Since GDPR became law in May 2018, the only substantial privacy-related action against a major tech company happened in the US, where Facebook was fined $5B
dont get me wrong — but it took 18 months for that FB probe to wrap in the U.S., roughly the same amount of time as GDPR was implemented. a lot of U.S. folks with political motivations are making that point, and i'd caution strongly against it https://twitter.com/... Politico Europe / @politicoeurope : More than 18 months after the European Union began implementing GDPR, the bloc's ability to rein in Big Tech is increasingly in doubt https://www.politico.eu/... Fred Logue / @fredplogue : The comments attributed to Commissioner Dixon in the article are at odds with the Schrems II AG's discussion of the supervisor's obligation to act diligently and take all necessary steps to ensure proper application of the GDPR https://twitter.com/... Dr Solomon Passy / @passysolomon : This is what @AtlanticClubBG and @DNA_BG came across with at the beginning of #GDPR. Our conclusion: start with simpler legislation and after successful implementation upgrade it step by step. Just like the traffic law which originates from few simple rules in 19th century. https://twitter.com/... Gatan Goldberg / @goldbergaetan : The only decision @NOYBeu obtained so far from a DPA is almost one year old (Google Jan 19') and the cross border cooperation mechanism wasn't even triggered in that case. So what is taking so long? I comment alongside esteemed colleagues in this article. https://twitter.com/... Cam Kerry / @cam_kerry : Irony “that after plenty of crowing about Europe's comprehensive approach to privacy, it's in the US, where regulators have hit Facebook with a $5 billion fine over the Cambridge Analytica scandal, that enforcement has been the quickest.” An advantage to a federal authority. https://twitter.com/... Marietje Schaake / @marietjeschaake : #GDPR's fans should be its most serious critics ↘️ https://twitter.com/... David Carroll / @profcarroll : Oddly enough though, despite expectations, the EU arguably lags behind the USA in data rights enforcement despite not having a law as strong as the GDPR. Authorities in Ireland, UK, and Luxembourg seem reluctant to drop the hammer they wield. #DataRights https://twitter.com/... https://twitter.com/... Max Schrems / @maxschrems : Very good article by @NicholasVinocur on the “bottelneck” that @DPCIreland creates. We are waiting for 19 months on the “forced consent” cases filed on 25/5/2018 and Helen Dixon says it has not even reached her table... 🤬🙄 #GDPR #LeprechaunEnforcement https://www.politico.eu/... pic.twitter.com/lzLzRyzPvD
Context & Ripple Effects
Eighteen months after GDPR took effect, Politico's audit lands on an awkward scorecard: the only substantial privacy penalty against a major tech company came from the US FTC's $5B Cambridge Analytica settlement with Facebook, not from Brussels. The bottleneck was visible earlier in the year, when critics questioned whether Ireland's Data Protection Commission — the EU's lead enforcer for most US tech firms — was willing to police companies so central to Ireland's economy.
What makes this 2019 snapshot worth revisiting is how the enforcement gap subsequently closed: not through fast lead-authority action, but through inter-regulator fights and litigation, culminating years later in the Irish DPC's €390M Meta fine and the EU's record €1.2B data-transfer penalty against Meta.
First-order effects
- Facebook enters 2020 having paid a $5B US fine while facing no comparable EU penalty, leaving the Irish DPC — its lead GDPR supervisor — exposed to charges that enforcement tracks Ireland's economic dependence on tech employers.
Second-order effects
- Frustrated by regulator pace, consumer groups and privacy activists shift their GDPR complaints toward court litigation for faster resolution, bypassing the DPC entirely.
- Disagreement among EU regulators over how much to fine Twitter for its 2018 breach stalls parallel investigations into Facebook and Google, compounding the delay the Politico piece documents.
Third-order effects
- If the pattern holds, GDPR enforcement matures through friction — cross-border regulator disputes and court cases — rather than swift lead-authority fines, a path that eventually produced the Irish DPC's €390M Meta penalty and the EU's record €1.2B fine over transatlantic data transfers.
- The credibility of the EU's one-stop-shop enforcement model becomes the structural question: if lead regulators in company-friendly jurisdictions stay slow, authority effectively migrates to courts and to non-Irish regulators forcing decisions.
The trend: GDPR enforcement is evolving from a stalled lead-regulator model into a slower, contested process driven by inter-regulator conflict and private litigation before large fines arrive.