Privacy

The GDPR fines that should worry every firm using AI

Jul 8, 20265 min read

A penalty large enough to end a small firm can now arrive over a single act of mishandled personal data. European regulators have shown they will act, and they will act at a scale that makes the risk impossible to file under "later". The fines below are widely reported and, by any measure, severe. What ties them to your business is not their size but their cause: personal data moved or processed in a way the law did not permit. Every AI tool your staff touches is a fresh chance to do exactly that, often without anyone noticing until it is too late.

The fines are real, and they are large

The figures that follow are approximate and as reported, but the direction is clear. Regulators across Europe have been willing to issue penalties that run into the hundreds of millions of euros, and in one case past a billion.

  • Meta was fined about 1.2 billion euros in 2023 by Ireland's regulator over the transfer of personal data from the EU to the United States.
  • Amazon was fined about 746 million euros in 2021 by Luxembourg's regulator.
  • Google was fined 50 million euros in 2019 by France's data protection authority, the CNIL.
  • OpenAI was fined 15 million euros in 2024 by Italy's regulator, the Garante, over how ChatGPT handled personal data.
  • Clearview AI has been fined around 20 million euros by several European regulators, including those in Italy, France, and Greece, for unlawful processing of facial images.

Read the list again and notice the spread. These are not all advertising giants caught over targeting. Two of them, OpenAI and Clearview, were penalised over how an AI system collected or processed personal information. The regulators are not waiting for AI to mature before they apply the law. They are applying it now.

Why this should worry firms that are not Meta

It is easy to look at a 1.2 billion euro penalty and decide it belongs to a different world. Your firm does not transfer data across continents at industrial scale, so the headline number feels like someone else's problem. That comfort is misplaced.

The law that produced these fines is the same law that governs a lawyer pasting a client file into a chatbot to draft a letter. It is the same law that applies when an accountant uploads a spreadsheet of names and bank details to summarise it, or when a recruiter feeds a stack of CVs into an AI tool to rank candidates. The General Data Protection Regulation does not have a small business exemption for the moment personal data leaves your control. It asks whether you had a lawful basis, whether the data was kept secure, and whether you sent it somewhere it should not have gone.

You will almost certainly never be fined 1.2 billion euros. But penalties scale to the organisation, and a sum that a global firm absorbs as a line item can close a practice of ten people. The exposure is not theoretical. It is the everyday gap between what staff do to save time and what the regulation actually allows.

AI tools create new ways to mishandle data

The trouble with most AI tools is that using them well and using them safely pull in opposite directions. To get a useful answer, people give the tool context, and the most useful context is often the most sensitive: the real name, the real account number, the real medical detail. The tool works better the more you tell it, which is precisely the behaviour the law is built to restrain.

Once that information is pasted into a third-party service, you have made a transfer. You may not know where the provider stores it, whether it is used to train future models, which country the servers sit in, or how long it is retained. Each of those unknowns maps onto a question a regulator can ask. The OpenAI and Clearview cases show that authorities are already asking them of AI systems specifically.

The risk is also quiet. A bad data transfer through an AI tool leaves no broken window and no obvious alarm. A staff member is simply trying to finish a task, and the personal data goes out with the prompt. By the time anyone reviews it, the data has already left.

The fix is to keep personal data out of the tools

The good news is that this exposure is avoidable, and the principle is simple. If personal data never reaches the third-party tool, there is no unlawful transfer to be fined over. You do not have to ban AI to stay on the right side of the law. You have to stop sending it the information it has no business holding.

That is the idea behind masking data locally before it ever leaves your device. Names, account numbers, addresses, and other identifiers are detected and replaced on your own machine. The AI tool receives a version of the text with the sensitive parts removed, does its work, and the real values are restored on your side afterwards. The model still helps, but it never sees the data that would put you at risk. The personal information stays where it belongs, under your control.

This is not a workaround bolted on after a breach. It is a change to the path the data takes, so that the dangerous transfer never happens in the first place.

Where to start

The fines on this page are a warning, not a forecast. Most firms will not make headlines. But the same law that produced them applies to the smallest, most routine use of an AI tool, and the cost of getting it wrong is high enough to take seriously. The sensible response is to make the safe path the easy path, so staff can use AI without ever handing over what they should not.

Velum masks personal data on your device before it reaches any AI tool, so the information stays with you. If you want to see how it fits your firm's work, request a demo.

Share this article
XLinkedIn