Last updated: 18 July 2026. NIS2 transposition data verified 18 July 2026, all other figures verified 12 July 2026 against primary sources.
As of 12 July 2026, only one of the eight major EU regulatory frameworks has produced confirmed, published fines against companies. The GDPR accounts for the entire published enforcement value, with cumulative fines of €7.1 billion since May 2018, while NIS2, DORA, the AI Act, CSRD, CBAM, EUDR and the CRA have not produced a single publicly confirmed corporate fine.
That does not mean nothing is happening. Supervisors have issued 70 formal orders across Germany and France, 47 by the BSI under Germany’s NIS2 law and 23 by ANSSI under France’s existing 2018 framework while NIS2 transposition is pending, four member states were referred to the Court of Justice in July 2026, and 19 critical ICT providers are under direct EU oversight through DORA. This page tracks confirmed enforcement, per-country penalty regimes, transposition status and open infringement proceedings for all eight frameworks, with a primary source for every figure. The NIS2 Transposition Delay Index below puts a number of days on every member state’s delay. For deadline questions, use the EU Deadline Tracker. For side-by-side penalty ceilings across frameworks, see the Comparison Matrix.
Seven of the eight major EU regulatory frameworks have yet to produce a single confirmed corporate fine, leaving the GDPR responsible for 100 per cent of published Big 8 enforcement value as of 12 July 2026.
Jump to a framework: GDPR | NIS2 | Delay Index | DORA | AI Act | CSRD | CBAM | EUDR | CRA | Infringements
Enforcement status at a glance
| Framework | Confirmed enforcement (12 Jul 2026) | Highest fine or ceiling | Primary source |
|---|---|---|---|
| GDPR | 2,685 to 3,202 fines (count varies by tracker), €7.1bn cumulative | €1.2bn (Meta, Ireland, 2023) | DLA Piper, CMS |
| NIS2 | No fine. 47 BSI orders (DE, NIS2 law), 23 ANSSI orders (FR, 2018 framework), 4 states referred to CJEU | National ceilings, typically €10m or 2% (essential entities) | Legiscope, IP/26/1499 |
| DORA | No fine. 19 CTPPs designated under direct ESA oversight | National regimes, up to €20m or 10% (Italy) | ESAs, DLA Piper |
| AI Act | No fine. Penalty chapter applies since 2 Aug 2025 (Art. 113(b)), national regimes largely not operational | Up to €35m or 7% (prohibited practices) | AI Act Service Desk |
| CSRD | No fine. No EU-level penalty exists, sanctions are national | Germany up to €10m or 5% (national law) | ESGMaster |
| CBAM | No confirmed penalty. Definitive phase live since 1 Jan 2026 | €100 per tonne, first applicable 30 Sep 2027 | European Commission |
| EUDR | No enforcement possible. Obligations apply from 30 Dec 2026 | National penalties, not yet applicable | Council of the EU |
| CRA | No enforcement running. Full application 11 Dec 2027 | Penalty provisions not yet applicable | European Commission |
Only GDPR has produced confirmed fines, between €6.1 billion and €7.1 billion depending on the count
GDPR is the only Big 8 framework with published corporate fines. Cumulative fines reached €7.1 billion by 10 January 2026, with roughly €1.2 billion issued in 2025 alone.
The 2026 pace appears to have held. Secondary tracking puts new fines in the first half of 2026 above €600 million. ⚠️ Data note. That half-year figure comes from a secondary aggregator, not from official EDPB statistics, and should be quoted with that caveat.
Fine counts differ by methodology. The CMS GDPR Enforcement Tracker Report counts 2,685 fines with complete data (cut-off 1 March 2026, total approx. €6.11 billion), while Enforcementtracker.com records 3,202 actions totalling €6.31 billion as of July 2026, including 156 logged in 2026. The most conservative citable figure is €6.11 billion in confirmed fines, the most widely cited is €7.1 billion.
The ten largest GDPR fines (per CMS, cut-off 1 March 2026)
| # | Company | Country | Fine | Violation type | Date |
|---|---|---|---|---|---|
| 1 | Meta Platforms Ireland | Ireland | €1,200,000,000 | Unlawful US data transfers | 12 May 2023 |
| 2 | TikTok Technology | Ireland | €530,000,000 | EEA data transfers to China | 2 May 2025 |
| 3 | Meta Platforms, Inc. | Ireland | €405,000,000 | Children’s data (Instagram) | 5 Sep 2022 |
| 4 | Meta Platforms Ireland | Ireland | €390,000,000 | Processing principles | 4 Jan 2023 |
| 5 | TikTok Limited | Ireland | €345,000,000 | Children’s data | 1 Sep 2023 |
| 6 | Ireland | €310,000,000 | Insufficient legal basis | 24 Oct 2024 | |
| 7 | Uber | Netherlands | €290,000,000 | Driver data transfers to US | 22 Jul 2024 |
| 8 | Meta Platforms Ireland | Ireland | €265,000,000 | Technical and organisational measures | 25 Nov 2022 |
| 9 | Meta Platforms Ireland | Ireland | €251,000,000 | Technical and organisational measures | 27 Dec 2024 |
| 10 | WhatsApp Ireland | Ireland | €225,000,000 | Transparency obligations | 2 Sep 2021 |
Ireland’s DPC issued 9 of the 10 largest fines and holds €4.04 billion cumulatively, about 57 per cent of all GDPR fine value in Europe, a direct consequence of the one-stop-shop mechanism. France passed €1 billion cumulatively in 2025 and overtook Luxembourg as the second-largest issuer. By number of fines rather than value, Spain leads with 1,048 published decisions (CMS, cut-off 1 March 2026). ⚠️ Data note. No official ranked table with exact cumulative values exists for positions 4 to 10, individual trackers diverge.
Two large French decisions from September 2025 are frequently miscounted as GDPR fines. The CNIL fined Google €325 million for ads inside Gmail and non-consensual cookies, and Shein €150 million for cookies placed before consent. Both were issued under Article 82 of the French Data Protection Act (ePrivacy regime), not under the GDPR one-stop-shop.
⚠️ Court developments affecting the table above. The €746 million Amazon fine was annulled on procedural grounds in March 2026 and returned to the Luxembourg CNPD. The €530 million TikTok fine is under appeal, with a stay granted in November 2025. Italy’s €15 million OpenAI fine was reportedly annulled in March 2026, pending confirmation from the Garante’s official record.
On the diverging totals, our position is that RegDossier will not publish an invented consolidated figure. The honest number depends on counting method, so this page carries both endpoints. Cite €6.11 billion if you need the strictest confirmed count (CMS, complete records only, cut-off 1 March 2026) and €7.1 billion if you need the broadest survey figure (DLA Piper, 31 jurisdictions including the UK). A single midpoint would be easier to quote and harder to defend, and this page exists to be defended.
NIS2 has zero fines but 70 formal orders and four states before the Court of Justice
No NIS2 fine against a company has been published anywhere in the EU as of 12 July 2026. Supervisors have moved through formal orders instead, with 47 BSI orders in Germany under the NIS2UmsuCG and 23 ANSSI remediation orders in France issued under its existing 2018 NIS1 framework while transposition is pending, and the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026 for failing to transpose the directive.
The referral requests lump-sum and daily penalties against the four states. Case numbers per the July 2026 infringement package are INFR(2024)0279 (Ireland), INFR(2024)0270 (Spain), INFR(2024)0274 (France) and INFR(2024)0288 (Netherlands). ⚠️ Data note. The Netherlands adopted its Cyberbeveiligingswet on 7 July 2026, one day before the referral, with entry into force on 15 August 2026, and the Commission has typically withdrawn such cases once transposition is notified. One secondary source claims seven states were referred by May 2026, the official July press release names four, verify against the Commission presscorner before citing a count. A common sourcing trap: the Dutch €525,000 fine against a telecom provider circulating in NIS2 articles was issued under NIS1, not NIS2.
EU States Transposed NIS2 an Average of 246 Days Late, and Three Have No Law at All
Index last updated: 18 July 2026. Running delays for states without a law in force update daily. Method and per-row sources in the CSV below.
As of 18 July 2026, 22 of the 27 EU member states have a national NIS2 law in force, on average 246 days after the transposition deadline of 17 October 2024. Three states, France, Ireland and Spain, have adopted no law at all, and together with the Netherlands they were referred to the Court of Justice on 8 July 2026 (IP/26/1499).
The Commission filed its Dutch case on 8 July 2026, one day after the Dutch Senate adopted the Cyberbeveiligingswet, so the Court file opened against a state that had just finished the work. The Commission has typically withdrawn such cases once transposition is notified, so withdrawal is likely after the law takes effect on 15 August 2026. One number to treat with care: the “seven states referred” figure circulating in secondary coverage belongs to the CER Directive referral of 29 April 2026 (IP/26/910), not to NIS2. The NIS2 count is four.
| Member state | Law in force since | Days late ▼ | Infringement status |
|---|
Method: delay measured from the Article 41 transposition deadline of 17 October 2024 to the date the national law entered into force, the least ambiguous date across 27 gazettes. States in force before the deadline count as 0. Average across the 22 in-force states is 246 days, or 285 days if the three early transposers are excluded. Median 217.5 days. For states with no law in force the delay runs daily and is marked as running. Adoption and publication dates for every state sit in the CSV, so the figures can be recomputed on an adoption basis.
⚠️ Data note. Bulgaria’s law was promulgated in State Gazette No. 17 on 13 February 2026 and entered into force on 17 February 2026, the date confirmed by Bulgarian counsel at Boyanov and Kinstellar. One international firm cites 13 February, which is the publication date, not entry into force. The Cyprus date of 25 April 2025 for Law 60(I)/2025 is confirmed by the ECSO tracker, Eversheds Sutherland and Cypriot counsel. The Commission has typically withdrawn such cases once transposition is notified; withdrawal of the Dutch case INFR(2024)0288 is not yet confirmed.

Transposition and penalty status for all 27 member states (verified 18 July 2026 against the Commission transposition page, national gazettes and the ECSO tracker)
| Member state | Transposition status | National fine ceiling (essential / important) | Competent authority | Infringement status |
|---|---|---|---|---|
| Austria | Adopted, in force 1 Oct 2026 | Directive minimum (€10m/2% and €7m/1.4%) | BMI | Reasoned opinion May 2025 |
| Belgium | In force since 18 Oct 2024 | Directive minimum | CCB | None |
| Bulgaria | In force since 17 Feb 2026 | Directive minimum | National Cybersecurity Coordinator | Reasoned opinion May 2025, transposed since |
| Croatia | In force since 15 Feb 2024 | Directive minimum | NCSC-HR (SOA) | None |
| Cyprus | In force since 25 Apr 2025 (Law 60(I)/2025) | Directive minimum | Digital Security Authority | Reasoned opinion May 2025, transposed since |
| Czechia | In force since 1 Nov 2025 | Directive minimum | NÚKIB | Reasoned opinion May 2025, transposed since |
| Denmark | In force since 1 Jul 2025 | Directive minimum | CFCS | Reasoned opinion May 2025, transposed since |
| Estonia | In force since 1 Jan 2026 | Directive minimum | RIA | Reasoned opinion May 2025, transposed since |
| Finland | In force since 8 Apr 2025 | Directive minimum | Traficom / NCSC-FI | Reasoned opinion May 2025, transposed since |
| France | In parliament (Loi Résilience) | Not yet set (draft follows directive minimum) | ANSSI | Referred to CJEU 8 Jul 2026, INFR(2024)0274 |
| Germany | In force since 6 Dec 2025 (NIS2UmsuCG) | Directive minimum, personal management liability | BSI | Reasoned opinion May 2025, transposed since |
| Greece | In force since 27 Nov 2024 (Law 5160/2024, FEK A 195) | Directive minimum | NCSA | Formal notice Nov 2024 |
| Hungary | In force since 1 Jan 2025 | Directive minimum plus HUF 50m to 350m administrative ranges | SZTFH | Reasoned opinion May 2025, transposed since |
| Ireland | In pre-legislative scrutiny | Not yet set (draft) | NCSC | Referred to CJEU 8 Jul 2026, INFR(2024)0279 |
| Italy | In force since 16 Oct 2024 | Directive minimum plus temporary management bans | ACN | None |
| Latvia | In force since 1 Sep 2024 | Directive minimum | NCSC, CERT.LV | Reasoned opinion May 2025, transposed since |
| Lithuania | In force since 18 Oct 2024 | Directive minimum | NKSC | None |
| Luxembourg | In force since 10 May 2026 (Loi du 5 mai 2026) | Directive minimum | ILR | Reasoned opinion May 2025, transposed since |
| Malta | In force since 23 Jan 2026 (S.L. 460.41, all provisions) | Directive minimum | Critical Infrastructure Protection Dept | Formal notice Nov 2024 |
| Netherlands | Adopted 7 Jul 2026, in force 15 Aug 2026 | Up to €10m or 2%, personal director liability | NCSC | Referred 8 Jul 2026, INFR(2024)0288, withdrawal expected ⚠️ |
| Poland | In force since 3 Apr 2026 | Directive minimum | CSIRT GOV, MON, NASK | Reasoned opinion May 2025, transposed since |
| Portugal | In force since 3 Apr 2026 | Directive minimum | CNCS | Reasoned opinion May 2025, transposed since |
| Romania | In force since 30 Dec 2024 | Directive minimum | DNSC | Formal notice Nov 2024 |
| Slovakia | In force since 1 Jan 2025 | Directive minimum | NBÚ, SK-CERT | Formal notice Nov 2024 |
| Slovenia | In force since 19 Jun 2025 (ZInfV-1) | Directive minimum | URSIV, SI-CERT | Reasoned opinion May 2025, transposed since |
| Spain | Draft approved by cabinet Jan 2025 | Not yet set (draft) | CCN-CERT, INCIBE-CERT, planned CNC | Referred to CJEU 8 Jul 2026, INFR(2024)0270 |
| Sweden | In force since 15 Jan 2026 | Directive minimum | MSB and sector supervisors | Reasoned opinion May 2025, transposed since |
⚠️ Data note. The near-universal use of directive-minimum ceilings is based on secondary transposition trackers. For legal citation, verify the exact wording in each national official gazette. Bulgaria appears in some reports as referred to the CJEU: that referral is under the CER Directive (29 April 2026, IP/26/910), not NIS2, where Bulgaria’s law has been in force since 17 February 2026.
A 27-country table ages in weeks, not months, so the maintenance promise sits next to the data it covers. The verification date above this table moves with every fortnightly research cycle, not only the Last updated line at the top of the page. We considered showing just the aggregate, 24 member states with adopted legislation and 3 still in parliament, and parking the detail elsewhere. We decided against it. The per-country rows are the part people cite, and a tracker that hides its own data is not a tracker.
DORA supervision is live with 19 critical ICT providers and no fine issued
No DORA fine has been published by any ESA or national competent authority as of 12 July 2026, with the first formal fines expected in the second half of 2026. What is confirmed is structural: on 18 November 2025 the ESAs designated the first 19 Critical ICT Third-Party Providers, including AWS, Google Cloud, Microsoft, Deutsche Telekom, Oracle and SAP.
Designated CTPPs face a Lead Overseer from one of the three ESAs, joint examination teams, and periodic penalty payments of up to 1 per cent of average daily worldwide turnover for up to six months under Article 35(6). Non-EU CTPPs must establish an EU presence within 12 months of designation. ⚠️ Data note. One secondary source cites 12 designated providers as of early 2026, the official ESA statement of 18 November 2025 names 19, the official figure prevails. Several vendors claim DORA enforcement has been “live since January 2025” without naming a single case with an amount, country and date, treat such claims as marketing.
DORA sets no single EU-wide fine for financial entities. Article 50 delegates penalties to member states, and the regimes diverge sharply (per DLA Piper, data as at November 2025):
| Country | National legislation | Authority | Max penalty, entities | Max penalty, individuals |
|---|---|---|---|---|
| Italy | D.Lgs. 23/2025 | Banca d’Italia, Consob, IVASS, COVIP | €20m or 10% of turnover | €5m plus function bans |
| Ireland | SI 12/2025, SI 20/2025 | Central Bank of Ireland | €10m or 10% of turnover | €1m |
| Finland | Act 878/2008 | Finanssivalvonta | 10% of turnover, capped €10m | 10% of income, capped €100k |
| Belgium | National implementing law | NBB, FSMA | €5m or 10% of net turnover | €5m |
| Germany | FinmadiG | BaFin, Bundesbank | €5m (top rate only for Art. 19(4) and 26(1) breaches) | €5m |
| Netherlands | DNB supervisory framework | DNB | €5m (base amounts €10k to €2.5m) | ⚠️ no separate cap published |
| Luxembourg | DORA implementation law, Jul 2024 | CSSF, CAA | €5m | ⚠️ not published |
| Sweden | National implementing law | Finansinspektionen | Highest of €1m, 10% of net turnover, 3x benefit | Highest of €500k or 3x benefit |
| Czechia | Act 31/2025 Sb. | ČNB | CZK 50m (approx. €2m) | ⚠️ no DORA-specific cap |
| Spain | Draft law, not adopted ⚠️ | CNMV, Banco de España | Highest of €5m, 5% of net turnover, 5x benefit (draft) | Highest of €1m or 5x benefit (draft) |
⚠️ Data note. France and Spain had not formally adopted national DORA penalty regimes as of the source date. The table rests on a single authoritative source captured November 2025, re-verify before citing individual ceilings.
The AI Act penalty chapter has applied since August 2025 and still has no fine
No AI Act fine has been published anywhere in the EU. The penalty chapter, including Article 99, has applied since 2 August 2025 per Article 113(b), with GPAI fines under Article 101 following on 2 August 2026. The prohibitions themselves have applied since 2 February 2025. The gap between an applicable penalty chapter and zero fines has one explanation: most member states have not operationalised the national enforcement structures the fines run through.
⚠️ Data note. Italy’s separate national AI law (Law 132/2025, in force October 2025, fines up to €774,685) has produced no known fine and is not AI Act enforcement in the strict sense.
The fine tiers under Article 99 are €35 million or 7 per cent of worldwide turnover for prohibited practices (Article 5), €15 million or 3 per cent for operator obligations (Articles 16, 22, 23, 24, 26, 31, 33, 50), and €7.5 million or 1 per cent for supplying incorrect or misleading information to authorities. For SMEs and start-ups the lower of the two amounts applies.
The enforcement timeline itself is moving. The Digital Omnibus on AI was adopted by the Council on 29 June 2026 and defers Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems to 2 August 2028. ⚠️ Data note. Publication in the Official Journal could not be confirmed with an OJ citation as of 12 July 2026, so the original AI Act dates remain the formal legal baseline until publication. All confirmed dates sit in the EU Deadline Tracker.
Institutional readiness is uneven. Per the Future of Life Institute tracker, 9 member states have designated both required authorities, 12 have partial arrangements and 6 have designated none, against a deadline of 2 August 2025. Article 74 assigns the special cases, the EDPS for EU institutions and the AI Office for GPAI-based systems. ⚠️ These counts change monthly, treat them as a snapshot. If you are unsure where your own organisation stands before August, our AI Act readiness quiz takes three minutes.
CSRD has no EU-level penalty and no national fine has been issued
There is no EU-level CSRD fine, by design. The directive delegates all sanctions to member states, and as of 12 July 2026 no national CSRD fine has been publicly issued, with regulators reviewing the first wave of FY2024 reports and first formal actions expected during 2026.
National ceilings where adopted include Germany at up to €10 million or 5 per cent of turnover, Italy at up to €5 million (CONSOB), the Netherlands at up to €4 million or 4 per cent (AFM), Poland at up to €1 million (KNF) and Sweden at up to €2 million or 3 per cent (FI). ⚠️ Data note. Sources conflict on France, one cites up to €18,750 for non-publication, another up to €5 million for companies and €500,000 for individuals, plus criminal exposure for obstructing audits. Both versions circulate, verify in the French ordinance before citing. Several national figures come from a secondary software-vendor source and have not been checked against national gazettes.
The scope itself shrank in February 2026. Directive (EU) 2026/470, published in the Official Journal on 26 February 2026, limits CSRD to companies with more than 1,000 employees and net turnover above €450 million, removing an estimated 80 per cent of companies from scope. The amended rules apply to financial years from 1 January 2027, with first reports in 2028 and a transposition deadline of 19 March 2027. ⚠️ Sources differ on entry into force, 18 or 19 March 2026.
CBAM cannot produce its main penalty before 30 September 2027
No CBAM penalty has been publicly confirmed as of 12 July 2026, and the headline €100 per tonne penalty structurally cannot arise before 30 September 2027, when the first annual declaration and certificate surrender for 2026 imports falls due. The definitive phase has been live since 1 January 2026.
Transitional-period penalties of €10 to €50 per tonne of unreported emissions have been legally available to national authorities since 2024, but no case has been published. The Dutch Emissions Authority has stated it will run a rectification procedure before any enforcement, a pattern likely to repeat elsewhere. ⚠️ Data note. Reports of small transitional penalties in Germany and Sweden could not be verified in official publications, no comprehensive EU-wide confirmation of absence exists either, verify with DEHSt and the Swedish authority before citing the zero.
The current rulebook follows the October 2025 simplification (Regulation (EU) 2025/2083): certificate sales start 1 February 2027, a 50-tonne de minimis threshold removes roughly 90 per cent of importers while keeping 99 per cent of embedded emissions in scope, unauthorised imports above the threshold attract penalties of three to five times the standard €100 per tonne, and the authorisation application deadline was 31 March 2026. Each member state runs its own competent authority (Germany’s DEHSt is the reference example), so enforcement will be national, not central.
EUDR enforcement starts 30 December 2026 at the earliest
No EUDR enforcement is possible today because the obligations do not yet apply. Regulation (EU) 2025/2650, in force since 26 December 2025, moved application to 30 December 2026 for large and medium companies and 30 June 2027 for micro and small companies.
The same amendment simplified the regime: only the first operator placing a product on the EU market files a full due diligence statement, micro and small companies get lighter obligations, and some printed materials left the scope entirely. The Commission must review the simplifications by 30 April 2026. Because obligations are not applicable, the absence of fines here is structural, not a supervisory choice.
CRA has no notified bodies and no applicable penalties until December 2027
No CRA enforcement is running, and none can run, since full application of Regulation (EU) 2024/2847 arrives on 11 December 2027. The interim milestones are conformity assessment rules from 11 June 2026 and mandatory vulnerability and incident reporting for manufacturers from 11 September 2026 via the ENISA platform.
The machinery is visibly not built yet. As at 24 June 2026, NANDO listed no notified body for the CRA and no harmonised CRA standard had been published in the Official Journal. ⚠️ Data note. Sources differ on entry into force, 10 or 11 December 2024, a 20-day publication artefact with no practical effect on the enforcement dates above.
Active infringement proceedings cluster around NIS2 and CSRD
Of the eight frameworks, only NIS2 has confirmed proceedings before the Court of Justice, and CSRD is the other framework where transposition-related proceedings are highly likely to be open. Under the seven frameworks younger than the GDPR, the only parties taken to court so far are four governments. Six of the eight are regulations with direct application or deferred deadlines, so classic non-transposition proceedings either cannot exist or could not be confirmed.
The NIS2 escalation ran in three waves: formal notices to 23 member states on 28 November 2024, reasoned opinions to 19 on 7 May 2025, and CJEU referrals for four states on 8 July 2026. For CSRD, the transposition deadline passed on 6 July 2024 and proceedings ran through 2024 and 2025, but ⚠️ no confirmed count of open cases as of 12 July 2026 was found, check the Commission infringement database by INFR number before citing. For GDPR, DORA, the AI Act, CBAM, EUDR and the CRA, no open infringement proceedings could be publicly confirmed. ⚠️ For the AI Act, the Commission has signalled possible proceedings against states that missed the 2 August 2025 authority-designation deadline, none confirmed as of the update date.
Enforcement moves faster than annual reports. The RegDossier newsletter tracks every new fine, referral and transposition change across all eight frameworks, with primary sources attached, every two weeks and only what actually changed. Subscribe below and cite with confidence.
