← All enforcement actions
GDPRE-Commerce

Amazon Europe Core€746M GDPR fine (2021)

Largest GDPR fine at the time — behavioural ad targeting without valid consent

Penalty
€746M
Regulator
CNPD (Luxembourg)
Jurisdiction
European Union

What happened

Luxembourg's data-protection authority fined Amazon €746M for processing personal data for behavioural advertising without freely given, specific, informed consent. The CNPD held that Amazon's consent mechanism was bundled with service use and therefore not valid under Articles 6 and 7 GDPR.

Root cause

What every team should do

  1. Separate consent for advertising from consent to provide the service
  2. Use unbundled, granular toggles with equal-prominence reject button
  3. Document the consent record with timestamp, scope, and revocation log
Source: Amazon 10-Q (Jul 2021), CNPD decision.
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GDPR controls you are missing — mapped to enforcement patterns like this one.

Run my GDPR audit Generate missing policies

Related enforcement actions

Meta Platforms
€1.2B
Largest GDPR fine ever — EU→US data transfers under invalidated Privacy Shield framework
TikTok
€345M
Children's accounts defaulted to public — GDPR Articles 5, 12, 24, 25 violations
Meta / Instagram
€405M
Children's business-account email + phone exposed publicly
British Airways
£20M
Magecart-style skimmer on payment page — 429K records exposed