European GDPR authorities issued €225,879,175 in fines during Q2 2026—about €2.48 million per day and 230% more than Q1. The largest penalty was a €100 million fine against MLU B.V., the company behind the Yango taxi app, over inadequate safeguards for transfers of personal data to Russia.
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Finbold’s August 20, 2026 research reveal about the surge in GDPR enforcement during the second quarter of 2026—including the total. Article summary: Finbold reported that GDPR authorities imposed €225,879,175 ($260.59 million) in Q2 2026—about €2.48 million per day. This was roughly 230% above Q1’s €68.18 million and brought the first-half total to about €295 million. Topic tags: general, general web, user generated, government. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, ch
Finbold’s Q2 2026 review points to a sharp acceleration in European data-protection enforcement. Authorities issued €225,879,175 ($260.59 million) in GDPR fines between April 1 and June 30—equivalent to roughly €2.48 million ($2.86 million) per day. The quarterly total was about 230% higher than Q1’s €68.18 million, taking fines for the first half of 2026 to approximately €295 million ($340.5 million).
The headline total was heavily influenced by a small number of major cases. That means the figures show the financial scale of enforcement, but not necessarily a uniform increase in the size of every penalty.
| Period | Reported GDPR fines | Approximate daily average |
|---|---|---|
| Q1 2026 | €68.18 million | €757,600 |
| Q2 2026 | €225.88 million | €2.48 million |
| H1 2026 | About €295 million | — |
Finbold’s Q1 review put the first-quarter daily average at approximately €757,600. The Q2 figure therefore represented a substantial change in enforcement intensity by value, even though quarterly totals can be skewed by one-off, high-value decisions.
The Netherlands recorded the quarter’s largest individual case: a €100 million fine against MLU B.V., the European company behind the Yango taxi app. The Dutch Data Protection Authority found problems with the safeguards used for transferring personal data to Russia and ordered the company to stop transfers where GDPR requirements were not met.
The case illustrates why international data transfers require more than a formal contractual mechanism. Organisations must assess whether the destination country and the practical arrangements surrounding the transfer provide protections that are effectively equivalent to those required under EU data-protection law. The Dutch decision was specifically associated with inadequate guarantees for third-country transfers.
At approximately €100 million, the Yango-related penalty represented about 44% of the entire Q2 total. That concentration helps explain both the quarter’s surge and the importance of reviewing cross-border data flows as part of financial-risk management.
Other significant cases reported for the quarter included:
The Reddit case shows that children’s privacy remains a high-risk enforcement area. Age assurance, lawful processing of children’s information and measures designed to reduce foreseeable harm can all become central to regulatory scrutiny.
The Q2 pattern was not limited to a single type of violation. The most prominent themes included:
Security failures appeared in several of the major cases, including the French telecom penalties and the Italian banking decision. Organisations handling large volumes of customer information need controls that are appropriate to the sensitivity, scale and operational context of that processing.
Insufficient legal grounds for processing remain among the most frequent reasons for significant GDPR fines, according to the CMS GDPR Enforcement Tracker’s executive summary. Companies should be able to connect each material processing activity to a documented lawful basis and demonstrate that the basis matches what the organisation actually does.
The Yango-related case places third-country transfers among the clearest high-value risks in the Q2 data. Transfer assessments should cover the actual flow of information, the entities receiving it, access by authorities in the destination country and the effectiveness of supplementary safeguards—not simply whether standard paperwork exists.
The ICO’s Reddit decision reinforces the need for age-appropriate design, reliable age-assurance processes and a defensible approach to the lawful use of children’s personal data.
Media and finance companies accounted for six of the ten largest Q2 fines in Finbold’s reported breakdown. These sectors, along with technology, telecommunications and other consumer-facing industries, often process personal data at significant scale or use it in complex, highly interconnected systems.
The implication is not that every company in these sectors faces the same level of risk. Rather, the largest exposure tends to arise where organisations combine high data volumes with behavioural profiling, sensitive information, large user bases, cross-border infrastructure or complicated third-party arrangements.
The Q2 enforcement pattern translates into five practical priorities:
The reported €225.9 million Q2 total shows how quickly a single major decision can change the enforcement landscape. The Yango-related penalty accounted for nearly half of the quarter’s fines, while cases involving telecoms, finance and children’s privacy show that regulators are examining both core security practices and the legitimacy of how personal data is used.
For companies operating in Europe, the clearest lesson is to treat GDPR controls as part of enterprise risk management. Lawful processing, security, children’s protections and international data transfers should be tested continuously and supported by evidence that can withstand regulatory scrutiny.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
European GDPR authorities issued €225,879,175 in fines during Q2 2026—about €2.48 million per day and 230% more than Q1.
European GDPR authorities issued €225,879,175 in fines during Q2 2026—about €2.48 million per day and 230% more than Q1. The largest penalty was a €100 million fine against MLU B.V., the company behind the Yango taxi app, over inadequate safeguards for transfers of personal data to Russia.
Security failures, weak legal grounds for processing, international transfer failures and inadequate protections for children’s data were among the central enforcement risks.