Penalties issued under the Digital Services Act (DSA), the EU’s landmark content moderation law, are also contested. Chinese e-commerce giant Temu has argued a Commission fine of €200 million levied against it in May is “disproportionate” — though it’s far below the DSA’s higher threshold for fines, which is 6 percent of the company’s annual global revenue.
A Commission official, speaking on condition of anonymity to discuss internal deliberations, said that calculating fines under the DSA includes consideration of factors like “gravity, nature, duration [and] mitigating circumstances.”
The GDPR leaves the levying of fines to national independent privacy regulators rather than the Commission. In theory, that makes the arithmetic less vulnerable to political influence, but presents its own problem — trying to get more than 40 different privacy regulators across the bloc to use the same formula.
In any case, even the highest ever privacy fine of €1.2 billion against Meta didn’t come near the maximum 4 percent of annual turnover allowed under the EU’s privacy regulation. Plus, almost all of the more than €4 billion in fines handed down by the Irish data watchdog, Europe’s key GDPR enforcer, are caught up in court challenges and have not yet been paid.
Where does the money go?
Into EU coffers — but only once all appeals have been run, meaning the cash can take years to arrive. Funds received through fines don’t go towards specific EU spending, but instead reduce the amount that national governments have to pay into the joint budget.
Unlike the DSA and DMA, cash from GDPR fines goes into national governments’ wallets.


