← Enforcement
GDPR EU 2016/679

Big Tech GDPR fines: the largest data-protection penalties in EU history

A registry of the biggest GDPR fines ever issued — Meta €1.2 billion, Amazon €746 million, TikTok €530 million, Uber €290 million and more. Who was fined, how much, for what, why almost all of them come out of Ireland, and which ones courts have already overturned — every amount sourced to the regulator or the binding EU decision behind it.

The headline numbers under GDPR are enormous — and they cluster around a handful of names. Meta, Amazon, TikTok, Google, Uber, LinkedIn, WhatsApp. The thirteen decisions in this registry were imposed for more than €5 billion between them, and all but two came from a single regulator in a single city: Ireland’s Data Protection Commission in Dublin.

That is not an accident, and it is the first thing to understand about EU data-protection enforcement: the size of a fine tells you about the size of the company, the EU mechanism that set the number, and the kind of violation — far more than it tells you about which country the data subjects live in.

This post is the registry of those mega-fines: exact amounts, the GDPR articles behind each, the corrective orders, and — the part press coverage tends to drop the day after — what happened next in court. Because one of these fines, the second-largest ever, has already been annulled. Every figure links to the issuing authority or the binding EU decision behind it.

Why almost all of them come from Ireland

The pattern looks strange at first: a €1.2 billion fine against Facebook, decided not in Washington, Brussels or Berlin, but by the regulator of a country with five million people. The reason is a GDPR mechanism called the one-stop-shop.

Under the one-stop-shop, a company that operates across the EU answers to one lead regulator — the lead supervisory authority (LSA), defined as the data protection authority of the country where the company has its main establishment (the place where it takes the key decisions about how and why it processes data — in practice, its EU headquarters). Meta, Google, Apple, TikTok, X, LinkedIn and many others run their EU operations from Dublin. So for cross-border processing — anything affecting users in more than one EU country — their lead regulator is Ireland’s DPC, even though the people affected live all over the EU.

That is why the DPC, structurally a national regulator, issues fines that reshape global products. It is also why the other authorities in this registry are exactly the regulators of the countries where a given company’s EU base happens to sit: Amazon answers to Luxembourg’s CNPD because Amazon Europe Core is headquartered there; Uber answers to the Netherlands’ Autoriteit Persoonsgegevens (AP) because its EU base is in Amsterdam. The one exception is Google’s 2019 fine from France’s CNIL — issued before Google had designated an EU main establishment, so the one-stop-shop did not yet apply and any DPA could act.

Why the fines kept getting bigger: the Article 65 mechanism

A second structural fact explains why these numbers climbed from tens of millions to over a billion: the DPC rarely set the final figure on its own.

When a lead authority drafts a cross-border decision, every other concerned EU regulator gets to object. If even one objection cannot be resolved, the dispute goes to the European Data Protection Board (EDPB) — the body that coordinates all 27 national authorities — which issues a binding decision under Article 65 GDPR that the lead authority must follow. In several of the cases below, the DPC proposed a smaller fine (or none) and the EDPB instructed it to raise the amount or add findings:

  • The Meta €1.2 billion transfer fine followed an EDPB binding decision of 13 April 2023.
  • The Meta €390 million advertising fines followed an EDPB binding decision that rejected Meta’s “contract” legal basis.
  • The TikTok €345 million children’s-data fine was increased after EDPB Binding Decision 2/2023 added a finding the DPC had not made.

So when you read “Ireland fined Meta,” the more accurate picture is often “the EDPB, through Ireland, fined Meta.” This is the EU’s consistency mechanism working as designed — and the reason a minority objection from, say, the Italian or Berlin regulator can move a fine by hundreds of millions.

The two violations behind the biggest numbers

Strip out the company names and almost every mega-fine falls into one of two buckets:

  1. Unlawful data transfers to a third country. After the EU’s top court struck down the EU–US “Privacy Shield” in the 2020 Schrems II judgment, sending personal data to the US (or China) became lawful only with Standard Contractual Clauses (SCCs — a pre-approved EU contract template for exports) plus additional safeguards that actually work. Meta’s €1.2 billion (US), Uber’s €290 million (US) and TikTok’s €530 million (China) are all this violation — Chapter V of the GDPR, the rules on international transfers (Articles 44–46).

  2. No valid legal basis for behavioural advertising. To process your data at all, a company needs one of six lawful bases in Article 6 — consent, contract, legal obligation, vital interest, public task, or legitimate interest. Meta tried to bury ad-targeting consent inside its terms-of-service “contract”; Amazon and Google relied on “legitimate interest” or defective consent. Regulators said none of that works for behavioural advertising (building ad profiles from your activity). Meta’s €390 million, Amazon’s €746 million, Google’s €50 million and LinkedIn’s €310 million are all this violation.

A third, smaller cluster is about children’s data (Instagram €405 million, TikTok €345 million) and security failures (Meta’s €265 million scraping, €251 million breach, €91 million passwords).

Quick guide to the GDPR articles cited below (so you don’t need EUR-Lex open in another tab):

  • Art. 5 — the core principles: lawfulness, fairness and transparency (5(1)(a)); purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality / security (5(1)(f)); accountability.
  • Art. 6 — the six lawful bases for processing. You need exactly one.
  • Art. 12–14 — transparency: you must tell people, clearly, what you collect, why, for how long, and what their rights are.
  • Art. 25 — data protection by design and by default: privacy safeguards built into systems from the start, not bolted on.
  • Art. 32 — security of processing: appropriate technical and organisational measures (encryption, access control, monitoring).
  • Art. 33 — breach notification: report qualifying personal-data breaches to the regulator, normally within 72 hours.
  • Art. 44–46 (Chapter V) — international transfers: data may leave the EU only with an adequate level of protection, e.g. valid SCCs plus effective safeguards.
  • Art. 65 — the EDPB’s binding dispute-resolution power over disagreeing national regulators.
  • Art. 83 (GDPR text) — how fines are set: a higher tier up to €20 million or 4% of total worldwide annual turnover, whichever is higher (for breaches of principles, legal basis and transfers), and a lower tier up to €10 million / 2% for more procedural failings.

The registry — by amount

Ordered from the record down. For each: what happened, how much, the articles, the status, and a source link.

1. Meta Platforms Ireland (Facebook) — €1,200,000,000 — 22 May 2023

What happened. Meta kept transferring European Facebook users’ personal data to the United States on the basis of Standard Contractual Clauses, even after Schrems II held that US surveillance law meant those clauses, on their own, did not guarantee EU-equivalent protection. The DPC found the transfers unlawful from 16 July 2020 onward.

Articles. Chapter V (Article 46(1)) — international transfers without adequate safeguards.

Decision. €1.2 billion — the largest GDPR fine ever issued — plus an order to suspend future transfers and to bring past processing into compliance within six months. The figure was set following an EDPB binding decision of 13 April 2023; the DPC’s earlier draft had proposed no fine at all for the transfers.

Status. Issued; Meta has challenged the decision in the courts. The underlying legal pressure eased when the European Commission adopted a new EU–US Data Privacy Framework adequacy decision in July 2023, giving Meta a renewed transfer route going forward.

Source: EDPB — €1.2 billion fine for Facebook.


2. Amazon Europe Core (Luxembourg) — €746,000,000 — 16 July 2021 — ANNULLED 2026

What happened. Following a 2018 complaint by the French group La Quadrature du Net about how Amazon obtained consent for targeted advertising, Luxembourg’s CNPD found that Amazon could not rely on “legitimate interest” as the legal basis for processing personal data for behavioural advertising, and that its information practices breached the GDPR. The amount was first disclosed in Amazon’s July 2021 SEC filing.

Articles. Article 6 (no valid legal basis for behavioural advertising) and transparency/information requirements.

Decision. €746 million — at the time the second-largest GDPR fine ever.

Status. ANNULLED. On 12 March 2026 the Luxembourg Cour administrative (Administrative Court) annulled the fine. Crucially, the court did not clear Amazon on the substance — it confirmed that Amazon’s reliance on legitimate interest was not justified and that its information procedures did not comply. It struck the penalty down on procedural grounds: the CNPD had not properly analysed Amazon’s degree of negligence, in light of EU case law that developed after the 2021 decision. The CNPD must now re-run that analysis. This is the clearest illustration in the whole registry that a headline fine is not final until the courts have finished with it.

Sources: CNPD statement on the 12 March 2026 ruling; original amount per ICLG.


3. TikTok Technology — €530,000,000 — 2 May 2025

What happened. The DPC found that TikTok transferred EEA users’ data to the People’s Republic of China without demonstrating that the data was afforded EU-equivalent protection against access under Chinese law, and that it failed its transparency duties about those transfers. During the inquiry TikTok had told the DPC it did not store EEA data on servers in China; in April 2025 it disclosed that, contrary to that evidence, limited EEA data had in fact been stored on Chinese servers.

Articles. Article 46(1) (transfers — €485 million) and Article 13(1)(f) (transparency — €45 million).

Decision. €530 million total, plus an order to bring processing into compliance within six months, failing which transfers to China are to be suspended.

Source: DPC — TikTok fined €530 million.


4. Meta Platforms Ireland (Instagram) — €405,000,000 — September 2022

What happened. An inquiry into how Instagram handled children’s data found that the accounts of users aged 13–17 were set to public by default, and that a “business account” feature publicly exposed children’s email addresses and phone numbers.

Articles. Children’s data; public-by-default settings; transparency and lawful-basis failings.

Decision. €405 million — at the time a record fine for children’s data. The DPC’s final decision was made on 2 September 2022 and announced on 15 September 2022.

Source: DPC — decision in the Instagram inquiry.


5. Meta Platforms Ireland (Facebook + Instagram) — €390,000,000 — 4 January 2023

What happened. Since GDPR took effect in 2018, Meta had stopped asking for consent to behavioural advertising and instead buried it in the “performance of a contract” legal basis — treating personalised ads as part of the service users sign up for. Following an EDPB binding decision, the DPC ruled Meta was not entitled to rely on “contract” for behavioural advertising.

Articles. Article 6 (legal basis) for behavioural advertising.

Decision. Two fines — €210 million (Facebook) and €180 million (Instagram), €390 million combined — plus three months to bring processing into compliance.

Source: IAPP — DPC fines Meta €390M over legal basis for personalised ads.


6. TikTok Technology — €345,000,000 — 15 September 2023

What happened. A separate, earlier TikTok inquiry — into the platform’s handling of children’s data between 31 July and 31 December 2020 — found unfair default settings and weak protections for users aged 13–17. After the DPC’s draft decision, the Italian and Berlin authorities objected, and EDPB Binding Decision 2/2023 of 2 August 2023 required the DPC to add a finding that TikTok had breached the fairness principle.

Articles. Children’s data; fairness (Article 5(1)(a)); transparency (the €180 million component).

Decision. €345 million total, a reprimand, and an order to bring processing into compliance within three months.

Source: DPC — €345 million fine of TikTok; EDPB Binding Decision 2/2023.


7. LinkedIn Ireland — €310,000,000 — 22 October 2024

What happened. The DPC found LinkedIn (owned by Microsoft) had no valid legal basis for processing members’ personal data for behavioural advertising and analytics, and that its transparency to users was inadequate.

Articles. Article 5(1)(a) (lawfulness, fairness, transparency), Article 6(1) (legal basis), Articles 13(1)(c) and 14(1)(c) (information duties).

Decision. €310 million, a reprimand, and an order to bring processing into compliance. (Recorded in the DPC Annual Report 2024, the regulator’s own enforcement record.)

Source: DPC Annual Report 2024.


8. Uber — €290,000,000 — 22 July 2024

What happened. The Netherlands’ AP found that Uber had, for over two years, transferred sensitive data on European drivers — taxi licences, location data, photos, payment details, identity documents, and in some cases criminal and medical data — to the United States without any transfer tool at all (it stopped using SCCs in August 2021). The case began with complaints from more than 170 French drivers. It was the third Dutch fine on Uber, after €600,000 in 2018 and €10 million in 2023.

Articles. Chapter V — Articles 44 and 46 (international transfers without appropriate safeguards), in the higher fine tier (up to 4% of global turnover).

Decision. €290 million. The final decision was made on 22 July 2024 and announced on 26 August 2024.

Source: EDPB — Dutch SA fines Uber €290 million.


9. Meta Platforms Ireland (Facebook) — €265,000,000 — 25 November 2022

What happened. After the data of 533 million Facebook users (phone numbers, dates of birth, email addresses, locations) was scraped and leaked online, the DPC examined Facebook’s Search, Messenger Contact Importer and Instagram Contact Importer tools. It found Meta had not built in adequate data-protection-by-design measures to prevent the scraping.

Articles. Article 25(1) and 25(2) — data protection by design and by default.

Decision. €265 million (composed of €150 million and €115 million counts), a reprimand and an order to remediate. Meta has challenged the decision in the Irish courts.

Source: DPC — decision in the Facebook “Data Scraping” inquiry.


10. Meta Platforms Ireland (Facebook) — €251,000,000 — 12 December 2024

What happened. This is the fine for the 2018 access-token breach — the “View As” vulnerability through which attackers could take over user accounts, affecting around 29 million accounts. The DPC issued its decision on 12 December 2024, split across two findings.

Articles. Article 33 (breach notification — €11 million) and Article 25 (data protection by design — €240 million).

Decision. €251 million combined. (Recorded in the DPC Annual Report 2024.)

Source: DPC Annual Report 2024.


11. WhatsApp Ireland — €225,000,000 — 2 September 2021

What happened. The DPC found WhatsApp had failed to tell users and non-users clearly enough how it processed their data — including how data was shared with other Meta companies. The fine was substantially increased after an EDPB Article 65 binding decision; the DPC’s draft had been far lower.

Articles. Transparency — Articles 12, 13, 14 and the overarching principle in Article 5(1)(a).

Decision. €225 million, plus an order to bring its privacy notices into compliance — which WhatsApp did by rewriting its European privacy policy.

Source: DPC — decision in the WhatsApp inquiry.


12. Meta Platforms Ireland (Facebook) — €91,000,000 — 26 September 2024

What happened. Meta had stored hundreds of millions of user passwords in plaintext — unencrypted and readable — in its internal systems, and failed to notify and document the issue as required.

Articles. Article 5(1)(f) (security principle), Article 32(1) (security of processing), Article 33(1) and 33(5) (breach notification and documentation).

Decision. €91 million and a reprimand. Per the DPC Annual Report 2024, the decision has been appealed by Meta.

Source: DPC Annual Report 2024.


13. Google LLC — €50,000,000 — 21 January 2019

What happened. The fine that started the era. Acting on complaints from the groups noyb (Max Schrems) and La Quadrature du Net, France’s CNIL found that when users set up an Android phone, Google did not give clear, accessible information about its data processing and did not obtain valid consent for personalising ads. Because Google had not yet designated an EU main establishment, the one-stop-shop did not apply and the CNIL could act directly.

Articles. Transparency and information duties; lack of a valid legal basis (consent) for ad personalisation.

Decision. €50 million — the first multi-million-euro GDPR fine. Google appealed; on 19 June 2020 France’s highest administrative court, the Conseil d’État, upheld the fine in full, making it final.

Source: EDPB / CNIL — €50 million penalty against Google LLC.


A note on Clearview AI

The US facial-recognition company Clearview AI has collected several GDPR fines from EU regulators (Italy, Greece, France, the Netherlands) of €20–30.5 million each — large, but in a different category from the cases above, because Clearview has no EU establishment and has paid none of them. That story has its own registry: Clearview AI fines.

The appeals reality: a fine is not a payment

The single most misreported thing about these numbers is that they are final. They are not. Under Irish law every DPC fine must be confirmed by a court before it can be collected, and the companies appeal. As this registry shows:

  • Amazon’s €746 million was annulled in 2026 — the second-largest GDPR fine ever, struck down on procedure (though the substance was upheld and the case sent back).
  • Google’s €50 million was upheld all the way to the Conseil d’État — proof that fines do survive appeal.
  • Meta is contesting the €265 million scraping fine and has appealed the €91 million passwords fine.

So the right way to read a headline is: “regulator X has decided to fine company Y €Z, subject to the courts.” Some of these will shrink, some will be annulled and re-issued, and a few will stand exactly as written. The direction of travel, though, is unambiguous — the ceiling has moved from Google’s €50 million in 2019 to Meta’s €1.2 billion in 2023, and the higher tier of Article 83 (4% of global turnover) is now routinely in play.

What this means if you run a business or build a product

You are not Meta, and no regulator is going to open a flagship cross-border inquiry into your startup. But the violations that produced these fines are exactly the ones a small company stumbles into without noticing:

  • Sending personal data outside the EU without a working transfer basis. This is the single most common theme above (Meta, Uber, TikTok). If you use a US analytics, email, CRM or cloud tool, you are exporting personal data — and you need a valid mechanism (the EU–US Data Privacy Framework for certified US firms, or SCCs plus a real transfer-risk assessment), not just a checkbox.
  • Behavioural advertising on the wrong legal basis. Meta, Amazon, Google and LinkedIn were all told the same thing: you cannot smuggle ad-profiling consent into a “contract” or “legitimate interest.” If you profile users to target them, you almost always need freely given, specific, informed consent — and “freely given” means the service still works if they say no.
  • Default settings that expose data, especially children’s. Instagram and TikTok were fined for public-by-default. Privacy-by-default (Article 25) means the safe setting is the one a user gets without touching anything.
  • Security basics. Meta’s €265 million, €251 million and €91 million were, at bottom, engineering failures: scraping not designed against, an unpatched account-takeover flaw, passwords stored in plaintext. Encryption, access control, monitoring and breach discipline are GDPR obligations, not nice-to-haves.

The cheapest way to stay off a list like this is structural: collect less, keep it shorter, keep it in the EU, and don’t make consent a formality you bury. A product designed that way is not relying on a regulator’s mercy — it simply has far less to be fined for.

Sources for independent verification

Short conclusion

The biggest GDPR fines are, overwhelmingly, Big Tech fines — and overwhelmingly Irish ones, because that is where Big Tech keeps its EU headquarters and the one-stop-shop sends the cases. The EDPB’s Article 65 power pushed the numbers from tens of millions into the billions. But the Amazon annulment is the reminder that closes this registry: a fine is a regulator’s decision, not a final judgment, and the real story of any one of these numbers only ends when the last court does.