← Back to Blog €5.88B in GDPR Fines Since 2018. Your Outbound Setup Needs Fixing This Quarter, Not in 2031.

€5.88B in GDPR Fines Since 2018. Your Outbound Setup Needs Fixing This Quarter, Not in 2031.

EU GDPR reform won't land until 2031, but €5.88B in fines already hit. Fix cookie dark patterns and AI legitimate interest assessments first.

The EU's proposed GDPR amendments are stalled until 2031. Enforcement is not. Regulators have issued €5.88 billion in cumulative fines since 2018, and the current priorities are cookie consent dark patterns and legitimate interest assessments for AI tools. If you run outbound, those two items are your problem this quarter, not in five years.

The reform timeline is a distraction from the enforcement timeline

The reform package includes SME exemptions and cookie standardisation. Both are sensible. Both are also years away from taking effect. We've written before about what changes when SME exemptions land, and the short version is: nothing changes for you until the legislation actually passes and member states transpose it.

That transposition gap matters more than the headline announcements suggest. A regulation applies directly, but reform of this scope will likely move through directive-style amendments and national implementing acts, each with its own drafting quirks and supervisory priorities. Even after passage, member states negotiate derogations, publish guidance, and staff up before anyone enforces the new text. Realistically, the compliance surface you operate against in 2026 is the one regulators are already enforcing, not the one being debated in Brussels.

Meanwhile, data protection authorities are not waiting. Spain's AEPD has accelerated its enforcement cadence. The ICO has turned its AI guidance into something closer to law. France's CNIL has been explicit that cookie banners are a priority. The fines are not theoretical.

What that means in practice is that the enforcement timeline is running on a different clock, and it rewards different behaviour:

So the practical question is not "what will the reform do?" It's "what are regulators actually fining right now?"

Cookie consent dark patterns are the easiest fine to avoid

If your cookie banner has a big green "Accept all" button and a grey "Manage preferences" link buried three clicks deep, you have a dark pattern. Regulators have been consistent on this. The consent has to be freely given, specific, informed, and unambiguous. A pre-ticked box is not consent. A banner that makes rejection harder than acceptance is not consent.

The reason this category of violation is worth prioritizing is that it is almost entirely within your control. Unlike cross-border data transfers or records-of-processing obligations, which require legal interpretation and vendor coordination, banner design is a front-end decision you can change today. Enforcement actions across EU member states have repeatedly centered on the same handful of design choices: unequal button prominence, color contrast that steers users toward acceptance, consent walls that block access to content until someone agrees, and "legitimate interest" toggles that are on by default and off by several clicks. None of these require a lawyer to identify. They require someone to look.

We audited our own site last year and found two problems. The reject button was smaller than the accept button. And the cookie policy link opened in a new tab that most people never read. Neither was intentional. Both were the kind of thing that accumulates when you ship fast and nobody owns compliance.

Fixing it took an afternoon. We made the buttons the same size. We put "Reject all" next to "Accept all" instead of hiding it. We stopped loading analytics until someone actively opted in. Conversion on the banner went down. Nothing else did.

If you use a consent management platform, check the default settings. Most ship with the accept button styled more prominently. That's a product decision, not a legal one, and it's the kind of thing regulators notice. The practical move is to treat your banner as a compliance artifact with an owner, not a growth experiment. Review it quarterly, screenshot it, and keep a record of when each version was live. If a regulator asks what your banner looked like in March, "we think it was fine" is not an answer. A dated screenshot is.

Legitimate interest assessments for AI tools are now table stakes

Every AI enrichment tool you use processes personal data. If you're running prospect data through a scoring model, an email drafting tool, or a meeting brief generator, you need a legitimate interest assessment on file. Not because the reform says so, but because the ICO's AI code and the EU AI Act both point the same direction.

The assessment doesn't have to be long. Ours is two pages. It covers:

The key phrase is "human review before sending." If your AI tool auto-sends, you have a harder argument. We built MiraReach so that nothing goes out without a human pressing the button. That's partly a product decision and partly a compliance one. It's much easier to defend legitimate interest when a person is in the loop.

We've written about how regulators are targeting AI enrichment and pre-checked boxes. The pattern is consistent: they look for automated decisions that affect people without meaningful human oversight. If you can show a human reviews every outbound message, you're in a better position.

What this means for your outbound setup

Two things to do this month.

First, fix your cookie banner. Make reject as easy as accept. Stop loading non-essential cookies before consent. Document what you changed and when. This matters more than most operators realize: consent mode is the part of GDPR enforcement that regulators can audit without ever opening your CRM. If your banner offers a prominent "Accept all" button and buries rejection behind a second click or a toggle screen, you are running what the EDPB treats as a dark pattern, and the fix is cheap. The documentation piece is what separates a defensible position from an assumption. A dated changelog showing when you corrected the banner, what the prior behavior was, and who approved the change is the kind of evidence that shortens an inquiry.

Second, write a legitimate interest assessment for every AI tool in your stack. If you use Apollo, Clay, Instantly, Smartlead, or anything similar, you need one. The assessment should name the tool, describe the data flow, and explain why legitimate interest applies. Keep it short. Keep it current. The reason this is not busywork: enrichment and sequencing tools sit at the point where personal data enters your pipeline, and that is exactly where a supervisory authority will look first. A three-part test — is the interest legitimate, is the processing necessary, does it survive balancing against the individual's rights — is enough structure. What fails is the absence of any written reasoning at all, or an assessment dated two years ago that still lists a tool you cancelled.

If you're running outbound into the EU or UK, this is not optional. The fines are real, and the enforcement is active. The reform will change some of this eventually. It won't change it soon enough to matter for your next campaign.

We've also written about how US state privacy laws affect cold email. The pattern is similar: no federal floor, aggressive state enforcement, and a lot of operators assuming they're too small to matter. They're not.

What we'd do next

Audit your cookie banner today. Most banners still rely on implied consent or pre-ticked boxes, both of which enforcement actions have already flagged as invalid. If your banner doesn't offer a genuine reject-all option on the first layer, treat that as your first fix. Write your legitimate interest assessments this week. The reform proposals narrow the gap between "we have a legitimate interest" and "we documented why it outweighs the data subject's rights" — regulators now expect a written balancing test, not a checkbox. If you rely on legitimate interest for outreach, prospecting, or analytics, each use case needs its own assessment with a stated retention period and an opt-out path that works without friction.

Then map your data flows before the 2026 deadlines force the issue. That means knowing which vendors touch personal data, where that data sits, and which of them can respond to a deletion or access request within the statutory window. For small teams, the practical move is to consolidate vendors rather than add another compliance tool on top of the stack. Fewer processors means fewer DPAs to track, fewer transfer mechanisms to validate, and a shorter path from request to response.

Finally, build the human-review step into your workflow now, not after an incident. Automated outreach that never passes through a person is exactly the pattern regulators have been targeting, and retrofitting review into a live pipeline is far more expensive than designing it in. If you want to see how MiraReach handles the human-review requirement, give MiraReach a try. We built it so that compliance isn't an afterthought.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →