The Corporate Veil Does Not Work the Way You Think
Most founders assume incorporation protects them. That assumption died in 2024. The Irish High Court ruled in Nolan & Ors v Dildar & Ors that a company director was personally liable for unlawful disclosure — not the company, the person. He was the "human author" of the breach.
The Three-Element Test: Knowledge, Authority, Omission
The Dutch DPA made the framework explicit with the Clearview AI €30.5 million fine (September 2024):
- You knew the GDPR was being violated
- You had authority to stop the violation
- You consciously omitted to do so
| Element | Startup Founder Reality |
|---|---|
| Knowledge | You built the product. You know how it handles data. |
| Authority | You are the founder. You can change anything. |
| Conscious omission | You noticed the cookie banner was wrong three months ago and "deprioritized" the fix. |
The Enforcement Numbers
€5.65 billion in cumulative fines. 2,245 enforcement actions since 2018.
| Company | Fine | Violation |
|---|---|---|
| €310M | Unlawful targeted advertising | |
| Uber | €290M | Illegal US data transfers |
| Meta | €251M | 2018 data breach |
| Clearview AI | €30.5M | Illegal facial recognition |
What This Means at Your Scale
| Business Size | Turnover | Fine Range |
|---|---|---|
| Micro enterprise | Up to €2M | 0.2% – 0.4% of turnover |
| Small enterprise | €2M – €10M | 0.4% – 2% of turnover |
| Medium enterprise | €10M – €50M | 2% – 10% of turnover |
The Violations That Create Personal Exposure
| Violation | Total Fines | Founder Risk |
|---|---|---|
| Insufficient legal basis | €1.65B | Critical |
| Non-compliance with principles | €2.4B | Critical |
| Insufficient security | €480M | High |
| Failure to comply with data subject rights | €200M+ | High |
Why Your Insurance Probably Will Not Save You
| Coverage Type | Typically Included? |
|---|---|
| Legal defense costs | Yes |
| Settlement payments | Sometimes |
| GDPR fines (negligent) | Rarely |
| GDPR fines (intentional) | Never |
The Founder's Personal Protection Checklist
Essential Documentation
- Data processing register
- Legal basis documentation for each processing activity
- Privacy policy — accurate, up-to-date, and actually followed
- Data processing agreements with all processors
- Security measures documentation
- Training records
- Incident response plan
- Board minutes recording compliance decisions
Actions That Demonstrate Good Faith
| Action | How It Protects You |
|---|---|
| Regular compliance reviews | Shows ongoing attention, not "conscious omission" |
| Legal consultation on data practices | Demonstrates you sought expert guidance |
| Documented risk assessments | Shows you identified and addressed risks |
| Data protection impact assessments | Required for high-risk processing |
When to Use AI vs. When to Call a Lawyer
| Approach | Monthly Cost | Protection Level |
|---|---|---|
| DIY + templates | €0 – €500 | Low |
| AI-assisted (like Outlex) | €69,99 – €549/mo | Medium |
| Law firm engagement | €5,000 – €20,000+ | High |
| Hybrid: AI + periodic review | €69,99–549/mo + €2,000/year | High |
The Bottom Line
Personal liability for GDPR violations is not theoretical. It is precedent. Your company's data practices are your personal responsibility. Build the documentation. Get the review. Protect yourself.
Related: €5.65B in GDPR fines: what SMEs can learn | GDPR reforms and AI training
€5.65 Billion in GDPR Fines: What SMEs Can Learn from 2,245 Enforcement Actions
The Enforcement Landscape: What 2,245 Fines Tell Us
Since May 2018, European data protection authorities have issued 2,245 GDPR fines totaling approximately €5.65 billion — and enforcement continues to intensify across all company sizes.
Enforcement by the Numbers (Through March 2025)
| Metric | Value |
|---|---|
| Total cumulative fines | €5.65 billion |
| Total enforcement actions | 2,245 |
| Average fine (all sizes) | €2.36 million (skewed by mega-fines) |
| 2024 fines only | €1.2 billion (33% decrease from 2023) |
The Three Violations That Drive 85% of GDPR Fines
Violation 1: Non-Compliance with Data Processing Principles — €2.41B (617 Fines)
The most expensive violation category. It covers GDPR Article 5 principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity/confidentiality.
SME Red Flag: If your signup form collects more fields than you use, or you have never deleted a customer record, you are likely violating data minimization and storage limitation principles.
Violation 2: Insufficient Legal Basis — €1.65B (669 Fines)
The most common violation by number of fines. GDPR Article 6 requires one of six legal grounds: consent, contract, legal obligation, vital interests, public task, or legitimate interest.
The LinkedIn Lesson: LinkedIn's €310 million fine (2024) came down to consent quality — their consent was not "freely given, sufficiently informed or specific, or unambiguous."
SME Red Flag: If your cookie banner has an "Accept All" button more prominent than "Reject All," your consent mechanism is likely deficient.
Violation 3: Insufficient Security Measures — €480M (418 Fines)
GDPR Article 32 requires "appropriate technical and organizational measures" to protect data.
Enforcement Patterns by Country
| Country | Fines | Average Fine |
|---|---|---|
| Spain | 416 | €185K |
| Germany | 281 | €340K |
| Italy | 180 | €1.4M |
| Romania | 95 | €12K |
| Hungary | 65 | €45K |
SME Fine Scaling: What You Actually Risk
| Business Size | Turnover | Fine Range |
|---|---|---|
| Micro enterprise | Up to €2M | €4K – €8K |
| Small enterprise | €2M – €10M | €40K – €200K |
| Medium enterprise | €10M – €50M | €1M – €5M |
| Large enterprise | €50M+ | Up to €20M or 4% global turnover |
For a seed-stage startup with €1M in revenue, the total risk exposure is €50,000–€150,000 — enough to affect runway significantly.
The Five Most Preventable SME Violations
- Marketing Without Valid Consent — Sending promotional emails to purchased lists without opt-in.
- Cookie Consent Theatre — Banners without meaningful choice.
- Ignoring Subject Access Requests — Failing to respond within 30 days.
- Silent Data Breaches — Not reporting breaches within 72 hours.
- Endless Data Retention — Keeping customer data indefinitely.
Building SME-Appropriate Compliance: The 80/20 Approach
- Priority 1 — Establish Legal Basis: Map all data processing activities and document legal basis for each.
- Priority 2 — Follow Data Principles: Clear privacy policy, retention schedule, SAR response process.
- Priority 3 — Secure Data: HTTPS everywhere, encrypted databases, role-based access, breach response plan.
What 2,245 Enforcement Actions Teach SMEs
The data from seven years of GDPR enforcement is clear: the same three violation categories catch companies of all sizes, and they are fundamentally preventable.
Need help? Learn why founders now face personal liability for GDPR violations, or explore how proposed GDPR reforms affect AI training.



