Skip to content

What the data shows

The directory currently tracks 65 penalties totalling roughly $67.6B (excluding annulled cases) across 10 companies and 22 regulators. Amounts below use the USD approximation at the time of each decision. Annulled penalties are excluded from every total.

Total imposed by company

Meta
$23.9B
Apple
$17.8B
Google
$16.5B
Amazon
$3.8B
Microsoft
$2.8B
Didi
$1.2B
TikTok
$973.8M
Uber
$313M
X (Twitter)
$290M

By violation category

Antitrust
$21.1B
Deception
$18.1B
Dark patterns
$15.5B
Children
$14.1B
Tax
$14B
Privacy
$13.8B
Biometrics
$3.4B
Security
$1.5B
Content
$498M

Privacy and antitrust dominate. Nearly every major penalty reduces to one of three failures: collecting or using personal data without a valid legal basis, abusing platform dominance to disadvantage rivals, or deceiving consumers through dark patterns and hidden behaviour.

By year

2004
$537M
2006
$303M
2008
$929M
2012
$22.5M
2013
$606M
2016
$14B
2017
$2.6B
2018
$4.5B
2019
$5.2B
2020
$1.2B
2021
$3.1B
2022
$3.4B
2023
$2.8B
2024
$4.9B
2025
$9.4B
2026
$14.1B

The billion-euro era begins with the GDPR (2018) and the Digital Markets Act (2023 onward), and 2026 breaks the scale entirely: Meta’s settlement with 51 state attorneys general commits at least $12.1B over ten years, more than every European penalty in this directory combined. The single largest line remains the 2016 Apple tax recovery, which is a state-aid case rather than a fine; see the methodology.

By jurisdiction

European Union
$31.8B
United States
$26B
Ireland
$4B
France
$2.1B
Italy
$1.2B
China
$1.2B
Netherlands
$367M
Russia
$358M
India
$274M
South Korea
$192M
Brazil
$29.8M

The EU set the pace for a decade, and Ireland’s Data Protection Commission and the European Commission still account for most of the largest European penalties. But 2026 shifted the centre of gravity: US state attorneys general, acting together and at trial, now hold the two biggest child-safety awards on record.

The pattern beneath the numbers

Read as a security and identity practitioner rather than a headline-watcher, the record is remarkably consistent. The recurring root cause is not a single bad actor but a business model: personal data collected by default, a legal basis assembled after the fact, and consent flows engineered to produce a “yes.” The biometric settlements in Texas and Illinois, the GDPR transfer fines, and the cookie-consent penalties are variations on the same theme.

The second pattern is that fines rarely change behaviour on their own. Independent analyses estimate that the 2025 penalties across Apple, Alphabet, Meta, and Amazon amount to roughly a month of their combined free cash flow. Structural remedies, such as the DMA's conduct rules or forced unbundling, move the needle more than the euros do.

The 2026 child-safety cases are the clearest test of that reading so far. What Meta agreed to in the multistate settlement is not really the money: it is default two-hour time limits for minors, an overnight block, hidden like counts, age assurance with removal of under-13 accounts, and an independent auditor who reports to the attorneys general. New Mexico's judgment goes further and orders an under-13 prediction model and deletion of data already collected from children. Those are product mandates enforced by a court, which is a different instrument from a fine, and they arrive alongside an age assurance problem that every consumer platform now has to solve.

If you build or buy customer-identity and privacy systems, these cases are a checklist of what regulators now treat as unlawful by design. That is the throughline in the CIAM Compass and the cybersecurity research on guptadeepak.com.

Want the raw data? Every figure here comes from the public JSON dataset, or export a filtered CSV from the directory.