Why GDPR fines have not stopped Big Tech’s data abuse
The General Data Protection Regulation was meant to make personal information expensive to misuse. Since it came into force in 2018, European regulators have issued billions of euros in penalties against technology companies, advertising platforms and data brokers. Yet the underlying machinery of surveillance has largely survived: tracking remains embedded in apps, behavioural profiles still shape what people see, and companies continue to collect information far beyond what most users understand.
The problem is not that GDPR is powerless on paper. Its rules cover lawful processing, consent, transparency, data minimisation and individual rights, with maximum penalties of €20 million or 4% of worldwide annual turnover. The problem is that enforcement has been slow, fragmented and easy to absorb. For Australians watching the Privacy Act reform process, the European experience offers a useful warning: large fines alone rarely change a business model built around personal data.
A penalty can become a predictable operating cost
For a small business, a multimillion-euro privacy penalty could threaten survival. For a global platform with tens of billions in annual revenue, even a large fine may be treated as a financial provision. If the company can earn more from intensive data collection than it expects to lose through occasional enforcement, the economic incentive remains intact.
This calculation is especially powerful for firms that dominate digital advertising, app distribution, cloud services or online search. Their data systems generate revenue every day, while a regulatory case can take years to reach a final decision. Appeals, procedural challenges and negotiations can delay payment and reduce the immediate impact of a sanction. A fine imposed long after the conduct occurred does little to change the next auction for an advertisement or the next request for location data.
The size of the penalty can also distract from its practical effect. A headline figure may look severe, but the relevant comparison is not the company’s total turnover. It is the profit produced by the offending practice, the cost of changing it and the value of any competitive advantage gained through surveillance. Unless enforcement removes that advantage, a company may simply update its compliance documents while preserving the same extraction system.
Enforcement is slower than the data economy
Privacy regulators face a structural mismatch. A technology company can launch a new tracking tool in weeks, connect it to thousands of partners and process billions of events before an authority has completed an investigation. By the time a decision arrives, the product may have changed names, moved to another legal entity or been replaced by a similar system.
GDPR enforcement is also divided among national data protection authorities. The regulation created a one-stop-shop process for companies operating across Europe, but cross-border cases can become complex and politically sensitive. A lead regulator may need to coordinate with authorities in many countries, respond to legal objections and defend its decision through multiple stages of appeal. This is a sensible safeguard against arbitrary state power, but it also gives well-funded companies time and procedural opportunities that ordinary data subjects do not have.
The Irish Data Protection Commission illustrates the tension because many major technology companies have their European headquarters in Ireland. That arrangement concentrates responsibility for some of the most consequential cases in one regulator, even though the effects are felt across the continent. Regulators can issue substantial decisions, but their workload, technical expertise and litigation budgets remain small compared with the companies they supervise.
Consent does not fix an unequal bargain
GDPR treats consent as one possible legal basis for processing, but consent screens often turn privacy into a test of endurance. Users may face long notices, confusing settings, repeated pop-ups and interfaces designed to steer them towards “accept all”. A person who wants to read the news, use a map or sign up for a service may have little practical ability to refuse tracking.
This is especially clear in advertising technology. A single webpage can trigger requests involving publishers, analytics firms, demand-side platforms, identity providers and other intermediaries. Most people cannot identify these companies, assess their purposes or know where their data will travel. Formal disclosure exists, but meaningful comprehension is missing. A box ticked under pressure does not resemble the informed choice that privacy law imagines.
The issue is bigger than consent banners. Large platforms often make participation in social, professional or commercial life dependent on accepting extensive data collection. The user technically has a choice, but leaving may mean losing access to friends, work contacts, stored photographs, business pages or essential services. That imbalance weakens the idea that a contract between a person and a platform is genuinely voluntary.
A useful related question is whether privacy protection can survive if the underlying communications are readable by intermediaries. The case for a right to encryption shows why confidentiality cannot depend solely on promises about responsible data handling. Information that is never exposed is harder to misuse, profile or sell.
Data collection is profitable before anyone sees a breach
Public debate often focuses on spectacular incidents such as a stolen database or a ransomware attack. Those events matter, but much of Big Tech’s data abuse is routine and lawful-looking. It happens through persistent identifiers, location histories, inferred interests, device fingerprints, voice recordings, purchase records and connections between accounts.
Advertisers and brokers can draw conclusions that users never directly supplied. A person might not disclose their health condition, financial stress or likely political views, yet their browsing patterns and app activity can support an inference. Once created, that profile may circulate through an opaque chain of companies. Deleting one account does not necessarily delete the copies, predictions or audience segments derived from it.
The Australian market shows how ordinary these arrangements have become. Loyalty schemes at Woolworths and Coles encourage shoppers to exchange detailed purchasing histories for discounts and personalised offers. In Sydney and Melbourne, transport, retail and delivery apps can link location and transaction data across everyday routines. These services may provide genuine convenience, but convenience can obscure the cumulative value of the information being collected.
Online therapy platforms make the stakes particularly clear because intimate information can be commercially valuable even when a company claims not to sell medical records directly. The online therapy trail demonstrates how visits, cookies, advertising pixels and third-party analytics can create sensitive exposure around a person seeking help. A fine after the fact cannot fully restore confidentiality or erase copies already distributed through an advertising ecosystem.
The Australian framework reveals the limits of deterrence
Australia does not have a direct equivalent to GDPR’s maximum 4% global turnover penalty, although privacy enforcement has strengthened. The Office of the Australian Information Commissioner can investigate breaches, seek civil penalties and issue determinations, while the Australian Competition and Consumer Commission has pursued companies over misleading data practices under consumer law. The Privacy Act review and proposed reforms have therefore attracted close attention from businesses, civil liberties groups and technology users.
The experience of major breaches involving Optus and Medibank also changed public expectations. Australians became more aware that identity documents, health information and contact details can remain dangerous long after a service relationship ends. Yet breach prevention and surveillance-based business models are related without being identical. Stronger security may stop criminals obtaining a database, while doing little to prevent a company from collecting excessive information in the first place.
Australian organisations also operate in a mixed legal environment. A company may comply with the Australian Privacy Principles, consumer law, sector-specific duties and overseas rules at the same time. That complexity can produce paperwork without producing restraint. A privacy policy may be legally reviewed and still be practically unreadable; a consent mechanism may satisfy a formal requirement while leaving a person with no meaningful alternative.
The local market has another complication: many of the biggest platforms are headquartered overseas. An Australian user can be affected by decisions made in California, Dublin or Singapore, while domestic regulators must obtain evidence and enforce rights across borders. The distance between the person experiencing the harm and the company controlling the system makes individual complaints slow and difficult.
What would make penalties change behaviour
Fines work best when they are swift, proportionate to the gains from misconduct and paired with orders that change how information is collected. A penalty should be accompanied by deletion requirements, limits on processing, independent audits and clear deadlines. If a platform can pay while retaining the data and competitive advantage, the deterrent is incomplete.
Regulators also need the power and resources to address repeated conduct. A company that violates privacy rules several times should face escalating consequences, including restrictions on particular processing activities. Senior executives may need clearer accountability when a business knowingly designs systems around excessive collection or deceptive consent. Otherwise, responsibility disappears into committees, vendors and technical settings.
Structural remedies matter because the problem is often structural. If a platform controls the operating system, advertising exchange, app marketplace and identity layer, it can make alternatives difficult to use. Competition policy, interoperability requirements and limits on combining data across services may reduce the concentration that allows surveillance to become a default condition of participation.
Individuals need remedies that are usable in real life. Australians should not have to understand ad-tech auctions, corporate group structures or international jurisdiction before challenging an improper data practice. Accessible complaint processes, representative actions and compensation for serious privacy harm can shift some power back towards the people whose information creates the value.
| Enforcement approach | Immediate benefit | Why it may fall short |
|---|---|---|
| Large financial penalty | Signals that misconduct has consequences | Can be absorbed as a business expense |
| Consent and transparency rules | Gives users information and formal choice | Interfaces can manipulate or overwhelm users |
| Data deletion orders | Removes some unlawfully held information | Copies, inferences and partner records may remain |
| Independent audits | Tests whether internal controls work | Audits may examine compliance without challenging the business model |
| Processing restrictions | Directly limits harmful data use | Requires technical expertise and sustained supervision |
| Competition and structural remedies | Reduces dependence on dominant platforms | Takes years and may face intense legal resistance |
The central lesson is that GDPR fines have not stopped Big Tech’s data abuse because surveillance is embedded in infrastructure, revenue models and everyday habits. Enforcement can punish a particular violation without changing the conditions that make widespread collection profitable. A platform may lose a case over consent while continuing to gather information through another legal basis, another product or another partner.
For people in Australia, privacy protection therefore cannot rest on penalties alone. Read permission screens carefully, disable unnecessary tracking where practical, use end-to-end encrypted services for sensitive conversations and treat loyalty discounts as an exchange involving data rather than free money. The broader policy goal should be simple: make companies collect less by default, keep less when they do collect, and face consequences that remove the gains from treating personal information as an unlimited resource.