← Back to Blog €5.88B in GDPR Fines Since 2018—and Spain's Enforcement Just Accelerated. Here's What Changes for Your Outbound.

€5.88B in GDPR Fines Since 2018—and Spain's Enforcement Just Accelerated. Here's What Changes for Your Outbound.

GDPR fines hit €5.88B. New EU proposals expand SME exemptions and clarify AI legitimate interest. Here's what changes for your outbound.

Cumulative GDPR fines just crossed €5.88 billion across 2,245 penalties since May 2018. Spain leads enforcement frequency. The European Commission's Q4 2025 Digital Package proposes SME exemptions, mandatory one-click cookie reject, and AI legitimate interest clarification. Implementation lands in 2031 or later. Here's what actually changes for your outbound today.

The fine numbers are real, but the risk profile shifted

€5.88 billion sounds terrifying. It should. But look closer at where the money lands. The biggest penalties hit Big Tech: Meta, Amazon, TikTok. The frequency leader is Spain, but most of those are small, repeatable violations from local businesses ignoring basic data subject requests. That divergence matters because it reveals the regulator’s actual enforcement logic: they pursue scale and systemic neglect, not the isolated misstep of a lean operator. The GDPR’s tiered fine structure—up to €10 million or 2% of global turnover for administrative breaches, versus €20 million or 4% for core data-processing failures—already signals that intent and severity are weighted heavily. What the headline number obscures is that the overwhelming majority of investigations never reach a fine at all; they end in reprimands, orders to comply, or quiet settlements.

For a founder sending 200 cold emails a week, the realistic risk isn't a nine-figure fine. It's a complaint-driven investigation that eats your week and forces you to prove consent and legitimate interest documentation. That's the cost that hurts. The 2026 amendments under discussion—particularly the proposed clarifications on legitimate interest and the “soft opt-in” for B2B outreach—could actually narrow this exposure, but only if you’ve built the paper trail now. Regulators are increasingly asking for evidence of a “balancing test” at the moment of collection, not retroactive justifications. If your CRM lacks a field for source, timestamp, and lawful basis per contact, you’re already behind the curve.

We track this because our users ask. The pattern is consistent: enforcement targets companies that ignore deletion requests, buy scraped lists, or send to people who never had any connection to the business. If you're doing manual, targeted outreach to decision-makers who fit your ICP, you're not the target. But the proposed amendments also hint at stricter documentation duties for automated outreach—even at low volume. The risk profile has shifted from “will I get fined” to “can I prove my process under audit.” That’s a lower bar, but it’s a non-negotiable one.

The Q4 2025 Digital Package: what the Commission actually proposed

The European Commission dropped three proposals in late 2025 that matter for anyone running outbound. They're not law yet. Expect implementation in 2031 or later. But the direction tells you where to build your compliance muscle now.

First, expanded SME exemptions. Companies under 250 employees get lighter administrative burdens. That's most of our readers. The catch: the exemption applies to record-keeping and documentation, not to the core principles. You still need a lawful basis for processing. You still need to honour opt-outs. In practice, this means your data mapping and retention schedules become internal discipline rather than auditable artefacts. The real risk is that a lighter administrative burden also means fewer formal checkpoints, which can lead to sloppy consent logs or untracked data flows. If you're a 40-person team, treat this as permission to simplify your paperwork, not to skip the underlying analysis.

Second, mandatory one-click cookie reject. This kills the dark-pattern cookie banners that make everyone click "Accept" out of frustration. For B2B outbound, this matters less directly, but it signals the Commission's mood: friction for the user is a violation, not a feature. The deeper implication is for your own website and any lead-generation forms. If the Commission is willing to mandate symmetric choice for cookies, expect similar logic to extend to consent checkboxes on gated content, webinar registrations, and demo requests. Build your forms now with the assumption that pre-ticked boxes and multi-step opt-outs will be deemed unlawful within the next enforcement cycle.

Third, and most relevant for us: clarification on AI legitimate interests. The proposal explicitly recognises that processing personal data for AI model training and inference can be a legitimate interest. That's a green light for AI-assisted prospecting tools that score inboxes or draft personalised lines. But it comes with conditions: transparency, human oversight, and the right to object. The transparency requirement is the one that will bite. You cannot simply claim legitimate interest in your privacy policy and move on. You need to document the specific AI use case, the categories of data involved, and the balancing test you ran. For a small team, that means building a one-page AI processing register per tool you use, not a 40-page legal memo. The right to object also has operational teeth: if a prospect asks you to stop using their data for model training, you need a mechanism to exclude them from your training set, not just from your outreach list. That is a technical constraint, not a legal one, and it will shape which vendors you choose.

What the AI legitimate interest clarification means for your stack

If you use AI tools to score inboxes or draft email variations, the Commission's proposal gives you a clearer legal footing. The key phrase is "human oversight." That aligns with how we built MiraReach: the AI drafts, you press send. No auto-send, no autonomous sequences.

This is the line in the sand. Tools that auto-send personalised emails at scale without human review are building on sand. The moment a complaint lands, they can't demonstrate oversight. You can. That's your defence. But the clarification cuts deeper than liability avoidance. It redefines where the "processing" actually occurs in your stack. When a model scores a lead based on behavioural signals, that's profiling under Article 22. When it generates subject lines from historical reply data, that's automated decision-making with legal effects — arguably. The legitimate interest basis only holds if your impact assessment shows the processing is necessary, proportionate, and balanced against data subject rights. A vague "we use AI for outreach" line in your privacy policy won't survive a supervisory authority's scrutiny. You need a documented balancing test that names the specific model, the data categories it touches, and the safeguards you've implemented.

Practical steps to document now:

That last point is the one that saves you. Fast opt-out processing is the cheapest insurance you can buy. But pair it with a retention schedule. If you keep prospect data indefinitely "just in case," your legitimate interest claim weakens proportionally. Set a 12-month maximum for inactive leads, and purge records automatically. The regulators aren't looking for perfect compliance — they're looking for demonstrable intent. Your documentation trail is the only evidence that intent exists.

Spain's enforcement frequency is a warning, not a blueprint

Spain's AEPD issues more fines than any other EU regulator. Most are small, but they're frequent. The pattern: complaints from individuals who asked for data deletion and got ignored, or who received unsolicited marketing without any prior relationship. This isn't a sign that the AEPD is uniquely aggressive; it's a sign that they've built a low-friction complaint pipeline and a penalty structure that punishes volume over severity. For a small operator, that's actually the worst possible combination. A single €500 fine for a cold email might not hurt your P&L, but the administrative drag of responding to a complaint, proving your legitimate interest assessment, and potentially adjusting your workflow is where the real cost lives. And because the AEPD publishes its decisions, each fine becomes a data point that plaintiffs' firms and competitors can cite in future complaints against you.

For your outbound, the lesson is simple. If you're emailing someone who never heard of you, you need a legitimate interest argument that holds up. That means relevance. A personalised email about their specific role at their specific company, referencing something they published or a problem they likely face, is defensible. A spray-and-pray template to 5,000 random addresses is not. The distinction isn't just legal; it's operational. When you can articulate why each recipient is a legitimate prospect, you can also document that reasoning in a legitimate interest assessment, which is exactly what regulators ask for when a complaint lands. Without that documentation, you're relying on a vague "we thought it was relevant" defense, which rarely survives scrutiny.

We've seen this play out with a customer running outbound to UK accountancy firms. They switched from a purchased list to manual research, cut volume by 60%, and doubled reply rates. The compliance risk dropped to near zero because every prospect had a documented reason for contact. That's the real blueprint: not chasing the AEPD's enforcement patterns, but building a process where each email is individually justifiable. The frequency of Spanish fines is a warning about what happens when you treat consent as an afterthought, not a template for how to operate.

What to do between now and 2031

The proposals won't become law for years. But the direction is clear: more exemptions for small operators, more friction for mass senders, more clarity for AI-assisted human-reviewed outreach. The strategic implication is that you should not wait for the final text to adjust your compliance posture. Regulators are already signalling that enforcement will reward demonstrable intent, not retroactive fixes. The proposed amendments, particularly around legitimate interest and the界定 of "automated decision-making," suggest that the burden of proof will shift toward documented, repeatable processes rather than one-off consent checkboxes.

Build your process as if the 2031 rules were already in force. That means treating every contact as a relationship to be earned, not a lead to be converted. The AI Act's risk-tiered framework will likely bleed into GDPR enforcement, meaning that high-volume, low-personalisation outreach will be presumed higher risk. Conversely, low-volume, high-context outreach will benefit from a lighter touch. This is not a loophole; it is a structural incentive toward quality over quantity.

Concretely, this requires a few operational shifts. First, segment your lists by engagement history and data source, not just by job title. Second, maintain a clear audit trail for every legitimate interest assessment, including the specific context of each prospect's role and your product's relevance to their stated business problem. Third, build a suppression mechanism that is both immediate and verifiable—not just a database flag, but a timestamped log that would survive a supervisory authority's inspection.

Keep your lists small and researched. Use AI to draft, not to blast. Document your legitimate interest reasoning. Honour every opt-out immediately. And never send anything you wouldn't put your name on in a public forum. The 2031 framework will likely codify what best practice already demands: that AI-assisted outreach is defensible only when a human can explain, justify, and take responsibility for each message.

If you want to see how we handle this in practice, give MiraReach a try. The AI drafts, scores, and prepares briefs. You stay in control of every send.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →