---
title: One Year Later - What Were the Biggest GDPR Fines?
description: By May 2019, the biggest GDPR fines were issued to Facebook, Google, and a Portuguese hospital. But were they really that big?
image: https://insights.comforte.com/hubfs/GDPR_1y_B.png
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![GDPR_1y_B](https://insights.comforte.com/hubfs/GDPR_1y_B.png)](https://insights.comforte.com/one-year-later-what-were-the-biggest-gdpr-fines)

[Dan Simmons](https://insights.comforte.com/author/dan-simmons) l May 24, 2019 l [GDPR](https://insights.comforte.com/tag/gdpr), [Compliance](https://insights.comforte.com/tag/compliance)

# One Year Later - What Were the Biggest GDPR Fines?

GDPR’s potential fines of 20 million EUR or 4% of global annual turnover had organizations across the globe shaking in their boots, but was the fear really warranted? Now that GDPR has been in effect for a full year, let’s take a look at what’s happened thus far.

## Who has been issued GDPR fines so far?

One month before GDPR came into effect, a study conducted by the Cloud Security Alliance found that [83% of companies didn’t feel very prepared](https://cloudsecurityalliance.org/articles/gdpr-preparation-and-challenges-survey-report/). One year later we see that many companies had a good reason to feel that way.

According to the European Data Protection Board (EDPB), 9 months after GDPR came into effect, Supervisory Authorities from 11 countries in the European Economic Area had already levied a total of almost 56 million EUR worth of fines.

Here are just a few examples:

German online chat platform “Knuddels” was [the first organization to be fined for a GDPR violation](https://www.itgovernance.co.uk/blog/gdpr-fine-for-german-chat-app-platform). The fine totaled 20,000 EUR and was issued after attackers were able to gain access to 330,000 user passwords stored in plain text. Leniency was shown for the company’s quick response to notify users and remedy the situation. In the months that followed, [40 more companies were issued fines in Germany alone](http://www.mondaq.com/germany/x/784740/data+protection/41+GDPR+Fines+Issued+By+German+Data+Protection+Authorities), the highest of which was 80,000 EUR for a case involving medical information that ended up on the internet. Further details on that particular case have not been released.

> *"20 grand here, 80 grand there... these all sound kind of low, where did the rest of the 56 million come from?"*

![hospital fined for gdpr violation](https://insights.comforte.com/hs-fs/hubfs/Stock%20images/success%20smart%20medical%20doctor%20working%20with%20operating%20room%20as%20concept.jpeg?width=300&name=success%20smart%20medical%20doctor%20working%20with%20operating%20room%20as%20concept.jpeg)

One of the larger fines included [a Portuguese hospital](https://iapp.org/news/a/first-gdpr-fine-in-portugal-issued-against-hospital-for-three-violations/) that was fined 400,000 EUR for multiple violations. They included failure to limit access to personal data to only those who needed it, a lack of technical and organizational measures to prevent unlawful access to personal data, and failure to assess risk.

Social media platform [Facebook was struck with a 500,000 GBP fine for violating the Data Privacy Act](https://www.theguardian.com/technology/2018/oct/25/facebook-fined-uk-privacy-access-user-data-cambridge-analytica), the UK’s equivalent to GDPR, for data breaches in the Cambridge Analytica scandal. The largest fine of all, which makes up almost 90% of the total fine amount cited in the EDPB report, was [a 50 million EUR fine issued to Google](https://www.reuters.com/article/us-google-privacy-france/france-fines-google-57-million-for-european-privacy-rule-breach-idUSKCN1PF208) for how it uses data for ad-targeting.

---

*In case you missed it, check out our GDPR review from after the half year mark to see how things have progressed:*

### [![4 key impacts of gdpr after first half year](https://insights.comforte.com/hs-fs/hubfs/Stock%20images/not%20available%20in%20europe.jpg?width=270&name=not%20available%20in%20europe.jpg)](https://insights.comforte.com/4-key-impacts-of-gdpr-since-becoming-enforceable?hsLang=en)[4 Key Impacts of GDPR Since May 25 ](https://insights.comforte.com/4-key-impacts-of-gdpr-since-becoming-enforceable?hsLang=en)

[November 26, 2019](https://insights.comforte.com/4-key-impacts-of-gdpr-since-becoming-enforceable?hsLang=en)

[*"It’s now been half a year since GDPR came into force (officially on May 25, 2018) – so it begs the question – what has been the impact?"*](https://insights.comforte.com/4-key-impacts-of-gdpr-since-becoming-enforceable?hsLang=en)

---

## How big were Google and Facebook's GDPR fines really?

For smaller organizations, even a 10,000 EUR fine could be very painful. For tech giants like Google and Facebook on the other hand, 50 million is pocket change.

To put things in perspective, in 2018, Facebook’s global annual turnover was 55.9 billion USD. 500,000 GBP is equivalent to about 630,000 USD, meaning that fine amounted to 0.0011% of their global annual turnover. That’s virtually nothing. For someone who makes 50 grand a year, that’s the same as being fined 55 cents.

Google’s parent company, Alphabet Inc., makes more than twice as much as Facebook on a yearly basis. Since 2016, Alphabet Inc.’s global annual turnover has consistently been upwards of 100 billion USD. [In 2018 it was 136.8 billion](https://abc.xyz/investor/static/pdf/2018Q4_alphabet_earnings_release.pdf). 50 million is 0.037% of that. If you work a full time job you could compare that to having half an hour’s worth of pay docked from your annual salary. That’s not nothing, but it’s still not much. If we compare it to 50 grand a year again, 0.037% of that would be $18.50.

## Is GDPR just a paper tiger?

![gdpr paper kitty cat](https://insights.comforte.com/hs-fs/hubfs/Stock%20images/Portrait%20of%20kitty%20cat%20in%20hands.jpeg?width=300&name=Portrait%20of%20kitty%20cat%20in%20hands.jpeg)It might seem that way for now, but there are fines looming that may have much bigger teeth than what we've seen so far. Facebook is currently facing [a potential 2.2 billion USD fine](https://www.businessinsider.de/facebook-faces-2-2-billion-fine-email-contacts-harvesting-ireland-data-protection-2019-4) for insecurely storing users' passwords. Just a few days ago, Ireland's Data Protection Commissioner opened an investigation into the way Google handles personal data for its ads, which is just [one of 51 large-scale investigations currently in progress](https://www.reuters.com/article/google-dataprotection/irish-regulator-opens-first-privacy-probe-into-google-idUSS8N21D027).

As many of the companies that were subject to GDPR, the legislators meant to enforce it were also unprepared and many countries reported that although the current workload was manageable, more staff and funds will be necessary to handle the growing number of breach notifications and complaints coming in. As Supervisory Authorities across the EEA begin to get the swing of things, multimillion and even billion euro fines for GDPR violations could become a regular occurrence. 

## What's next after GDPR?

[GDPR-like laws are appearing in more and more parts of the world](https://insights.comforte.com/13-countries-with-gdpr-like-data-privacy-laws?hsLang=en). No matter what geography you’re in, sooner or later most companies in the world will be subject to data privacy laws on par with GDPR. GDPR has already inspired similar regulations such as CCPA in the US and LGPD in Brazil. Since CCPA passed,  proposals for similar legislation have been made with bipartisan support in many other States and on the federal level. Even industry leaders are suggesting a GDPR-like federal data privacy law in the US, including [Apple CEO Tim Cook](https://insights.comforte.com/apple-ceo-tim-cook-calls-for-federal-privacy-laws-in-the-us?hsLang=en). For their sake, a federally applicable standard would be much easier to mange than 50 different ones. 

As more of these regulations begin to appear, globally operating organizations will have to look towards [cross-regulatory compliance](https://www.comforte.com/enterprise-data-protection/compliance/) strategies in order to more efficiently manage and fulfill overlapping requirements. 

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/one-year-later-what-were-the-biggest-gdpr-fines&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/one-year-later-what-were-the-biggest-gdpr-fines&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/one-year-later-what-were-the-biggest-gdpr-fines&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/one-year-later-what-were-the-biggest-gdpr-fines&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/one-year-later-what-were-the-biggest-gdpr-fines&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Looking to synergize your compliance efforts?

Many data privacy regulations overlap in numerous ways. The most efficient way to achieve compliance is to map out these similarities and develop a cross-regulatory compliance strategy in order to get the most out of your investments.  Check out our white paper to see how it can be done using PCI DSS and GDPR as an example. 

[![Download White Paper](https://no-cache.hubspot.com/cta/default/4026697/aea1fd18-c4e0-4e49-8af5-2f3ba7b8a21c.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/aea1fd18-c4e0-4e49-8af5-2f3ba7b8a21c)

### Related posts

![OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/hubfs/comforte%20AG_blog%20post_AI.png)

 Apr 6, 2023 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [AI](https://insights.comforte.com/tag/ai)

### [OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

After several weeks of incredible growth, OpenAI has come in for a bumpy ride of late. First it revealed details of a data breach exposing a significant number of ChatGPT subscribers. Then the Italian data protection regulator (GPDP) became the...

[Read more](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

![How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/hubfs/Analytics%20on%20Red%20Button%20Enter%20on%20Black%20Computer%20Keyboard..jpeg)

 Aug 4, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

Cloud-based analytics offer a truly transformative opportunity for global organizations. By extracting insights from data, they are already helping companies better serve their customers, improve operational efficiencies and make better business...

[Read more](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

![17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/hubfs/Int_Datenschutz_Strategie_1.png)

 Jan 13, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

GDPR wasn't the beginning and it certainly won't be the end. Strict data privacy legislation with extraterritorial applicability is appearing in more and more economies across the globe, meaning the list of “GDPR-free” havens is growing shorter by...

[Read more](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>