GDPR came into force in May 2018. By the middle of 2026, cumulative fines under the regulation had crossed €7 billion, spread across more than three thousand enforcement actions. That headline number gets repeated every year with a slightly bigger figure attached, and it is easy to read it as a simple story of regulators getting bolder. The underlying picture is more uneven than that.
Ireland alone accounts for roughly 57 percent of all fine value issued since 2018, which is less a statement about Irish enforcement culture than a structural fact about GDPR's one-stop-shop mechanism: if your European headquarters is in Dublin, so is your lead supervisory authority, and Dublin happens to host Meta, TikTok, LinkedIn, Google and Microsoft's EU operations. Spain, by contrast, has issued the most individual fines by count — nearly a thousand — but at far smaller average amounts, reflecting enforcement against domestic SMEs rather than platform giants.
The appeals track record matters just as much as the fines themselves. Meta's record €1.2 billion transfer fine from 2023 remains formally under appeal, with payment suspended pending the outcome. In March 2026, Luxembourg's administrative court went further and annulled Amazon's €746 million fine entirely — not because the underlying data protection violations were wrong, the court found, but on procedural grounds, sending the case back to the CNPD for a fresh analysis. A separate case against OpenAI was also annulled that same month on similar procedural grounds.
For anyone advising organisations on GDPR risk, the practical lesson from 2026 is not just what conduct draws the largest fines. It is that the fine, when it lands, is the opening move of a multi-year legal process, and the DPAs that issue the biggest headline numbers are also the ones most exposed to having their reasoning tested and occasionally unwound on appeal.