Number of personal data breaches in Europe increased by 22 per cent in 2025
DLA Piper’s annual GDPR report shows a 22 per cent increase over the past year, corresponding to an average of 443 reported incidents per day. This is the first time since 2018 that the daily average has exceeded 400, following several years of relative stability. At the same time, enforcement and sanction levels remain high. In 2025, Europe’s data protection authorities issued fines totalling approximately €1.2 billion, broadly in line with the previous year.
Anna Jussil Broms, Partner and Head of Intellectual Property and Technology at DLA Piper Sweden, comments:
“The continued rise in reported incidents demonstrates how rapidly the risk landscape is evolving. Against the backdrop of new regulations and tighter compliance requirements, many organisations need to work more systematically with governance, information security and resilience to address both regulatory and operational risks.”
Ireland continues to top the statistics, with cumulative fines of €4.04 billion since the GDPR came into force in May 2018. Despite another active year of supervision, the 2023 fine of €1.2 billion against Meta Platforms Ireland Limited remains the largest to date.
A new era of cyber threats is taking shape
Although the rise cannot be attributed to a single cause, the development must be viewed in the context of a year marked by geopolitical tensions, more advanced AI‑driven risk factors, and several major cyber incidents that caused significant operational disruption for global organisations.
The sharp increase in reported incidents indicates an elevated risk level and underscores the need to prioritise security and strengthen operational resilience. The Netherlands, Germany and Poland remain the countries reporting the highest number of personal data breaches over the period.
Gustav Lundin, Partner at DLA Piper Sweden, comments:
“The report confirms that cybersecurity issues are intensifying. For Swedish organisations, this means that both technical and organisational safeguards need to be reassessed to keep pace with the emerging risks and regulatory demands.”
€1.2 billion in GDPR fines – in line with 2024
Over the past year, GDPR fines in Europe amounted to approximately €1.2 billion, almost identical to the previous year. Even without an increase, the figure reflects continued high levels of regulatory activity rather than any easing. The sanction levels also show that supervisory authorities remain willing to impose significant financial penalties, despite criticism from stakeholders outside the EU. As in previous years, the largest fines continue to be concentrated in the technology and social media sectors, where nine of the ten highest GDPR fines issued to date have targeted companies in this industry.
A broader enforcement focus
While large technology companies continue to receive the most substantial fines, supervisory authorities are increasingly focusing on a wider range of sectors, including financial services, telecommunications, energy and technology providers. Moreover, while data transfers to the United States have been a central enforcement area for several years, 2025 marks the first time a major fine has been imposed in relation to a transfer to a third country outside the US. The Irish Data Protection Commission issued a €530 million fine against a media company for failing to ensure an essentially equivalent level of protection when transferring personal data to China. The case illustrates that the GDPR’s rules on international data transfers have global reach and extend far beyond the transatlantic context.