Is GDPR Shifting Focus to Personal Liability in Data Protection?

In 2024, the General Data Protection Regulation (GDPR) fines issued across Europe amounted to €1.2 billion ($1.26 billion), marking a 33% decrease compared to €2.9 billion ($3.1 billion) in 2023, and this significant reduction represents the first annual decline since GDPR’s inception in May 2018. This decrease is mainly due to the absence of a single large fine such as the €1.2 billion penalty imposed on Meta in May 2023 for transferring personal data to the US using standard contractual clauses (SCCs). However, experts caution that this reduction does not indicate a decline in data protection enforcement in the EU.

Rigorous Focus on Data Protection Enforcement

Despite the lower fines in 2024, the focus on data protection enforcement remains rigorous. Ross McKean, Partner and Chair of DLA Piper’s UK Data Protection and Cyber Practice, highlighted that the reduced figures should not be misinterpreted as a downturn in regulatory activity. McKean emphasized that European data regulators continue to strictly enforce data protection laws.

The Irish Data Protection Commission (DPC) continues to lead in enforcement, with a cumulative total of €3.5 billion ($3.7 billion) in fines since 2018, significantly surpassing the Luxembourg Data Protection Authority, the next highest regulator. This underscores the robust enforcement landscape within Europe, contributing to the overall total of €5.88 billion ($6.17 billion) in reported fines since GDPR took effect.

Major Fines Targeting Big Tech

In 2024, big tech and social media companies remained major targets for substantial fines. Notable penalties included a €310 million ($326 million) fine by the Irish DPC against LinkedIn in October for its handling of personal data in advertising practices. Additionally, the Dutch Data Protection Authority (AP) imposed a €290 million ($324 million) fine on Uber in August for storing driver data in the US without adequate safeguards. Meta faced another significant penalty with a €251 million ($263 million) fine by the Irish DPC in December for a data breach affecting around 29 million Facebook accounts in 2018.

Moreover, enforcement actions extended into other sectors such as financial services and energy. An example of this broader reach includes the Spanish Data Protection Authority issuing two fines totaling €6.2 million ($6.5 million) against CaixaBank for failing to implement robust security measures.

Emerging Trend: Personal Liability

A noteworthy emerging trend in 2024 is the shift towards personal liability in data protection enforcement actions. This is best exemplified by the Dutch Data Protection Commission investigating the possibility of holding the directors of Clearview AI personally liable for multiple GDPR breaches, following a €30.5 million ($32.03 million) fine against the company. McKean observed that 2024 marked the beginning of significant focus on individual accountability, with projections for 2025 indicating even greater attention on personal liability and public naming to foster compliance.

Persistent Emphasis on Data Protection

In 2024, the total General Data Protection Regulation (GDPR) fines levied across Europe amounted to €1.2 billion ($1.26 billion). This figure represents a significant 33% decline from the €2.9 billion ($3.1 billion) amassed in fines in 2023. Notably, this drop marks the first annual decrease since GDPR’s implementation in May 2018. The primary reason for this decline is the absence of any single large fine, like the massive €1.2 billion penalty imposed on Meta in May 2023 for transferring personal data to the United States using standard contractual clauses (SCCs). While this reduction in fines may seem like a relaxation of data protection enforcement within the European Union, experts emphasize that this is not the case. Authorities remain vigilant and committed to safeguarding personal data. The year 2023 was exceptional with the Meta fine skewing the numbers, hence 2024’s lower total shouldn’t be interpreted as a sign of diminishing regulatory rigor or enforcement efforts by the EU regarding data protection regulations.

Explore more

Can Brand-First Marketing Drive B2B Leads?

In the highly competitive and often formulaic world of B2B technology marketing, the prevailing wisdom has long been to prioritize lead generation and data-driven metrics over the seemingly less tangible goal of brand building. This approach, however, often results in a sea of sameness, where companies struggle to differentiate themselves beyond feature lists and pricing tables. But a recent campaign

How Did HR’s Watchdog Lose a $11.5M Bias Case?

The very institution that champions ethical workplace practices and certifies human resources professionals across the globe has found itself on the losing end of a staggering multi-million dollar discrimination lawsuit. A Colorado jury’s decision to award $11.5 million against the Society for Human Resource Management (SHRM) in a racial bias and retaliation case has created a profound sense of cognitive

Can Corporate DEI Survive Its Legal Reckoning?

With the legal landscape for diversity initiatives shifting dramatically, we sat down with Ling-yi Tsai, our HRTech expert with decades of experience helping organizations navigate change. In the wake of Florida’s lawsuit against Starbucks, which accuses the company of implementing illegal race-based policies, we explored the new fault lines in corporate DEI. Our conversation delves into the specific programs facing

AI-Powered SEO Planning – Review

The disjointed chaos of managing keyword spreadsheets, competitor research documents, and scattered content ideas is rapidly becoming a relic of digital marketing’s past. The adoption of AI in SEO Planning represents a significant advancement in the digital marketing sector, moving teams away from fragmented workflows and toward integrated, intelligent strategy execution. This review will explore the evolution of this technology,

How Are Robots Becoming More Human-Centric?

The familiar narrative of robotics has long been dominated by visions of autonomous machines performing repetitive tasks with cold efficiency, but a profound transformation is quietly reshaping this landscape from the factory floor to the research lab. A new generation of robotics is emerging, designed not merely to replace human labor but to augment it, collaborate with it, and even