There was a lot of noise a few years back about Meta getting billion-euro fines over GDPR violations.
I looked it up: they paid almost none of the fines.
If you get a ticket from a speed camera, the government will garnish your wages if you don’t pay the fine. For trillion dollar organisations payment is apparently optional.
A European-only, or even one that only primarily serves Europeans, likely won't make it to the front page as easily on the moderately American-centric HN - which further makes it seem like the only companies getting sued in the EU are American
That % should increase substantially with each violation too. It's hard to make fines hurt when the corporation you want to punish has more money than most countries.
They should multiply by 100 and then by another 100 with each violation. That'd help prevent companies from racking up fine after fine after fine. The real solution is to lock executives behind bars, but if the CEO is a citizen of another country you're kind of stuck with fines and bans
They just need to ban these companies from operating in their countries. They are fundamentally burdens on society run by bad people.
Your best case scenario with fines is getting them into the narrow definition of compliance just until a new "innovation" gives them a different way to conduct the same abuse while evading the letter of previous judgments.
This works best when you've got the ability to opt out of using those companies. If there's no meaningful replacement for a company's services or the entire internet is infested by it to the point where it's unavoidable a ban isn't going to do much good.
What would a ban on Google look like if people still want to email others using gmail accounts, watch youtube, or use android devices? What would a ban on cloudflare look like when all of your nation's traffic passes through them? One way or another these companies will end up with vast amounts of your people's data and the EU should be able to hold them accountable somehow for holding, selling, or using it in ways that violate their laws. Fines are pretty much the only lever they have to pull.
This is a judgement from the DPC in Ireland, which has a history of reluctance [0] when it comes to enforcing the GDPR on US corporations, e.g. in [1] they even had to be ordered by a court to start investigating. I don't see the Irish DPC voluntarily choosing to take on more oversight here.
The EU seems to live in a world all on its own. They can’t fine enough to actually change the behavior of big companies, but they can fine enough to kill their own startup culture.
I don’t feel bad for them anymore. Their voters seem to be fine with this status quo. And I get why other countries see these fines as trying to raise taxes by other means because it hasn’t and won’t change anything.
> They can’t fine enough to actually change the behavior of big companies
Of course they can fine enough. They just don't, which is why you see companies get fined again and again profiting from each violation.
The real issue is that fines are hard to set against companies with more money than they could ever need. What we need is for more CEOs to go to prison, but that's hard to do when the company's CEO is a citizen of another country.
for perspective, €403M = ~30 hours of net income, or ~10 hours of revenue (based on 2025 numbers, current exchange rates).
There was a lot of noise a few years back about Meta getting billion-euro fines over GDPR violations.
I looked it up: they paid almost none of the fines.
If you get a ticket from a speed camera, the government will garnish your wages if you don’t pay the fine. For trillion dollar organisations payment is apparently optional.
> they paid almost none of the fines.
Source?
https://dataprotection.ie/en/dpc-guidance/decisions/fines
So far they’ve paid something like €20 million out of €4.0 billion in GDPR fines.
Most of the fines (and all of the big ones) are simply "pending appeal".
The justice system is slow, that's why the fines are slow to be collected, that's all.
As if they'd end up paying?
They paid all the fines that were confirmed after appeal, you can look at the linked table yourself.
Do they only fine American companies in Europe?
No. For example:
https://www.enforcementtracker.com/ETid-3171 Yangoo. UAE.
https://www.enforcementtracker.com/ETid-1912 Criteo. French.
https://www.enforcementtracker.com/ETid-3162 Intesa Sanpaolo. Italian.
https://www.enforcementtracker.com/ETid-2864 Shein. Chinese.
https://www.enforcementtracker.com/ETid-2306 Enel Energia. Italian.
American companies fines tend to be highest since they are biggest and revenue affects the fine amount.
A European-only, or even one that only primarily serves Europeans, likely won't make it to the front page as easily on the moderately American-centric HN - which further makes it seem like the only companies getting sued in the EU are American
I’d think that EU companies are also have a better shot at not running into trouble given that they’re hopefully more familiar with them
Depends. Do you go and read European news about such cases, or just check HN when they post about a FAANG EU fine?
Pretty much the latter.
No, they also fine American companies in China and in Australia.
Plus Canada and Japan.
They don’t seem to be getting the message that companies need to comply with laws of the country they operate in.
Maybe start adding zeroes until it sinks in…
Someone recently fined Facebook $17 Billion. It was on the front page of NYT for 6 days (like as if it was a huge "get").
About 1% of FB's market cap. And their sins get washed away.
Everybody wins.
At this rate, fining tech-cos will be a major source of revenue for governments. Everybody wins.
It's like taxes with extra steps, except you get taxed for someone polluting you!
Fines like these are not an absolution though
Except for the consumers of course, but who cares about them.
it's depressing how small google's / meta's fines are. should be a % of revenue or total stock valuation or something.
That % should increase substantially with each violation too. It's hard to make fines hurt when the corporation you want to punish has more money than most countries.
They need to multiply by 100 to move that fine out of “cost of doing business” range.
They should multiply by 100 and then by another 100 with each violation. That'd help prevent companies from racking up fine after fine after fine. The real solution is to lock executives behind bars, but if the CEO is a citizen of another country you're kind of stuck with fines and bans
They just need to ban these companies from operating in their countries. They are fundamentally burdens on society run by bad people.
Your best case scenario with fines is getting them into the narrow definition of compliance just until a new "innovation" gives them a different way to conduct the same abuse while evading the letter of previous judgments.
This works best when you've got the ability to opt out of using those companies. If there's no meaningful replacement for a company's services or the entire internet is infested by it to the point where it's unavoidable a ban isn't going to do much good.
What would a ban on Google look like if people still want to email others using gmail accounts, watch youtube, or use android devices? What would a ban on cloudflare look like when all of your nation's traffic passes through them? One way or another these companies will end up with vast amounts of your people's data and the EU should be able to hold them accountable somehow for holding, selling, or using it in ways that violate their laws. Fines are pretty much the only lever they have to pull.
Result would be Balkanizing the internet. The cure might be worse than the disease.
there might be an oversight component of the settlement that is not prominent in the press releases
This is a judgement from the DPC in Ireland, which has a history of reluctance [0] when it comes to enforcing the GDPR on US corporations, e.g. in [1] they even had to be ordered by a court to start investigating. I don't see the Irish DPC voluntarily choosing to take on more oversight here.
[0] https://arstechnica.com/tech-policy/2021/09/ireland-fails-to...
[1] https://cooltechzone.com/news/court-irish-dpa-must-investiga...
Oh geez, GDPR again. Does this mean I'll have to close out a popup every time I open Google Maps or do a search?
If you're not doing so already then you seem to have already agreed to let Google do quite a lot of things with your data.
You may want to point your ire at the right parties, because that is not a GDPR demand.
The EU seems to live in a world all on its own. They can’t fine enough to actually change the behavior of big companies, but they can fine enough to kill their own startup culture.
I don’t feel bad for them anymore. Their voters seem to be fine with this status quo. And I get why other countries see these fines as trying to raise taxes by other means because it hasn’t and won’t change anything.
> They can’t fine enough to actually change the behavior of big companies
Of course they can fine enough. They just don't, which is why you see companies get fined again and again profiting from each violation.
The real issue is that fines are hard to set against companies with more money than they could ever need. What we need is for more CEOs to go to prison, but that's hard to do when the company's CEO is a citizen of another country.
Can you think of even 10 notable cases of startups being killed by fines? Let alone the 1,000+ you would need to identify to justify the claim.
I can't think of a single one. It barely registers as a risk.
Although I can think of several US startups that bankrupted themselves with fines for fraud etc....
The startup culture is what is killed by fines. It’s not possible to count how many companies are not started because of over regulation
The very same startup culture of "Screw the law, we could make a lot of money" hasn't exactly endeared me to it
> they can fine enough to kill their own startup culture
But they don't.
Exactly