← Back to Blog GDPR Fines Hit €5.88B in 2024 Alone—But the EU Just Carved Out an Exemption for Your Firm

GDPR Fines Hit €5.88B in 2024 Alone—But the EU Just Carved Out an Exemption for Your Firm

GDPR fines hit €5.88B cumulative, with €1.2B in 2024 alone. The EU proposes SME exemptions and cookie banner rules. Here's what changes for B2B outbound.

GDPR fines have crossed €5.88B cumulative. Enforcement added €1.2B in 2024 alone. And the EU is now proposing legislation that would exempt smaller businesses from parts of the regime while standardising cookie banners across the bloc. If you run outbound, this is the most consequential compliance shift since 2018.

Here's the short version: the fines aren't slowing down, but the rules might get simpler for teams your size. The catch is that AI-related processing and dark pattern enforcement are getting sharper, not softer.

The €5.88B number is not a scare tactic. It's a trend line.

We've written about this before. The cumulative fine total crossed €5.88B and the enforcement curve hasn't flattened. What changed in 2024 is who's getting hit.

It used to be the Metas and Googles of the world. Now it's mid-market companies with 200-person sales teams and a CRM full of scraped contacts. The Irish DPC, the Spanish AEPD, and the Dutch AP have all accelerated their pipelines. Spain alone issued more fines in 2024 than in the previous three years combined.

The pattern is consistent. Regulators aren't going after the biggest fish anymore. They're going after the easiest cases. And the easiest cases are companies that bought a list, enriched it with AI, and sent cold email without a lawful basis.

That shift matters because it changes the economics of enforcement. A case against a large platform takes years, involves multiple supervisory authorities, and often ends in appeals that stretch the timeline further. A case against a mid-market outbound team is procedurally simple: the complainant kept the email, the CRM export shows the source, and the lawful basis is either documented or it isn't. Regulators can close these files in months, which is why complaint-driven enforcement has become the dominant mechanism. One recipient who knows how to file with their national authority can trigger a full inquiry.

The proposed SME exemptions don't change this calculus as much as founders hope. Exemptions tend to target record-keeping and impact-assessment obligations, not the core requirement that processing have a lawful basis. A smaller company may face a lighter procedural burden, but sending cold email to scraped contacts without consent or a documented legitimate-interest assessment remains exposed. The cookie banner standardization proposal is similarly narrow — it addresses consent fatigue at the front door, not the provenance of the data behind it.

Read the trend line correctly: the total is a lagging indicator of complaints filed years ago. The leading indicator is how many of your contacts could produce a valid complaint if they chose to.

What the SME exemptions actually cover

The proposed amendments would create a lighter-touch regime for businesses under 250 employees. The specifics are still being negotiated, but the direction is clear:

That last point matters most for outbound. Right now, if you're running a website with any tracking, you're navigating 27 different interpretations of what "informed consent" means. A German court says one thing. A French court says another. The standardisation would give you one rulebook.

It's worth being precise about what the exemptions don't do, because the framing around "SME relief" invites over-reading. The 250-employee threshold is a proxy, not a shield. A two-person operation processing special category data at scale still triggers the full DPO requirement. A solo founder running automated profiling still sits inside the high-risk perimeter. The waiver on Article 30 records, meanwhile, is conditional rather than absolute — the moment processing becomes "high-risk," the documentation obligation snaps back, and you'll need records you may not have kept. In practice, that means the exemption rewards companies that can demonstrate low-risk processing, not companies that simply stay small.

But here's the trade-off. The exemptions don't cover AI processing. If you're using enrichment tools to score inboxes or draft personalised emails, you're still in scope. The legislation explicitly carves out automated decision-making and profiling as high-risk activities regardless of company size. For outbound teams, that carve-out is the operative clause — it means the compliance burden follows the technique, not the headcount. A 12-person startup running AI-assisted lead scoring faces a materially heavier regime than a 200-person firm doing manual outreach. The practical implication: audit your stack for anything that scores, ranks, or generates content about a person before assuming the SME exemption applies to you.

AI processing is the next enforcement frontier

We've been tracking this since the ICO's AI code became law. The pattern is consistent across regulators: if you're using AI to make decisions about people, you need to be able to explain how.

For outbound, that means three things:

First, enrichment is processing. When you run a prospect list through an AI tool that infers job title, company size, or buying intent, you're processing personal data. You need a lawful basis. Legitimate interest works, but you have to document it.

Second, scoring is profiling. If your tool assigns a score to a prospect based on their behaviour or attributes, that's automated decision-making under Article 22. You need to be able to explain the logic and offer a human review path.

Third, drafting is not exempt. Even if a human presses send, if an AI drafted the email based on personal data, the processing still happened. The human-in-the-loop doesn't erase the compliance requirement.

We built MiraReach with this in mind. Every draft is generated from data you've already lawfully collected, and nothing sends without a human clicking the button. But we're not lawyers, and neither is your CRM vendor. If you're running outbound at scale, get a DPA in place with every tool in your stack.

Dark patterns are the other shoe

The same legislative package includes provisions on dark patterns in consent interfaces. Pre-checked boxes, confusing opt-out flows, and "accept all" buttons that are three times the size of "reject all" are all in scope. The significance is structural: dark patterns sit at the intersection of the two enforcement tracks. A non-compliant consent banner is both a transparency failure under the GDPR and, increasingly, an unfair commercial practice under consumer protection law, which means the same interface can draw scrutiny from two regulators with different mandates and different penalty schedules.

This matters for outbound because your landing pages and lead capture forms are part of the same compliance surface. If you're running a webinar registration page with a pre-checked consent box for marketing emails, you're exposed. The pre-checked box enforcement has already started in Spain and the Netherlands.

The fix is simple. Uncheck the box by default. Make the reject button the same size as the accept button. Don't bury the opt-out in a sub-menu. These aren't hard changes, but they require someone to actually look at your forms.

Two process points are worth building into your review cadence. First, consent must be granular: separate purposes need separate affirmative actions, so a single "I agree to the terms and to receive marketing" checkbox fails on its face. Second, you need a record of what was shown and when. Regulators assess the interface as it existed at the moment of consent, not as it looks after you fix it, so version your forms and keep dated screenshots.

For small teams, the practical implication is that form hygiene is now a recurring maintenance task rather than a one-time launch item. Audit every capture point — demo requests, newsletter signups, gated content, event registrations — on a fixed schedule, and treat any change to a form as a change to your compliance posture. The cost of a five-minute review is trivial next to the cost of defending a consent claim.

What we'd do next

If you're running outbound to EU contacts, audit your stack this week. Check every tool that touches personal data. Confirm you have a lawful basis for processing. And document it. That means mapping the full path a prospect's data takes — from the moment a lead enters your CRM, through enrichment and sequencing tools, to the inbox it lands in. Most small teams discover two or three vendors they forgot were processing data on their behalf. Each one is a potential liability if your lawful basis doesn't extend to it.

The SME exemptions are coming, but they won't cover AI processing or dark patterns. The draft language carves out lighter obligations for smaller entities on record-keeping and certain consent requirements — not on the core principles of lawfulness, fairness, and transparency. If your outreach relies on automated scoring, intent signals, or AI-drafted personalization, you're still in scope regardless of headcount. The same applies to anything a regulator could read as manipulative consent design.

So the practical move is to separate what the exemptions might actually relieve from what they won't. Assume the core obligations stay. Build your process as if no exemption applies, then treat any relief as margin rather than foundation. That posture also protects you from the cookie banner standardization effort — if consent capture becomes uniform across the EU, the differentiator shifts from how you present the banner to whether you can prove what was consented to and when.

The teams that get ahead of this now will be the ones still sending when the next enforcement wave hits. If you want to see how MiraReach handles compliance-aware outbound, give MiraReach a try. We don't send anything without your finger on the button.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →