Two numbers have been circulating in privacy circles this year: cumulative GDPR fines have crossed €7.1 billion since the regulation took effect in 2018, and 20 US states now have their own comprehensive privacy law on the books, three of them brand new as of January 1, 2026.
Both numbers get cited a lot. Neither gets explained well. Here's what's actually behind them — and the one thing they have in common that determines whether your team is exposed or covered.
Since 2018, EU and UK regulators have issued more than 2,245 documented fines under GDPR, and the pace hasn't slowed — 2025 alone accounted for roughly €1.2 billion of that total, and over 60% of all fines to date have been issued since January 2023. Enforcement isn't just getting bigger. It's getting broader.
The headline cases from the last year make that shift obvious. Reddit was fined £14.5 million by the UK's ICO for insufficient age verification of minors. Free, the French telecom, was fined €15 million for security failures and poor breach communication after a customer data incident, and its parent company Free Mobile was separately fined €27 million for related security and retention failures affecting 24 million customer contracts. France Travail, the French public employment agency, was fined €5 million after weak access controls exposed job seekers' national insurance numbers and addresses going back 20 years.
Telecom. Government. Social media. None of these are the ad-tech giants that used to dominate the GDPR fine lists. Finance, healthcare, and public-sector organizations are all seeing more regulatory attention in 2026, and breach notifications are climbing alongside the fines — EU regulators are now receiving 443 breach notifications a day, a 22% year-over-year increase and the first time daily notifications have crossed 400 since GDPR came into force.
The pattern in the fine details is worth noticing too: a large share of recent enforcement isn't about a single dramatic violation. It's about the unglamorous stuff — access controls, retention policies, how (and how fast) an organization communicates with the people whose data it holds.
While GDPR enforcement was broadening, the US privacy landscape was quietly turning into 20 separate rulebooks.
Three states brought comprehensive privacy laws into effect on January 1, 2026: Indiana, Kentucky, and Rhode Island — bringing the national total to 20 states with their own version of consumer privacy rights. All three grant residents the right to access their data, correct inaccuracies, delete it (with some exceptions), and opt out of targeted advertising, data sales, and automated profiling.
But "similar" doesn't mean identical, and the differences are exactly the kind that trip up a manual process:
That's three states, three thresholds, and at least two different response clocks — and that's before layering in California's 45-day CCPA deadline, Colorado, Virginia, and the fifteen other states already on the books. A company operating nationally isn't tracking one deadline. It's tracking a spreadsheet's worth of them, each with its own trigger date, cure period, and penalty structure.
Strip away the jurisdiction and the currency, and GDPR's €7.1 billion and the US's 20-state patchwork are pointing at the same operational reality: the request is rarely the risk. The deadline is. That's the clock Article 15 sets for GDPR access requests, and every US state above runs its own version of the same deadline.
Nearly every fine above involves some version of "we didn't respond fast enough, securely enough, or completely enough" — not "we refused a request outright." Regulators aren't primarily punishing companies for saying no. They're punishing companies for not having a defensible process to say anything at all, on time, with a record to prove it.
That's true whether the clock is GDPR's 30 days, CCPA's 45 days, Rhode Island's 15-day consent window, or whatever the 21st state legislates next year. The number of days changes. The underlying failure mode — a request landing in a shared inbox, getting missed, and surfacing again three weeks later as a regulatory inquiry — doesn't.
A few practical takeaways, if you're the one who owns this:
For a plain-language breakdown of what actually triggers a DSAR, see What Actually Counts as a DSAR?. Plans for small teams start at $29/month.
None of this requires an enterprise privacy program. It requires knowing which deadline applies to which request, and not finding out you missed one from a regulator instead of a calendar reminder.
DSAR Lite tracks every access, deletion, rectification, and portability request in one queue, calculates the correct deadline by jurisdiction — GDPR, CCPA, or any of the twenty state laws now in effect — and keeps the record ready before anyone has to ask for it. Start a 14-day trial — no credit card required.
Sources: GDPR Fines Hit €7.1 Billion: Data Privacy Enforcement Trends in 2026 – Kiteworks · Biggest GDPR Fines of 2026 – Skillcast · 20 State Privacy Laws in Effect in 2026 – MultiState · 2026 State Privacy Laws: Indiana, Kentucky, Rhode Island – TrustArc