Eight years after Europe introduced one of the world’s toughest data protection regimes, the financial cost of falling foul of it is still climbing.
Since the General Data Protection Regulation (GDPR), came into force in 2018, Europe’s data protection authorities have handled 3,202 cases with cumulative penalties reaching €6.31 billion ($7.28 billion) in fines.
Data acquired by Finbold shows that enforcement drive accelerated in the second quarter (Q2) of 2026. The value of GDPR fines jumped by roughly 230% quarter-over-quarter from €68.18 million ($73.63 million) between January 1 and March 31 to €225,879,175 ($260.59 million) between April 1 and June 30, bringing the H1 2026 total to around €295 million ($340.5 million).
Spread across the quarter, that equates to €2.48 million ($2.86 million) in penalties per day, or €17.36 million ($20.02 million) per week. The surge was also heavily concentrated geographically. The Netherlands recorded the highest total at €100.25 million ($115.64 million), accounting for nearly 49% of all penalties imposed in the European Union (EU).
The shift pushed France, Q1’s most heavily fined country, into second place, with €52 million ($59.98) in fines. Italy ranked third at €45.50 million ($52.47 million), followed by the United Kingdom (U.K.) at €18 million ($20.76 million).
The biggest GDPR fines in Q2 2026
The second quarter of 2026 saw several major GDPR penalties across Europe, with the 10 largest fines in the period totaling over €215 million ($248 million).
As mentioned, the largest was a €100.25 million ($115.64 million) penalty imposed on Dutch company Ridetech International B.V., the operator of the taxi app Yangoo, which accounted for nearly half of the total fines on the list for failing to implement adequate guarantees for the transfer of personal data into a third country.
Italy also recorded two of the quarter’s largest penalties. Notably, Intesa Sanpaolo S.p.A. was fined €31.8 million over serious shortcomings in the protection of customers’ banking data. Namely, an investigation found that an employee had accessed the banking information of 3,573 customers more than 6,600 times without a legitimate reason.
France followed with two substantial penalties against its telecommunications companies. FREE MOBILE received a €27 million fine, while its parent company FREE was fined €15 million, likewise over a major data breach. Specifically, the French data protection authorities said the companies experienced a data breach due to insufficient technical and organisational measures. Similar issues led to the country’s record-breaking fines in the first quarter too.
In the U.K., Reddit suffered a major blow with a €16.61 million penalty. The U.K. Information Commissioner’s Office fined the social media company £14.47 million after finding that its platform failed to implement an age-verification procedure and therefore lacked a lawful basis for processing the personal information of children under 13.
Other notable Q2 penalties included €6.62 million and €5.88 million against Italy’s Poste Italiane and PostePay for banking application mismanagement, €5 million against France Travail due to cyber attacks, as well as €5 million against IQVIA Operations France for for health data breaches and €2.68 million against the Polish company DPD Polska for not having a data processing agreement with the subcontractors.
European privacy laws stricter than in the first quarter
Comparing the data from the past two quarters, it becomes clear that data protection efforts in Europe are becoming increasingly more serious. As already made clear, the €225.88 million in Q2 GDPR fines was a 230% increase compared to Q1’s €68.18 million.
As in the first quarter, security failures and lack of legal ground for data processing remain the most common guideline violations, accounting for virtually all of the major penalties. With its €100.25 million fine, the Netherlands dominated the previous quarter, overtaking France and the U.K., which were responsible for 94% of all fines in Q1.
Media and finance remain the most problematic sectors number-wise, each responsible for three of the ten largest fines, followed by transportation and energy, which accounted for two, including the largest one in the Netherlands. Health care, public sector, and education sectors were close behind, accounting for the remaining two.
Featured image via Shutterstock