Cullen International’s new benchmark shows that data protection authorities in half of the 16 surveyed European countries imposed fines on big tech companies for either General Data Protection Regulation (GDPR) or e‑Privacy Directive (ePD) infringements since the entry into application of the GDPR in May 2018.

The benchmark shows that Luxembourg is the country with the highest sum of fines imposed with €746m, followed by Ireland and France.
Amazon, WhatsApp and Google are the big tech companies which incurred in the highest sum of fines at €781m, €225m and €155.7m respectively.
The benchmark also looks at whether, in the event of GDPR infringement in multiple EU member states, big tech companies benefitted from the cooperation and consistency mechanism introduced by the GDPR. The mechanism aims to achieve the consistent application of the GDPR throughout the EU.
For more information and access to the benchmark, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
26 January 26
The DNA explained: addressing fragmented national approaches to spectrum
Cullen International is issuing a series of analyses on different aspects of the Digital Networks Act (DNA) proposal. This report covers radio spectrum.
23 January 26
Analysis of how UK Cyber Security and Resilience Bill compares to EU NIS2
Our new report analyzes how the UK Cyber Security and Resilience Bill compares to the EU NIS2 DIrective. The UK bill proposes amendments to the existing UK NIS Regulations that would align the UK cybersecurity regime closer with the EU framework established under the NIS2.
22 January 26
Digital Networks Act (DNA) proposal: great ambitions, moderate means
An EU-level authorisation regime for satellite services, a new EU access product, a voluntary “conciliation process” on IP interconnection disputes and a focus on network resilience are among the main innovations proposed under the Digital Networks Act.