Updated December 2024

AI Compliance Penalty Database

Track every major AI and data privacy enforcement action worldwide. Learn from others' mistakes before regulators come knocking.

€3,497,241,800
Total Fines Tracked
16
Enforcement Actions
€233,149,453
Average Fine
4
Pending/Appealed
Showing 16 of 16 cases

LinkedIn

GDPREU (Ireland)Oct 24, 2024
€310,000,000
Final

Fined for using member data for behavioral analysis and targeted advertising without proper consent.

Uber

GDPRNetherlandsAug 26, 2024
€290,000,000
Final

Fined for transferring EU driver data to US without adequate safeguards after Schrems II ruling.

Dutch DPAData Privacy

Workday

Title VII / ADEAUnited StatesJul 12, 2024
TBD
Pending

Class action lawsuit alleging AI hiring tools discriminate against Black and older applicants. Case ongoing.

OpenAI

GDPRItalyMar 20, 2024
€15,000,000
Pending

Investigation into ChatGPT data collection practices. Temporary ban lifted after compliance measures implemented.

Italian GaranteData Privacy

TikTok

GDPREU (Ireland)Sep 15, 2023
€345,000,000
Final

Fined for failing to protect children's privacy and making accounts public by default for users aged 13-17.

iTutorGroup

NYC Local Law 144New York CityAug 9, 2023
$365,000
Final

First enforcement action under NYC LL144. Fined for using AI hiring tool that discriminated against older applicants.

EEOCAi Bias

Meta (Facebook)

GDPREU (Ireland)May 22, 2023
€1,300,000,000
Appealed

Record GDPR fine for transferring EU user data to US servers without adequate protection. Largest GDPR penalty ever issued.

Microsoft

GDPRFranceDec 22, 2022
€60,000,000
Final

Fined for dropping advertising cookies on Bing without user consent.

CNIL FranceTransparency

Clearview AI

GDPRFranceOct 20, 2022
€20,000,000
Final

Fined for illegally collecting and using biometric data of French citizens through facial recognition technology.

Clearview AI

UK GDPRUnited KingdomMay 23, 2022
£9,400,000
Final

Fined for collecting facial images of UK residents without consent and failing to have a lawful basis for processing.

UK ICOAi Bias

Google

GDPRFranceDec 31, 2021
€90,000,000
Final

Fined for making it difficult for users to refuse cookies on YouTube, violating consent requirements.

CNIL FranceTransparency

WhatsApp

GDPREU (Ireland)Sep 2, 2021
€225,000,000
Final

Fined for lack of transparency about how user data is shared with Facebook.

Amazon

GDPRLuxembourgJul 16, 2021
€746,000,000
Appealed

Fined for processing personal data in violation of GDPR, particularly regarding targeted advertising practices.

Luxembourg CNPDData Privacy

Marriott International

UK GDPRUnited KingdomOct 30, 2020
£20,400,000
Final

Fined for data breach affecting 339 million guest records worldwide, including 7 million UK residents.

UK ICOData Privacy

British Airways

UK GDPRUnited KingdomOct 16, 2020
£22,000,000
Final

Fined for data breach affecting 400,000+ customers. Original fine of £183M reduced due to COVID-19 impact.

UK ICOData Privacy

H&M

GDPRGermanyOct 1, 2020
€35,300,000
Final

Fined for extensive surveillance of employees, including recording personal details about health, family, and religion.

Hamburg DPAEmployment

Don't Become the Next Case Study

The average AI compliance fine is over €200M. Our assessments help you identify and fix compliance gaps before regulators find them.

Understanding AI Compliance Penalties

Key Regulations

  • GDPR (EU) - Up to €20M or 4% of global revenue
  • NYC Local Law 144 - $500-$1,500 per violation per day
  • Colorado AI Act - $20,000 per violation (effective Feb 2026)
  • EU AI Act - Up to €35M or 7% of global revenue
  • UK GDPR - Up to £17.5M or 4% of global revenue

Common Violations

  • AI Bias in Hiring - Discriminatory algorithms in recruitment
  • Data Transfers - Moving data without adequate safeguards
  • Lack of Transparency - Not disclosing AI decision-making
  • Missing Consent - Processing data without proper consent
  • Inadequate Security - Data breaches from poor protection