The Fines Are Not Landing Where You Think
The enforcement headlines are Meta. TikTok. Amazon. Billions in revenue, armies of compliance staff, and they still got it wrong.
That is the wrong frame.
The regulator does not ask about your headcount before opening an investigation.
According to DLA Piper's January 2026 survey, cumulative GDPR fines from May 2018 to January 2026 reached €7.1 billion. More than 60% of that total was issued after January 2023. The EDPB's 2026 Coordinated Enforcement Framework action focuses on transparency and information obligations under Articles 12, 13, and 14 GDPR, with 25 data protection authorities participating. Coordinated enforcement actions of this type increase the likelihood that transparency failures will be identified, escalated, and followed by targeted supervisory action.
GDPR applies to companies established in the EU, and to companies outside the EU that target individuals in the EU, offer them goods or services, or monitor their behaviour in the EU. If any of those conditions apply to your business, the regulation applies to you.
The Risk Framework: What Regulators Are Actually Looking For
Privacy enforcement in 2026 is not primarily about data breaches. Breaches trigger investigations, but the fines that follow are almost always about what was already wrong before the breach occurred.
Public enforcement data shows that three violation categories account for the overwhelming majority of GDPR fine value: unlawful legal basis for processing, non-compliance with general data processing principles, and insufficient security measures. International transfer cases are fewer in number but disproportionately high in penalty value.
Unlawful processing (Article 6). Insufficient legal basis for processing, weak or manipulative consent mechanisms, failure to establish lawful grounds. This is the single largest source of enforcement action. Analytics tools, advertising pixels, and CRM systems processing personal data without a documented legal basis are the most common exposure.
Non-compliance with general data processing principles (Article 5). Data minimisation failures, purpose limitation violations, retention of data beyond its original purpose. A company that collects more data than it needs, keeps it longer than necessary, or uses it for purposes not disclosed at collection is in this category. This is where the gap between privacy policy and actual practice becomes a fine.
Insufficient technical and organisational security measures (Article 32). Free Mobile and Free were fined a combined €42 million by the CNIL in 2026 after a breach affecting personal data linked to 24 million subscriber contracts. The enforcement issue was not merely that an attacker got in. The sanction focused on inadequate security measures and failures in notifying affected individuals.
International data transfers (Articles 44 to 49). EU user data transferred to non-adequate countries without a valid legal mechanism remains a high-impact enforcement area. TikTok's €530 million fine in 2025 and Meta's €1.2 billion fine in 2023 both fall here. For companies using US-based processors, the EU-US Data Privacy Framework provides a valid transfer mechanism for certified organisations. For non-certified US recipients, Standard Contractual Clauses or another approved tool are required.
Understanding which of these categories applies to your business is the starting point for everything else.
Five Things Growth-Stage Companies Get Wrong
1. Treating the Privacy Policy as the Compliance Programme
A privacy policy is a public commitment. It is not an internal control. A company can have a well-drafted privacy policy and still carry significant exposure because the policy describes how data should be handled, while the actual tech stack does something different.
Regulators check the gap between the two. In the United States, the FTC can act where a company makes privacy promises it does not keep. Under GDPR, the same gap constitutes unlawful processing. The FTC's position is explicit: if a company makes privacy promises, expressly or by implication, it must live up to those claims.
The compliance programme is the data map, the processing records, the legal basis documentation, the vendor agreements, and the internal policies. The privacy policy is the public face of that programme. In early-stage companies, the public face exists. The programme behind it often does not.
2. Assuming Small Companies Are Not Targets
This assumption is wrong and it is expensive.
Spain remains far ahead in Europe by number of published GDPR fines, followed by Italy and Romania. Those countries do not necessarily impose the highest average fines, but their enforcement pattern shows why smaller and mid-market companies should not assume GDPR enforcement is only a Big Tech issue.
The practical exposure for a growth-stage SaaS company is not a €500 million headline fine. It is a €50,000 penalty from a national DPA following a customer complaint, combined with a remediation order and the operational disruption that follows. For a company at seed or Series A, that combination is a serious business event.
3. Ignoring the US State Law Patchwork
Around twenty US states have now enacted comprehensive privacy laws, each with different effective dates, thresholds, rights regimes, and enforcement models. California's CPRA is the most demanding, but Virginia, Colorado, Connecticut, Texas, and others impose their own requirements. California has a private right of action for data breaches, with statutory damages currently adjusted to $107 to $799 per consumer per incident, or actual damages if greater.
For an Israeli or European SaaS company with US users, this patchwork creates real exposure that sits completely outside GDPR. The companies most at risk are those that invested in GDPR compliance and assumed that covered their US obligations. It does not.
Related reading: The US Privacy Minefield
4. Separating Privacy from Product Architecture
The companies with the largest enforcement exposure are almost never the ones that ignored privacy entirely. They are the ones that added a privacy layer on top of a product that was not built with privacy in mind.
This creates a structural problem. The product collects data the policy does not disclose. The retention timeline in the policy does not match what the database actually does. Third-party integrations were never mapped into the processing records. The consent flow was designed for conversion, not for compliance.
Retrofitting privacy into existing architecture is always more expensive than building it in from the start. It is also more visible to regulators, because the gap between stated practice and actual practice is wider.
Related reading: Data Protection: The Key to Startup Success in Global Markets
5. Missing the Vendor Risk
Most growth-stage companies process a significant portion of their users' personal data through third-party tools: analytics platforms, CRM systems, marketing automation, customer support software, payment processors.
Many of those vendors will be processors under GDPR. Some may be independent controllers or joint controllers. The first step is classification. Where a vendor processes personal data on your behalf, Article 28 requires a Data Processing Agreement. Where subprocessors are used, the compliance chain extends further.
This issue surfaces in fundraising due diligence more than most founders expect. The company believed its privacy position was clean. The data room review found vendor relationships without DPAs, and the process slowed while the gap was addressed.
How J.A. Consulting Works on This
Privacy work at J.A. Consulting covers three areas, depending on where the company sits.
Framework builds for market entry. For companies entering the EU market or bringing their privacy posture into line with GDPR, this covers data mapping and classification, legal basis documentation, privacy policy and terms of use aligned with actual data practices, DPA execution with key vendors, and internal policies. The output is a privacy framework that functions operationally, not one that exists only in documents.
Israeli law and cross-border alignment. For Israeli companies dealing with Amendment 13 obligations or managing dual compliance across Israeli and EU frameworks, this covers the gap analysis between the two regimes, the practical changes required, and how to structure a single programme that covers both without running two parallel compliance efforts.
US privacy mapping. For companies with US users or US market ambitions, this covers the state law landscape, the FTC enforcement exposure, California-specific requirements under CCPA and CPRA, and how to structure a privacy policy that accurately reflects actual data practices.
For most companies at the consideration stage, the right entry point is understanding which of these three areas is the immediate priority.
Related reading: How to Prepare Legal Due Diligence Documentation
Most of my clients come to me after a close call. A few come before one. The second group sleeps better.
The EDPB's 2026 coordinated enforcement action on transparency is running now. Transparency failures identified during coordinated actions tend to attract targeted supervisory follow-up. For a company without a functioning privacy programme, that is not a comfortable position.
Thirty minutes is enough to understand where the real risk may sit. This is general information only. A call is required to assess your company's specific position.