Most business owners hear the acronym GDPR and assume it refers to something that happened back in 2018, generated some headlines, and is now largely handled by whoever built their website. This assumption is costing businesses across Europe real money — and the pace of enforcement is accelerating, not slowing down.
In 2025, European data protection authorities issued over €1.2 billion in GDPR fines — the highest annual total since the regulation came into force. The enforcement bodies across France, Spain, Belgium, Poland, the Netherlands and the Nordic countries have all demonstrated not only willingness but appetite for investigating non-compliant websites.
The Cases That Matter Most
When compliance professionals talk about GDPR enforcement, the conversation often gravitates toward the headline fines — Amazon’s €746 million, Meta’s €1.2 billion. These numbers are accurate but they create a dangerous misimpression: that GDPR enforcement is something that happens to technology giants.
The enforcement record tells a different story. The cases that should concern every small and medium business owner are the ones that never make international headlines:
A Montessori school in Spain was fined €3,000 by the AEPD — the Spanish data protection authority — for operating a website without a cookie consent banner. Not a technology company. Not a media conglomerate. A school. The violation was simple and the fine was proportionate, but the message is unambiguous: size does not confer protection.
A retailer in Poland was fined €25,000 by the UODO for failing to obtain proper user consent for analytics cookies and not providing clear information about how those cookies were used. The business was not informed in advance that an investigation had opened. The first contact was a formal notice.
A publisher in France was fined €750,000 by the CNIL for placing advertising and analytics cookies on visitors’ devices before obtaining any consent. The CNIL has been particularly active in enforcing cookie consent standards and has made clear that pre-ticked boxes, notification-only banners and consent that is more difficult to withdraw than to give do not meet the legal standard.
What Constitutes a Violation
The most common GDPR violation found on websites is also the simplest to understand: non-essential cookies — analytics, advertising, preference tracking — being set on a visitor’s device before that visitor has actively agreed to them.
This means that if your website uses Google Analytics, your booking platform sets tracking cookies, or any advertising pixel fires when someone visits your homepage, you are almost certainly in violation unless you have a compliant consent mechanism in place.
Compliant consent must be:
- Freely given — a genuine choice, not a condition of using the site
- Specific — the visitor must know what they are consenting to
- Informed — clear explanation of each cookie category
- Unambiguous — a pre-ticked box is not consent
- Withdrawable — as easy to withdraw as to give
A banner that says “We use cookies to improve your experience. By continuing to browse you accept our use of cookies” does not meet this standard. Continuing to browse is not active consent. It has not been since May 25, 2018.
How Complaints Reach Regulators
One of the most persistent misconceptions about GDPR enforcement is that it is complaint-driven — that a business only faces investigation if a customer actively files a report. This is partially true but significantly understates the risk.
Privacy advocacy organisations across Europe run automated scans of websites specifically looking for cookie consent failures. Competitors sometimes file reports. Individual privacy-conscious users — increasingly common, particularly in Northern European markets — know exactly how to file a GDPR complaint and do so regularly.
More importantly: you do not receive a warning first. Regulators are not required to notify a business that it is being investigated before an investigation opens. The first contact many businesses receive is a formal investigation notice — at which point non-compliance has already been documented.
The Cost Beyond the Fine
The financial penalty, while significant, is often not the largest cost of a GDPR enforcement action. Businesses that receive a formal enforcement decision also face:
- Mandatory remediation requirements — implementing compliance under regulatory supervision
- Reputational damage — enforcement decisions are published publicly by most European authorities
- Legal costs — responding to an investigation requires professional legal advice
- Management time — investigations are disruptive and time-consuming regardless of outcome
A compliance audit that identifies and resolves these issues before an investigation opens costs a fraction of the cheapest enforcement outcome. The question is not whether you can afford to be compliant — it is whether you can afford not to be.