The Dutch result was dominated by a €100 million fine against MLU B.V., the operator of the Yango ride-hailing app and successor to Ridetech International B.V. The Dutch Data Protection Authority found that personal data from users and drivers in Finland and Norway had been transferred to Russia without adequate protection and ordered the transfers to stop unless GDPR-compliant safeguards were in place.
The case highlights a central risk in international data transfers: using Standard Contractual Clauses does not, by itself, resolve every transfer concern. The available reporting says the Dutch authority considered factors including Russian access to encryption keys and shared Dutch-Russian management, which could create risks around access to data and re-identification.
The Dutch regulator’s guidance explains that transfers to third countries require an adequate level of protection, appropriate safeguards, or a specific exception. Standard Contractual Clauses are one possible safeguard, but organizations must still ensure that the protection is effective in the circumstances of the transfer.
France’s €52 million total included several significant cases. FREE MOBILE received a €27 million penalty and its parent company FREE received €15 million following a major breach. IQVIA Operations France was fined €15 million over health-data breaches.
Taken together, these cases reinforce the financial exposure created when organizations fail to protect sensitive information or maintain effective security controls. The penalties also show that enforcement can extend across related companies when responsibility for data processing and security is distributed within a corporate group.
Italy recorded €45.50 million in fines. The largest component was a €31.8 million penalty against Intesa Sanpaolo for shortcomings in protecting customers’ banking data. Poste Italiane and PostePay also received penalties of €6.62 million and €5.88 million, respectively, for failures involving banking-app management.
The Italian cases place financial institutions among the sectors facing the greatest consequences when access controls, data governance, or digital-service processes do not adequately protect customer information.
The UK Information Commissioner’s Office imposed a £14.47 million (€16.61 million) fine on Reddit for inadequate age verification and unlawful processing of children’s data.
The case broadens the enforcement picture beyond data breaches and international transfers. Platforms that process information about children must also be able to demonstrate that their age-related controls and processing practices have a lawful basis and provide appropriate protection.
Finbold’s review found that security failures and the absence of a lawful basis for processing accounted for virtually all of the major penalties in its Q2 analysis.
Among the ten largest fines, the media and finance sectors each appeared three times. Transportation and energy each accounted for two of the ten largest penalties, including the largest Dutch/Yango case.
The pattern is significant for organizations that view GDPR exposure as primarily a technical-security issue. The Q2 cases indicate that regulators are also examining the foundations around personal-data use: whether processing is lawful, whether safeguards work in practice, whether international transfers are defensible, and whether companies properly oversee their partners and corporate structures.
The headline increase does not mean that every organization faces the same level of exposure, and the research is a compilation of reported enforcement totals rather than a forecast of future fines. But it does provide a clear compliance signal: large penalties can arise from weaknesses that span legal, operational, technical, and organizational controls.
For companies processing personal data, the most important review areas are:
The main conclusion from Finbold’s Q2 review is that GDPR enforcement is becoming a material financial risk for organizations with weak data governance. The largest cases were not limited to isolated technical errors; they involved foundational failures in lawful processing, security, international-transfer safeguards, and oversight.