An analysis of enforcement actions under GDPR since 2018 reveals clear and consistent patterns in supervisory authority priorities. Understanding those patterns is essential for compliance programme design – not because enforcement should drive compliance, but because enforcement reveals where regulators have concluded that substantive obligations are most frequently and most seriously breached.
What are the most common grounds for large GDPR fines?
The largest penalties imposed to date have consistently involved a small number of violation types: unlawful processing without a valid legal basis; insufficient security measures leading to large-scale data breaches; violations of the rules on international data transfers; lack of transparency toward data subjects; and failures of purpose limitation, where data collected for one purpose was used for another.
Meta Platforms has received the largest aggregate fines across multiple proceedings, with penalties issued by the Irish Data Protection Commission for unlawful transfer of EU residents' data to the US, reliance on contractual necessity as a legal basis for behavioural advertising, and related transparency failures. The fines in those proceedings reached into the hundreds of millions of euros.
Which supervisory authorities are most active?
The Irish DPC, as lead supervisory authority for many of the largest technology platforms under the one-stop-shop mechanism, has issued the largest individual fines. Luxembourg, France (CNIL), Italy (Garante), and Germany's state-level authorities have also been significant enforcers. The EDPB's binding decisions under Article 65 have resolved disagreements between national authorities and resulted in upward revisions to proposed fines in several major cases.
In 2025, supervisory authorities across the EU collectively imposed fines totalling over €4.5 billion since GDPR entered into application. The pace of enforcement has increased each year, with 2024 and 2025 showing particular activity in the areas of AI and automated processing, direct marketing, and employee monitoring.
What do enforcement patterns tell compliance teams?
Three consistent messages emerge from the enforcement record.
First, legal basis selection is treated as a substantive matter, not an administrative formality. Regulators examine whether the legal basis chosen is genuinely applicable to the processing, whether the analysis is documented, and whether data subjects receive accurate information about it.
Second, international transfer compliance is actively scrutinised. Reliance on mechanisms that are formally available but substantively inadequate – including SCCs applied without Transfer Impact Assessments, or DPF certification without genuine adherence to the framework's requirements – does not provide protection.
Third, transparency violations are frequently identified alongside substantive violations and treated as aggravating factors. Privacy notices that do not accurately describe processing, or that use language that does not enable data subjects to understand the purposes and legal bases, feature regularly in enforcement decisions.
What this means for your organisation
- Enforcement patterns reveal where regulators have concluded obligations are most frequently and most seriously breached. These are the areas that should receive priority in compliance programme design.
- Legal basis selection, international transfers, and transparency are the three areas attracting the largest penalties. If your programme is weakest in any of these areas, the enforcement record tells you the cost of that weakness.
- Supervisory authorities are increasingly coordinating across borders through the EDPB's coordinated enforcement framework. A compliance failure that might previously have attracted attention from one national authority now risks multi-authority scrutiny.
- Enforcement activity has increased each year since 2018 and shows no sign of slowing. The question is not whether enforcement affects your sector, but when.
What you should do now
- Assess your legal basis documentation across all processing activities – can you demonstrate that each basis was genuinely selected and applied?
- Review your international transfer arrangements and Transfer Impact Assessments against current regulatory expectations.
- Audit your privacy notices for accuracy – do they correctly describe the processing, legal bases, and data subject rights for each activity?
- Map your highest-risk processing activities against the enforcement record to identify where regulatory scrutiny is most likely.
- Ensure your breach response procedures are documented and tested – breach notification failures feature prominently in enforcement decisions.
How Priventia helps
Priventia's Regulatory Intelligence module tracks GDPR enforcement decisions and maps them to the obligations and controls in the platform. The Compliance Intelligence Assessment scores your posture against the obligations most frequently implicated in enforcement action, producing a prioritised remediation roadmap.