← Back to Blog €5.88B in GDPR Fines—and Regulators Are Now Targeting Your AI Enrichment and Pre-Checked Boxes

€5.88B in GDPR Fines—and Regulators Are Now Targeting Your AI Enrichment and Pre-Checked Boxes

GDPR fines hit €5.88B with AI and dark patterns now targeted. Here's what changes for B2B sales outreach and how to stay compliant.

GDPR enforcement just got more expensive. Cumulative fines hit €5.88 billion, and regulators are now targeting AI systems and dark patterns, not just sloppy data handling. If your outbound relies on automated enrichment, AI-drafted emails, or pre-checked consent boxes, you're in the crosshairs. Here's what actually changes for your pipeline.

€5.88 billion is the headline. The targets are the story.

That number isn't just a milestone. It's a signal about where enforcement is heading. The European Data Protection Board (EDPB) isn't just fining big tech for data breaches anymore. They're going after the mechanics of how you acquire and process data. The shift is from reactive penalties for incidents to proactive scrutiny of system design. Regulators are now asking not just "what went wrong?" but "how was this built to influence or exclude?" That distinction matters because it moves compliance from a checkbox exercise into the architecture of your outreach stack.

Three areas matter for anyone running B2B outreach:

For a solo founder sending 50 emails a week, this feels distant. It isn't. The enforcement actions are setting precedents that trickle down to how regulators treat smaller operators. The same logic used to fine a multinational for dark patterns in its consent flow will be applied to your newsletter signup form. The same reasoning about AI scoring will be used to evaluate your CRM's lead-ranking feature. You don't need a legal team to act on this — you need to audit your own mechanics before a complaint forces you to.

The EU AI Act deadline is closer than you think

August 2026 is the compliance deadline for high-risk AI systems under the EU AI Act. That's not a distant horizon. It's next quarter for anyone planning a Q3 product launch.

Here's the part most sales teams miss: the AI Act and GDPR now overlap. If your outreach tool uses AI to score prospects, draft emails, or predict buying intent, you're running a system that processes personal data. That means dual obligations. The GDPR demands a lawful basis for every data point you feed into the model, while the AI Act requires you to assess whether that processing creates systemic risk. The two regimes don't just coexist—they compound. A compliance gap in one is a violation of the other, and regulators are increasingly coordinating enforcement across both frameworks.

We covered the 7% global turnover fines for high-risk systems before. The practical takeaway hasn't changed: you need to document what your AI does with personal data, and you need a human in the loop for any decision that affects an individual. But documentation alone won't save you. The AI Act's transparency obligations mean you must also demonstrate that your model's outputs are traceable—every scoring decision, every suppression rule, every automated exclusion needs an audit trail that links back to specific input data and algorithmic logic. That's not a legal exercise; it's an engineering one.

That last part is where most AI sales tools fail. They auto-send, auto-follow-up, and auto-qualify. If a prospect gets excluded from your pipeline because an algorithm decided they weren't a fit, that's a decision with consequences. Under the new rules, you need to be able to explain why. Not just to a regulator—to the prospect themselves if they ask. The burden shifts from "we have a tool" to "we can justify every action that tool takes." For solo operators and small teams, this means building review checkpoints into your workflow now, before the deadline forces you to retrofit them under pressure.

What this means for your cold email setup

If you're using tools like Instantly, Smartlead, or Lemlist with AI-powered personalisation, here's what needs to change:

1. Audit your data sources. Where did you get those email addresses? If you scraped them from LinkedIn or bought a list, that's a problem. Legitimate interest under GDPR requires a reasonable expectation that the person wants to hear from you. A scraped list doesn't meet that bar. The €5.88 billion figure isn't just noise—it reflects a regulatory shift toward examining the provenance chain of every contact. Regulators are now asking not just "did you have consent" but "what was the lifecycle of this data point?" If you can't trace an address back to a specific, documented interaction—a download, a conference handshake, a direct inquiry—you're carrying unquantifiable risk. The practical test is simple: would the prospect be surprised to see your email? If yes, your source is likely non-compliant, regardless of how well your copy performs.

2. Check your consent mechanics. If you have a newsletter signup or a lead magnet, look at the checkbox. Is it pre-ticked? That's a dark pattern. Is the opt-out buried in a footer? Also a dark pattern. Regulators are actively testing these flows now, and they're not just looking at the obvious violations. They're examining the entire user journey—the color contrast of the opt-out link, the number of clicks required to unsubscribe, the wording of your privacy notice. The new enforcement wave treats friction as evidence of bad faith. For cold email specifically, this means your unsubscribe mechanism must be as easy to find as your value proposition. If a recipient has to scroll, search, or click through multiple pages to remove themselves, you're building a case file against yourself.

3. Document your AI's decision-making. If you're using AI to score leads, write down what factors go into that score. If a prospect asks why they were contacted, you need to be able to answer. That's not just good practice. It's now a legal requirement for high-risk systems. The AI Act's transparency provisions are bleeding into GDPR enforcement, and the intersection is where your outreach lives. When your AI model decides that a "high-value prospect" is someone who visited your pricing page three times, that's a decision with legal consequences. You need a written record of the variables, the weighting, and the threshold for action. More importantly, you need to be able to explain why a specific individual was flagged—not in abstract terms, but with reference to their actual behavior. If your AI is a black box, you're not just risking a fine; you're risking a complete shutdown of your outreach operation while an investigation unfolds.

Healthcare data is a different game entirely

If your ICP includes healthtech, biotech, or any company that processes patient data, the rules just got stricter. The EDPB is prioritising enforcement in this sector, and the fines are substantial. This isn't just about the headline €5.88 billion figure—it's about the multiplier effect. A single violation involving health data can trigger cascading penalties under both GDPR and sector-specific regulations like HIPAA in the US, and the EU's proposed European Health Data Space (EHDS) will add another layer of auditability. For sales teams, the risk isn't the fine itself; it's the reputational damage and the chilling effect on future deals when a prospect's legal team flags your outreach as a compliance incident.

We've seen biotech seed rounds hit $80M in 2026, which means there's real money flowing into this space. But that money comes with scrutiny. Institutional investors are now running GDPR due diligence on their portfolio companies' vendor relationships, including sales tools. If your platform stores or processes any personal data—even email addresses—you're part of that supply chain. The practical implication: your outreach strategy must be defensible in writing, not just in intent.

Practical advice: don't reference patient data, clinical trial results, or any health-related information in your outreach. Even if it's publicly available, using it to target someone creates a special category data issue under Article 9. The EDPB's recent guidance clarifies that inferred health data—like "this executive works on oncology trials"—carries the same weight as explicit medical records. Stick to company-level signals: funding rounds, hiring plans, product launches. These are corporate facts, not personal data. And document your sourcing logic. If a prospect's legal team asks how you obtained their contact, you need a clear, auditable trail that shows you never touched protected categories. That's not just compliance—it's competitive advantage in a sector where trust is the real currency.

What we'd do next

Run a compliance audit on your current setup this week. Map every data source, every AI tool, and every consent flow. If you can't explain where a prospect's data came from, stop using it. That last point is non-negotiable, and it's where most small teams get burned. The GDPR doesn't care whether you bought a list from a reputable vendor or scraped it from LinkedIn; it cares about the legal basis for processing. If your CRM is a black box of imported contacts, you're already exposed. The €5.88 billion in fines isn't a distant threat—it's a signal that regulators are now auditing the provenance of data, not just its storage. So go beyond the surface map. Document the lawful basis for each contact, note the source URL or contract, and timestamp every consent refresh. That audit trail is your only defense if a supervisory authority comes knocking.

For the AI side, keep a human in the loop. That's not just a regulatory requirement. It's better sales practice. We built MiraReach so that no email goes out without a human pressing send. That's not a feature. It's a compliance posture. But think deeper about what "human in the loop" means under the GDPR's Article 22. If your AI scores leads or decides who to contact, that's automated decision-making with legal effects. You need a documented override mechanism, not just a review screen. And with dark patterns now a key enforcement target, your consent flows must be unambiguous. No pre-ticked boxes, no confusing double negatives, no "accept all" buried under a "manage preferences" link. Regulators are testing these interfaces, and they're fining for friction that nudges users toward consent. So audit your forms with fresh eyes. If a user has to work to say no, you've built a dark pattern. Fix it before a regulator does.

If you want to see how we handle this, give MiraReach a try. We'll show you the audit trail.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →