EUR114 million in fines have been imposed by European authorities under GDPR

0

Breach notifications exceed 160,000 in Europe since the introduction of GDPR according to a survey by DLA Piper

European data protection regulators have imposed EUR114 million in fines under the GDPR regime. A further EUR329 million in fines have been threatened by the UK regulator

  • France has imposed the highest fines to date, while per capita the Netherlands tops the rankings for breach notifications
  • Disparities found in levels of reporting across Europe. Italy with a population of more than 62 million people only recorded 1886 breach notifications

Over 160,000 data breach notifications have been reported across the 28 European Union Member States plus Norway, Iceland and Liechtenstein since the GDPR came into force on 25th May 2018. According to DLA Piper’s latest GDPR Data Breach Survey, data protection regulators have imposed EUR114 million (approximately USD126 million / GBP97 million) in fines under the GDPR regime for a wide range of GDPR infringements, not just for the data breach. France, Germany and Austria topped the rankings for the total value of GDPR fines imposed with just over EUR51 million, EUR24.5 million and EUR18 million respectively. The Netherlands, Germany and the UK topped the table for the number of data breaches notified to regulators with 40,647, 37,636 and 22,181 notifications each.

The daily rate of breach notifications has also increased by 12.6% from 247 notifications per day for the first eight months of GDPR from 25 May 2018 to 27 January 2019, to 278 breach notifications per day for the current year.

Weighting the results against country populations, The Netherlands again come top with 147.2 reported breaches per 100,000 people, up from 89.8 per 100,000 people last year, followed by Ireland and Denmark. From the 27 countries that provided data on breach notifications, the UK, Germany and France ranked thirteenth, eleventh and twenty-third respectively on a reported fine per capita basis. Italy, Romania and Greece reported the fewest number of breaches per capita. Italy, a country with a population of over 62 million people, only recorded 1886 data breach notifications illustrating the cultural differences in approach to breach notification.

The highest GDPR fine to date was EUR50 million imposed by the French data protection regulator on Google, for alleged infringements of the transparency principle and lack of valid consent, rather than for data breach. Following two high profile data breaches, the UK ICO published two notices of intent to impose fines in July 2019 totalling GBP282 million (approximately EUR329 million / USD366 million) although neither of these was finalised as at the date of this report.

Commenting on the report, Ross McKean, a partner at DLA Piper specialising in cyber and data protection, said: “GDPR has driven the issue of data breach well and truly into the open. The rate of breach notification has increased by over 12% compared to last year’s report and regulators have been busy road-testing their new powers to sanction and fine organisations. The total amount of fines of €114 million imposed to date is relatively low compared to the potential maximum fines that can be imposed under GDPR, indicating that we are still in the early days of enforcement. We expect to see momentum build with more multi-million Euro fines being imposed over the coming year as regulators ramp up their enforcement activity.”

Patrick Van Eecke, chair of DLA Piper’s international data protection practice, said “The early GDPR fines raise many questions. Ask two different regulators on how GDPR fines should be calculated and you will get two different answers. We are years away from having legal certainty on this crucial question, but one thing is for certain, we can expect to see many more fines and appeals over the coming years.”

Download a full copy of the report

Not all Member States of the European Economic Area make breach notification statistics publicly available. Many have only provided statistics for part of the period covered by this report so the figures have been rounded up and in some cases extrapolated to provide best approximations. Similarly, not all GDPR fines are publicly reported.