HeadFlash

Topic · 19 stories

GDPR fines: biggest penalties and latest news

Updated · Edited by Marcin Rybak

In short

GDPR fines are administrative penalties that national data protection authorities impose on organizations that break the regulation: up to €20 million or 4% of worldwide annual turnover. In 2026 the largest was Uber's €825 million from the Dutch regulator, and in September Ireland fined Google €403 million. Big fines are rarely the last word: Uber is appealing, and TikTok lost its UK appeal and will pay £12.7 million.

What are GDPR fines and who administers them

GDPR fines are administrative penalties that national data protection authorities impose on organizations that break the GDPR. The regulation does not fine anyone itself. Each country’s authority does: Ireland’s DPC, France’s CNIL, Italy’s Garante, Sweden’s IMY, Norway’s Datatilsynet, and in Poland the President of the UODO. According to Article 83 on EUR-Lex (checked 10 October 2026), every fine must be effective, proportionate and dissuasive. The authority weighs the nature, gravity and duration of the breach, the number of people affected, intent or negligence, cooperation with the authority and earlier infringements. It can fine instead of, or on top of, other corrective measures.

How high are GDPR fines

The ceiling is €20 million or 4% of worldwide annual turnover for the gravest breaches and €10 million or 2% for lesser ones, whichever is higher. From Article 83(4) and (5), as of 10 October 2026:

Tier Maximum for a company What it covers
Lower €10 million or 2% of prior-year worldwide turnover controller and processor duties, including security and breach notification (Articles 25 to 39)
Higher €20 million or 4% of prior-year worldwide turnover processing principles and consent (Articles 5 to 7 and 9), data subject rights (Articles 12 to 22), transfers to third countries (Articles 44 to 49), non-compliance with an authority’s order

If one operation breaks several provisions, the total cannot exceed the amount for the gravest one (Article 83(3)). In Poland, public finance bodies, research institutes and the central bank face up to 100,000 zł, and some other public bodies up to 10,000 zł (Article 102 of the Polish data protection act, 2019 consolidated text).

Biggest GDPR fines in 2026

The biggest fine in 2026 reports is Uber’s €825 million from the Dutch regulator. Fines reported this year:

Who Country Amount Why Announced
Uber Netherlands €825 million (about $964 million) automated suspension of driver accounts without human review August 2026
Google Ireland €403 million location data collected even with tracking switched off September 2026
TikTok United Kingdom £12.7 million data of under-13s without parental consent imposed 2023, final from September 2026
Telecom Italia (TIM) Italy €9.5 million spoofed calls and fake consent for telemarketing August 2026
IQVIA Italy €7 million patient database held to be personal data, not anonymous decision of 23 September 2026
Elkjop Norway NOK 20 million loyalty club consent forced as one package decision of 1 June 2026
HSE Ireland €645,000 rotting paper psychiatric records September 2026
Hôpital privé de la Loire France €500,000 weak security, breach of 727,000 people’s data September 2026
Miljödata Sweden SEK 1.8 million (about $183,000) inadequate security, breach of 2.2 million people September 2026

The Netherlands fined Uber €825 million for 2018 to 2022 practices: the GDPR bans fully automated decisions, and drivers were not told the suspensions were automatic. It is the fourth fine from this regulator against Uber. The previous record was €290 million in 2024 for sending drivers’ data to the US.

Ireland’s DPC fined Google €403 million over Web & App Activity, Timeline and Google Location Accuracy data collected between 25 May 2018 and 4 February 2020. Sources convert it to $459 million or $462 million. Google has six months to bring its practices into line and says the case concerns historical policies. In the report on tracking despite location being off, Web & App Activity collected location in a non-obvious way, and the feature remains live in more than 30 countries. See Google and location tracking.

How to avoid GDPR fines: what regulators punished in 2026

Fix the failures regulators punished this year: weak access controls, bundled consent, false anonymisation and fully automated decisions. Four patterns:

Not every breach ends in a fine. Sweden’s IMY ruled Securitas’s AI driver cameras unlawful but issued only a reprimand because the pilot was limited. More in workplace surveillance. Courts and guidelines also shape the rules: the EU Court of Justice blocked Sweden’s GDPR exemption for a paid convictions database, and the EDPB held encrypted blockchain data to be personal data.

What happens if you ignore a GDPR fine

Ignoring an authority’s order is a fineable offence of its own, up to €20 million or 4% of worldwide turnover (Article 83(5)(e) and 83(6)). Poland shows how it works. In October 2026 the UODO president fined the Warsaw company Costalea 29,112 zł. According to the UODO announcement of 5 October 2026, the company did not carry out a 2025 decision ordering it to inform a complainant, and ignored a request for explanations and a formal reminder. The amount reflected the company’s last financial year, and the UODO says it will keep pressing for the original decision to be carried out.

Companies also appeal. Uber says it will challenge the €825 million, and IQVIA has 30 days to appeal or can settle for half. TikTok withdrew its appeal, and paying the fine lets the ICO resume a separate probe of its recommender systems.

Where do GDPR fines go

It depends on the country: Article 83 sets amounts and criteria but does not say who receives the money. In Poland, funds from an administrative fine are state budget revenue (Article 104 of the Polish act). The fine is due within 14 days of the court deadline passing or the ruling becoming final, and the UODO can defer it or allow instalments (Article 105).

How other countries fine: the UK and South Korea

South Korea has had the world’s highest national fine ceiling since 11 September 2026: up to 10% of global annual revenue. The amended PIPA took effect on 11 September and sets a base tier of up to 3% of revenue tied to the violation and an elevated tier of 10%, makes the CEO accountable, and allows up to 40% off for documented privacy investment. In June the PIPC fined Coupang a record 624.6 billion won, about $409 million, after a breach of about 37.55 million people. See South Korea data breaches.

The UK fines rarely. The Good Law Project and Open Rights Group say the ICO averaged under seven fines a year from more than 220,000 complaints in six years, and threaten legal action over its triage system.

What it means for you

  • Audit access to personal data: VPN and multi-factor authentication for every outside user, real-time alerts, and a plan to notify everyone whose data leaks.
  • Split consent by purpose. One bundled box cost Elkjop NOK 20 million.
  • Do not call a dataset anonymous if a persistent identifier lets you single people out.
  • Carry out an authority’s decision or challenge it. Silence cost Costalea 29,112 zł and did not close the case.

Still open: whether Uber wins its appeal, how Google changes practices within six months, whether IQVIA settles for €3.5 million, and whether the ICO changes how it handles complaints after the legal threat.

Key facts

  • Italy's Garante fined IQVIA €7 million: its LPD database of about one million patients was personal data, not anonymous. IQVIA has 120 days to make the data flow lawful. (source)
  • Ireland's Data Protection Commission fined Google €403 million for storing location data even when users had switched tracking off. The data covers 2018 to 2020. (source)
  • TikTok dropped its appeal and will pay the UK ICO's £12.7m fine over children's data. The ICO can resume a separate probe into how recommenders use teenagers' data. (source)
  • South Korea's amended PIPA took effect with fines up to 10% of global annual revenue, against 4% in the EU GDPR, plus personal accountability for the CEO. (source)
  • France's CNIL fined Hôpital privé de la Loire €500,000 after a breach of 727,000 people's data. Outside users had no VPN or multi-factor authentication. (source)
  • The Dutch regulator fined Uber €825 million for suspending driver accounts by automated software without human review. Uber says it will appeal. (source)
  • The EU Court of Justice ruled on 9 July 2026 that Sweden cannot exempt a paid criminal-convictions database from the GDPR, reviving a SEK 300,000 damages claim. (source)
  • South Korea's PIPC fined Coupang a record 624.6 billion won (about $409 million) after a breach exposing about 37.55 million people. (source)

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. Italy Fines IQVIA €7M Over Health Data of One Million Patients Privacy
  2. Irish regulator fines Google €403M over location tracking Privacy
  3. TikTok Pays £12.7m UK Fine Over Children’s Data After Dropping Appeal Privacy
  4. Sweden Fines Miljödata $183,000 Over Breach Affecting 2.2 Million Privacy
  5. Ireland fines Google $462M over location data tracking Privacy
  6. South Korea’s Amended PIPA Takes Effect With 10% Global Revenue Fines and CEO Liability Privacy
  7. French Hospital Fined €500,000 Over Breach of 727,000 Records Privacy
  8. CNIL Details Security Failures Behind Hospital Data Theft Privacy
  9. Hospital Penalized for Failing to Notify All Breach Victims Privacy
  10. Irish Watchdog Fines HSE $750K Over Rotting Psychiatric Records Privacy
Show older (9 stories)
  1. Uber fined $964 million by Dutch regulator over automated driver account suspensions Privacy
  2. TikTok loses appeal against £12.7m fine for processing under-13s’ data without parental consent Privacy
  3. Italy Fines TIM $10.9M for Spoofed Calls That Laundered Illicit Leads Privacy
  4. CJEU Blocks Sweden’s GDPR Exemption for Criminal Convictions Database Privacy
  5. EDPB Finalizes GDPR Blockchain Guidelines, Rejects Anonymisation Workaround Privacy
  6. Sweden Rules Securitas AI Driver Monitoring Unlawful Under GDPR Privacy
  7. UK Data Regulator Faces Legal Threat Over Dismissal of Complaints Privacy
  8. South Korea fines Coupang record $409 million over massive data breach affecting 37 million customers Security
  9. Norwegian Authority Fines Elkjop NOK 20 Million for Loyalty Program GDPR Violations Privacy

FAQ

How high are the fines for GDPR non-compliance?

Up to €20 million or 4% of worldwide annual turnover for the gravest infringements, and up to €10 million or 2% for lesser ones, whichever amount is higher. That is Article 83(4) and (5) of the regulation on EUR-Lex (checked 10 October 2026). The regulator sets the actual amount from the gravity, duration and number of people affected.

Who administers GDPR fines?

National data protection authorities: Ireland's Data Protection Commission, France's CNIL, Italy's Garante, Sweden's IMY, Norway's Datatilsynet and, in Poland, the President of the UODO. The GDPR sets the ceilings and criteria, but the authority of the country where the case is handled decides on the fine.

What happens if you ignore a GDPR fine?

Ignoring an authority's order is itself fineable, up to €20 million or 4% of worldwide turnover. In October 2026 Poland's UODO fined the Warsaw company Costalea 29,112 zł for not carrying out a 2025 decision and not answering its requests. Paying the fine did not cancel the original order.

Where do GDPR fines go?

It depends on the country. In Poland, GDPR fines are state budget revenue under Article 104 of the Polish data protection act. Article 83 of the GDPR sets amounts and criteria and does not say who receives the money, so other member states follow their own law.

How to avoid GDPR fines?

Fix what regulators punished in 2026: no VPN or multi-factor authentication for outside users, no real-time monitoring, consent bundled into one all-or-nothing package, data called anonymous despite a persistent ID, and automated decisions without human review. Each of these drew a fine, from €500,000 for a French hospital to €825 million for Uber.

What was the biggest GDPR fine in 2026?

The largest in these reports is Uber's €825 million, imposed by the Dutch regulator over automated suspensions of driver accounts. Google's €403 million from Ireland is second. Uber disagrees with the decision and said it will appeal.