TwitterDeutsche Version
GDPR
Data Breaches
Fines

Review of GDPR fines and data breaches 2025

rueckblick_dsgvo_bussgelder_und_datenpannen_2025
Datum23. February 2026

Review of GDPR fines and data breaches

2025 is over – and we're taking a look back at the year that was, as we always do. We will be highlighting the significant decline in fines recorded by our database and are going to examine relevant security incidents and court decisions from the past year.

Further decline in the total amount of penalties imposed

Just like in 2024, the total amount of fines recorded by us declined again in 2025: instead of EUR 1.22 billion in 2024, we recorded only EUR 689.98 million for 2025 – a decline of more than EUR 530 million. This means that for the first time since 2021, the total amount of fines imposed has fallen below the EUR 1 billion mark. It should be noted that when querying our database, we only record fines for which we know the date the decision was released. The query period covered January 1 to December 31, 2025.

However, this does not mean that there were no significantly high fines in 2025. The French data protection authority (CNIL) was particularly consistent: it imposed a fine of EUR 325 million on the European branch of Google and EUR 150 million on Shein's EU branch, Infinite Styles Services Co.

Google was prosecuted for advertising that the software giant placed in its Gmail mailboxes. These were imported without the consent of users and were deceptively similar to genuine emails. With the fine against Shein, the CNIL punished the company's cookie practices. When users visited the fast fashion giant's website, it placed cookies on their devices without obtaining their consent. Even if users objected, the cookies continued to be read and new ones were stored.

As usual, however, the highest fine of the year came from Ireland, where the DPC imposed a €530 million fine on TikTok Technology Limited. These fines were imposed because the company transferred user data to China without adequately informing users. It should be noted, however, that according to recent reports, the Irish Data Protection Authority actually collects only a tiny percentage of the fines it imposes, as most of the cases in question are still under appeal, according to the authority.

But even in Germany, there have been isolated cases of very high fines by local standards. The Federal Commissioner for Data Protection and Freedom of Information (BfDI) imposed two fines totaling EUR 45 million on Vodafone. The reason for the EUR 15 million fine was the inadequate screening of the processors involved, which enabled their employees to create fake contracts. The BfDI imposed a fine of EUR 30 million because the authentication processes implemented by Vodafone were insufficient.

German fines

This year, the German supervisory authorities reported a total of 249 fines amounting to around EUR 46.9 million. Although this represents a decline in the number of penalties imposed, it nevertheless represents a massive increase in the sum total of sanctions imposed. As always, it should be noted that not all authorities provided us with figures, which is why this amount should be understood as a lower limit. Most of the penalties in 2025 again came from Bremen, which imposed 101 fines, more than twice as many as Hesse, which once again ranked second with 47 sanctions – exactly the same number as in 2024.

As already mentioned, the highest fine in 2025 was imposed by the BfDI, which fined Vodafone EUR 45 million. The second-highest fine was imposed by the Hamburg Commissioner for Data Protection and Freedom of Information: EUR 492,000 against a finance company that failed to respond to requests to exercise data subject rights after rejecting several credit applications despite the applicants' good credit ratings.

Fines imposed by the Federal Network Agency

This year, we yet again asked the Federal Network Agency (BNetzA) about the fines it imposed. Although this authority does not impose fines under the GDPR, the fines often relate to data protection issues, such as unauthorized contact for advertising purposes.

In 2025, the Federal Network Agency imposed a total of 13 fines amounting to almost EUR 901,000 – a decrease compared to the previous year. These primarily concern unauthorized telephone advertising, in particular cold calls, which constitute unreasonable harassment pursuant to Section 7 (2) No. 1 of the Unfair Competition Act (UWG). Violations of the prohibition on suppressing phone numbers in advertising calls pursuant to Section 28 (1) No. 9 in conjunction with Section 15 (2) HS 1 TDDDG were also subject to fines. In addition, in 2025, violations of the obligation to document and store advertising consents pursuant to Section 20 (1) No. 2 and paragraphs 2 and 3 in conjunction with Section 7a (1) UWG were also punished for the first time. Ten of the proceedings were still pending as of December 31, 2025.

In comparison with other EU countries

As in previous years, we compared the activities of the German authorities with the fine practices of other large EU countries. This year, we again took a closer look at France, Spain, and Italy.

France

According to its annual report for 2025, the French data protection authority (CNIL) imposed fines totaling EUR 486.8 million—a significant increase compared to the approximately EUR 55.2 million from the previous year. This sum is distributed across 83 sanctions, 4 fewer than in 2024. This significant difference is primarily due to the aforementioned penalties imposed on Google and Shein, which total EUR 475 million. In simplified proceedings, the CNIL issued 42 fines, which also represents a decline. The authority did not disclose the total amount of these penalties.

Italy

According to the fines we have recorded so far, the total amount in Italy fell sharply in 2025: instead of EUR 122 million in 2024, our database currently shows just under EUR 12.6 million in penalties imposed by the data protection authority (GPDP) in 2025. The number of penalties fell slightly from 146 in 2024 to 140 in 2025. It should be noted, however, that the Italian data protection authority often releases fines from the previous year well into the following year.

Spain

The Spanish have again seen a significant increase in the total amount of fines imposed: instead of EUR 38.6 million and 289 sanctions in 2024, the fines in 2025 amount to EUR 54.48 million spread over a total of 342 penalties. The most notable fine is the €10 million imposed by the data protection authority (AEPD) on airport operator Aena – the company had used facial recognition software without conducting a data protection impact assessment.

The results of our comparison

Due to the record-high fine imposed on Vodafone, the German authorities also recorded a massive increase in their total fines compared to other countries. This is only less than EUR 10 million below the AEPD's total and EUR 34 million above the fines reported by the GPDP to date.

Data breaches in Germany

In 2025, a total of 10,259 data breaches were reported to the German authorities – an increase compared to the previous year (8,623), but still less than half of the breaches reported in 2023 (24,749). However, this figure should also be understood as a lower limit, as statistics for the reporting year were not yet available from all supervisory authorities at the time of going to press.

As in the previous year, Hesse recorded the most breaches with 2,730, followed by Bavaria (1,500) and Berlin (1,460). In 2025, these were primarily related to misdirected documents and hacker attacks.

Security incidents

In 2025, there were several more security incidents with global implications. One of these was attributed to the “CL0P” group, which has been known for years and exploited a vulnerability in Oracle's E-Business Suite (EBS) in August 2025. The vulnerability affected several versions of EBS and allowed hackers to access the systems of a number of institutions and companies, including several universities and tech giants such as Logitech. Significantly, Oracle only released a patch for the problem after about two months.

In October, however, Amazon Web Services (AWS) cloud services were down worldwide for several hours. This was caused by a faulty DNS update in a data center, which resulted in over 4 million fault reports within two hours – the systems themselves recorded 17 million outages in 60 countries. After about three hours, most of the affected services were accessible again.

Back in March, hackers from the “Scattered Lapsus$ Hunters” group gained access to the GitHub repository of the Salesloft Drift application. In August, they then used their access to grab OAuth tokens from the application's AWS environment. They used these to break into the Salesforce instances of various globally known companies, steal data, and use it to blackmail their victims.

After the messaging app Discord incorporated age verification measures in response to legislative changes in the UK and Australia, the service provider 5CA, which was brought in for this purpose, promptly fell victim to a massive attack in October. The perpetrators stole photos of individuals, as well as their ID cards, which had been submitted for age verification. This affected 8.4 million support cases, triggered by 5.5 million individuals, including 70,000 verification documents. According to Discord's previous announcements, these should have been deleted immediately after the verification process was completed.

Court rulings

In 2025, European courts also published some noteworthy decisions. In March, the European Court of Justice (ECJ) ruled that national authorities are obliged to correct incorrect entries regarding gender identities if these are incorrect according to Art. 5 (1) (d) GDPR. The data subject may provide evidence of this; the authorities are not permitted to require gender reassignment surgery as a condition.

In September, the ECJ emphasized that pseudonymized data is not automatically personal data. The decisive factor is whether it is possible to identify the data subject on the basis of the available information. According to the ruling, the pseudonymized data remained personal data for the sender, as he had the additional information necessary to identify the data subjects. For the recipient of the data, it was no longer possible to re-identify the data subjects, so that, in the opinion of the ECJ, it was no longer personal data. The decisive factors are therefore the specific circumstances of the processing and what information is available to the individual parties involved.

In December, the Court finally published a decision on the responsibility of online marketplace operators for the content published by their users. A user of an online marketplace operated by Russmedia had published an illegal advertisement on it, offering sexual services on behalf of the plaintiff. Russmedia quickly deleted the advertisement, but it continued to spread on other platforms.

The ECJ held Russmedia partially responsible: operators are obliged to verify whether the identity of the poster matches that of the person allegedly advertising – and if this is not the case, it is up to the operator to ensure that the user has the permission of the person concerned. If this is not possible, the marketplace must refuse publication.

Outlook

Although the expected large fines and court rulings in the field of AI failed to materialize – there were isolated penalties, mainly in Italy (e.g., against Luka Inc. and Menarini Silicon Biosystems) – no landmark decisions were made. However, this could change in light of the investigation of X (formerly Twitter) announced by the Irish Data Protection Authority in February 2026 regarding the AI chatbot “Grok” integrated into the platform.

The upcoming EU-wide review of the implementation of information obligations by data protection authorities – or rather its results – is also noteworthy; especially in the area of fines, consequences are to be expected for companies that show deficiencies in this regard.

The “Digital Omnibus” continues to be discussed: Following the proposals for reforming the GDPR presented in November 2025, the European Data Protection Board published a strongly critical statement on the Commission's plans in February 2026. The issue will certainly continue to occupy us in 2026.

Tensions are also looming in the area of age verification: apps such as Discord are forging ahead following legislative changes in the UK and Australia and plan to implement similar measures for users from all other countries as well – even though there are no legal requirements to do so.

Overview by supervisory authority

This table includes the fines reported to us by the supervisory authorities. It will be updated accordingly as the authorities submit further information.

 

Supervisory authority Fines total Total in € Data breaches
Baden-Württemberg n.a. n.a. n.a.
Bavaria (non-public sector) n.a. n.a. n.a.
Bavaria (public sector) 0 0 1.500
Berlin 13 79.450 1.462
BfDI n.a. n.a. n.a.
Brandenburg 25 109.000 576
Bremen 101 75.077 259
Hamburg n.a. n.a. n.a.
Hesse 47 190.000 2.730
Mecklenburg-Vorpommern n.a. n.a. n.a.
Lower Saxony 34 705.000 n.a.
North Rhine-Westphalia n.a. n.a. n.a.
Rhineland-Palatinate 7 21.350 988
Saarland 9 13.233 911

Saxony (public sector)

Saxony (non-public sector)

8

n.a.

10.875

n.a.

1.058
Saxony-Anhalt n.a. 7.080 n.a.
Schleswig-Holstein 5 281.371,50 775
Thuringia n.a. n.a. n.a.
Total 249 1.412.986,50 10.259