Global data protection enforcement statistics

Privacy enforcement is no longer a European story. Arasy Intelligence tracks 46,000+ enforcement and regulatory records across 44 jurisdictions: EU and UK data protection authorities, US federal regulators, and the authorities in Latin America, Asia-Pacific, and Africa that no English-language tracker aggregates. GDPR-only databases stop at the EU border; enforcement does not.
46,000+
Enforcement and regulatory records collected
44
Jurisdictions monitored
35
Sources translated to English from originals

Records collected by authority (top 15)

AuthorityJurisdictionRecords collected
ICO (Information Commissioner's Office)United Kingdom29,658
GDPR Enforcement Tracker (EU/EEA fines)EU / EEA5,171
FTC (Federal Trade Commission)United States3,250
Garante (published decisions)Italy3,225
PRODHABCosta Rica735
DatatilsynetDenmark611
AEPDSpain543
ASICAustralia359
CNILFrance303
EDPB (national DPA actions)EU291
ODPCKenya283
IMYSweden269
CFPBUnited States262
DVILatvia204
ANSPDCPRomania174

Plus 29 more monitored authorities including Brazil ANPD, South Korea PIPC, Hungary NAIH, Switzerland FDPIC, Canadian provincial commissioners, Germany BayLDA and NRW LDI, UK FCA, Cyprus DPC, Philippines NPC, Uruguay URCDP, Ireland DPC, and China CAC and MIIT. Record counts reflect what each authority publishes; publication practices differ by jurisdiction.

Figures as of August 11, 2026, refreshed from daily collection.

Why a global view matters

The GDPR-only picture is shrinking as a share of reality. The best-known enforcement databases cover the EU and EEA exclusively. But data protection laws with active enforcement now operate across Latin America (Brazil, Uruguay, Colombia, Peru, Ecuador, Panama, Costa Rica), Asia-Pacific (China, South Korea, Thailand, Philippines, Singapore), Africa (Kenya, Nigeria), and Turkey. Most publish only in their own language, which is why no English-language aggregation existed.

Enforcement is a supply chain signal. A regulator action against a vendor is often the first public confirmation of an incident that never made the news. Every record here is linked to an organization in our registry, so enforcement against a subsidiary surfaces as exposure on its corporate family, which is the layer the platform adds.

Frequently asked questions

Which authority publishes the most enforcement records?

In our corpus, the UK ICO by a wide margin (29,658 records), reflecting its practice of publishing enforcement actions across all its regimes. Publication volume is not the same as fine volume.

Does this track more than GDPR?

Yes. GDPR fines are one source among 44 jurisdictions: US federal regulators (FTC, CFPB, and others), financial regulators, and data protection authorities across LATAM, APAC, and Africa, translated to English where the originals are not.

Where do the numbers come from?

Directly from each authority's published decisions, collected continuously by the Tupã engine and normalized to one schema. Every record retains a link to its primary source.

Has a regulator already named one of your vendors?

Overlay your supplier list and see enforcement actions across all 44 jurisdictions against your vendors and their corporate families. We are running a small number of pilot demos.

Request a pilot demo Estimate your breach cost