Or: why most of the panic proved unnecessary — and which issues still matter
Remember May 2018? A GDPR apocalypse appeared to be approaching. Lawyers predicted waves of legal claims, consultants sold expensive emergency packages and every other newsletter seemed to announce the end of the internet.
Almost seven years later, it is time for an honest assessment. What actually happened? The internet is still here, most businesses survived and those headline-grabbing multimillion-euro fines deserve some context.

After the panic: some surprising figures
The feared flood of enforcement never arrived on the scale many expected. The Bitkom surveys cited in the original article suggest that around 20% of companies report at least one data-protection incident within a year, while only a small proportion result in a fine.
An analysis cited in the original article puts the average published German GDPR fine in 2018 at roughly €8,500 — far below the multimillion-euro maximums often used in headlines.
For context:
- Maximum penalties highlighted in 2018: up to €20 million
- Average published fine cited for SMEs: €8,500
- Common lower-level outcome: a warning without a fine
Across the published figures for recent years, Germany recorded roughly 1,600 to 1,700 known cases..
Even allowing for cases that were not published,
the number is small relative to the total business population.
Germany has more than 3.5 million businesses, so formal fines remain comparatively rare. Rare does not mean impossible, however — the risk depends heavily on the nature of the breach.
📊 Table — GDPR fines in Germany, 2018–2023
| Year | Number of fines | Total value of fines (€m) | Reported data breaches |
|---|---|---|---|
| 2018 | around 40 | — | — |
| 2019 | 187 | > 25 | — |
| 2020 | 284 | 48,15 | 26.057 |
| 2021 | 373 | 2,11 | 13.890 |
| 2022 | 453 | 5,81 | 21.170 |
| 2023 | 357 | 4,94 | 24.749 |
- Figures published by German state authorities or collated by DSGVO-Portal.de. Data-protection law firms and DSGVO-Portal.de
- Some totals are reported only as minimum values because not every authority published complete figures. The figure cited for 2020 is €48.15 million. dsgvo-portal.de+1
- Reported data breaches do not automatically result in fines.
- The figure of approximately 40 cases in 2018 is based on the cited Wikipedia summary. Wikipedia+1
- For 2019, the cited DSGVO-Portal review records 187 fines totalling more than €25 million. dsgvo-portal.de
- The 2020 figures cited from DSGVO-Portal comprise 26,057 reports, 284 fines and €48.15 million in penalties. dsgvo-portal.de+1
- For 2021, the cited minimum is 373 fines totalling €2.11 million. dsgvo-portal.de
- For 2022, the cited figures are 453 fines totalling €5.81 million. dsgvo-portal.de+1
- For 2023, the cited figures are 357 fines totalling €4.94 million. dsgvo-portal.de
Note: The original source did not provide a reliable complete total for 2024.
According to the figures in the table, fewer than 1,700 GDPR fines were published in Germany between 2018 and 2023. Set against roughly 3.5 million businesses, that equates to approximately one fine for every 2,000 companies over the period — although this simple comparison does not measure the risk faced by any individual organisation.
What enforcement authorities tend to prioritise
Several years of enforcement activity now provide a clearer picture of the issues most likely to attract attention. The pattern is more nuanced than many of the warnings circulated in 2018 suggested.
Issues that genuinely matter:
1. Failing to report a qualifying data breach — If a breach is legally reportable, failing to notify the supervisory authority within the applicable 72-hour period can create a serious problem.
Regulators’ activity reports repeatedly identify delayed or missing notifications as an enforcement issue, particularly when a breach is extensive.
2. Ignoring data-access requests — If someone requests access to their personal data and your organisation fails to respond, the consequences can quickly become expensive.
German courts have awarded compensation in a range of cases, with the amount depending on the facts and the harm established.
One example cited in the original article:
The Oldenburg Labour Court awarded €10,000 after an employer took 20 months to answer a former employee’s access request.
Smaller online retailers can also face claims when they ignore valid requests completely.
3. Sending marketing emails without valid consent — This has been a recurring compliance issue for many years.
Unsolicited marketing emails continue to generate complaints and legal disputes.
Sending newsletters without a valid legal basis remains an avoidable risk.
Lower-profile issues that still require attention:
- Cookie-banner presentation details: The colour or position of a button is less important than whether the consent mechanism is genuinely compliant and gives users a valid choice.
- Missing data-processing agreements: These agreements may receive less attention during routine browsing, but they are a legal requirement where applicable and can become important during an investigation.
- Outdated privacy notices: A privacy notice should accurately describe current processing. An old date alone is not decisive, but inaccurate or incomplete information creates unnecessary risk.
Three practical risks for websites in 2025
Risk 1: loading Google Fonts from external servers
A 2022 decision by the Munich Regional Court held that loading Google Fonts from US servers without consent infringed the GDPR in the case before it. The claimant received €100 in damages, after which opportunistic mass claims followed. at least 100,000 demand letters were reportedly sent across Germany, often seeking around €170 in compensation. The relatively low demand led many recipients to pay rather than contest the claim.
The practical solution remains straightforward:
- Host web fonts locally
- or use system fonts instead.
- Proxy-based approaches also exist but add technical complexity.
The important point is that Google Fonts disputes continued through 2023, 2024 and 2025. Some courts have treated mass claims as abusive, but individual outcomes still depend on the circumstances and the current case law.
Risk 2: using Google Analytics without an appropriate legal basis
Data-protection authorities in Austria, France and Italy have challenged particular Google Analytics configurations and international data transfers. Website operators should not assume that a default installation is automatically compliant.
What this means in practice:
- There has been no general wave of mass claims
- but regulators can examine analytics configurations closely after a complaint.
Using Google Analytics without an appropriate legal basis is not a minor technicality.
Authorities in the EU have already issued four- and five-figure penaltiesdepending on the configuration, scale and seriousness of the infringement.
German enforcement has been less prominent in the cited examples, but complaints can still trigger detailed scrutiny.
Options to consider:
- Configure Google Analytics carefully, including consent and the required processing arrangements
- Use a privacy-focused European analytics alternative, such as Matomo or Plausible
- or decide that you do not need analytics at all.
Risk 3: unencrypted contact forms
Some websites still transmit contact-form data without HTTPS. That exposes personal information in transit and can lead to regulatory action.
Example cited from 2024: The original article reports a €3,500 fine for a trades business that used an unencrypted contact form, described as negligent exposure of personal data.
The remedy:
- Use a free TLS certificate from a provider such as Let’s Encrypt
- Installation can often be completed quickly
- There is little justification for leaving forms unencrypted
Why are cookie banners still everywhere?

Enforcement is not the only reason businesses deploy consent banners. They are often required by the services a website chooses to use.
The uncomfortable reality:
😧 Many consent banners are implemented incorrectly
🤔 The source cited in the original article reports consent rates of only 3–8%
🙄 Formal claims about banner design remain less common than complaints about substantive tracking practices
Even so, consent banners remain widespread.
Sometimes that is necessary; sometimes it reflects a legacy setup that nobody has reviewed since 2018.
The key question is simpler:
A consent banner is generally relevant when a website uses non-essential services that store or access information on a user’s device, share data with third parties or track behaviour.
Examples include:
- Analytics tools that use tracking cookies or fingerprinting
- Advertising and marketing scripts, such as Meta Pixel or Google Ads
- External resources that transmit personal data
- Embedded services that track users, such as YouTube, maps or social feeds
If you remove these services or integrate them in a genuinely privacy-friendly way, you may no longer need a conventional consent banner. The exact position depends on your implementation and applicable law.
Less external tracking can mean fewer consent requirements and a simpler user experience.
Modern cookieless analytics tools can still provide useful aggregated insights while reducing consent friction and data-protection risk.
Try Trackboxx free for 30 days now
No payment information required! No automatic renewal! Your Trackboxx ready to go in 1 minute.
What changed in 2025?
AI and data protection: a new area of risk
ChatGPT, Claude and Midjourney are now everyday tools. The relevant question is not simply whether your team uses AI, but how it uses it and what data is submitted.
Can I enter customer data into ChatGPT? Do not submit customer data without first establishing an appropriate legal basis, contractual safeguards and an approved organisational process. An enterprise contract alone does not automatically resolve every GDPR question.
What about AI-generated copy on my website? The copy itself is not automatically a GDPR issue. The risk depends on whether personal data was used in the prompt, training process or published output.
The next development: the Digital Services Act
The DSA has applied broadly since February 2024. Its main obligations concern intermediary services and online platforms rather than every ordinary business website.
- Very large online platforms and search engines with at least 45 million monthly EU users
- Social-media platforms
- Certain forums, communities and marketplace services
The reassuring part: A conventional website is not automatically subject to the platform obligations simply because the DSA exists.
A five-point reality check for your website
Enough theory. Start by checking these five practical basics:
- Is HTTPS active across the website? → If not, fix it immediately
- Is the privacy notice complete and current? → Review it against the services you actually use
- Is the legal notice easy to reach? → Keep it no more than a couple of clicks away
- Does the newsletter use double opt-in where appropriate? → If not, review the subscription process
- Are web fonts hosted locally? → If not, change the setup or obtain appropriate consent
If all five checks are complete, you have already addressed several of the most common website risks.

A conclusion that should put the risk into perspective
Seven years after the GDPR took effect, the internet has not collapsed and the predicted flood of claims did not materialise at the expected scale. The largest fines have generally involved major organisations and serious processing failures.
What matters:
- Get the foundations right: HTTPS, an accurate privacy notice and an accessible legal notice
- Address material risks involving external fonts, analytics and unencrypted forms
- Evaluate alarming compliance claims critically and seek qualified advice when the risk is significant
The lesson from 2018 is not to ignore data protection, but to replace panic with proportionate, evidence-based compliance.
Next in the series: Why consent banners frustrate users — and how a genuinely privacy-friendly analytics setup may reduce the need for them.



