Five fines dominate 2026’s GDPR enforcement record so far, ranked by size: a combined €42 million penalty against two French telecom brands, a £14.47 million children’s privacy fine against Reddit, a €5 million health data fine against IQVIA, a €1.7 million breach fine against Italian telecom Wind Tre, and a £963,900 fine against a UK water utility. Together they cover four regulators, three countries, and violations ranging from weak VPN authentication to missing age checks.
This list covers fines actually issued between January and early August 2026, ranked by amount. It excludes older fines that were merely upheld or annulled on appeal during 2026, such as Criteo’s 2023 fine or the reversed Amazon and OpenAI decisions, since those weren’t new enforcement actions.
| Rank | Unternehmen | Fine | Regulator | Date | Main violation |
|---|---|---|---|---|---|
| 1 | Free Mobile & Free | €42 million (€27M + €15M) | CNIL (France) | 13 January 2026 | Inadequate security (Article 32), incomplete breach notice (Article 34), excessive retention (Article 5(1)(e)) |
| 2 | Reddit, Inc. | £14,472,500 | ICO (UK) | 23 February 2026 | No lawful basis for under-13 data, no DPIA (Articles 6, 8, 35) |
| 3 | IQVIA Operations France | €5 million | CNIL (France) | 28 May 2026 | Health data warehouses inadequately secured; pseudonymised data wrongly treated as anonymised |
| 4 | Wind Tre | €1,715,600 | Garante (Italy) | July 2026 | Data breaches via social engineering; payment data exposed |
| 5 | South Staffordshire Water | £963,900 | ICO (UK) | 7 May 2026 | Ransomware breach undetected for 20 months (Articles 5(1)(f), 32(1)) |
• The largest 2026 GDPR fine so far is the combined €42 million penalty CNIL issued against Free Mobile and Free on 13 January 2026, following a 2024 breach that exposed 24 million subscriber records including IBANs.
• Reddit’s £14.47 million fine from the UK ICO shows that children’s data enforcement, specifically the lack of age assurance and a missing Article 35 DPIA, is now a live regulatory priority backed by an eight-figure penalty.
• IQVIA’s €5 million fine confirms that pseudonymised data still falls under GDPR in full. The CNIL rejected IQVIA’s claim that its health data warehouses were anonymised, since re-identification remained possible with additional information.
• Basic security failures, weak authentication, ineffective anomaly detection, and unpatched entry points for social engineering appear in three of the five cases and remain the most common trigger for GDPR enforcement.
• UK GDPR fines from the ICO sit alongside EU GDPR fines from CNIL and the Garante on this list, since the UK GDPR mirrors the EU regulation and the ICO enforces it using the same fine tiers and legal tests.
The biggest GDPR fine of 2026 is the combined €42 million penalty CNIL issued against Free Mobile and Free on 13 January 2026: €27 million against Free Mobile and €15 million against Free, its sister brand.
The fine followed an October 2024 breach in which an attacker infiltrated the companies’ systems and accessed data tied to 24 million subscriber contracts, including IBANs for customers of both brands. CNIL’s inspection found three separate GDPR breaches. Under Article 32, the VPN authentication procedure used for remote employee access fell short of the standard GDPR expects, and the companies’ systems for detecting abnormal activity were ineffective. Under Article 34, the breach notification email sent to affected customers omitted information the regulation requires, leaving people unable to understand the consequences or the steps they could take to protect themselves. Free Mobile alone was also found to have kept millions of former subscribers’ records without justification, breaching the storage limitation principle in Article 5(1)(e).
CNIL ordered both companies to complete security fixes already underway within three months and gave Free Mobile six months to finish sorting and deleting the excess data.
The UK’s Information Commissioner’s Office fined Reddit £14,472,500 on 23 February 2026 for processing children’s personal data without a lawful basis and without the required impact assessment.
The ICO’s penalty notice found Reddit breached Articles 5(1)(a), 6, 8, and 35 of the UK GDPR. Reddit had no effective age assurance mechanism in place, so it had no valid lawful basis for processing data belonging to users under 13. It also hadn’t completed a Data Protection Impact Assessment to identify and mitigate the risks children faced on the platform before January 2025. The ICO said the size of the fine reflected the number of children affected, the potential for harm, and how long the failings had continued. Reddit introduced age verification and self-declared age checks in July 2025, after the conduct under investigation.
This case is a direct illustration of why a Data Protection Impact Assessment isn’t optional paperwork: Reddit’s absence of one was cited as a standalone violation, separate from the lawful basis failure.
France’s CNIL fined IQVIA Operations France €5 million on 28 May 2026 for failing to secure two large health data warehouses that together held records on tens of millions of patients.
Neither warehouse had a process for regularly reviewing connection logs or detecting unusual activity. The EMR warehouse specifically lacked multi-factor authentication, gave patients an inaccurate information sheet, and had no working process for people to object to their data being processed. For the LRX warehouse, CNIL found that none of the four pharmacies it inspected had told customers their data was being transferred to IQVIA at all.
IQVIA’s central defence was that the warehoused data was anonymised and therefore outside GDPR’s scope. CNIL rejected that argument, ruling the data was pseudonymised and still re-identifiable using additional information held elsewhere. That distinction, covered in Article 4(5) and Recital 26 of GDPR, decided the entire case. Pseudonymised data stays inside GDPR’s full scope regardless of how difficult re-identification is made. IQVIA has six months to fix the remaining breaches or face a further €10,000 per day.
Italy’s Garante fined telecom operator Wind Tre €1,715,600 in July 2026 after two separate data breaches carried out through social engineering, where attackers posed as IT support staff to trick employees at Wind Tre retail stores.
The breaches exposed data belonging to more than 365,000 customers. Of those, 41,359 had payment details exposed, including IBANs, masked card numbers, and expiry dates. The Garante’s investigation followed a breach disclosure in February 2025 and found the company’s data security measures inadequate to prevent the kind of impersonation attack that led to the exposure. As part of the decision, Wind Tre was ordered to strengthen credential and certificate protections and to put better password management tools in place for staff.
The ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 on 7 May 2026 over a ransomware attack that went undetected inside the company’s network for 20 months.
The intrusion began with a phishing email in September 2020. An employee opened a malicious attachment, and the resulting malware sat undetected until May 2022, when the attacker, later linked to the Cl0p ransomware group, escalated to domain administrator privileges, the highest level of access on the network. The breach itself wasn’t detected until July 2022, when engineers investigating performance issues found it. Personal data belonging to roughly 633,887 people was exposed, including names, addresses, dates of birth, and, for customers, account credentials and bank details. The ICO found breaches of Article 5(1)(f) and Article 32(1) of the UK GDPR. The fine was reduced by 40% after the company cooperated with the investigation and admitted the failings early.
Three of the five cases, Free Mobile and Free, Wind Tre, and South Staffordshire Water, trace back to security fundamentals that failed: weak authentication, ineffective anomaly detection, or a phishing email that went unnoticed for 20 months. None of these attacks required particularly advanced techniques to succeed.
The other two cases show regulators pushing into areas that get less attention than security. Reddit’s fine confirms regulators now treat a missing DPIA as a standalone violation, carrying its own financial consequence separate from the lawful basis failure. IQVIA’s fine confirms that calling data “anonymised” doesn’t make it so; the CNIL tested that claim against the actual technical possibility of re-identification and rejected it.
For any organisation reviewing its own exposure, the fines point to the same starting questions: is multi-factor authentication actually enforced for remote access and sensitive systems, is there a working process for people to object to processing, and has every dataset labelled “anonymised” actually been tested against that standard rather than just described that way in a policy document?
The five biggest GDPR fines of 2026 span four regulators and cover breach notification failures, weak authentication, missing children’s data safeguards, and a mislabelled anonymisation claim. What connects them is less about any single dramatic failure and more about controls that should have been routine: multi-factor authentication, a completed DPIA before processing children’s data, and an honest technical assessment of whether “anonymised” data can actually be traced back to a person. Organisations that build these into recurring operational checks are the ones least likely to appear on next year’s list.
Need help assessing your organisation’s GDPR exposure? Our team can help. Contact us at info@gdprlocal.com.
The combined €42 million fine CNIL issued against Free Mobile and Free on 13 January 2026, following a 2024 data breach that exposed 24 million subscriber records including IBANs.
Yes. The UK GDPR mirrors the EU GDPR following Brexit, and the ICO enforces it using the same legal tests and a comparable fine structure. Reddit’s £14.47 million fine and South Staffordshire Water’s £963,900 fine were both issued under the UK GDPR.
Yes. Pseudonymised data remains personal data under GDPR because re-identification is still possible using additional information held separately. IQVIA’s €5 million fine turned on exactly this point: the CNIL ruled its health data warehouses held pseudonymised data, still re-identifiable and therefore inside GDPR’s scope, despite IQVIA’s anonymisation claim.
Based on this list, inadequate security measures under Article 32, weak authentication, ineffective breach detection, and unpatched exposure to phishing or social engineering are the most common triggers, appearing in three of the five largest cases.
Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.