← Back to Blog €5.88B in GDPR Fines Since 2018—and Regulators Are Working Through Your Inbox Right Now

€5.88B in GDPR Fines Since 2018—and Regulators Are Working Through Your Inbox Right Now

EU GDPR reform is stalled until 2031, but €5.88B in fines says enforcement is live. Fix cookie dark patterns and AI legitimate interest now.

The EU's proposed GDPR amendments are not coming to save you. SME exemptions and cookie standardisation are drafted, debated, and parked until 2031 at the earliest. Meanwhile regulators have issued €5.88 billion in cumulative fines and are actively working through a backlog that includes B2B outbound operators. If you run your own pipeline, the legislation you need to worry about is the one already being enforced.

Reform is a 2031 problem. Enforcement is a this-quarter problem.

Here is the gap that catches founders. You read about SME exemptions and assume relief is coming. You read about cookie standardisation and assume the consent banner mess will sort itself out. Both are true in the long run. Neither changes what a data protection authority will ask you about if a complaint lands tomorrow.

The current enforcement priorities are narrow and specific. Dark patterns in cookie consent. Legitimate interest assessments for AI tools that process personal data. Those two categories are where the fines are landing, and they map directly onto how most small B2B teams run outbound.

We covered the fine totals and the SME exemption timeline in our breakdown of the €5.88B in GDPR fines and what changes when SME exemptions land. The short version: exemptions won't retroactively cover conduct from 2024 or 2025. If you're building a prospect list today, you're operating under the current rules, not the 2031 ones.

Cookie consent is the easiest place to get caught

Most B2B SaaS sites have a cookie banner that fails on at least one of three tests.

The first is pre-checked boxes. If your banner loads with analytics or marketing cookies already ticked, that is not consent. It is a dark pattern, and it is one of the specific things regulators have been told to prioritise. The fix is a single line of config in most consent management platforms. It takes ten minutes and removes an entire category of exposure.

The second is a reject button that is harder to find than the accept button. Same colour, same size, same position. If a user has to hunt for it, you have a problem. This is the pattern that generated the largest cookie-related fines in the last two years.

The third is consent that doesn't actually gate the script. You show the banner, the user clicks reject, and Google Analytics still fires because the tag manager trigger was never wired to the consent state. We have audited sites where this was true for eighteen months and nobody noticed.

None of this is glamorous. All of it is checkable in an afternoon. If you run a small team and you're doing outbound, your website is the first thing a prospect sees and the first thing a regulator checks.

Legitimate interest assessments for AI tools are the new frontline

This is the one that catches outbound operators specifically. Every AI tool in your stack that touches personal data needs a documented legitimate interest assessment, or a different lawful basis, and most teams have never written one.

Walk through your stack. Enrichment tools that append job titles and emails. Scoring models that rank prospects by likelihood to reply. Meeting brief generators that pull public information into a summary. Drafting tools that process the recipient's name, company, and role to personalise an email.

Each of those is processing personal data. Each needs a lawful basis. For most B2B outbound use cases, legitimate interest is the right basis, but it is not automatic. You have to document the assessment: what the interest is, why it's legitimate, whether the processing is necessary, and how you balanced it against the individual's rights.

We wrote about the ICO's AI code becoming enforceable and what a misconfigured scoring model costs in our piece on the ICO AI code and scoring model liability. The headline: a scoring model that makes decisions about individuals without a documented basis is exactly the kind of thing regulators are now equipped to investigate.

The practical version for a small team is a one-page document per tool. Not a legal treatise. A paragraph on the interest, a paragraph on necessity, a paragraph on balancing, and a date. Store it somewhere you can find it in five minutes if someone asks.

What actually changes for your outbound setup

Three things, in priority order.

What doesn't change: cold email itself is still lawful in the EU under legitimate interest for B2B, provided you're targeting business roles, the message is relevant to the recipient's function, and you offer a clear opt-out. The legislation hasn't moved on that. The enforcement has.

We've seen teams panic and switch to consent-only models, which kills outbound volume for no compliance benefit. That's the wrong trade. The right trade is documenting the basis you're already relying on.

What we'd do next

If you're running outbound into the EU or UK, spend one afternoon on the cookie banner and one afternoon on the legitimate interest assessments. That covers the two categories regulators are actively pursuing. The 2031 reform will arrive eventually, and when it does, the teams with clean documentation will have the easiest transition.

If you want a tool that keeps the human in the loop on every send and doesn't auto-fire emails you haven't reviewed, give MiraReach a try. We built it for exactly this kind of operator.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →