← Back to Blog €5.88B in GDPR Fines Since 2018—and Your Email Setup Is Probably Next

€5.88B in GDPR Fines Since 2018—and Your Email Setup Is Probably Next

GDPR fines hit €5.88B across 2,245 penalties. Here's what the Q4 2025 Digital Package changes for email compliance, and what to fix in your outbound setup now.

GDPR fines have hit €5.88 billion across 2,245 penalties since May 2018. Spain leads on enforcement frequency. The European Commission's Q4 2025 Digital Package proposes SME exemptions, mandatory one-click cookie reject, and an AI legitimate-interests clarification. Implementation lands in 2031 or later. So the rules you're operating under today are the rules that matter for the next five years.

If you run outbound, that gap between proposal and enforcement is the whole story. Here's what actually changes for your email compliance setup, and what doesn't.

The €5.88B number is a lagging indicator, not a warning shot

Fines accumulate slowly. A complaint filed in 2022 gets decided in 2025. The number you see today reflects enforcement decisions on data practices from three or four years ago. Which means the fines landing in 2029 will be about what you're doing right now.

Spain's frequency lead is worth noting. The AEPD has been the most active DPA in the bloc, and it's been aggressive on marketing-adjacent cases: consent for cookies, lawful basis for prospecting, retention on lead lists. If your ICP includes Spanish companies, or you're sending into Spain, your exposure is higher than the headline number suggests.

We've written before about what Spain's enforcement acceleration means for outbound. The short version: they audit the paper trail, not the intent.

What the Q4 2025 Digital Package actually proposes

Three things matter for anyone running cold email or AI-assisted prospecting.

SME exemptions expansion. The Commission wants to widen the categories of small businesses that get lighter-touch obligations. The current draft is vague on thresholds, but the direction is clear: if you're under 50 employees and not processing sensitive data at scale, you may get relief on record-keeping and DPIA requirements. Not on consent. Not on lawful basis. Just on the paperwork overhead.

Mandatory one-click cookie reject. This is the one that catches B2B SaaS founders off guard. If your marketing site uses a cookie banner with a "reject all" button buried two clicks deep, that's already non-compliant in most member states. The Digital Package makes it explicit and bloc-wide. Your web team needs to fix this before 2027, not 2031.

AI legitimate interests clarification. This is the interesting one for outbound. The Commission is signalling that using AI to score, enrich, or prioritise prospects can fall under legitimate interests, provided you can document the reasoning and the data sources. That's not a green light. It's a framework. But it's the first time the EU has acknowledged that AI-assisted prospecting isn't automatically a consent problem.

We covered the AI enrichment angle in more detail in this piece on AI enrichment and consent boxes. The clarification doesn't change the underlying test: can you explain, in plain language, why this person's data was processed and what legitimate interest you're relying on?

What doesn't change between now and 2031

Everything that actually gets you fined.

None of this is new. The Digital Package doesn't relax any of it. It just changes the paperwork burden for small operators.

The AI Act deadline is the one to watch

The AI Act's high-risk obligations kick in from August 2026. Most outbound tools won't qualify as high-risk. But if you're using AI to make automated decisions about individuals, including scoring them for credit, employment, or access to services, you're in scope.

Prospect scoring for sales outreach is not high-risk. Prospect scoring that determines whether someone gets a loan is. Know which side of the line you're on.

The ICO's AI Code is already law in the UK, and we've written about what a misconfigured scoring model can cost you. The EU version is broader but the principle is the same: if you can't explain how the model reached its output, you can't defend it.

What we'd do this quarter

Three things, in order.

First, audit your cookie banner. If "reject all" isn't on the first layer, fix it. This is the cheapest compliance win available and it's about to become mandatory.

Second, write down your legitimate interests assessment for cold email. One page. What data you process, why, what the balancing test is, how someone opts out. If a DPA asks, you have an answer. If they don't, you've clarified your own thinking.

Third, check your DPAs. Every tool in your stack. If a vendor won't sign one, that's a signal.

None of this requires waiting for 2031. The enforcement regime you're operating under today is the one that generates the fines you'll read about in 2029. The Digital Package is a proposal. Your inbox is not.

If you want a sequencer that keeps a human on the send button and logs the compliance trail, give MiraReach a try. We built it because we got tired of tools that treated compliance as an afterthought.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →