Who Actually Punished Big Tech in 2026? What the Tech Fines Tracker Shows
The 2026 Big Tech enforcement record in one place: four penalties worth about $14.1B, led by US states rather than Brussels, and dominated by children's safety. Here is what the Tech Fines tracker shows and how to follow it.

Four authorities penalised Big Tech in 2026, according to the Tech Fines 2026 record, for a combined floor of about $14.1 billion. Three of those four cases were about children. The largest came not from Brussels but from 51 US state and territory attorneys general acting together.
Verified as of 26 September 2026 against the sources linked inline.
That is a different picture from the one most people carry around. For a decade, "Big Tech fine" meant a European privacy or antitrust decision. The 2026 record says the centre of gravity has moved, and the subject matter has moved with it.
What is happening
Four decisions define the year so far. Each one came from a different kind of authority, in a different country, under a different law.
23 July, Brussels. The European Commission fined Google 890 million euros under the Digital Markets Act. The Digital Markets Act (DMA) is the EU law that sets conduct rules for the largest "gatekeeper" platforms. The fine splits into 460 million euros for favouring Google's own results in Search and 430 million euros for blocking Play Store developers from steering users to cheaper offers.
6 August, Santa Fe. A New Mexico court entered final judgment against Meta for $942 million. A jury had already awarded $375 million in civil penalties in March, and the judge added $567 million in remedies. New Mexico became the first US state to beat a major technology company at trial over harm to young people. Meta has said it will appeal.
25 August, Brasília. Brazil's data protection authority, the ANPD, fined ByteDance, TikTok's owner, BRL 153.7 million. The regulator found TikTok processed children's and teenagers' data without a valid legal basis. That covered both registered accounts and visitors browsing without an account.
26 August, nationwide. Meta settled with 51 state and territory attorneys general for a guaranteed $12.1 billion over ten years. The figure rises to $17.1 billion if other major social platforms adopt comparable safeguards. The California Attorney General's announcement lists the product changes, including a default two-hour daily limit and an overnight block for users under 18.
Courts also reshaped older fines this year. On 2 July, the EU Court of Justice dismissed Google's final appeal in the Android case, making the 4.125 billion euro fine from 2018 definitive. On 12 March, Luxembourg's Administrative Court annulled Amazon's 746 million euro GDPR fine and sent it back to the regulator, while confirming the underlying breaches.
Why it matters to you
If you work in privacy or compliance, enforcement is your best guide to what regulators actually care about. Guidance documents tell you what is allowed. Penalties tell you what gets punished, by whom, and how hard.
The 2026 record sends three plain signals.
- Children's data and teen safety are now the lead enforcement theme. If your product has any users under 18, knowing who they are is no longer optional.
- The enforcer you need to watch may be a US state, not a federal agency. State attorneys general and state courts produced the two biggest 2026 actions.
- Money is only part of the penalty. The Meta and TikTok decisions came with product mandates, deletion orders and, in Meta's settlement, an independent auditor.
How large are these fines for the companies themselves? Alphabet reported 2025 revenue of $402.8 billion. The DMA fine, about $1.03 billion, is roughly 0.26 percent of that. That is less than one day of Alphabet's 2025 revenue.
Meta reported 2025 revenue of $201.0 billion. Its two 2026 penalties add up to about $13.0 billion at the guaranteed floor. That equals roughly 6.5 percent of one year of revenue, or about 24 days of sales.
ByteDance is private and does not publish audited revenue, so no fair ratio exists for the TikTok fine. What the Brazil case shows instead is reach: a regulator outside the EU and US imposing its largest penalty to date on a global platform.
If you are a consumer, the record matters for a simpler reason. The changes you will actually notice, such as teen time limits, stricter default privacy for under-16 accounts and age checks, came out of these cases, not out of product roadmaps. I looked at what those fines mean for your own privacy in Billions in Fines, Barely a Bruise, so this post stays on the record itself.
What the Tech Fines tracker shows
Tech Fines is a free directory of major penalties against large technology companies. It covers 65 penalties across 10 companies and 22 regulators and courts, from 2004 to today. Each entry records the amount in its original currency, the regulator, the law, what happened, how it affected users and its current appeal status.
How every entry is sourced
The directory has one hard rule. Every entry must cite at least one source that is a regulator or a court. A news article alone fails the build.
The only exception is a written note explaining why no primary link exists. That note appears on the entry page for readers to see. Exactly one of the 65 entries uses it, and none of the 2026 entries do.
Two more rules shape the numbers. Amounts are kept in the currency the regulator announced, with a USD approximation used only for sorting and totals. Annulled fines stay visible but are excluded from every total, because nothing is owed. The methodology page explains each policy.
The totals also respect conditional amounts. Meta's settlement is shown at its $17.1 billion headline, but only the guaranteed $12.1 billion counts toward totals. That is why the 2026 total is $14.1 billion rather than $19.1 billion.
A short personal note on why this exists. I founded LoginRadius in 2013 and scaled it past a billion identities, so consent, age and data handling were daily engineering problems. Nearly every entry in this directory is a privacy or identity decision that ended with a price tag.
The 2026 record at a glance
| Authority | Company | Conduct | Announced amount | Counted in totals (USD) | Status |
|---|---|---|---|---|---|
| US State Attorneys General (51) | Meta | Children's safety, deception, dark patterns | $12.1B to $17.1B | $12.1B | Final |
| European Commission | Antitrust (DMA), deception | EUR 890M | $1.03B | Under appeal | |
| New Mexico First Judicial District Court | Meta | Children's safety, deception | $942M | $942M | Under appeal |
| Brazil ANPD | ByteDance (TikTok) | Privacy, children's safety | BRL 153.7M | $29.8M | Final in tracker |
| Total | 3 companies | about $14.1B |
Finding 1: children's safety took over the year
Three of the four 2026 entries carry the children's safety category. Together they account for about $13.07 billion, or roughly 93 percent of the year's total.
Privacy in the classic sense barely appears. Only the Brazil decision is tagged privacy, and it is also a children's case. No 2026 entry involves biometrics. The most recent biometric case in the tracker is Google's $1.375 billion Texas settlement from May 2025.
The common thread is age. Meta's settlement requires age assurance and removal of users under 13. New Mexico's judgment orders an under-13 prediction model. Brazil ordered stricter defaults for under-16 accounts that only a guardian can change. I wrote about why that makes age assurance an identity problem in Meta's $17B settlement is really an age assurance mandate.
Finding 2: US states, not Brussels, set the record
About 92 percent of 2026's counted total came from US state action. The US State Attorneys General and one New Mexico trial court produced about $13.04 billion between them. The European Commission produced about $1.03 billion.
That reverses the usual pattern. Across all years in the tracker, the EU still leads at about $31.8 billion against $26 billion for the United States. One settlement in 2026 closed most of that gap.
The European Commission is still the most active single enforcer in the directory, with 16 of the 65 entries. Its 2026 role was different, though. The Google decision is an ex ante conduct case under the DMA, meaning rules written in advance for gatekeepers. It is not a traditional after-the-fact antitrust investigation.
Finding 3: fewer penalties, bigger numbers, and courts in the middle
The tracker records nine penalties in 2025, worth about $9.4 billion. It records four so far in 2026, worth about $14.1 billion. Fewer actions produced a larger total, almost entirely because of one settlement.
Courts mattered as much as regulators this year. Two of the four 2026 penalties, Google's DMA fine and New Mexico's judgment, are under appeal. Meanwhile the Android ruling confirmed an eight-year-old fine. The Luxembourg ruling erased another, while confirming the breaches behind it. A headline number and the final number are often not the same figure.
How to use it
You can follow enforcement in a few minutes a month. Here is the order that works best.
- Start with the year. Open the 2026 year page for every penalty announced this year, largest first, with status badges.
- Pick the enforcer that governs you. Each regulator page lists every action by that authority. If you sell into the EU, watch the European Commission. If you run a consumer app in the US, watch the state attorneys general.
- Filter by conduct. Category pages group cases by what the company did: privacy, antitrust, children's safety, biometrics, dark patterns and more. Use the one closest to your own risk.
- Check the company. The Meta company page shows a repeat pattern across years. Company pages are useful when a vendor or partner is in the dataset.
- Open the entry and read the status timeline. For example, the New Mexico entry shows the jury award, the added remedies and the appeal notice as separate dated events.
- Click through to the primary source. Every entry links the regulator's or court's own document. Cite that, not the tracker, in anything formal.
- Subscribe to changes. New penalties and status changes are logged in the changelog and the RSS feed.
What to do next
Use the 2026 record as a checklist for your own product and vendors this quarter.
- Find out whether any of your users are under 18, and how you would know. If the answer is "self-declared birthday", treat that as a gap.
- Review default settings for minors. The 2026 cases set the bar at restrictive defaults that only a guardian can loosen.
- Check guest or logged-out data collection. Brazil fined TikTok for profiling visitors who never created an account.
- Add your US state attorneys general to your regulatory watch list, not just the FTC.
- If you are an EU gatekeeper's customer or developer, read the Google DMA entry for the steering rules that now apply to app stores.
- Track appeals before quoting numbers. Record the status alongside the figure in any board or risk report.
Frequently Asked Questions
Which regulators fined Big Tech in 2026?
In the Tech Fines tracker, four authorities did: the European Commission (Google), a coalition of 51 US state and territory attorneys general (Meta), the New Mexico First Judicial District Court (Meta), and Brazil's ANPD (ByteDance, TikTok's owner).
What was the biggest tech fine of 2026?
Meta's settlement with 51 attorneys general is the largest, at a guaranteed $12.1 billion over ten years. It rises to $17.1 billion if other major social platforms adopt the same safeguards. The tracker counts only the $12.1 billion floor in its totals.
How much did Big Tech pay in fines in 2026?
The tracker records about $14.1 billion across four penalties, counting guaranteed amounts only. Two of those penalties, worth about $1.97 billion together, are under appeal, so the amount finally paid may change.
Why are so many 2026 tech fines about children?
Three of the four 2026 cases concern minors: how platforms were designed for teenagers, what they said publicly about safety, and whether they collected children's data lawfully. The remedies focus on age assurance, restrictive defaults and deleting children's data.
How does the Tech Fines tracker verify its data?
Every entry must link at least one regulator or court source, and news-only sourcing fails the build. Amounts stay in their original currency, annulled fines are excluded from totals, and each entry shows a last-verified date and a status timeline.
More like this
All Scams & Cybersecurity- Scams & CybersecurityAge Assurance: The Compliance Architecture, Not the Vendor ListPicking an age verification vendor is the last decision, not the first. The duty you are actually under, the methods ladder, the one-bit…
- Scams & CybersecurityWhen the Data Breach Alarm Fails: A Global Guide to Who Should Tell You and How to Protect YourselfYour data is constantly at risk, but who's required to tell you when it's compromised?
- Identity & CIAMMeta's $17B Settlement Is Really an Age Assurance MandateMeta's settlement with 51 attorneys general commits at least $12.1 billion, but the money is the survivable part. Every teen safety term…
Get new Scams & Cybersecurity writing
Enjoyed this? Subscribe and tell us what you read most. Scams & Cybersecurity is already ticked for you. No tracking pixels, unsubscribe with one click.