Media, telecoms, and broadcasting companies absorbed 70% of the fines imposed on companies under the GDPR through March 2025, more than any other industry for the fourth year running, according to CMS’s 2025 GDPR Enforcement Tracker Report. Cookie and tracking consent failures sit close to the center of that exposure: the single biggest violation category tracked in the same report, insufficient legal basis for processing, covers exactly the kind of consent gap a cookie policy and banner exist to close.

Enforcement risk is not spread evenly. Some industries get fined constantly and for large sums, others barely register, and a separate survey of privacy professionals shows program maturity following a similar uneven pattern. Below is what the data actually says about which industries carry the most cookie and consent risk in 2026, and which ones are best prepared for it.

Which industry gets fined the most under GDPR in 2026?

Media, telecoms and broadcasting take most GDPR fines 70% of GDPR fines hit media,telecoms and broadcasting firms

Media, telecoms, and broadcasting is, in CMS’s own words, “one of the most fined sectors,” making up 70% of the fines imposed on companies under the GDPR. CMS’s Data Protection Group has now flagged this sector as the highest-exposure industry for four consecutive editions of its Enforcement Tracker Report, pointing to the large platforms and broadcasters in the group and the sheer relevance of personal data to their business models.

Employment ranks second in fines by sector, driven by a EUR290 million Dutch DPA fine tied to unlawful employee monitoring records. Industry and commerce, real estate, healthcare, accommodation and hospitality, transportation and energy, and the public sector round out the rest of the list, each with a distinct failure pattern: healthcare gets fined mainly for weak technical security measures, accommodation and hospitality for unlawful video surveillance, and transportation and energy for abusive marketing practices flagged by consumer complaints.

If your business sits in media, broadcasting, or a tech platform that monetizes personal data, you are, statistically, in the sector regulators watch hardest.

How concentrated are GDPR fines within the top sector?

A 70% share for one sector out of roughly a dozen tracked categories is a striking concentration, not a narrow lead.

Share of GDPR fines by sector, through March 2025 7030Media, telecoms and broadcasting70All other tracked sectors combined30

Figure 1: Sector share of GDPR fines imposed on companies. Source: CMS GDPR Enforcement Tracker Report 2025, 6th edition.

Warning

CMS’s sector chapters describe rankings and shares in prose rather than publishing a full percentage breakdown for every sector, so this figure is a two-way split built directly from the one number the report states explicitly. Treat the “all other sectors” 30% as a residual, not a verified aggregate of individually confirmed sector shares.

Geography compounds the picture. Spain has led every country on the number of fines issued for six consecutive years, while Ireland, Luxembourg, and the Netherlands lead on total fine amount, a direct reflection of the record fines those regulators have imposed on large tech and platform companies headquartered in their jurisdictions.

What actually triggers a GDPR fine, and how does it connect to cookies?

Across the 2,245 fines CMS recorded through March 2025, worth EUR5.65 billion combined, one violation type outranks every other: insufficient legal basis for data processing, with 669 fines averaging EUR2.9 million each.

Top GDPR violation types by fine count, through March 2025 Insufficient legal basis669Non-compliance, general principles644Insufficient security measures (TOMs)418

Figure 2: Leading GDPR violation categories by fine count. Source: CMS GDPR Enforcement Tracker Report 2025.

“Insufficient legal basis” is the catch-all category for processing personal data without a valid reason under GDPR Article 6, and consent is the legal basis almost every cookie banner exists to establish. CMS’s own sector notes make the link explicit: in the finance, insurance, and consulting sector, “the highest fines were all imposed due to a lack of adequate internal compliance measures to ensure a sufficient legal basis for the processing of customer data. In each case, the controllers had failed to obtain effective consent for the data processing.” A cookie policy that accurately discloses what is collected and why is one half of that compliance chain; a banner that records a genuine, revocable choice is the other.

Two of 2025’s largest, most publicized fines were explicitly about cookies, not general data handling, and both sit in industries outside the media/telecom leader.

Figure 3: The minimum test regulators are applying to cookie consent in 2025-2026 enforcement. Source: synthesized from CNIL and CMS enforcement decisions cited in this article.

France’s CNIL fined Shein’s operating company, Infinite Styles Services Co. Limited, EUR150 million in September 2025 specifically for unlawful cookie use, a case CMS places within the industry and commerce sector. That sector’s overall fine total, EUR778 million, is itself dominated by one repeat offender: fines against the Amazon Group make up more than 80% of the sector’s entire fine volume. CNIL separately fined Google EUR325 million in 2025, also tied to cookies set without valid consent; our cookie consent statistics for 2026 covers that decision and the broader accept/reject-rate data in full.

The pattern holds across both cases: regulators are not fining companies for having cookies, they are fining them for setting cookies before a real choice is recorded and for making rejection harder to find than acceptance. A Cookie Policy Generator that documents purpose and retention up front, paired with a banner that offers an equally prominent reject option, addresses both failure points these fines describe.

Which industries have the strongest privacy programs heading into 2026?

Enforcement data shows where regulators are looking. A separate, self-reported benchmark shows where organizations think they stand, and the two pictures do not fully overlap.

TrustArc 2026 Global Privacy Index by industry 020406080%64Financial services62Technology53Global average45Retail

Figure 4: Privacy program maturity by industry. Source: TrustArc 2026 Global Privacy Benchmarks Report, n=1,844 professionals across 17 industries.

Financial services ranks first of the 17 industries TrustArc surveyed for its 2026 Global Privacy Benchmarks Report, scoring 64%, with technology close behind at 62%. Retail, the sector that includes Shein’s cookie fine above, ranks 11th of 17 at 45%, nine points under the global average. The overall Global Privacy Index fell to 53% in 2026 from 61% in 2025, and TrustArc attributes much of that drop to AI adoption outpacing governance: organizations with fully implemented consent management, alongside data inventory and data subject request handling, score an average of 75%, roughly four times higher than organizations with partial, fragmented programs.

Consent management sitting inside that top-tier bundle is the detail worth underlining. It means the same operational discipline that keeps a cookie policy current and a banner’s reject option working is directly, measurably tied to the privacy scores that separate the top third of TrustArc’s respondents from the 38% now scoring in the failing range. How a banner performs at the point of decision matters too; see our data on how long users spend on cookie banners for what that moment actually looks like for visitors. A device-level breakdown of consent behavior is a natural next cut of this data, though we don’t yet have a dedicated post on that split to link to here.

GDPR fines and privacy maturity by industry: a side-by-side view

CMS’s Enforcement Tracker groups companies by regulatory sector; TrustArc surveys a separate set of 17 self-reported industries. The two taxonomies are not identical, so treat the table below as context placed side by side, not a single ranked list.

IndustryGDPR fine exposure (CMS, through Mar. 2025)2026 Privacy Index (TrustArc)2025 cookie-specific case
Media, telecoms and broadcasting70% of all GDPR fines, highest for 4 years runningNot separately surveyedGoogle, EUR325M (CNIL)
Industry and commerce (incl. retail)EUR778M sector total; 80%+ from one companyRetail: 45% (11th of 17)Shein operator, EUR150M (CNIL)
Financial services, insurance and consulting4 fines over EUR1M in 2025 ETR vs. 2 the year before64% (1st of 17)None in this data set
Technology (cross-sector)Frequently the controller behind media-sector fines62% (2nd of 17)See Google case above

The gap in the last two rows is the headline takeaway: the industries with the most mature, best-scoring privacy programs are not the ones absorbing most of the GDPR fine total. That mismatch is exactly why a documented, current cookie policy matters even for a well-resourced privacy team, since maturity on paper does not automatically prevent a single consent-flow mistake from turning into a nine-figure fine.

How has GDPR enforcement escalated since 2018?

Figure 5: Key GDPR enforcement milestones. Sources: CMS GDPR Enforcement Tracker Report 2025 and 2025/2026 Numbers and Figures update, CNIL decisions, TrustArc 2026 Global Privacy Benchmarks Report.

Seven years in, enforcement has not slowed down. CMS’s most recent public count, current as of March 2026, puts the running total at 2,685 fines worth EUR6.11 billion, an increase of 440 fines and roughly EUR488 million over the prior year’s count. The direction is consistent even as the exact totals move with each quarterly update.

The Bottom Line

The industries that get fined most under the GDPR and the industries that score best on self-reported privacy maturity are, for the most part, different lists. Media, telecoms, and broadcasting absorbs 70% of GDPR fines despite plenty of resources to spend on compliance, while financial services leads the maturity rankings without being the most-fined sector. The connective tissue across both data sets is consent: the top violation category by fine count is a legal-basis failure, the two largest named cookie fines of 2025 were both about consent collected badly or not at all, and TrustArc ties strong consent management directly to a 75% average score versus a fragmented program’s much lower one. Whatever industry a site operates in, a cookie policy that accurately documents purpose and retention, paired with a banner that makes reject as easy to find as accept, addresses the specific failure regulators keep citing.

Frequently Asked Questions

Which industry gets fined the most under GDPR? Media, telecoms, and broadcasting. The sector makes up 70% of the fines imposed on companies under the GDPR and has led every other sector for four consecutive years, according to CMS’s 2025 GDPR Enforcement Tracker Report.

What is the most common reason companies get fined under GDPR? Insufficient legal basis for data processing, which triggered 669 fines averaging EUR2.9 million each through March 2025 (CMS, 2025). This category covers exactly the kind of consent failure a cookie banner and cookie policy are meant to document and prevent.

Which industries have the strongest privacy programs in 2026? Financial services leads TrustArc’s 2026 Global Privacy Benchmarks at 64% of 17 surveyed industries, with technology second at 62%. Retail trails at 45%, and the overall Global Privacy Index fell to 53% in 2026, down from 61% in 2025.

Are cookie banners still a major source of GDPR fines in 2026? Yes. France’s CNIL fined Google EUR325 million and Shein’s operating company EUR150 million in 2025, both explicitly for placing cookies without valid consent, making cookie enforcement one of the clearest through-lines in the 2025 fine data.

Sources and References

  1. CMS Data Protection Group. (2025). “GDPR Enforcement Tracker Report,” 6th edition. 2,245 fines recorded, cutoff March 1, 2025.
  2. CMS Data Protection Group. “Numbers and Figures,” GDPR Enforcement Tracker Report. Live update, cutoff March 1, 2026: 2,685 fines, EUR6.11 billion.
  3. TrustArc. (2026). “Privacy Capability Struggles to Keep Pace With AI Adoption.” 7th Annual Global Privacy Benchmarks Report, released May 6, 2026, n=1,800+ professionals.
  4. TrustArc. (2026). “State of Privacy Management in Financial Services Industry Brief.” n=244 of 1,844 total respondents.
  5. TrustArc. (2026). “State of Privacy Management in Retail Industry Brief.” n=154 of 1,844 total respondents.
  6. CNIL. (2025). “Cookies Placed Without Consent: Shein Fined 150 Million Euros.” Official regulator decision, September 9, 2025.
  7. CNIL. (2025). Google cookie consent decision, 325 million euros. Official regulator decision.

Note: All figures verified as of July 2026. The CMS fine totals and TrustArc index scores are both periodically-updated benchmarks rather than fixed historical facts; each is cited here with its own stated cutoff date (March 2025, March 2026, and May 2026 respectively), and both are expected to move again at each publisher’s next annual update.