← Back to Blog GDPR Fines Hit €5.88B—But the Real Threat to Your Cold Email Isn't the Penalty, It's the AI Scrutiny

GDPR Fines Hit €5.88B—But the Real Threat to Your Cold Email Isn't the Penalty, It's the AI Scrutiny

GDPR fines hit €5.88B cumulative, with €1.2B in 2024 alone. Proposed SME exemptions and cookie standardisation are coming. Here's what B2B sellers should do now.

GDPR fines have crossed €5.88B cumulative. Enforcement added €1.2B in 2024 alone. The EU is now proposing SME exemptions and standardised cookie banners, but the same package tightens scrutiny on AI-driven processing and dark patterns. If you run outbound, the legislation is moving in two directions at once.

The headline number is not the story

€5.88B sounds like a rounding error for Big Tech. It is not a rounding error for a five-person sales team. The fines that matter to founders are not the headline cases against Meta or TikTok. They are the €20k to €200k penalties handed to mid-market companies for things like running enrichment on scraped data without a lawful basis, or pre-ticking a consent box on a demo request form.

We have written before about how regulators are targeting AI enrichment and pre-checked boxes. That trend has not slowed. If anything, 2024 enforcement data shows data protection authorities are getting more comfortable with mid-tier penalties. They are cheaper to litigate, they generate press, and they do not require a decade of appeals.

The €1.2B figure for 2024 is not evenly distributed. A handful of large fines dominate the total. But the count of smaller enforcement actions is rising. That is the number to watch if you are a founder running your own pipeline.

What the SME exemptions actually cover

The proposed amendments would ease compliance for small and medium enterprises. The details matter more than the headline.

Under the current draft, SMEs would get:

None of this is law yet. The legislative process is slow, and the European Parliament has already signalled it wants the AI-related provisions strengthened before it signs off. We covered the timeline in our earlier piece on GDPR reform stalling until 2031. That timeline has not moved.

So the practical position for a founder in 2026 is this: assume the exemptions will land eventually, but do not build your outbound process around them today. The enforcement regime you are operating under right now is the one that will fine you.

Cookie banner standardisation is the quiet win

The cookie banner standardisation proposal is less exciting than SME exemptions but more immediately useful. Right now, every EU member state interprets consent requirements slightly differently. A banner that passes in Germany may fail in France. That is a nightmare for any company running a website with EU traffic.

Standardisation would create a single accepted format. That means one banner, one consent flow, one set of records. For B2B sellers running demo request forms and gated content, this removes a genuine operational headache.

But standardisation cuts both ways. A standardised banner makes it easier for regulators to spot non-compliant ones. If your current banner uses a pre-ticked box, a confusing reject button, or a colour scheme that makes "accept all" the only visible option, you are exactly the target the dark pattern enforcement provisions are designed to catch.

AI processing is where the new scrutiny lands

The proposed amendments do not loosen AI-related processing rules. They tighten them. Specifically, the draft language calls for:

Explicit disclosure when personal data is used to train or fine-tune AI models. Clear lawful basis for automated scoring or ranking of individuals. A right to human review for decisions made by automated systems that have legal or significant effects.

For outbound sales, this touches two things directly. First, any AI tool that scores or ranks prospects based on personal data needs a documented lawful basis. Second, any AI tool that drafts personalised emails using personal data needs to be covered by your privacy notice and, in some interpretations, by explicit consent.

We built MiraReach around a human-presses-send model partly for this reason. The AI finds prospects, scores inboxes, drafts emails, and prepares meeting briefs. It does not send. That is not just a product decision. It is a compliance decision. When a human reviews and sends, the automated processing is advisory, not decisive. That distinction matters under the proposed rules.

If you are using a tool that auto-sends, you should be asking your vendor some uncomfortable questions about their lawful basis for processing. And you should be documenting your own.

What to do before the legislation lands

You do not need to wait for the final text. Three things are worth doing now.

Audit your consent flows. Every form, every banner, every gated asset. If a box is pre-ticked, untick it. If rejecting cookies is harder than accepting them, fix it. If your privacy notice does not mention AI processing, add it.

Document your lawful basis for outbound. Legitimate interest is the usual answer for B2B cold email, but it requires a legitimate interest assessment. If you do not have one, write one. It does not need to be long. It needs to exist.

Check your enrichment sources. If you are buying prospect data from a vendor, you need to know where they got it and whether they had a lawful basis to share it. "We bought a list" is not a defence. We have written about how US state privacy laws create a similar patchwork, and the same principle applies: you own the compliance risk, not your data vendor.

The SME exemptions, when they arrive, will reduce the administrative burden. They will not eliminate the need for a lawful basis. They will not protect you from dark pattern enforcement. And they will not cover AI processing, which is the area regulators are most actively expanding.

What we would do next

If you are running outbound to EU prospects, spend an hour this week documenting your lawful basis and auditing your consent flows. That hour is cheaper than a fine. If you want a tool that keeps a human in the loop on every send, give MiraReach a try. We built it for exactly this regulatory environment.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →