For the first few years, plenty of organisations treated GDPR as a compliance formality - a banner on the website, a policy in a drawer, and a quiet hope that regulators were too busy to look. That grace period is over. Enforcement has matured, fines have grown, and - crucially for planning - the patterns behind them are consistent enough to learn from.
This is not legal advice, and every jurisdiction has its nuances. But across the enforcement actions we have studied, the same handful of causes come up again and again. Here is where the penalties actually land, and what to do about each.
Pattern 1: No valid legal basis for the processing
A large share of significant fines come down to a simple failure: the organisation could not point to a lawful reason for what it was doing with people's data. Consent that was bundled, pre-ticked, or effectively impossible to refuse is treated as no consent at all. "Legitimate interests" claimed without ever doing the balancing assessment falls apart under scrutiny.
For every category of personal data you process, be able to state the specific lawful basis in one sentence - and have the record that backs it. If your basis is consent, make sure it is freely given, specific, and as easy to withdraw as to give. If it is legitimate interests, write down the balancing test before you need it.
Pattern 2: Security failures that enabled a breach
GDPR requires "appropriate technical and organisational measures", and regulators have shown they will judge, after the fact, whether your measures were appropriate. The recurring failures are unglamorous: unencrypted data, credentials with far too much access, unpatched systems, and no meaningful monitoring. When a breach follows one of these, the regulator's view is that it was foreseeable and preventable.
Regulators rarely fine you for being unlucky. They fine you for being careless in a way that made the harm predictable.
The overlap with ordinary security hygiene is almost total. Encryption, least-privilege access, patching, and logging are the same controls that protect you operationally - they simply also happen to be what "appropriate measures" looks like in practice.
Pattern 3: Botched breach notification
This is the one that catches organisations out most often, and it is entirely self-inflicted. GDPR generally requires notifying the regulator of a qualifying breach without undue delay and, where feasible, within 72 hours. A striking number of penalties are driven less by the breach itself than by what came after: notifying late, not at all, or telling regulators and affected people a reassuring story that later proved false.
The 72-hour clock starts when you become aware, not when you have finished investigating. Organisations that wait until they "know everything" before notifying routinely miss the deadline. You are expected to notify with what you know and update as you learn more.
The practical defence is to decide your notification process before an incident, not during one: who assesses whether a breach is notifiable, who drafts the notification, who approves it, and how you hit a 72-hour deadline while you are still in the middle of responding.
Pattern 4: Keeping data you never needed
Every record you hold is both an asset and a liability, and for old data the balance is usually all liability. Regulators have penalised organisations for retaining personal data with no defined purpose or retention limit - data that added no value but sat there waiting to be stolen and then to feature in a fine.
Set and enforce retention periods. Delete or properly anonymise data once its purpose is served. Data minimisation is the rare privacy control that reduces cost, reduces breach impact, and reduces regulatory exposure all at once - the data you do not hold cannot be breached and cannot be fined.
Pattern 5: No demonstrable accountability
GDPR does not only ask you to be compliant - it asks you to show it. When something goes wrong, the organisations that fare best are the ones that can produce records: their processing inventory, their assessments, their decision logs, evidence that they took privacy seriously as an ongoing practice. Those that can only offer good intentions tend to be treated as though they had none.
In the eyes of a regulator, a decision you cannot evidence is a decision you did not make.
The realistic path forward
None of this requires turning your organisation into a law firm. The organisations that stay off the enforcement list tend to do a small number of things consistently:
- Know what personal data they hold, why, and under what lawful basis.
- Apply the same security hygiene regulators consider "appropriate" - encryption, least privilege, patching, monitoring.
- Have a breach-response process that can actually meet a 72-hour deadline.
- Delete what they no longer need.
- Keep enough records to demonstrate all of the above.
Six years of enforcement have made the risks legible. The fines cluster around predictable, avoidable failures - and most of the fixes are things a well-run security and privacy programme would do anyway. Treat privacy as an operational discipline rather than a document, and you are most of the way there.
If you want to turn compliance obligations into a pragmatic, defensible programme - without the box-ticking - that is exactly what our data privacy practice helps organisations do.