GDPR fines jump 230% to €225.88 million in Q2 2026
- GDPR fines surged 230% QoQ to €225.88 million in Q2 2026
- The Netherlands led with €100.25 million, nearly 49% of EU total
- Ridetech International B.V. faced the largest single penalty of €100 million
- Media and finance sectors accounted for six of the ten largest fines

*this image is generated using AI for illustrative purposes only.
General Data Protection Regulation (GDPR) enforcement authorities issued €225.88 million ($260.59 million) in fines during the second quarter of 2026. The total represents a 230% quarter-over-quarter increase from €68.18 million ($73.63 million) in the first quarter.
The surge brings the H1 2026 total to approximately €295 million ($340.5 million). During the second quarter, companies paid an average of €2.48 million ($2.86 million) per day in penalties, or €17.36 million ($20.02 million) per week.
Regional Breakdown
The Netherlands recorded the highest total at €100.25 million ($115.64 million), accounting for nearly 49% of all EU penalties. France followed with €52 million ($59.98 million), while Italy ranked third with €45.50 million ($52.47 million). The United Kingdom contributed €18 million ($20.76 million).
| Country | Fine Amount (€) | Share of Total |
|---|---|---|
| Netherlands | €100.25 million | ~49% |
| France | €52 million | ~23% |
| Italy | €45.50 million | ~20% |
| United Kingdom | €18 million | ~8% |
Major Infractions
The largest single penalty was a €100 million fine imposed on Ridetech International B.V. in the Netherlands for failing to implement adequate guarantees for third-country data transfers. In Italy, Intesa Sanpaolo S.p.A. was fined €31.8 million ($36.68 million) over shortcomings in protecting customer banking data.
France issued a €27 million ($31.14 million) fine against FREE MOBILE and a €15 million ($17.3 million) penalty against its parent company FREE for a major data breach. In the UK, Reddit received a €16.61 million ($19.16 million) fine from the Information Commissioner’s Office (ICO) for failing to implement age-verification procedures.
Other notable penalties included:
- €6.62 million ($7.64 million) and €5.88 million ($6.78 million) against Poste Italiane and PostePay for banking application mismanagement.
- €5 million ($5.77 million) against France Travail due to cyberattacks.
- €15 million ($17.3 million) against IQVIA Operations France for health data breaches.
- €2.68 million ($3.09 million) against DPD Polska for lacking data processing agreements with subcontractors.
What the Numbers Show
Security failures and lack of legal ground for data processing remain the primary drivers of penalties. Media and finance sectors each accounted for three of the ten largest fines, indicating concentrated compliance risks in these industries. Transportation and energy sectors followed with two major penalties each, including the largest case in the Netherlands.
Jordan Major, Chief Editor at Finbold, noted that the scale of the increase highlights GDPR enforcement as a material financial risk. Diana Paluteder, Head of Content at Finbold, added that regulators are focusing on core compliance failures rather than isolated technical breaches.
Will the significant enforcement surge in Q2 2026 signal a permanent shift in regulatory posture, or is this a temporary spike driven by specific high-profile cases?
How might the disproportionate share of fines levied in the Netherlands influence cross-border data transfer strategies for multinational corporations operating within the EU?
Given the heavy penalties in the finance and media sectors, what specific compliance frameworks are likely to become industry standards to mitigate these concentrated risks?

























