← Back to blog

What a GDPR data breach really costs

· TinyX · 5 min read

What a GDPR data breach really costs

When a European organization leaks personal data, the public sees the apology and the credit-monitoring offer. What boards feel is the long shadow: forensics, Article 33 and 34 clocks, supervisory scrutiny, churn, and — in the worst cases — a fine measured against worldwide turnover.

IBM's Cost of a Data Breach Report 2025 still frames the global economics. For EU operators, the regulatory ledger sits on top of that average — and it has its own clocks.

The economics underneath the fine

The 2025 global average cost of a data breach fell 9% year over year, from $4.88 million to $4.44 million. That total is not just IT overtime. IBM breaks it into detection and escalation, notification, post-breach response, and lost business. Lost business is often the largest share: customers leave, renewals stall, and procurement asks harder questions about how you handle files.

Lifecycle still matters. The 2025 global average time to identify and contain a breach fell to 241 days — roughly eight months of exposure and follow-up. Organizations that used security automation extensively shortened that lifecycle by about 80 days and saved roughly $1.9 million versus those that did not.

In the first 72 hours the costs are visceral: forensic firms, outside counsel, a war room, systems taken offline. Notification is its own invoice — before any Article 83 fine is assessed.

GDPR: the two-tier fine regime

GDPR is a two-tier administrative-fine regime under Article 83. The lower tier caps at €10 million or 2% of worldwide annual turnover (record-keeping, processor contracts, and security under Article 32 among other duties). The upper tier — core principles, data-subject rights, international transfers — caps at €20 million or 4% of turnover, whichever is higher.

Cooperation, mitigation, and prior compliance history are explicit mitigating factors. Demonstrating due diligence does not erase exposure, but it changes what a supervisory authority can reasonably assess.

Independent trackers put cumulative GDPR fines above €6 billion across thousands of published decisions (see the CMS GDPR Enforcement Tracker). Two cases still show up in every board pack:

  • British Airways (2018 breach). Roughly 400,000 customers were diverted to a fraudulent page. The UK ICO originally proposed about £183 million and settled at £20 million, citing Article 32 failures around technical and organizational measures — plus COVID-era mitigation.
  • Meta Platforms Ireland (2023). A €1.2 billion fine for continued EU-to-U.S. transfers after Schrems II — still the largest GDPR fine. The EDPB decision shows that unlawful processing, not only a classic hack, can land in the same regulatory ledger.

The notification clock is not optional

Under GDPR Article 33, you notify the supervisory authority within 72 hours of becoming aware, where feasible. Article 34 requires communication to people when risk is high. Each notice must cover nature, categories, approximate numbers, likely consequences, and mitigation.

Drafting that under legal review, translating it for a pan-European customer base, and staffing inbound queries is real spend — often six figures — before any fine is on the table. Miss the clock and the fine discussion starts from a worse place.

NIS2 raises the operational bar

NIS2 raises the bar for essential and important entities: early warning within 24 hours, incident notification within 72 hours, and a final report within one month. Member States must provide for fines of at least €10 million or 2% of turnover for essential entities. Senior management accountability is part of the design — this is not only an IT problem.

If you are in scope, your incident-response plan needs both the GDPR 72-hour path and the NIS2 24/72/one-month ladder mapped, tested, and owned.

Three circles, one EU budget conversation

Think of breach cost as three concentric circles.

  1. Inner circle — containable costs. Incident-response retainers, logging, backup tests, data minimization, and how you move files when someone outside the company needs them. Relatively cheap. High return.
  2. Middle circle — regulatory costs. Fines, notification, credit monitoring, legal defense. Article 83 explicitly weighs cooperation and mitigation.
  3. Outer circle — existential costs. Loss of a market license, payment processing if PCI status collapses, or a corrective action plan that blocks you from handling sensitive categories of data.

Organizations that spend on the inner circle are the ones that usually avoid living in the outer two.

Practical pressure that still holds up:

  • A tested incident-response plan mapped to Article 33/34 and, if you are in scope, NIS2's reporting ladder.
  • Data minimization. You cannot leak what you do not hold.
  • Encryption and pseudonymization where they change the legal and practical outcome — at rest, in transit, and when a file leaves your perimeter with clear custody of who can open it.
  • Vendor risk. A processor incident is still your incident under GDPR Article 28.
  • Controlled sharing. Permanent "anyone with the link" URLs are a quiet way leaks keep compounding years later. See share links that never expire for that failure mode in plain language.

For the U.S. mosaic — CCPA class actions, state clocks, and the SEC 8-K path — see What a US data breach really costs.

Controlled sharing as an inner-circle mitigation

Who can open a shared file — and whether that link is still live next quarter — is one of the cheapest levers in the inner circle. It does not replace forensics, logging, or an incident plan. It does cut a common way personal data keeps circulating after a project ends.

TinyX is built for that handoff. Free covers outgoing file share with expiry and passwords; upload drops start on Pro+. Caps and plans are on pricing; the product surface is on features.

The cheapest breach is the one that never happens. The second cheapest is the one you were already set up to contain.