Privacy-first analytics · cookieless marketing · ethical SEO Written by Sophie Darge
Darge
Industry News

GDPR Fines: What Website Owners Must Know Now

GDPR Fines: What Website Owners Must Know Now
GDPR lock symbol with EU stars on a digital blue background representing data protection fines in 2026

If you run a website that serves European visitors, GDPR fines are no longer a distant threat reserved for tech giants. By early 2025, European data protection authorities had issued €5.65 billion in total fines across 2,245 individual penalties, with an average fine of €2.36 million. Enforcement is accelerating, not slowing down.

The assumption that regulators only target household names is increasingly dangerous. This article walks through the current state of GDPR enforcement, explains exactly how smaller websites get caught, and gives you a practical checklist to act on today.

Short answer: GDPR fines apply to any website collecting data from EU residents — regardless of your company size or location. The most common violations are non-compliant cookie banners, Google Analytics loaded without consent, and vague privacy policies. Regulators find these issues through user complaints and automated website scans, and they are increasingly fining smaller organizations, not just big tech.

The State of GDPR Enforcement: A €5.65 Billion Wake-Up Call

GDPR entered into force in May 2018. The first couple of years were cautious — regulators gave organizations time to adapt. That grace period ended a long time ago.

According to data compiled by GDPR Enforcement Tracker, total fine values have grown exponentially year over year. Regulators across all 27 EU member states — plus EEA countries — have built the infrastructure, hired the staff, and established the precedent to pursue violations at scale. This is no longer a nascent framework finding its feet.

Here is what the enforcement landscape looks like:

MetricValue
Total fines issued (cumulative by early 2025)€5.65 billion
Total number of individual fines2,245
Average fine amount€2.36 million
Countries with active enforcement30+
Largest single fine (Meta, 2023)€1.2 billion

The European Data Protection Board (EDPB) has been working to harmonize enforcement across member states. Inconsistent regulatory action was always a temporary phase. It is closing fast.

The Biggest GDPR Fines and What They Were For

The largest fines reveal where regulators focus. These are not obscure technicalities — they are practices that thousands of websites still use today.

CompanyFineYearPrimary Violation
Meta (Facebook)€1.2 billion2023Unlawful transfer of personal data to the US without adequate safeguards
Amazon€746 million*2021Non-compliant advertising targeting and consent practices (*annulled on procedural grounds in 2026; the violation findings stood)
Meta (Instagram)€405 million2022Processing children’s personal data, public-by-default settings
TikTok€345 million2023Children’s data processing, transparency, and data minimization failures
Meta (WhatsApp)€225 million2021Transparency failures in privacy notices
Google (France)€150 million2022Cookie consent mechanisms that made rejection harder than acceptance
H&M€35.3 million2020Excessive employee surveillance and data collection

One fine deserves closer attention: Google’s €150 million from CNIL (France’s data protection authority). It was not about some obscure data transfer technicality. It targeted cookie consent design — the banner on a website that nudges users toward accepting tracking. If that applies to Google, it applies to you.

Compliance document with shield and gavel illustration representing GDPR enforcement and legal penalties

Analytics and Tracking Violations: The Rulings That Changed Everything

The most consequential GDPR rulings for website owners since 2022 were not the billion-euro headlines. They were the rulings about Google Analytics.

Starting in late 2021, the privacy advocacy organization noyb (None of Your Business) filed 101 complaints across nearly every EU member state, all targeting websites that used Google Analytics. The argument was specific: Google Analytics transfers European user data to US servers, where it can be accessed by US intelligence agencies under Section 702 of FISA and Executive Order 12333, without adequate protections under GDPR — particularly after the Schrems II ruling invalidated the Privacy Shield.

The dominoes fell in order:

  • Austria (DSB), January 2022: Ruled that a health-sector website’s use of Google Analytics violated GDPR because data transfers to the US lacked sufficient safeguards after Schrems II.
  • France (CNIL), February 2022: Issued formal notices to multiple website operators finding Google Analytics use constituted unlawful data transfers, with a one-month compliance deadline.
  • Italy (Garante), June 2022: Declared Google Analytics illegal and gave Italian website operators 90 days to switch to compliant solutions.
  • Denmark, Norway, Finland: Further rulings and guidance followed, reinforcing the same position across Scandinavia.

The EU-US Data Privacy Framework (DPF), adopted in July 2023, created a new legal basis for transatlantic data transfers. Whether it holds is a different question. Privacy advocates have already signaled legal challenges, and many legal experts consider a “Schrems III” ruling inevitable. Staking your entire compliance posture on the DPF surviving is a bet, not a strategy.

There is a cleaner approach: tools that process data entirely within the EU, without setting cookies or building user profiles. No transfer risk to manage because there is no transfer. If you are considering the migration, our step-by-step guide to switching from Google Analytics covers the practical side.

How Small and Medium Websites Get Caught

Regulators do not need to audit you proactively. There are two reliable mechanisms that surface violations — and both are in active use.

Complaint-Driven Enforcement

Under GDPR Article 77, any individual can lodge a complaint with their national supervisory authority. Organizations like noyb have automated and scaled this process, filing thousands of complaints on behalf of individual users. A single visitor who notices a non-compliant cookie banner on your site can trigger a formal investigation. You do not have to be a target — you just have to be visible.

Automated Scanning

Several data protection authorities have developed or adopted automated tools that crawl websites at scale — checking for cookies set before consent, tracking scripts loaded on page visit, and missing or inadequate consent mechanisms. The Belgian, Dutch, and Danish authorities have all run systematic website scans. The point is not that every scan leads to a fine. The point is that your site can appear in a regulatory database without anyone deliberately targeting you.

The Three Most Common Violations for Smaller Sites

1. Non-compliant cookie banners. This is the most widespread issue by a significant margin. Banners that pre-tick consent boxes, use visual tricks to nudge users toward “Accept All,” bury the reject option in secondary menus, or set non-essential cookies before any choice is made — all violate GDPR and the ePrivacy Directive. The detailed guide to cookie consent banner compliance explains precisely what regulators expect at each layer of the banner.

2. Google Analytics firing without consent. Even under the DPF, Google Analytics requires explicit consent before loading, accurate privacy policy disclosures, and a current Data Processing Agreement with Google. Many sites still load it on every page visit regardless of what the user chose — or ignores. That is a documented violation, not a technicality.

3. Privacy policies that do not reflect reality. GDPR requires specific, accurate information: what data you collect, why you collect it, how long you retain it, and exactly who you share it with — not just “trusted partners.” Template privacy policies copied from other sites fail this standard every time, because they describe someone else’s data practices, not yours.

Person typing on laptop with EU flag in background representing GDPR compliance for website owners

GDPR Compliance Checklist for Website Owners

Compliance is achievable. The following covers the areas regulators are actively investigating right now.

Cookie Consent

  • Your banner must offer a clear “Reject All” option that is equally prominent as “Accept All” on the first layer — not buried under “Manage preferences.”
  • No non-essential cookies or tracking scripts may load before the user makes an explicit choice.
  • Consent must be freely given — cookie walls that block content until the user accepts tracking are not compliant.
  • Withdrawing consent must be as simple as giving it.
  • Consent records must be stored and producible to regulators on request.

Analytics and Tracking

  • Audit every third-party script. Identify which ones transfer data outside the EU/EEA.
  • If using Google Analytics, ensure it only fires after explicit consent and that your Data Processing Agreement with Google is current.
  • Consider migrating to a privacy-first analytics platform that does not require consent banners because it does not collect personal data or transfer data internationally.
  • Review all marketing pixels (Meta Pixel, TikTok Pixel, LinkedIn Insight Tag) — none should fire without consent.

Privacy Policy and Transparency

  • List every specific third party that receives personal data, not just categories like “advertising partners.”
  • Include the legal basis for each type of processing: consent, legitimate interest, or contractual necessity.
  • State data retention periods for each category of data.
  • Give clear instructions for how users can exercise their rights: access, deletion, portability, objection.
  • Name your Data Protection Officer if you are required to have one, or a clear privacy contact point.

Data Transfers

  • Map all international data flows from your website.
  • Verify that every transfer has a valid legal mechanism: adequacy decision, Standard Contractual Clauses (SCCs), or the EU-US DPF where applicable.
  • Conduct Transfer Impact Assessments for transfers to countries without adequacy decisions.
  • Have a contingency plan in case the DPF is invalidated.

Privacy-First Alternatives That Eliminate the Risk

The most durable approach to GDPR compliance is stopping the collection of personal data where you can. Not because the law requires you to — but because data you never collect cannot be fined, breached, or mishandled.

A growing category of analytics tools is built around this principle. They give you meaningful website data — pageviews, referrers, top pages, conversion events — without setting cookies, building user profiles, or routing data through US servers. Tools like Plausible and Umami fall into this category. Some host everything in the EU by default; others you self-host entirely.

These tools typically:

  • Do not use cookies or any form of persistent tracking.
  • Process all data within the EU.
  • Do not collect IP addresses or device fingerprints in identifiable form.
  • Provide aggregate data rather than individual user profiles.
  • Do not require cookie consent banners because there is nothing to consent to.

If you are currently using Google Analytics and want to understand the practical migration path, the migration guide covers the full process — what to export, how to recreate your key reports, and what you give up versus what you gain.

What Is Coming: ePrivacy Regulation and Increased Enforcement

GDPR enforcement is not the only pressure website owners face. The proposed ePrivacy Regulation — a long-delayed replacement for the 2002 ePrivacy Directive — continues to advance through EU negotiations. When it arrives, it will bring stricter, more specific rules about cookies, electronic communications, and online tracking, with fines aligned to GDPR’s structure: up to 4% of global annual turnover. The relationship between the ePrivacy Directive and GDPR is worth understanding now, before the newer regulation locks in.

Several trends are shaping the enforcement picture beyond that:

  • Coordinated enforcement actions. The EDPB is increasingly coordinating enforcement across multiple member states simultaneously. Instead of one regulator, companies may face parallel investigations in several countries at once.
  • Higher baseline fines. Regulators have signaled that the era of warnings and small administrative fines for first-time offenders is ending. The UK’s Information Commissioner’s Office (ICO) and EU counterparts are moving toward fines that are proportionate and dissuasive from the first offense.
  • AI and automated decision-making scrutiny. Websites using AI-powered personalization, chatbots that process personal data, or automated profiling for advertising will face heightened scrutiny under both GDPR Article 22 and upcoming AI regulation.
  • Class action and collective redress. Consumer organizations across Europe are gaining legal standing to bring collective GDPR claims on behalf of individuals, increasing financial risk beyond regulatory fines to include civil damages.

The direction is clear. Privacy enforcement will become more systematic, more severe, and harder to avoid through inertia. Compliance built now costs a fraction of what a reactive response to an enforcement action costs — in time, legal fees, and reputational damage.

Frequently Asked Questions About GDPR Fines

Can a small business really be fined under GDPR?

Yes. GDPR applies to any organization that processes personal data of EU residents, regardless of size or location. Fines are meant to be proportionate, but small businesses have received penalties ranging from a few thousand euros to six figures. The Spanish and Italian data protection authorities have been particularly active in fining SMEs.

What is the maximum GDPR fine?

The maximum is the higher of €20 million or 4% of global annual turnover. For most smaller organizations, the €20 million cap is the relevant ceiling. In practice, regulators scale penalties to an organization’s size and the severity of the breach, and most small-site cases land well below that ceiling.

Is Google Analytics still legal in the EU?

It is not categorically banned, but it requires strict compliance measures to use legally. You need valid user consent before loading the tracking script, a current Data Processing Agreement with Google, accurate privacy disclosures, and a valid data transfer mechanism. Many organizations find that doing this correctly costs more in engineering and legal time than switching to a cookieless alternative.

Does GDPR apply to websites outside the EU?

Yes. If your website is accessible to and collects data from EU residents — regardless of where your business is based — GDPR applies under its extraterritorial scope as set out in Article 3. Location of the company is irrelevant; location of the data subjects is what matters.

How do I know if my cookie banner is compliant?

A compliant banner presents accept and reject options with equal prominence on the first screen, sets no non-essential cookies before the user chooses, uses no deceptive design patterns, and lets users update their preferences at any time. The cookie consent banner compliance guide covers each requirement with specific examples of what passes and what fails.

What should I do if I receive a GDPR complaint?

Respond promptly. Under GDPR you must acknowledge data subject requests within one month. Document everything from the moment the complaint arrives. If the complaint comes from a supervisory authority, get legal advice immediately — failing to cooperate with a regulatory inquiry is itself a violation that can increase any resulting fine.

The Bottom Line for Website Owners

GDPR fines are present-day consequences for practices that many website owners still consider routine. The regulatory framework has matured, the precedents are set, and the enforcement infrastructure is active across Europe. The question is no longer whether enforcement is real — it is whether your site gives it a reason to land on you.

The practical path forward is not complicated: fix your cookie banner, put analytics behind consent or replace it with a cookieless alternative, and write a privacy policy that reflects what your site actually does. Each of those tasks is finite. An enforcement investigation is not.

If you want to start with the highest-risk item, go to your cookie banner first. That is where regulators are looking, that is where automated scans catch violations, and that is where your quickest compliance win lives.

Written by

Sophie Darge

Digital Marketing Consultant with 8+ years of experience in privacy-first analytics, SEO strategy, and cookieless marketing. Certified in Google Analytics, Google Ads, and HubSpot Inbound Marketing. Specializing in GDPR-compliant analytics solutions including Plausible, Fathom, and Matomo. Helping businesses grow online while respecting user privacy — no invasive tracking needed.