Historical and retrospective context. The original 14 October 2022 date is retained. This article discusses the 2022 position and later corrections, not a current tally. No cumulative fine total is asserted without a dated, reproducible dataset and scope. Two dated decisions illustrate the scale without proving a cumulative total. Amazon disclosed a EUR 746 million Luxembourg decision dated 16 July 2021 and said it intended to appeal. The Irish DPC announced a EUR 405 million Instagram decision on 15 September 2022, adopted on 2 September. Announced penalties are not automatically final or paid amounts. Four and a half years in, the more useful observation is that enforcement has changed shape. It has moved from punishing incidents to challenging structures.
Nobody is fined for the policy on the website. They are fined for the gap between the policy and the system
Read the decisions rather than the headlines and the same pattern recurs. The organisation had a privacy notice. It had a policy. What it did not have was a defensible account of why a particular processing activity was lawful, what actually happened to the data inside its systems, how long the data was kept, and who else received it. The categories generating penalties are consistent: an insufficient or wrongly chosen legal basis, inadequate technical and organisational measures, transparency failures, and — increasingly this year — international transfers. Very few of these are security breaches. Most are design decisions that nobody documented.
The order to stop is the real exposure
Fines attract attention because they are quantifiable. The corrective powers sitting alongside them are more consequential: an instruction to cease a processing activity, to suspend a transfer, or to delete data already collected. This year made that concrete. A series of decisions from Austrian, French and Italian authorities found that a common web analytics configuration transferred personal data unlawfully to the United States. The monetary component was minor or absent. The operative part told organisations to stop using the tool as configured. For most businesses, being told to switch off a system in ninety days is a far worse outcome than a fine they could have absorbed, and it is the scenario worth planning against. On transfers more broadly, an executive order signed in Washington a week ago starts the process toward a new transatlantic arrangement. That deserves its own discussion rather than a paragraph here; the short operational answer is to change nothing yet, because standard contractual clauses and transfer assessments will remain the fallback regardless of what happens next year.
Compliance turned out to be operations, not a project
The organisations that handle this well are not the ones with the thickest documentation. They are the ones running four capabilities continuously. A record of processing that matches reality. Not the version written by consultants in 2018. A living record that changes when a system changes, owned by someone whose job includes updating it. A request-handling operation with real capacity. Access, deletion and objection requests arrive unpredictably and carry a statutory clock. The failure mode is never the first request; it is the eleventh in a month when the person who handles them is on leave. A breach assessment process that functions at three in the morning on a Friday. The controller's Article 33 duty is notification without undue delay and, where feasible, within 72 hours after awareness, unless a breach is unlikely to risk individuals' rights and freedoms. Awareness requires reasonable certainty that personal data was compromised; processor escalation and communication to individuals have distinct duties. EDPB guidance explains the thresholds. A vendor and subprocessor register with change notification. Your processors change their subprocessors. If you learn about it from a newsletter, your transfer position is fiction.
Five failure patterns behind most enforcement
Consent used as a fallback for everything, including processing that consent cannot lawfully support. Records describing an organisation that no longer exists. Retention rules that live in a policy and nowhere in a database. Vendor changes nobody sees. And legitimate interests asserted as a basis with no balancing assessment ever written down — which is the single most common gap found in a serious review.
A health check that takes two weeks
Pick five processing activities that matter: payroll, customer marketing, website analytics, recruitment, and one core operational system. Trace each end to end — what is collected, which systems hold it, on what basis, for how long, who receives it, where it goes geographically, and how it is deleted. Then compare that trace against your formal record. Count the discrepancies. That number, not your policy library, is your actual compliance position, and it is usually the most sobering slide anyone shows the audit committee that year.
Practical Guidance for GDPR Compliance Health Check
- Trace five real processing activities end to end and compare them against your records.
- Write the balancing assessment for every activity relying on legitimate interests.
- Test the request process with a live exercise, including one from a former employee.
- Rehearse the breach clock with a scenario that starts outside working hours.
- Reconcile your subprocessor register against what your vendors actually publish today.
- Check analytics, advertising and support tooling for transfers nobody approved.
- Confirm retention is enforced in systems, not asserted in documents.
- Name one accountable owner per processing activity, because unowned records rot immediately.
The Regional Angle
Three regional considerations matter more than the European headline numbers. The first is that regional teams are being asked to build to a standard that has not finished being published. The Emirates federal data protection decree-law came into force at the start of this year with a transition period, and the executive regulations that will define much of the practical detail are still awaited. A later Saudi official circular records the updated PDPL taking effect on 14 September 2023 with a one-year adjustment period. That later chronology is not a spring 2022 effective date. The temptation is to wait. The better approach is to build the portable core now — records of processing, a request-handling process, breach assessment, vendor terms, retention enforcement — because every regional regime published so far has borrowed the same architecture from the European model, and none of that work is wasted when the detail lands. Check currently applicable localisation, registration and notification duties before deciding timing. Uncertainty or a historical transition does not justify deferring an obligation already in force. The second is that the European regulation reaches regional companies through three doors, and only one of them is obvious. Selling to consumers in Europe is the door everyone considers. Acting as a processor for a European customer is the door most regional service providers actually walk through, and it arrives as contract language rather than as regulation. The third door is the one that catches people: monitoring the behaviour of people in Europe, which is what a regional hotel group, e-commerce operator or airline does every time it runs targeted advertising and behavioural analytics aimed at European visitors. That is precisely the activity this year's analytics decisions addressed. Any regional marketing team running European campaigns with standard tracking tools should be treated as in scope until someone demonstrates otherwise. The third is that access requests here often arrive in an unfamiliar shape. Rather than a form submitted through a privacy portal, the regional pattern is a letter from a lawyer during a termination dispute, a demand for the personnel file alongside a gratuity claim, or a request routed through a labour authority or court process. The legal analysis differs, but the operational point is the same: if requests can arrive through human resources, legal, the service desk and the labour dispute channel, then all four need one intake path and one clock. Train the human resources team specifically, because in this region they will receive more of these than the privacy function ever will.
The objection worth taking seriously
The strongest objection is that four and a half years of this have produced cookie banners and paperwork. Total fines across the entire European economy remain small relative to the compliance spending they provoked, the largest penalties land on companies for whom they are a rounding error, regulators in the key jurisdictions are visibly under-resourced and slow, and the practical enforcement risk faced by a mid-sized company outside Europe is close to zero. Customer terms and security controls do not replace applicable statutory duties. No recommendation to ignore mandatory obligations follows from an estimated enforcement probability. Much of that critique is fair, and the profession should be more honest about how much of the spending bought artefacts rather than protection. But the exposure was never mainly the fine. It is the corrective order that switches off a system you depend on, and this year showed that those orders are landing on ordinary tooling choices rather than on exotic misconduct. It is the customer contract, enforced by a counterparty who is motivated, fast and uninterested in regulatory backlogs. And the four capabilities recommended here — accurate records, a request operation, a functioning breach clock, and a current subprocessor register — are the same capabilities that reduce the cost of a real incident. They are operations, not documentation, which is precisely why so few organisations have them.
Common Questions
Does the regulation apply to us if we have no European entity?
Possibly, through offering goods and services to people in Europe or monitoring their behaviour — and almost certainly through your contracts if you process data for European customers.
Is consent the safest legal basis?
No. It is the most fragile, because it can be withdrawn and must be freely given. Contract necessity and legitimate interests are often more appropriate, provided the reasoning is written down.
How much should a mid-sized company spend on this?
Less than most spend on documentation and more than most spend on operations. If you have a policy library and no request process, your budget is allocated backwards.
What should we expect over the next twelve months?
Expect the new transatlantic arrangement to move through the European approval process during next year and to be challenged immediately when it arrives. Expect more decisions aimed at analytics, advertising technology and transfers rather than at breaches, because that is where regulators have found leverage. Expect the European board's dispute mechanism to keep revising lead-authority decisions upward, which raises the effective penalty level without any change to the law. Expect the regional executive regulations to be published and to look reassuringly familiar to anyone who has done this work already. And expect request volumes to rise steadily as awareness spreads, which is the workload that catches unprepared organisations rather than the fines.
GDPR Compliance Health Check — we trace five real processing activities end to end, count the gaps between your records and your systems, and build the portable core that survives whatever the regional regulations finally say.
