement.
- Cross-border data transfers remain one of the highest-risk compliance areas, generating some of the largest regulatory penalties.
- Regulators continue prioritizing compliance with transparency obligations, including clear privacy notices and accessible information for individuals.
- Organizations increasingly conduct Data Protection Impact Assessments (DPIAs) when deploying AI systems or high-risk processing activities to satisfy GDPR requirements.
- Compliance programs now place greater emphasis on incident response planning, reflecting the sharp rise in reported personal data breaches.
- European regulators continue encouraging organizations to demonstrate accountability, maintain processing records, and document lawful processing decisions.
- Companies increasingly align GDPR compliance with emerging European regulations covering AI, cybersecurity, and digital operational resilience, reducing duplicated governance efforts.
- Large multinational organizations remain the primary targets for complex cross-border investigations because of the scale of their personal data processing activities.
GDPR Fines Statistics
- European regulators imposed approximately €1.2 billion in GDPR fines during 2025.
- The cumulative value of GDPR fines reached approximately €7.1 billion by January 2026.
- Ireland continues leading Europe in total GDPR penalties, exceeding €4.04 billion since 2018.
- The largest single fine in 2025 totaled €530 million, issued against TikTok for unlawful international data transfers.
- The largest GDPR fine ever issued remains €1.2 billion against Meta in 2023.
- Nine of the top ten largest GDPR fines have been imposed on major technology companies.
- Regulators maintained similar fine levels in 2025 and 2024, demonstrating sustained enforcement rather than declining oversight.
- Information security failures, unlawful international transfers, transparency shortcomings, and accountability failures remain among the most common reasons for major financial penalties.
- Large multinational organizations continue receiving the highest-value sanctions because enforcement calculations consider the organization’s global revenue under GDPR rules.
Largest GDPR Fines
- Meta Platforms Ireland Limited received the largest GDPR fine, totaling €1.2 billion in May 2023.
- The second-largest penalty was issued to TikTok Technology Limited, amounting to €530 million in May 2025.
- Meta Platforms, Inc. faced a €405 million fine in September 2022, ranking third overall.
- Meta Platforms Ireland Limited also received a separate €390 million penalty in January 2023.
- TikTok Limited was fined €345 million in September 2023, giving TikTok two entries among the ten largest penalties.
- LinkedIn received a GDPR fine of €310 million in October 2024.
- Uber Technologies Inc. and Uber B.V. were penalized €290 million in July 2024.
- Meta Platforms Ireland Limited accounted for four of the ten largest GDPR fines, highlighting repeated regulatory action against the company.
- The ten largest fines shown in the dataset totaled approximately €4.21 billion.
- Meta-related companies accounted for about €2.51 billion, representing nearly 60% of the combined top-ten fine value.
- The smallest fine among the ten largest penalties was €225 million, issued to WhatsApp Ireland Ltd. in September 2021.
- Every fine in the top ten exceeded €200 million, demonstrating the substantial financial consequences of major GDPR violations.

GDPR Data Breach Statistics
- European organizations averaged 443 notified personal data breaches per day between Jan. 28, 2025, and Jan. 27, 2026.
- Daily breach notifications rose 22% year over year, up from 363 during the previous reporting period.
- The latest period marked the first time since GDPR took effect that average notifications exceeded 400 breaches per day.
- At 443 reports per day, the annualized notification volume equals approximately 161,700 reports, although the underlying survey uses daily averages rather than a single consolidated European count.
- The Netherlands recorded 44,374 breach notifications in 2025, or roughly 122 reports per day.
- The 2025 Dutch total exceeded the 39,773 annual notifications reported for the prior comparative period in a separate cross-country analysis.
- Germany recorded approximately 34,467 breach notifications, while Poland recorded about 19,065 in the comparative European dataset.
- A 2018 Facebook breach affected 29 million accounts worldwide and exposed data including names, contact information, locations, workplaces and dates of birth.
- Approximately 3 million accounts affected by that Facebook incident belonged to users in the European Union and European Economic Area.
- LastPass’s 2022 incident affected personal information tied to as many as 1.6 million UK customers, although investigators found no evidence that attackers decrypted locally stored passwords.
GDPR Breach Notification Statistics
- Organizations must report a qualifying data breach within a strict 72-hour window.
- The daily notification rate surged from 363 to 443 in the year ending Jan. 27, 2026.
- Authorities observed an increase of exactly 80 additional reports per day.
- This growth represents 29,200 additional notifications on an annualized basis.
- Reporting levels experienced a 22% annual increase after several plateaued years.
- The Netherlands recorded exactly 44,374 total notifications throughout 2025.
- Dutch regulators processed an average of 3,698 breach cases per month in 2025.
- The UK regulator releases breach datasets quarterly, with data spanning into March 2026.
Countries With the Highest GDPR Fines
- Ireland leads the ranking with €4.04 billion in cumulative GDPR fines, far exceeding every other country.
- France ranks second with €1.10 billion, equal to roughly one quarter of Ireland’s total.
- Luxembourg has accumulated €0.75 billion in fines, placing it third despite its relatively small market size.
- Italy recorded €0.35 billion in cumulative penalties, less than half of Luxembourg’s total.
- Spain completes the top five with €0.18 billion in GDPR fines between 2018 and 2026.
- Together, these five countries account for approximately €6.42 billion in cumulative GDPR penalties.
- Ireland alone represents nearly 63% of the combined fines imposed across the five leading countries.
- The gap between Ireland and France is €2.94 billion, highlighting the concentration of major enforcement actions in Ireland.

GDPR Penalties Over Time
- European authorities imposed approximately €1.2 billion in GDPR fines during 2025, broadly matching the amount issued in 2024 and signaling sustained enforcement rather than a one-year spike.
- Cumulative GDPR penalties exceeded €7.1 billion between May 2018 and January 2026. More than 60% of that value accumulated from 2023 onward.
- The cumulative fine total stood near €5.9 billion at the beginning of 2025, meaning regulators added roughly €1.2 billion within one year. This calculation uses the reported 2026 cumulative and annual totals.
- The current record fine remains €1.2 billion, imposed in 2023 for unlawful transfers of European user data to the United States.
- A €530 million penalty issued in 2025 ranked as the year’s largest fine and became one of the largest GDPR sanctions on record.
- France increased its annual fine total from €55.2 million in 2024 to nearly €487 million in 2025, an increase driven largely by two high-value decisions.
- France issued 87 sanctions in 2024 and 83 in 2025. Therefore, its sanction count fell slightly even as the total monetary value increased almost ninefold.
- Technology businesses continue to dominate the top of the historical rankings, accounting for nine of the 10 largest fines recorded through early 2026.
GDPR Violation Statistics
- French regulators issued 78 monetary fines in 2025, including 27 decisions that also carried compliance injunctions backed by potential periodic payments.
- Cookie and tracking violations affected 21 sanctioned entities, equal to about one-quarter of France’s 83 sanctions during the year.
- Employee video surveillance violations produced 16 sanctions, accounting for about 19% of the country’s 2025 sanction total.
- Weak data-security measures appeared in 14 simplified decisions, including cases involving weak passwords and shared user accounts.
- Another 14 organizations and professionals received sanctions for failing to respond to regulatory requests.
- Authorities issued 14 decisions for failures to honor access, deletion, or objection requests from individuals.
- Commercial or political outreach violations accounted for 10 penalty decisions, often because organizations lacked valid consent for electronic messages or partner data sharing.
- A 2025 study covering 254,148 website observations across 31 countries found that 67% of websites displayed a consent interface.
- Only 15% of the studied websites met the researchers’ minimum compliance standard, commonly because the interface lacked an effective rejection option.
- Consent-management platforms supplied 67% of observed interfaces, while three providers controlled 37% of that market. Platform choice explained 18% of measured compliance variation.
GDPR Fines by Violation Type
- Non-compliance with general data processing principles generated the highest fines at €3.63 billion.
- An insufficient legal basis for data processing resulted in €2.38 billion in penalties.
- Weak technical and organizational security measures led to fines totaling €1.73 billion.
- Failure to meet information obligations accounted for €1.25 billion in GDPR fines.
- The four leading violation categories collectively generated approximately €8.99 billion in penalties.
- Failure to properly fulfill data subjects’ rights resulted in fines of €355.61 million.
- Breaches of data breach notification obligations attracted €78.45 million in penalties.
- Inadequate data processing agreements generated fines totaling €72.02 million.
- Insufficient cooperation with a supervisory authority resulted in €43.49 million in fines.
- Data protection officer violations were comparatively smaller, with €39.12 million for insufficient involvement and €33.76 million for failure to appoint one.

GDPR Regulatory Activity
- In 2025, the coordinating body adopted 29 formal opinions for consistent interpretation.
- Regulators issued four sets of major guidance in 2025 covering topics like blockchain.
- The public register held 1,333 final one-stop-shop decisions by July 2026.
- One authority completed 323 investigations and issued 259 corrective measures in 2025.
- The 259 measures contained 143 compliance orders, 31 reminders, and two warnings.
- Nearly 80 national decisions entered the European cooperation process during 2025.
- 32 supervisory authorities gathered responses from 764 controllers regarding erasure requests.
- 25 authorities joined a 2026 coordinated initiative to review privacy information clarity.
- Authorities receive over 100,000 complaints yearly and have launched 20,000 investigations.
Consumer Privacy Awareness Statistics
- Seventy-two percent of EU residents surveyed in 2024 had heard of GDPR, while 40% said they knew what the regulation was.
- GDPR awareness exceeded 70% in 19 EU member states, demonstrating broad but uneven familiarity across the region.
- Sweden recorded the highest measured GDPR awareness at 92%, followed by the Netherlands at 88%.
- Malta and Denmark each recorded 84% awareness, placing them among the highest-ranking countries in the survey.
- Bulgaria recorded the lowest GDPR awareness at 59%, followed by Lithuania at 63% and France at 64%.
- Sixty-eight percent of respondents had heard of a national authority responsible for protecting data rights. However, only 24% could identify the relevant public authority.
- Awareness of national regulators reached 82% in the Netherlands, compared with 56% in Austria and 58% in Spain.
- In a 2024 digital survey, 46% of respondents identified misuse of personal data as an online issue with a major personal impact.
- A 2026 survey found that 39% of Europeans expressed privacy or data protection concerns about generative AI tools, while 47% cited potential misuse of personal data as a broader online risk.
- During 2025, one regulator’s 266 in-person educational initiatives reached more than 20,000 people, while its staff answered 35,403 calls and 14,654 written information requests.

Data Subject Rights Request Statistics
- One national regulator received a record 20,150 complaints in 2025, up 10% from 2024.
- Based on the reported growth rate, the same authority received approximately 18,300 complaints in 2024, making the 2025 total an increase of around 1,800 cases.
- Approximately 1,900 complaints submitted in 2025 directly concerned personal data breaches, equal to about 9% of the annual complaint total.
- The authority transferred more than 230 cross-border complaints to European counterparts and responded to 600 requests from other regulators during 2025.
- In 2024, the UK regulator completed 36,049 data protection complaints, illustrating the scale of public demand for privacy enforcement outside the EU’s institutional structure.
- The right to erasure ranks among the most frequently exercised GDPR rights and generates a growing number of complaints and regulatory decisions across Europe.
- The 2025 coordinated erasure review involved 764 organizations across different sectors and business sizes.
- Regulators in the coordinated review represented 32 supervisory authorities, giving the assessment broad geographic coverage across the European Economic Area.
- In 2025, 14 organizations and professionals received sanctions in one jurisdiction for failing to respect requests involving access, deletion or objection rights.
- European regulators collectively receive more than 100,000 complaints each year, placing rights-request and complaint management among their largest continuing workloads.
Industry-Wise GDPR Statistics
- Technology and social media account for nine of the 10 largest GDPR fines.
- Online advertising saw 21 organizations sanctioned for cookie violations in 2025.
- Workplace monitoring led to 16 sanctions in 2025 for improper video surveillance.
- Cybersecurity weaknesses caused roughly 30% of sanctions and one-third of inspections in 2025.
- Health organizations submitted 539 applications in 2025, including 406 for health research.
- Commercial marketing led to 10 simplified penalties in 2025 due to lack of valid consent.
- Five candidates in the 2024 European elections received sanctions related to political outreach.
- GDPR reduced weekly visits for 6,286 websites by 4.88% initially and 10.02% after 18 months.
- Revenue effects averaged $7 million for e-commerce and $2.5 million for ad-supported sites.
- GDPR reduced online trackers across 294 publishers by 14.79%, or four per publisher.
GDPR Fines by Industry in the EU
- Media, telecoms, and broadcasting received the largest GDPR fines, totaling €4,970.52 million as of May 2026.
- This sector accounted for approximately 80.8% of the €6.15 billion in fines shown across all industries.
- Industry and commerce ranked second with €372.84 million, followed closely by employment at €351.70 million.
- The top three industries collectively accumulated about €5.70 billion, representing nearly 92.6% of total fines.
- Transportation and energy recorded €230.61 million, while finance, insurance, and consulting faced €122.97 million in penalties.
- Fines were considerably lower in the public sector and education (€37.56 million), health care (€32.36 million), and accommodation and hospitality (€22.78 million).
- Individuals and private associations, unassigned cases, and real estate each recorded less than €5 million in cumulative GDPR fines.
- The data highlights a substantial concentration of GDPR penalties within data-intensive industries, particularly media and telecommunications.

GDPR Key Trends
- Personal data breach notifications increased 22% year over year, rising from 363 to 443 reports per day in the period ending Jan. 27, 2026.
- The daily average exceeded 400 notifications for the first time since GDPR enforcement began in May 2018.
- France recorded 6,167 breach notifications in 2025, and hacking accounted for about half of those incidents.
- In response to rising cyber risk, that regulator allocated 50% of its 2026 inspections and enforcement activity to personal data security.
- Transparency has become a major 2026 enforcement theme, with 25 European authorities examining compliance with GDPR information requirements.
- AI now sits at the center of privacy governance; 39% of Europeans reported privacy or data protection concerns about generative AI.
- Cookie compliance remains weak. A 2025 study of 254,148 website observations found that 67% displayed consent interfaces, but only 15% met a minimum compliance standard.
- Consent-management services supplied 67% of the interfaces in that study, while three providers controlled 37% of the market and platform choice explained 18% of compliance variation.
- Regulatory guidance increasingly connects GDPR with blockchain systems, online platforms, foreign data transfers, pseudonymization and AI-related processing.
- Enforcement now combines financial penalties with compliance orders, warnings, coordinated investigations and sector-specific reviews, indicating a broader regulatory strategy than fines alone.
Frequently Asked Questions (FAQs)
European regulators imposed approximately €1.2 billion in GDPR fines during 2025, bringing cumulative penalties since May 2018 to more than €7.1 billion.
European authorities received an average of 443 personal data breach notifications per day from Jan. 28, 2025, to Jan. 27, 2026, a 22% year-over-year increase from 363.
As of July 31, 2026, a major enforcement database tracked 3,202 GDPR enforcement actions, including 156 recorded during 2026, with total fines of approximately €6.31 billion.
One European regulator received a record 20,150 complaints in 2025, up 10% from 2024, with about 1,900 complaints directly involving personal data breaches.
Technology companies accounted for nine of the 10 largest GDPR fines, while the largest single penalty remained €1.2 billion.
Conclusion
GDPR continues to shape global privacy compliance through stronger enforcement, rising breach notifications and growing consumer awareness. The latest statistics show that regulators are expanding their focus beyond financial penalties to include AI governance, cybersecurity, transparency, online tracking and data subject rights. As organizations face increasingly complex privacy obligations, maintaining robust compliance programs, effective security controls and clear data governance practices will remain essential for reducing regulatory risk and building long-term trust with customers.