GDPR

Knowledge Base | GDPR | What are the biggest GDPR fines so far?

What are the biggest GDPR fines so far?

As of 26 September 2026, the largest GDPR fine announced remains the €1.2 billion penalty imposed on Meta Ireland in May 2023 over Facebook’s transfers of personal data to the United States. Major decisions include the following. These are the amounts originally imposed; subsequent court decisions can change their status.

Organisation

Original fine

Year

Main issue

Meta Ireland — Facebook

€1.2 billion

2023

Transfers of EU/EEA users’ data to the US without sufficient safeguards.

Amazon Europe Core

€746 million

2021

Behavioural advertising practices. The fine was annulled in March 2026.

TikTok

€530 million

2025

Transfers of EEA users’ data to China and inadequate transparency.

Meta Ireland — Instagram

€405 million

2022

Children’s contact details being publicly disclosed and accounts being public by default.

Google Ireland

€403 million

2026

Unlawful and unfair location-data processing, transparency, accountability and retention failures.

The Google decision was announced on 21 September 2026. These figures concern regulatory decisions, rather than amounts confirmed as collected.

Amazon’s original penalty needs particular context: Luxembourg’s Administrative Court annulled the fine on 12 March 2026, while largely upholding the regulator’s underlying findings. The CNPD must reassess the financial sanction in light of the applicable case law.