The Biggest GDPR Fines of 2023 (2024)

The financial penalties for breaching the GDPR can be staggering, running into hundreds of millions of euro.

by Niall McCarthy |Updated: 16.01.2024| 5 min

    The Biggest GDPR Fines of 2023 (1)

    Europe’s General Data Protection Regulation (GDPR) contains hundreds of pages’ worth of requirements and it is considered one of the toughest privacy and security laws globally. In effect since May 25, 2018, the regulation imposes obligations on organisations anywhere in the world as long as they target or collect data related to people in the EU.

    The scale and complexity of the GDPR has turned it into a daunting prospect for compliance departments, though the availability of state-of-the art integrated compliance management platforms has helped ease the burden.

    Nevertheless, breaches are serious and fines regularly run into hundreds of millions of euro with a record penalty smashing the billion threshold last year. This article looks back at the biggest fines of 2023.

    The Biggest GDPR Fines of 2023 (2)

    1. Meta – €1.2 billion (Ireland)

    In May 2023, Ireland’s Data Protection Commission imposed a record $1.2 billion fine on Facebook owner Meta. The mammoth penalty related to the transfer of European Facebook user data to the United States without sufficient protection from Washington’s intelligence agencies. Meta was also ordered to suspend the transfer of user data between the EU and the US within six months. Andrea Jelinek, Chair of the European Data Protection Board, said: “The EDPB found that Meta IE’s infringement is very serious since it concerns transfers that are systematic, repetitive and continuous. Facebook has millions of users in Europe, so the volume of personal data transferred is massive. The unprecedented fine is a strong signal to organisations that serious infringements have far-reaching consequences.”

    2. Meta – €390 million (Ireland)

    The Irish Data Protection Commission also slapped Meta with the second-highest penalty of 2023 when two fines were imposed on the company adding up to a collective €390 million. The decision was announced on 4 January 2023 with a €210 million fine relating to GDPR breaches by Facebook and a further €180 million penalty due to breaches by Instagram. Whereas Meta used to rely on users providing their informed consent to be served with personalised and behavioural advertisem*nts, it later added a clause whereby users were effectively forced to agree that their data could be used, leading to the January 2023 fine.

    3. TikTok – €345 million (Ireland)

    Irish regulators fined TikTok €345 million after an investigation found that the platform improperly processed children’s data. It examined the age verification aspect of the registration phase and the processing of children’s personal data between 31 July and 31 December 2020. The investigation found that videos posted to children’s user accounts were public by default while comments were also enabled by default. The Chinese-owned-platform said that it “respectfully disagreed” with the scale of the fine imposed.

    4. Criteo – €40 million (France)

    French advertising technology company Criteo was fined €40 million by France’s Data Protection Authority (CNIL) for GDPR breaches related to targeted advertising. CNIL stated that it found fine GDPR infringements after the company used tracking and data processing techniques to profile internet users for more specific ads. Criteo argued that this “behavioral retargeting” was not deliberate and that the fine was disproportionate compared to the penalties handed out to US tech companies. This resulted in CNIL reducing the initial sum by a third.

    The Biggest GDPR Fines of 2023 (3)

    5. TikTok – €14.5 million (UK)

    The UK’s Information Commissioner’s Office fined TikTok €14.5 million for failing to comply with data protection principles under the GDPR after allowed children under the age of 13 were allowed to create accounts on the platform. This was in violation of the GDPR’s requirement for organisations to obtain parental consent for the collection and processing of data from children under 13 yeas of age. In addition to a lack of adequate measures to prevent children from accessing the platform, TikTok also failed to provide information to children about how their data would be collected and processed.

    6. Axpo Italia Spa – €10 million (Italy)

    Garante, the Italian Data Protection Authority, imposed a €10 million fine on Axpo Italia in late September 2023. The producer and trader of renewable energy products was penalized for processing outdated and inaccurate customer data, violating Articles 5(1)(a), 5(1)(d), 5(2), and 24 of the GDPR. It was found that Axpo acquired new electricity and gas contracts through a network of sales agents and sub-agents without having appropriate procedures in place to ensure the data corresponded to the actual users. On top of the fine, Garante ordered Axpo to adopt a series of corrective measures.

    7. Tim S.p.A. – €7.6 million (Italy)

    Italy also saw another considerable fine for multiple GDPR breaches in April 2023 when Garante penalized TIM S.p.A. to the tune of €7.6 million. An investigation was launched after complaints were received from multiple individuals alleging that the company’s telemarketing activities were unlawful. These included a failure to address data subject rights requests, a lack of documentation to demonstrate recipients’ consent to commercial communications as well as non-compliance with the information provision obligations under the GDPR. As a result, Articles 5(2), 6, 7, 12(2), 12(3), 13, 14, 15(1), 24, and 32(1)(b) of the GDPR were breached.

    8. WhatsApp – €5.5 million (Ireland)

    WhatsApp was handed a €5.5 million fine by Ireland’s Data Protection Commission at the start of the year. The penalty was imposed after an individual complained about how the app asked users to agree to its updated terms of service when the GDPR came into effect. If they declined, they would no longer be able to access the service and the individual in question argued that users were being “forced” to consent to the processing of their personal data. While the fine was described as “administrative” and low in comparison to other financial penalties imposed on Meta’s services, WhatsApp nevertheless signalled that it would appeal the decision. Ireland’s regulator fined WhatsApp €225 million for transparency beaches in a previous case.

    9. EOS Matrix – €5.5 million (Croatia)

    In October 2023, Croatia’s data protection regulator announced that it imposed a €5.47 million fine on debt collection agency EOS Matrix for significant GDPR breaches. Action was taken after an anonymous petition alleged that EOS Matrix unlawfully processed the personal data of 181,641 individuals with outstanding debts with credit institutions. Among the GDPR breaches, it was found that EOS Matrix processed the data of individuals without a legal basis, failed to implement appropriate technical measuresto protect personal data and failed to inform data subjects about their data being processed.

    10. Clearview AI – €5.2 million (France)

    Clearview AI added to its tally of serious GDPR breaches in 2022 with an additional €5.2 million fine in May 2023. CNIL, France’s data protection authority, levied a €20 million fine on the US company in October 2022, ordering it to cease the collection and processing of data on individuals located in France without any legal basis. It was given two months to comply and was threatened with further penalties if it failed to do so, costing €100,000 per overdue day. Clearview AI did not send any proof of compliance within the time limit, resulting in the €5.2 million fine being imposed. So far, the company has also been penalised by data protection authorities in the UK, Italy and Greece to the tune of tens of millions of euros. It remains unclear if these fines will ever be paid given the company’s persistent lack of cooperation with European regulators.

    In summary

    GDPR fines are designed to make non-compliance around data security a costly mistake and they can be separated into two tiers. Less severe infringements can result in a fine of €10 million or 2% of a firm’s annual revenue from the preceding financial year, depending on which amount is higher. More serious violations can result in a fine of up to €20 million or 4% of a firm’s annual revenue from the preceding year, depending on what is higher.

    Both the uptick in violations and mammoth fines levied in recent years highlight a growing lack of consent and transparency. Despite that worrying trend, it has been reassuring to see European regulators actively enforcing the law and imposing fines at a rate never seen before. Before 2021, the largest fine on record was levied in 2019 when Google was penalised €50 million for how it communicated privacy to its users as well as various data processing offences.

    By 2021, financial penalties had increased significantly and Amazon was fined a then record €746 million. It only seemed a matter of time until the billion-euro barrier was broken and Meta set the next unwelcome record with its astronomical fine in 2023. It will be interesting to see if that penalty will be topped in 2024.

    Browse the full list of GDPR violations

    The Biggest GDPR Fines of 2023 (4)

    Building an effective anti-bribery and corruption programme

    Key principles of establishing an effective ABC programme

    Download now

    The Biggest GDPR Fines of 2023 (5)

    Niall McCarthy

    Niall is a Content Writer at the EQS Group. Originally from Ireland, he previously worked as a journalist, which included reporting on major corruption trends worldwide.

    Contact

    The Biggest GDPR Fines of 2023 (2024)

    FAQs

    What is the largest GDPR fine in 2023? ›

    The Top 10 Biggest GDPR Fines and Penalties of 2023 [Updated December 2023]
    • Meta Platforms Ireland Ltd. ( EUR 1.2 billion)
    • Meta Platforms Ireland Ltd. ( EUR 390 million)
    • TikTok Ltd. ( EUR 345 million)
    • Criteo (EUR 40 million)
    • TikTok (GBP 12.7 million)
    • TIM SpA (EUR 7.6 million)
    • WhatsApp Ireland Ltd. ( ...
    • Clearview AI Inc. (
    Jan 2, 2024

    What is the highest amount that we could be fined for infringements of the GDPR? ›

    For especially severe violations, listed in Art. 83(5) GDPR, the fine framework can be up to 20 million euros, or in the case of an undertaking, up to 4 % of their total global turnover of the preceding fiscal year, whichever is higher.

    What are the current GDPR fines? ›

    The EU GDPR sets a maximum fine of €20 million (about £18 million) or 4% of annual global turnover – whichever is greater – for infringements. However, not all GDPR infringements lead to data protection fines.

    What is the biggest data breach in 2023? ›

    See the full list of data breaches for September 2023. September saw the biggest data breach of the year by far, when the digital risk protection company DarkBeam exposed an astounding 3.8 billion records thanks to a misconfigured Elasticsearch and Kibana interface.

    How many data breaches in 2023? ›

    There were 3,205 data compromises in 2023, impacting 353 million total victims, a figure that includes people who appear in more than one publicly-reported data breach notice, according to the resource center, a non-profit that tracks publicly reported incidents of compromised personal information and consumer data in ...

    Which of the following companies paid the biggest fine for the violation of the GDPR? ›

    The biggest fine issued under the GDPR to date came in July 2021 when Luxembourg fined tech giant Amazon €746m ($877m) for non-compliance with general data processing principles.

    What is a serious breach of GDPR? ›

    A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This means that a breach is more than just losing personal data.

    What is a cookie consent fine? ›

    Cookie consent fines happen when businesses fail to comply with state and federal data privacy laws. Having a legally-compliant cookie banner is a business requirement in Europe, North America, and other jurisdictions. So if your business isn't compliant, it runs the risk of GDPR cookie fines.

    What is Principle 5 of GDPR? ›

    Article 5 of the UK GDPR sets out seven key principles which lie at the heart of the general data protection regime. Article 5(1) requires that personal data shall be: “(a) processed lawfully, fairly and in a transparent manner in relation to individuals ('lawfulness, fairness and transparency');

    How can I avoid GDPR fines? ›

    Here's what you should be practicing to avoid GDPR fines.
    1. Focus on Data Mapping. ...
    2. Always Obtain Express Consent. ...
    3. Keep Your GDPR-compliant Privacy Policy Up To Date. ...
    4. Minimize the Personal Data You Collect. ...
    5. Report Data Breaches on Time. ...
    6. Make Cybersecurity Your Priority.

    What company was fined for data breach? ›

    The FCA has fined Equifax Ltd (Equifax) £11,164,400 for failing to manage and monitor the security of UK consumer data it had outsourced to its parent company based in the US. The breach allowed hackers to access the personal data of millions of people and exposed UK consumers to the risk of financial crime.

    Is GDPR still in effect? ›

    Does the GDPR still apply? Yes. The GDPR is retained in domestic law as the UK GDPR, but the UK has the independence to keep the framework under review.

    What is the maximum fine for ICO? ›

    Tools at our disposal include assessment notices, warnings, reprimands, enforcement notices and penalty notices (administrative fines). For serious breaches of the data protection principles, we have the power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher.

    Why is there no GDPR in the US? ›

    Even if GDPR-style data protection were sufficient, the US is too different from Europe to implement and enforce such a framework effectively on those terms. Any US version of GDPR would, in practice, be something of a GDPR-lite. Data-protection regulation is not the only option, however.

    What are the privacy enforcement actions 2023? ›

    The FTC also has remained active in targeting companies that fail to implement reasonable data security measures to protect consumer data. In 2022 and 2023 alone, the FTC announced or finalized enforcement actions against Global Tel*Link, Drizly, Chegg, and CafePress for data security failures.

    Top Articles
    Latest Posts
    Article information

    Author: Sen. Ignacio Ratke

    Last Updated:

    Views: 6474

    Rating: 4.6 / 5 (76 voted)

    Reviews: 83% of readers found this page helpful

    Author information

    Name: Sen. Ignacio Ratke

    Birthday: 1999-05-27

    Address: Apt. 171 8116 Bailey Via, Roberthaven, GA 58289

    Phone: +2585395768220

    Job: Lead Liaison

    Hobby: Lockpicking, LARPing, Lego building, Lapidary, Macrame, Book restoration, Bodybuilding

    Introduction: My name is Sen. Ignacio Ratke, I am a adventurous, zealous, outstanding, agreeable, precious, excited, gifted person who loves writing and wants to share my knowledge and understanding with you.