Don’t do SECURITY. Do business SECURELY.

Amazon hit with record €746 million GDPR fine in Luxembourg

Amazon discloses a €746 million fine from Luxembourg's data protection regulator over targeted advertising, a record GDPR penalty.

Amazon disclosed in a financial filing that Luxembourg’s data protection regulator, the CNPD, had fined it €746 million over its processing of personal data for targeted advertising. It was the largest GDPR fine issued up to that time.

What happened

  • The CNPD’s decision was dated 16 July 2021 and was first revealed in Amazon’s quarterly report on 30 July.
  • The case began with a 2018 complaint by the French privacy group La Quadrature du Net.
  • Amazon said there had been no data breach and that it strongly disagreed with the ruling.
  • Luxembourg’s administrative court upheld the fine in March 2025.

Why it mattered

The fine was about 15 times larger than the previous GDPR record and showed that targeted advertising practices were firmly in regulators’ sights.

Lessons for organisations

Review the lawful basis for advertising and profiling, make sure consent is valid where it is required, and keep evidence of how decisions on data use are made. Keep marketing and advertising teams involved in data protection reviews, since tracking and profiling tools are a frequent source of risk. Keep consent records and cookie settings under regular review as practices change.

Source: The Register

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights