Amazon disclosed in a financial filing that Luxembourg’s data protection regulator, the CNPD, had fined it €746 million over its processing of personal data for targeted advertising. It was the largest GDPR fine issued up to that time.
What happened
- The CNPD’s decision was dated 16 July 2021 and was first revealed in Amazon’s quarterly report on 30 July.
- The case began with a 2018 complaint by the French privacy group La Quadrature du Net.
- Amazon said there had been no data breach and that it strongly disagreed with the ruling.
- Luxembourg’s administrative court upheld the fine in March 2025.
Why it mattered
The fine was about 15 times larger than the previous GDPR record and showed that targeted advertising practices were firmly in regulators’ sights.
Lessons for organisations
Review the lawful basis for advertising and profiling, make sure consent is valid where it is required, and keep evidence of how decisions on data use are made. Keep marketing and advertising teams involved in data protection reviews, since tracking and profiling tools are a frequent source of risk. Keep consent records and cookie settings under regular review as practices change.
Source: The Register
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.