Historical and retrospective context. The original 1 October 2018 date is retained. The opening and forecasts describe the 2018 position, not today's enforcement. Later context includes DLA Piper's January 2020 survey, which reported EUR 114 million in GDPR fines since May 2018, not a first-year or October 2018 total.
Four months after the regulation took effect, the most common question in boardrooms is whether anyone has actually been fined under GDPR, and the honest answer is that the penalties everyone budgeted for have not landed. That absence is being read as leniency. It is nothing of the kind. It is a pipeline that has not finished running, and the organisations treating it as a reprieve are the ones most likely to be surprised when it does. GDPR enforcement is not slow because regulators have gone soft. It is slow because the machinery the regulation itself created takes a long time to produce a decision, and because the first cases entered that machinery on the very first day.
What has actually happened since May
Complaints arrived immediately and deliberately. On 25 May, a campaign group founded by Max Schrems filed complaints against Google, Facebook, Instagram and WhatsApp on the argument that consent conditioned on continued use of the service is not freely given. A French collective filed a parallel set against the same category of company. These are not opportunistic grievances; they were drafted in advance, aimed at the consent model underpinning the advertising economy, and framed to test the regulation's most contested provision first. The United Kingdom's regulator served what is understood to be the first formal enforcement notice under the new regime in July, against a Canadian data analytics firm, which is notable less for the target than for the demonstration: a company with no European establishment, told to stop processing European personal data. A later ICO decision on 25 October 2018 imposed a GBP 500,000 penalty on Facebook under the Data Protection Act 1998, not GDPR. This post-dates the original article date. The different statutory penalty ceilings do not establish what a hypothetical GDPR penalty would have been. Underneath the visible cases, volume. Supervisory authorities across Europe are reporting sharp increases in both complaints and breach notifications, in several cases multiples of the previous run rate. Some of that is genuine improvement in reporting discipline. A good deal of it is organisations notifying defensively because the assessment of whether a breach is notifiable is harder than simply reporting it, which is its own signal about the state of internal capability.
Why the fines are slow, structurally
The delay is built into the design, and it is worth understanding in detail because it determines the timing of everything else. A cross-border case does not belong to one regulator. The authority for the main establishment leads, every authority with affected residents is a concerned authority, and the lead must circulate a draft decision to them. Objections trigger a further process, and unresolved disagreement escalates to the European Data Protection Board under the consistency mechanism. Each stage has its own clock. Then national procedural law governs how the penalty is actually imposed, and every significant decision will be appealed. Add resourcing. The authorities took on a substantially expanded mandate without a proportionate increase in staff, and the ones leading the largest cases are the ones facing the biggest queues, because the one-stop-shop concentrates the major technology companies in a small number of jurisdictions. Add legislative lag: several member states were late passing the national laws that sit alongside the regulation, which affects the exercise of derogations and, in some cases, the authority's own powers. The result is arithmetic rather than philosophy. A complaint filed in May 2018 that runs the full route cannot plausibly produce a final, unappealable outcome for a long time. The first substantial penalties will come from simpler cases with a single national authority and clear facts, which is to say from security failures and from organisations that ignored a regulator's instruction, rather than from the flagship consent complaints.
The cost that has already been paid
While everyone watches the fine register, the actual bill has been operational, and it has fallen unevenly. Subject access requests went from a curiosity to a routine workload, with a one-month clock and a standing expectation that they be handled free of charge. Breach assessment became a defined process with a seventy-two hour horizon. Contract renegotiation consumed months of legal time across every supplier relationship that touches personal data. Sales cycles lengthened, because security and data protection questionnaires now arrive early and are read by someone. Marketing lists shrank, sometimes dramatically, where re-permissioning campaigns went out and most recipients simply did not respond. None of that shows up in a penalty total, and all of it is the real first-year cost of the regulation. A compliance audit that measures readiness only against the risk of a fine is measuring the smaller number.
| Capability | Evidence to examine |
|---|---|
| Access request | Locate relevant records and document redaction and response decisions. |
| Breach assessment | Rehearse risk assessment and the notification decision. |
| Processing inventory | Check that records reflect real activities and copies. |
| Transfers | Match each applicable mechanism to the actual data flow. |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for a GDPR Compliance Audit
- Audit against the obligations that generate work, not the ones that generate documents. Access requests, breach assessment, erasure, supplier assurance. These are the processes that will be exercised whether or not a regulator ever calls.
- Time your own subject access response end to end. One volunteer, one full request, one stopwatch. Most organisations discover the month is tight and the redaction of other people's data is the unbudgeted part.
- Check the lawful basis you actually rely on, not the one in the notice. Consent collected badly is worse than legitimate interests documented honestly, and the first wave of complaints is aimed precisely at that distinction.
- Keep the records of processing current enough to be useful. The obligation is modest. The value is that it is the only document that answers the first question in any incident, which is what is affected.
- Close the transfer question properly. Know which mechanism covers each flow outside the EEA, including the ones created by support access and backups, and keep the paperwork matched to reality rather than to intention.
- Rehearse the breach decision, not just the notification. The difficult part is assessing risk to individuals with incomplete information inside three days, and it is a judgement that should not be made for the first time under pressure.
- Track your own complaint and request volumes. They are the earliest indicator of where your exposure sits, and they are free.
- Separate what you will fix from what you will accept, in writing. Document remediation priorities and owners. Risk acceptance does not waive a mandatory legal duty or make a known breach lawful.
The Regional Angle
The enforcement lag has a specific effect here, and it is unhelpful. Boards asking whether anyone has been fined are using the answer to defer, and in a region with no general federal data protection statute the deferral looks reasonable. It is not, because the enforcement that matters locally is not coming from a European regulator at all. It is coming from customers, through contractual security schedules and audit rights that are already being exercised, and from European parent companies pushing group standards down. There is also a structural point that is widely missed by exporters in this market. The one-stop-shop is a benefit of having an establishment in the Union. An organisation here that targets European customers or monitors European individuals, but has no EU establishment, does not get a single lead authority. Every supervisory authority with affected residents is potentially competent, and the Article 27 representative requirement must be assessed, including its limited Article 27(2) exemptions. That designation is the single most frequently skipped requirement among regional businesses selling into Europe, and it is cheap to satisfy and awkward to explain after the fact. Groups with a European subsidiary have the mirror-image problem. Whether that subsidiary is the main establishment depends on where decisions about processing are actually taken, not on where a company was incorporated for convenience. A holding structure that places the decision-making in Dubai while the European entity executes does not automatically get the lead authority the organisation chart implies. Locally, the regimes that do exist and do have regulators are the financial free zones, alongside sector rules from central banks and health authorities and Qatar's statute. A group spanning mainland, free zone, DIFC or ADGM entities faces different baselines across one shared infrastructure, which makes the useful audit question a scoping one: which entity carries which obligation, and does the shared configuration satisfy the strictest of them.
The objection worth taking seriously
The objection is that waiting is rational. Compliance spend is real and immediate, the regulation is vague in exactly the places where spending decisions get made, and the visible enforcement so far is aimed at very large technology companies over an advertising consent model that has nothing to do with a distributor, a contractor or a hospital group. Spending now to satisfy a standard no regulator has yet articulated is buying an unspecified product at an unknown price. The harder version is an expected value argument, and it is not stupid. The probability that any given mid-market organisation outside Europe attracts a European investigation in the next two years is low. The cost of comprehensive compliance is high and certain. Fines scale with turnover, but investigations are triggered overwhelmingly by complaints and reported breaches, so an organisation with few European data subjects and no incident has a genuinely small exposure. A low estimated enforcement probability does not make partial non-compliance lawful or defensible; mandatory duties remain binding. What that reasoning gets wrong is the binding constraint. For most organisations in this region the cost of non-compliance will not be a penalty; it will be a lost renewal, a failed customer audit, or a procurement process that stops at the data protection annexe. Those events are far more likely than an investigation and they arrive without notice. The second thing it gets wrong is the shape of the cost curve: remediation done calmly is a project, and remediation done in the ninety days after an incident, with a customer and possibly a regulator watching, is the same project at several times the price. Prioritise remediation by harm and urgency without treating it as permission to omit mandatory duties. Document outstanding gaps and deadlines, obtain advice on current obligations, and do not infer exemption from an empty historical fine register.
Common Questions
Has anyone been fined under GDPR yet?
Not in any amount that has changed behaviour. The penalties reported so far relate to conduct that predates May and were issued under the previous national laws, with their much lower ceilings. The first genuine GDPR penalties are likely to be modest, national, and driven by security failures or by refusal to cooperate.
Does GDPR apply to us if we have no European office?
It can. The test is whether you offer goods or services to individuals in the Union or monitor their behaviour, not where you are incorporated. For activities caught by Article 3(2), assess the Article 27 representative requirement and its limited exemptions rather than assume it applies to every non-established entity.
Where should an organisation with limited budget start?
Know what personal data you hold and where copies go, be able to answer an access request inside a month, be able to assess a breach inside three days, and have your transfers covered by a mechanism that matches what actually happens. Those four capabilities absorb most of the real risk. Those capabilities are not an exhaustive legal minimum. Complete all applicable documentation and other mandatory obligations on their required timelines, not only when demanded.
What should we expect over the next twelve months?
Expect the first meaningful penalties in 2019, and expect them to come from single-country cases rather than the cross-border flagship complaints, which will still be working through the cooperation process. Expect early decisions to concentrate on transparency and lawful basis rather than security. Expect breach notification volumes to keep climbing and to become the main source of investigations. Expect the ePrivacy reform to remain stuck, leaving cookie and direct marketing rules governed by the old regime for longer than anyone planned. And expect the case that actually moves budgets in this region to involve a mid-sized company with poor access controls rather than a household name, because that is the case every board will recognise.
GDPR Compliance Audit — we test the four capabilities that carry the real exposure, entity by entity, and tell you plainly which gaps are worth funding now and which need further legal review and a dated remediation plan, without waiving mandatory duties.
