Fines worth €272m issued by GDPR regulators

€272 million (£245.3 million) worth of fines have been dished out by regulators under Europe’s tough data protection laws, according to research by DLA Piper.

According to the law firm’s annual fines and data breach report, Italy has had to pay €69.3 million (£62.4 million) in fines since General Data Protection Regulation (GDPR) was established in 2018, topping the rankings for Europe.

Italy was closely followed by Germany (€69.1 million) and France (€54.4 million.)

The research found that there have been over 281,000 data breach notifications since 2018, Germany (77,747), The Netherlands (66,527) and the UK (30,536) saw the highest number of data breaches notified to regulators.

While France and Italy, countries with populations over 67 million and 62 million people respectively, only recorded 5389 and 3460 data breach notifications for the same period.

DLA Piper attributes this to “cultural differences in approach to breach notification.”

The report also discovered that the aggregate daily rate of breach notifications in Europe experienced double digit growth for the second year running with 331 notifications per day since 28 January 2020.

This represents a 19 per cent increase compared to 278 breach notifications per day for the previous year.

The highest GDPR fine to date remains the €50 million fine (£45 million) imposed by the French data protection regulator on Google, for alleged infringements of the transparency principle and lack of valid consent.

Following two high profile data breaches, the UK Information Commissioner’s Office (ICO) published two notices of intent to impose fines in July 2019 totalling £282 million.

But a significant climbdown by the ICO meant that the final fines imposed in October 2020 were greatly reduced to £20 million and £18.4 million.

According to the study Denmark saw the most breaches per 100,000 people, at 155.6, closely followed by The Netherlands at 150.

Ireland is in third place with 127.8 reported breaches per 100,000 people.
Greece, Italy and Croatia reported the fewest number of breaches per capita since 28 January 2020.

"Fines and breach notifications continue their double digit annual growth and European regulators have shown their willingness to use their enforcement powers,” said Ross McKean, chair of DLA Piper’s UK Data Protection & Security Group. “They have also adopted some extremely strict interpretations of GDPR setting the scene for heated legal battles in the years ahead.

He added: “However we have also seen regulators show a degree of leniency this year in response to the ongoing pandemic with several high profile fines being reduced due to financial hardship. During the coming year we anticipate the first enforcement actions relating to GDPR’s restrictions on transfers of personal data to the US and other “third countries” as the aftershocks from the ruling by Europe’s highest court in the Schrems II case continue to be felt."

Ewa Kurowska-Tober, global co-chair of DLA Piper's Data Protection & Security Group, said: "Regulators have been testing the limits of their powers this year issuing fines for a wide variety of infringements of Europe’s tough data protection laws. But they certainly haven’t had things all their own way with some notable successful appeals and large reductions in proposed fines. Given the large sums involved and the risk of follow-on claims for compensation we expect to see the trend of more appeals and more robust defences of enforcement action continue."

    Share Story:

Recent Stories


Creating value together: Strategic partnerships in the age of GCCs
As Global Capability Centres reshape the financial services landscape, one question stands out: how do leading banks balance in-house innovation with strategic partnerships to drive real transformation?

Data trust in the AI era: Building customer confidence through responsible banking
In the second episode of FStech’s three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech examines the critical relationship between data trust, transparency, and responsible AI implementation in financial services.

Banking's GenAI evolution: Beyond the hype, building the future
In the first episode of a three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech explores how financial institutions can navigate the transformative potential of Generative AI while building lasting foundations for innovation.

Beyond compliance: Building unshakeable operational resilience in financial services
In today's rapidly evolving financial landscape, operational resilience has become a critical focus for institutions worldwide. As regulatory requirements grow more complex and cyber threats, particularly ransomware, become increasingly sophisticated, financial services providers must adapt and strengthen their defences. The intersection of compliance, technology, and security presents both challenges and opportunities.