

Australia’s privacy law landscape doesn’t grant the same rights individuals resident in the EU and UK enjoy. But organisations operating in Australia can learn plenty of lessons from the enforcement actions and penalties imposed in Europe. In this post, we’ll explore some of the themes we’re seeing in enforcement in Europe and outline the key takeaways:
The key issues seen in enforcement in the EU seem to be an echo chamber: consent, spam, inadequate security, and unlawful data processing. Other trends we (are continuing to) see include record-breaking (eyewatering) fines and the debate heating up around ‘pay or okay’ models for service.
Penalties under the GDPR can be steep, and the dollar value of the ‘highest ever GDPR penalty’ continues to grow. Last year, we saw a staggering 1.3 billion USD penalty against Meta IE. But we wouldn’t be shocked to continue to see penalties in the billions against Meta, at least annually, for the next few years.
And yes, most of these large fines are being levied against large tech companies. But the ability of the European regulators to penalise companies to the tune of 4% of their global turnover shows that the rules there have teeth.
Some of the largest fines under the GDPR to date include:
The Pay or Okay debate refers to the business model some tech companies are adopting that requires users to either consent to extensive tracking and targeted advertising or pay a subscription fee to access the services.
Critics of this model (which includes many of the EU regulators) argue that this is contrary to the consent requirement under the GDPR, which requires consent to be freely given, specific, informed and unambiguous.
This issue is yet to be determined by EU courts, but for what it’s worth, transparency is typically a less damaging approach to privacy and consent. Your customers may consent to targeted advertising if they know and understand the potential benefits, such as more tailored recommendations and personalized offers. Positioning your offer this way is likely to reflect more positively on your organisation than strongarming your users into consenting or paying for it.
The UK privacy regulator (ICO) fined Pinnacle Life 80,000 pounds for its illegal call campaign from May 2021 – May 2022. Telemarketers made almost 48,000 illegal calls to people who had registered on the UK’s ‘Do Not Call’ list.
The company reportedly used aggressive, insulting, and harassing tactics during these marketing calls and made misleading statements, including that they worked for the company with which the call recipient had an insurance policy (when this was not the case).
“One complaint read as follows:
Asked for me by name and incorrect address. Said did I have life insurance [sic]. I said yes but [that] I was not interested and [asked them] to remove me from their marketing list at which point he became abusive and called me stupid. I hung up but the same number called me thirty minutes later, so I ignored it.”
While these tactics are extreme, the takeaway is very clear: do not engage in spam marketing. The ACMA is enforcing high penalties in Australia, alongside the reputational harm that comes with these claims.
Other lessons here include:
Strengthening Previous Takeaways:
This case reinforces many of the earlier takeaways:
A wide range of violations fall under the umbrella of ‘unlawful data processing’, including collecting data without a lawful basis for the collection, violating data subject rights, inadequate security, cross-border transfer violations, and insufficient transparency.
The GDPR Enforcement Tracker is littered with examples falling under this umbrella. But here are a few recent examples to demonstrate what’s happening in Europe:
Takeaways for Australian organisations from these enforcement actions include:
If you’re concerned about your compliance with the GDPR or privacy maturity on the whole, reach out. Our team would love to work with you.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.