Skip to content

Biggest Data Breach Fines: 70+ Penalties Over $500K (2026)

Osman Husain 7/30/26, 10:33 PM

Table of Contents

The largest data privacy fine ever is Facebook's $5 billion FTC penalty (2019) over the Cambridge Analytica scandal. The largest under GDPR is Meta's €1.2 billion ($1.3 billion) fine (2023) for unlawful data transfers to the U.S. In 2024 and 2025, Texas set new records with a $1.4 billion settlement from Meta and a $1.375 billion settlement from Google.

Enforcement in 2026 has shifted toward a steady wave of mid eight-figure fines, led by France's CNIL and Californian regulators.

Cumulative GDPR fines have passed €7.1 billion since 2018, and U.S. state privacy fines totalled an estimated $3.425 billion in 2025 alone, according to Gartner. Below are the biggest data breach fines and privacy violation penalties on record, each $500,000 or more, ranked by amount and updated for 2026.

Enzuzo's consent management platform helps mid-market teams avoid the consent and cookie failures behind many of these fines.

 

fines-5b-top-five

 

The biggest data breach fines, ranked high to low

1. Facebook: $5 billion (2019)

In the largest data privacy penalty in history, the FTC fined Facebook $5 billion in 2019 for deceiving users about their ability to control their personal information, in the wake of the Cambridge Analytica scandal.

2. Meta: $1.4 billion (2024)

Texas secured a $1.4 billion settlement from Meta over its unauthorized capture of biometric data (facial geometry) from photos and videos, in violation of the state's Capture or Use of Biometric Identifier Act.

3. Google: $1.375 billion (2025)

Finalized in October 2025, Texas secured a $1.375 billion settlement from Google over the unlawful tracking of users' geolocation, incognito browsing, and biometric data without consent, the second-largest privacy settlement on record.

4. Meta: $1.3 billion (2023)

As the largest GDPR fine ever, Ireland's Data Protection Commission fined Meta €1.2 billion (about $1.3 billion) in 2023 for continuing to transfer EU user data to the United States without adequate safeguards.

5. Didi Global: $1.2 billion (2022)

China's Cyberspace Administration fined ride-hailing giant Didi Global about $1.2 billion in 2022 for violating the country's data security and personal information protection laws.

6. Amazon: $886 million (2021)

Luxembourg's data protection authority fined Amazon €746 million (about $886 million) in 2021 over how it processed personal data for targeted advertising, the largest GDPR fine at the time.

7. Equifax: up to $700 million (2019)

Equifax agreed to pay at least $575 million, and potentially up to $700 million, in a settlement with the FTC, CFPB, and 50 states over its 2017 breach that exposed the data of 147 million people.

8. TikTok: $600 million (2025)

Ireland's Data Protection Commission fined TikTok €530 million (about $600 million) in 2025 for unlawfully transferring European user data to China and failing to guarantee it was protected from access by Chinese authorities.

9. Meta: $540 million (2025)

In November 2025, a Madrid commercial court ordered Meta to pay €479 million (about $540 million) to Spanish media publishers for using personal data for advertising without proper consent, a private unfair-competition judgment rather than a regulator fine.

10. Epic Games: $520 million (2022)

The FTC secured $520 million from Fortnite maker Epic Games in 2022, combining a COPPA penalty for collecting children's data without consent and a refund for dark-pattern billing practices.

11. T-Mobile: $500 million (2022)

T-Mobile agreed to a $500 million class-action settlement in 2022 over the cyberattack that exposed the data of about 76 million people.

12. Meta: $405 million (2022)

Ireland's DPC fined Meta €405 million (about $405 million) in 2022 after Instagram allowed teenagers' contact details and business-account email addresses to be exposed publicly.

13. Meta: $390 million (2023)

Ireland's DPC fined Meta €390 million (about $390 million) in 2023 for relying on an invalid legal basis to run personalized advertising on Facebook and Instagram.

14. TikTok: $390 million (2023)

Ireland's DPC fined TikTok €345 million (about $390 million) in 2023 over how it handled children's accounts, including default public settings and weak age verification.

15. LinkedIn: $336 million (2024)

Ireland's DPC fined LinkedIn €310 million (about $336 million) in 2024 over its handling of user data for targeted advertising and behavioral analysis.

16. Uber: $324 million (2024)

The Netherlands' data protection authority fined Uber €290 million (about $324 million) in 2024 for transferring European drivers' personal data to the United States without adequate protection.

17. Meta: $277 million (2022)

Ireland's DPC fined Meta €265 million (about $277 million) in 2022 after the data of 533 million users was scraped and published online.

18. Meta: $264 million (2024)

Ireland's DPC fined Meta €251 million (about $264 million) in 2024 over the 2018 breach in which attackers exploited a flaw to access around 29 million accounts.

fines-7d-meta-tally

19. WhatsApp: $255 million (2021)

Ireland's DPC fined WhatsApp €225 million (about $255 million) in 2021 for failing to properly tell users how it shared their data with parent company Meta.

20. Google: $225 million (2025)

France's CNIL fined Google LLC €200 million (about $225 million) in September 2025 as part of a €325 million decision covering ads inserted between Gmail messages and cookies dropped without consent.

21. Home Depot: $200+ million (2014-2020)

Across all settlements combining consumers, financial institutions, card networks, and states, Home Depot paid more than $200 million over its 2014 breach that exposed 56 million payment cards, including a $17.5 million multi-state settlement.

22. Capital One: $190 million (2021)

Capital One agreed to a $190 million class-action settlement in 2021 over its 2019 breach, which exposed the data of about 100 million people in the U.S.

23. SHEIN: $170 million (2025)

France's CNIL fined SHEIN operator Infinite Style €150 million (about $170 million) in 2025 for placing cookies on users' devices without valid consent.

24. Google: $170 million (2019)

Google and YouTube paid $170 million to the FTC and New York Attorney General in 2019 for collecting children's data without parental consent, in violation of COPPA.

25. Morgan Stanley: $155 million (2020-2022)

Across combined actions, Morgan Stanley paid about $155 million over its failure to properly wipe decommissioned hardware containing customer data, including a $60 million OCC penalty, a $35 million SEC penalty, and a $60 million class-action settlement.

26. Twitter: $150 million (2022)

Twitter paid $150 million to the FTC and DOJ in 2022 for using phone numbers and email addresses collected for security purposes to target advertising.

27. Uber: $148 million (2018)

Uber paid $148 million in a multi-state settlement in 2018 for concealing its 2016 breach, which exposed the data of 57 million riders and drivers.

28. Google Ireland: $141 million (2025)

France's CNIL fined Google Ireland €125 million (about $141 million) in September 2025, the second portion of the same €325 million decision covering unlawful cookies and Gmail advertising.

29. Anthem: $115 million (2018)

Health insurer Anthem reached a $115 million class-action settlement in 2018, the largest data-breach settlement at the time, over its 2015 breach affecting nearly 79 million people.

30. Meta: $102 million (2024)

Ireland's DPC fined Meta €91 million (about $102 million) in 2024 after it stored hundreds of millions of user passwords in plaintext.

31. Google: $101 million (2021)

France's CNIL fined Google LLC €90 million (about $101 million) in December 2021, part of a €150 million decision, for making it harder to refuse cookies than to accept them on YouTube and other sites.

32. Enel Energia: $89 million (2024)

Italy's Garante fined utility Enel Energia €79 million (about $89 million) in 2024 for using customer data for aggressive telemarketing without a valid legal basis.

33. Zoom: $85 million (2021)

Zoom agreed to an $85 million class-action settlement in 2021 over privacy and security lapses, including "zoombombing" and data-sharing practices.

34. T-Mobile USA: $80 million (2024)

The FCC fined T-Mobile $80 million in 2024 for selling customers' real-time location data without proper consent.

 

fines-7c-location-data

 

35. Capital One: $80 million (2020)

The Office of the Comptroller of the Currency fined Capital One $80 million in 2020 for security failures that led to its 2019 breach.

36. Google Ireland: $67 million (2021)

France's CNIL fined Google Ireland €60 million (about $67 million) in December 2021, the second portion of the €150 million cookie-consent decision.

37. Lehigh Valley Health Network: $65 million (2024)

Lehigh Valley Health Network reached a $65 million class-action settlement in 2024 after a ransomware attack led to the leak of patients' medical photos, including nude images.

38. AT&T: $57 million (2024)

The FCC fined AT&T about $57 million in 2024 for selling customers' location data without adequate safeguards.

39. Marriott International: $52 million (2024)

Marriott paid $52 million in a multi-state settlement in 2024 over the long-running Starwood breach that exposed the data of roughly 344 million guests.

40. Vodafone Germany: $51 million (2025)

Germany's federal data protection authority fined Vodafone Germany €45 million (about $51 million) in 2025 over security failings, including weaknesses exploited through its partner agencies.

41. Verizon: $47 million (2024)

The FCC fined Verizon about $47 million in 2024 for selling customers' location data without proper consent.

42. Anthem: $39.5 million (2020)

Anthem paid $39.5 million in a multi-state attorney-general settlement in 2020 over its 2015 breach, separate from the earlier class-action settlement.

43. Amazon France Logistique: $36 million (2023)

France's CNIL fined Amazon France Logistique €32 million (about $36 million) in 2023 for an excessively intrusive system that monitored warehouse workers' activity in fine detail.

44. Yahoo!: $35 million (2018)

The SEC fined Yahoo $35 million in 2018 for waiting two years to disclose its massive 2014 breach to investors, the first SEC penalty for failing to report a cyber incident.

45. Clearview AI: $34 million (2024)

The Netherlands' data protection authority fined Clearview AI €30.5 million (about $34 million) in 2024 for building an illegal database of billions of facial images scraped from the internet.

46. 23andMe: $30 million (2024)

23andMe agreed to a $30 million class-action settlement in 2024 over its 2023 breach, which exposed the genetic and personal data of nearly 7 million people (later revised upward in bankruptcy proceedings).

 

fines-7a-cookie-fines

 

47. Free Mobile: $29 million (2026)

France's CNIL fined Free Mobile €27 million (about $29 million) in January 2026 following an October 2024 breach that exposed the records of 24 million subscribers, including IBAN banking details.

48. AT&T: $25 million (2015)

The FCC fined AT&T $25 million in 2015 after call-center employees in three countries accessed the names and partial Social Security numbers of about 280,000 U.S. customers.

49. Google: $22.5 million (2012)

The FTC fined Google $22.5 million in 2012, then a record civil penalty, for bypassing privacy settings in Apple's Safari browser to place tracking cookies.

50. Uber: $20 million (2017)

The FTC secured $20 million from Uber in 2017 for misleading prospective drivers with exaggerated earnings claims and misrepresenting how it monitored access to personal data.

51. Reddit: $19.6 million (2026)

The UK's Information Commissioner's Office fined Reddit £14.47 million (about $19.6 million) in February 2026 for unlawfully processing the data of users under 13, with no effective age assurance and no children's data protection impact assessment.

52. Amadeus IT Group: $19.4 million (2026)

Spain's data protection agency issued a record €18 million (about $19.4 million) fine to travel-technology firm Amadeus in 2026 for reusing travelers' Passenger Name Record data in a profiling pilot without consent.

53. Target: $18.5 million (2017)

Target paid $18.5 million in a multi-state settlement in 2017 over its 2013 breach, which compromised the payment card data of about 41 million customers.

54. Capita: $18 million (2025)

The UK's ICO fined outsourcing firm Capita about £14 million (roughly $18 million) in 2025 over a 2023 ransomware attack that exposed the personal data of more than 6 million people.

55. Free (Iliad): $16 million (2026)

Alongside the Free Mobile penalty, France's CNIL fined parent company Free €15 million (about $16 million) in January 2026 for inadequate security and failure to notify customers over the same 2024 breach.

56. T-Mobile: $15.75 million (2024)

As part of a $31.5 million total settlement with the FCC in 2024, T-Mobile paid a $15.75 million civil penalty (with an equal amount committed to cybersecurity improvements) over a series of data breaches.

57. General Motors: $12.75 million (2026)

In 2026, a coalition of California authorities fined General Motors $12.75 million for selling OnStar drivers' geolocation and driving-behavior data to data brokers without consent, the largest CCPA penalty to date.

58. Disney: $10 million (2025)

A federal judge approved a $10 million FTC settlement with The Walt Disney Company in December 2025 for allowing the collection of children's data on YouTube without proper parental consent, in violation of COPPA.

fines-7b-childrens-privacy

59. Google: $8.25 million (2026)

An $8.25 million class-action settlement (A.B. v. Google LLC) was filed in January 2026 to resolve COPPA claims that Google's AdMob collected data from children under 13 through "Designed for Families" apps without parental consent, a private settlement rather than a regulator fine.

60. Luka Inc. (Replika): $5.8 million (2025)

Italy's Garante fined Luka Inc., maker of the Replika AI chatbot, €5 million (about $5.8 million) in 2025 for processing users' personal data without a valid legal basis and lacking effective age verification.

61. TikTok (Musical.ly): $5.7 million (2019)

The FTC fined Musical.ly, later merged into TikTok, $5.7 million in 2019, then a record COPPA penalty, for illegally collecting data from children.

62. IQVIA Operations France: $5.4 million (2026)

France's CNIL fined IQVIA Operations France €5 million (about $5.4 million) in May 2026, its first sanction against a health-data-warehouse operator, for failures in transparency and privacy-by-design obligations.

63. France Travail: $5.4 million (2026)

France's CNIL fined the public employment agency France Travail €5 million (about $5.4 million) in January 2026 after weak security enabled a social-engineering breach exposing decades of registrant data, including Social Security numbers.

64. ING Bank Śląski: $4.6 million (2025)

Poland's data protection authority fined ING Bank Śląski about PLN 18.4 million (roughly €4.3 million, or $4.6 million) in 2025 for unlawfully processing customers' identity-document data.

65. Acea Energia: $3.4 million (2025)

Italy's Garante fined utility Acea Energia €3 million (about $3.4 million) in 2025 over the unlawful handling of customer data in its energy operations.

66. The Walt Disney Company: $2.75 million (2026)

The California Attorney General announced a $2.75 million CCPA settlement with Disney in February 2026 for failing to honor consumers' opt-out of the sale and sharing of their data across all devices and services.

67. Zoetop (SHEIN/Romwe): $1.9 million (2022)

The New York Attorney General secured $1.9 million from Zoetop, owner of SHEIN and Romwe, in 2022 for concealing a 2018 breach that exposed the data of more than 39 million accounts.

68. Healthline: $1.55 million (2025)

California fined Healthline $1.55 million in 2025, the state's largest CCPA settlement at the time, for sharing consumers' health-related data without honoring opt-out signals.

69. South Staffordshire Water: $1.2 million (2026)

The UK's ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 (about $1.2 million) in May 2026 following a 2020 cyber-attack that exposed data on roughly 633,887 people.

70. Sephora: $1.2 million (2022)

California fined Sephora $1.2 million in 2022, its first public CCPA enforcement action, for selling consumer data without disclosure and failing to honor opt-out requests.

71. PlayOn Sports (GoFan): $1.1 million (2026)

The California Privacy Protection Agency fined PlayOn Sports, operator of the GoFan school-events platform, $1.1 million in March 2026 for tracking and selling student, parent, and school data without a valid opt-out, its first student-data enforcement action.

72. CafePress: $500,000 (2022)

The FTC secured $500,000 from CafePress in 2022 for covering up a data breach and failing to secure consumers' personal information.

 

fines-5c-trends

 

Key data break fines and enforcement trends for 2026

Eight themes define data privacy enforcement in 2026:

  1. Regulators traded warnings for record penalties. The two largest privacy penalties on record, Meta's $1.4 billion (Texas AG) and Google's $1.375 billion (Texas AG), both landed in 2024 and 2025, while cumulative GDPR fines have passed €7.1 billion.
  2. Children's privacy is the top enforcement target. From TikTok and Instagram to Reddit (ICO 2026), Epic Games, and Disney, regulators worldwide are prioritizing how platforms handle minors' data.
  3. Cookie consent is the most repeated offense. SHEIN's $170 million penalty (CNIL 2025) and a string of CNIL rulings against Google show invalid consent banners remain the fastest route to a fine.
  4. U.S. state privacy laws now have teeth. California's CCPA produced its largest fine yet against General Motors (IAPP 2026), and state privacy fines totaled an estimated $3.425 billion in 2025 (Gartner).
  5. Location data put telecoms in the crosshairs. The FCC's fines against T-Mobile, AT&T, and Verizon for selling location data (FCC) were upheld by the U.S. Supreme Court in June 2026.
  6. AI is the newest enforcement frontier. Clearview's facial-recognition database (Dutch DPA 2024), Replika's chatbot, and IQVIA's health-data warehouse all drew fines tied to how AI systems collect and use personal data.
  7. Breaches increasingly end in class actions, not just fines. T-Mobile's $500 million (settlement), Capital One's $190 million, Anthem, Zoom, and 23andMe show private litigation now rivals regulators as a financial risk.
  8. Europe still leads on enforcement volume. France's CNIL was the busiest regulator of 2025 and 2026, and EU authorities now receive 443 breach notifications per day, according to the DLA Piper GDPR Fines and Data Breach Survey (January 2026).

For mid-market teams, the pattern is clear: invalid consent, weak security, and mishandled cookies are the fastest routes to a regulator's attention. Enzuzo's consent management platform gives you compliant cookie consent, consent records, and Google Consent Mode v2 support in one place, so you can stay off lists like this one.

Book a call to see how Enzuzo keeps you protected from cookie consent fines, wiretapping laws, and CIPA fines

 

Data breach fines overview

Rank Company Fine (USD approx.) Year Regulator / Law
1 Facebook (Cambridge Analytica) $5 billion 2019 FTC
2 Meta (biometric data) $1.4 billion 2024 Texas / CUBI
3 Google (tracking + biometric) $1.375 billion 2025 Texas AG
4 Meta (data transfers) $1.3 billion 2023 GDPR (Ireland)
5 Didi Global $1.2 billion 2022 China / PIPL
6 Amazon $886 million 2021 GDPR (Luxembourg)
7 Equifax up to $700 million 2019 FTC / CFPB / states
8 TikTok $600 million 2025 GDPR (Ireland)
9 Meta (Spain, publisher suit) $540 million 2025 Madrid court (private)
10 Epic Games $520 million 2022 FTC / COPPA
11 T-Mobile $500 million 2022 Class action
12 Meta (Instagram, children) $405 million 2022 GDPR (Ireland)
13 Meta (personalized ads) $390 million 2023 GDPR (Ireland)
14 TikTok (children) $390 million 2023 GDPR (Ireland)
15 LinkedIn $336 million 2024 GDPR (Ireland)
16 Uber (driver data) $324 million 2024 GDPR (Netherlands)
17 Meta (533M scraping breach) $277 million 2022 GDPR (Ireland)
18 Meta (2018 breach) $264 million 2024 GDPR (Ireland)
19 WhatsApp $255 million 2021 GDPR (Ireland)
20 Google (Gmail ads) $225 million 2025 France / CNIL
21 Home Depot (combined settlements) $200+ million 2014-2020 Multi-state + private
22 Capital One $190 million 2021 Class action
23 SHEIN (cookie consent) $170 million 2025 France / CNIL
24 Google (YouTube, children) $170 million 2019 FTC / COPPA
25 Morgan Stanley (combined) $155 million 2020-2022 OCC + SEC + class action
26 Twitter $150 million 2022 FTC / DOJ
27 Uber (2016 breach) $148 million 2018 Multi-state
28 Google Ireland (cookies) $141 million 2025 France / CNIL
29 Anthem $115 million 2018 Class action
30 Meta (plaintext passwords) $102 million 2024 GDPR (Ireland)
31 Google (YouTube cookies) $101 million 2021 France / CNIL
32 Enel Energia $89 million 2024 GDPR (Italy)
33 Zoom $85 million 2021 Class action
34 T-Mobile USA (location data) $80 million 2024 FCC
35 Capital One $80 million 2020 OCC
36 Google Ireland (cookies) $67 million 2021 France / CNIL
37 Lehigh Valley Health Network $65 million 2024 Class action
38 AT&T (location data) $57 million 2024 FCC
39 Marriott International $52 million 2024 Multi-state
40 Vodafone Germany $51 million 2025 GDPR (Germany)
41 Verizon (location data) $47 million 2024 FCC
42 Anthem $39.5 million 2020 Multi-state
43 Amazon France Logistique $36 million 2023 GDPR (France)
44 Yahoo! $35 million 2018 SEC
45 Clearview AI $34 million 2024 GDPR (Netherlands)
46 23andMe $30 million 2024 Class action
47 Free Mobile $29 million (€27M) 2026 France / CNIL
48 AT&T $25 million 2015 FCC
49 Google $22.5 million 2012 FTC
50 Uber $20 million 2017 FTC
51 Reddit $19.6 million (£14.47M) 2026 ICO (UK)
52 Amadeus IT Group $19.4 million (€18M) 2026 Spain / AEPD
53 Target $18.5 million 2017 Multi-state
54 Capita (UK) $18 million 2025 ICO (UK)
55 Free (Iliad) $16 million (€15M) 2026 France / CNIL
56 T-Mobile (FCC settlement) $15.75 million 2024 FCC
57 General Motors $12.75 million 2026 California AG / CCPA
58 Disney (children's data) $10 million 2025 FTC / COPPA
59 Google (AdMob, class action) $8.25 million 2026 Class action (COPPA)
60 Luka Inc. (Replika) $5.8 million 2025 GDPR (Italy)
61 TikTok (Musical.ly) $5.7 million 2019 FTC / COPPA
62 IQVIA Operations France $5.4 million (€5M) 2026 France / CNIL
63 France Travail $5.4 million (€5M) 2026 France / CNIL
64 ING Bank Śląski (Poland) $4.6 million (€4.3M) 2025 GDPR (Poland)
65 Acea Energia (Italy) $3.4 million 2025 GDPR (Italy)
66 The Walt Disney Company $2.75 million 2026 California AG / CCPA
67 Zoetop (SHEIN/Romwe) $1.9 million 2022 New York AG
68 Healthline $1.55 million 2025 California / CCPA
69 South Staffordshire Water $1.2 million (£963,900) 2026 ICO (UK)
70 Sephora $1.2 million 2022 California / CCPA
71 PlayOn Sports (GoFan) $1.1 million 2026 California / CPPA
72 CafePress $500,000 2022 FTC

 

Frequently Asked Questions

What is the biggest data breach fine of all time?

The largest is Facebook's $5 billion penalty from the U.S. Federal Trade Commission in 2019, imposed after the Cambridge Analytica scandal, according to the FTC.

What is the biggest GDPR fine ever?

Meta holds the record with a €1.2 billion (about $1.3 billion) fine in 2023 from Ireland's Data Protection Commission for unlawfully transferring EU user data to the United States, according to the Irish Data Protection Commission.

What was the biggest privacy fine in 2025?

Texas secured a $1.375 billion settlement from Google, finalized in October 2025, over unlawful tracking of location and biometric data, the second-largest privacy settlement on record, according to the Texas Attorney General.

What are the biggest data privacy fines in 2026 so far?

The largest new action of early 2026 is France's CNIL fining Free Mobile €27 million (about $29 million) and sister company Free €15 million over a 2024 breach, according to the CNIL. Other notable 2026 fines include Reddit (£14.47 million, UK ICO) and General Motors ($12.75 million, California, the largest CCPA fine to date).

How much have companies been fined under GDPR in total?

Cumulative GDPR fines have surpassed €7.1 billion since the regulation took effect in 2018, with roughly €1.2 billion issued in 2025, according to the DLA Piper GDPR Fines and Data Breach Survey (January 2026).

How can a business avoid a cookie consent fine?

Many of the fines on this list, including SHEIN and multiple Google penalties in France, stem from invalid cookie consent. A compliant consent management platform captures and records user consent before non-essential cookies fire, which is the core requirement regulators enforce. Enzuzo's consent management platform handles this for GDPR, CCPA, and Google Consent Mode v2.

Protect your business from the next fine

The pattern across this list is clear: invalid consent, weak security, and mishandled cookies are the fastest routes to a regulator's attention. Enzuzo's consent management platform gives mid-market teams compliant cookie consent, consent records, and Google Consent Mode v2 support in one place. Start free with Enzuzo, no credit card required.

Osman Husain

Osman Husain

Osman is the content lead at Enzuzo. He has a background in data privacy management via a two-year role at ExpressVPN and extensive freelance work with cybersecurity and blockchain companies. Osman also holds an MBA from the Toronto Metropolitan University.