Published:

Privacy Penalties Aren’t Just for Big Businesses: 16 Examples of Small Businesses Getting Hit

General

CIPA, Fines, GDPR, privacy, Small Business

Photo of author

Hans Skillrud

Vice President of Termageddon

Smallbizfines examples

When you hear about a company getting hit with a massive privacy fine, who do you picture?

Probably Meta or TikTok.

Maybe Google.

Perhaps a multinational corporation with 40,000 employees, a legal department the size of a small city, and enough lawyers to form their own baseball team.

It’s easy to look at those headlines and think, “Well, that’s a big-business problem.”

But privacy enforcement doesn’t only happen to giant corporations. It just so happens that big businesses being fined half-a-billion for privacy violations makes for a more enticing headline.

Small businesses, micro-businesses, schools, nonprofits, online retailers, and other organizations have also faced privacy fines, lawsuits, and demand letters over issues involving their websites and the way they collect or share visitor information.

And sometimes, the issue isn’t some elaborate scheme to harvest millions of people’s data. It’s often just the website using a simple:

  • Analytics tool;
  • Contact Us form;
  • Map embed;
  • Video embed;
  • Digital ad;
  • Email newsletter; or
  • eCommerce tool.

The truth is, using tools like these without policies in place that contain all the required disclosures is all it takes to get you targeted. And all it takes is one person visiting your website and noticing these things are missing. 

The examples below illustrate just how broad the landscape can be.

1. A Montessori school: €3,000 for cookie compliance issues

Let’s start with a school.

Montessori School of Tres Cantos in Madrid, Spain, faced enforcement over its website’s use of cookies.

According to reporting on the case, the school’s website did not provide an appropriate cookie banner or sufficient information about the cookies being used.

The initial penalty was €5,000 and was ultimately reduced to €3,000.

That’s a significant amount for any small organization, particularly one whose primary purpose is educating children rather than operating a massive technology platform.

And the issue involved something that appears on millions of websites:

cookies.

[Source: Confilegal, July 2024]

2. A tiny Spanish business: €600 for a missing Privacy Policy

Amor Ideal, a small Spanish “love coaching” business, received a €600 penalty in a case involving its website’s privacy information.

According to the decision, the website did not have a Privacy Policy properly identifying the data controller.

This is a useful reminder that privacy obligations don’t disappear because a company is small.

If your business collects personal information through its website, you may have obligations regarding how that information is disclosed and handled.

[Source: Proteccion-de-Datos.es, May 2025]

3. A small Spanish e-commerce company: €3,000 for Google Analytics cookies

Grow Beats SL, a small Spanish e-commerce business, was fined €3,000 in a case involving Google Analytics cookies and inadequate cookie information.

The case also involved the lack of an effective mechanism for visitors to reject cookies.

Again, we’re not talking about some obscure surveillance technology.

We’re talking about Google Analytics, one of the most commonly used website analytics tools on the internet.

[Source: GDPRhub, AEPD decision PS/00092/2020]

4. A cycling-event organizer: €1,200

Trueba Sport, a cycling-event organizer in Spain, received a €1,200 fine in 2025.

The case involved the sharing of email addresses without appropriate consent, along with issues involving the privacy information available through the organization’s website.

This is another example of why privacy compliance extends beyond businesses whose primary product is technology.

A company organizing cycling events can have privacy obligations. A school can have privacy obligations. A local service business can have privacy obligations. And, of course, a website can be part of the equation.

[Source: DSGVO-Portal, August 2025]

5. A Spanish news website: €1,200 for Google Analytics cookies

EDA TV, a Spanish news website, was fined after Google Analytics cookies were placed before the required consent was obtained.

The original penalty was €2,000 and was reportedly reduced to €1,200.

The lesson is familiar by now:

What your website does when someone lands on it matters.

It’s not enough to look at the page and think, “There’s nothing sensitive here.”

A website can be collecting or transmitting information behind the scenes through scripts and cookies that visitors never see.

[Source: El Confidencial, March 2025]

6. A small Berlin e-commerce company: €7,000

A small German e-commerce company has also been cited in secondary reporting as receiving a €7,000 penalty related to tracking cookies being used without prior consent.

There is an important caveat here: this particular example comes from a secondary source citing the Enforcement Tracker, and the underlying primary entry has not been independently confirmed for this article.

So we’re including it with an asterisk rather than presenting it as equally well-established as the cases above.

Even with that caveat, it’s worth knowing about because it reflects the broader European enforcement environment surrounding non-essential cookies and consent.

[Source: AuraTech Legal, citing the Enforcement Tracker]

7. An unnamed German website owner: €100 over Google Fonts

Here’s one that might make a few website owners and developers look twice at their websites.

In 2022, a German court awarded a website visitor €100 after finding that the website’s use of remotely hosted Google Fonts resulted in the visitor’s IP address being transmitted to Google.

The website owner was ordered to stop the violation, with significant penalties potentially applying for continued noncompliance.

The case became particularly notable because Google Fonts was, and remains, incredibly common across the web.

The fallout reportedly included tens of thousands of copycat demand letters seeking amounts ranging from roughly €100 to €500 from website operators using remotely hosted fonts.

The important takeaway isn’t that Google Fonts is automatically illegal.

It isn’t.

The takeaway is that even something as seemingly harmless as loading a font can have privacy implications depending on how it’s implemented and what laws apply.

[Source: WP Tavern]

8. A family HVAC business: CIPA lawsuit over website tracking

Now let’s move from regulatory fines to private litigation.

Folsom Lake Heating & Air, a family HVAC business in the Folsom/Sacramento, California area, was sued under the California Invasion of Privacy Act (CIPA).

The lawsuit involved website analytics and the Housecall Pro booking tool.

According to CapRadio, the plaintiff sought $5,000 per website visit.

The case was ultimately settled by the vendor involved.

Whatever the ultimate merits of the individual allegations, the practical lesson for a small business is pretty obvious:

A website can create legal exposure that the business owner may never realize exists.

[Source: CapRadio, June 2026]

9. A residential solar company: approximately $30,000 just to defend the case

Element Electric, a residential solar and battery installer in Sonoma County, California, was also sued under CIPA over tracking technology on its website.

According to reporting by CapRadio, the company’s owner was quoted approximately $30,000 just to defend the case.

The same plaintiff reportedly sued three other Sonoma County businesses.

Think about that for a second.

This wasn’t a social media company. It wasn’t a data broker. It wasn’t an advertising network. 

It was a local company installing solar and battery systems.

And the potential cost wasn’t limited to whatever damages might ultimately be awarded. Legal defense itself can be expensive.

[Source: CapRadio, June 2026]

10. An online tutoring company: CIPA claims involving a TikTok pixel

C2 Education Systems, an online tutoring company, was named as a defendant in a California CIPA case involving the TikTok marketing pixel.

The plaintiff alleged that the pixel transmitted information without the required consent.

The case is part of a larger wave of litigation concerning tracking technologies installed on websites.

Again, this doesn’t mean every website using a TikTok pixel violates CIPA. The legal questions surrounding website tracking and CIPA are actively litigated.

But it does demonstrate how ordinary marketing technology can become relevant to privacy litigation.

[Source: National Law Review]

11. An apparel e-commerce company: CIPA pen-register litigation

The Haberdash Group, an e-commerce apparel seller operating in New York and Delaware, was also named in CIPA litigation brought by a California resident who visited its website.

The case, Palacios v. Haberdash, involved allegations concerning pen-register and trap-and-trace technology.

It’s another example of how a business doesn’t necessarily have to be physically located in California to become involved in litigation involving California privacy laws.

For an online business, the geographic boundaries can be considerably less obvious than they appear.

[Source: Association of Corporate Counsel, February 2025]

12. E-commerce websites sued over session replay and live chat in Florida

California isn’t the only state where website technology has become the subject of privacy litigation.

Businesses operating e-commerce and retail websites have also faced lawsuits under Florida’s Security of Communications Act (FSCA) involving technologies such as session replay and live chat.

Some of these cases have sought statutory damages of $500 or more per visitor.

Another analysis has described FSCA demand letters seeking $1,000 per alleged violation, with law firms including Salpeter Gitkin and Johnson Dalal filing cases in volume.

The exact legal outcome depends on the facts and circumstances of each case, and the application of Florida law to particular website technologies remains an evolving area.

But once again, the technology at issue isn’t something exotic.

Live chat is everywhere.

So is session replay.

[Sources: Kelley Kronenberg; Enzuzo]

13. Orlando Health: tracking pixels and Florida law

The issue has even reached the healthcare sector.

In March 2025, a federal court allowed claims involving tracking pixels under Florida’s Security of Communications Act to proceed against Orlando Health in W.W. v. Orlando Health.

The case involved allegations concerning tracking technology used on the organization’s website.

Healthcare organizations obviously have additional privacy considerations, so this isn’t a direct comparison to a local plumber or e-commerce store.

But the case is significant because it demonstrates that website tracking technology is being tested under multiple state privacy and communications laws, not just California’s CIPA.

[Source: Sidley, March 2025]

14. CIPA demand letters alleging “spyware” and “trap and trace” violations

You don’t necessarily have to be sued to have a privacy problem become expensive.

Businesses across the country have received CIPA-related demand letters alleging that ordinary website technologies constitute illegal “spyware,” “trap and trace” devices, or similar technology.

One report described businesses receiving demands from Pacific Trial Attorneys involving technologies such as pixels and chat tools that allegedly collect IP addresses or other information.

That means a website owner could potentially receive a legal demand based on something they didn’t even realize was collecting information.

And that’s one reason website owners need to know what their third-party scripts actually do.

A demand letter is not a court judgment, and an allegation is not proof of a violation. Businesses receiving these letters should have the claims and underlying technology reviewed by qualified counsel.

But ignoring the possibility entirely isn’t a great strategy either.

[Source: Jeffer Mangels Butler & Marmaro / ADA Jeffer]

15. Vivek Shah’s CIPA demand letters

Another example involves pro se plaintiff Vivek Shah, who has sent waves of individual CIPA demand letters involving website search bars, forms, and other functionality that allegedly transmits information to companies such as Google, HubSpot, and Meta.

According to Donahue Fitzgerald, some of these demands commonly open at around $15,000 and are structured in a way that can resemble a ready-to-file lawsuit.

Again, these are demand letters and allegations, not regulatory fines or findings that every recipient violated CIPA.

But they’re another illustration of how ordinary website functionality can become the basis for a privacy-related legal dispute.

[Source: Donahue Fitzgerald]

16. SEAT S.A.: €12,000 for cookies and an ineffective “reject all”

Not every example is a tiny company.

SEAT S.A., the Spanish automobile manufacturer, was fined €12,000 over cookies being placed at the beginning of a session without consent and an ineffective “reject all” mechanism.

Why include a large company in an article about small businesses?

Because it provides useful context.

The issue isn’t that small businesses are somehow being singled out.

The underlying privacy principles can apply across organizations of very different sizes.

The difference is that when a major corporation receives a privacy penalty, there’s a good chance you’ll see it in the news.

When a small business receives a €1,200 or €3,000 penalty, you probably won’t.

[Source: DSGVO-Portal]

So, is privacy compliance really a “big business” problem?

No.

But there’s an important nuance.

Large companies absolutely face enormous privacy enforcement actions. Those cases make the headlines because the numbers are enormous. A multimillion-dollar penalty against a household-name company makes for an easy news story. A €600 penalty against a tiny business doesn’t. Neither does a €1,200 fine against a small event organizer.

A lawsuit against a local HVAC company might not make national news either.

But for a small business, the financial impact can be far more significant relative to the size of the organization.

And regulatory fines aren’t the only concern.

Depending on the law and circumstances, a business could face:

  • Regulatory investigations
  • Administrative penalties
  • Private lawsuits
  • Demand letters
  • Legal defense costs
  • Settlement costs
  • Required changes to website technology
  • Time spent investigating what happened
  • Customer trust issues
  • And the cost of fixing the problem after the fact

That doesn’t mean every privacy complaint will turn into a fine or lawsuit.

It doesn’t mean every demand letter has merit.

And it certainly doesn’t mean that every website using analytics or other tracking technology is automatically violating the law.

Privacy laws are complicated, and their application to modern website technology continues to evolve.

What it does mean is that “We’re just a small business” isn’t a privacy compliance strategy.

Your website is part of your privacy compliance

The good news is that website privacy compliance doesn’t have to mean becoming a privacy lawyer or spending every weekend reading regulatory decisions.

Start by figuring out what your website actually does.

  • What tracking technologies are installed?
  • What cookies are being used?
  • What information is collected through forms?
  • Which third-party services receive visitor information?
  • Do visitors receive the notices required by the laws that apply to your business?
  • Are non-essential cookies or tracking technologies being activated before the appropriate consent?
  • Can visitors exercise applicable privacy rights?
  • And are your website policies actually describing what your website does?

These are much better questions to ask than:

“We’re a small business. Do we really need to worry about this?”

Because the examples above demonstrate that small organizations can and do end up on the receiving end of privacy enforcement and litigation.

The biggest companies may get the biggest headlines.

But they’re not the only ones being held accountable.

Your business may be small.

Your website isn’t exempt simply because of its size.

And when it comes to privacy, finding the problem before someone else does is almost always a better time to discover it.

Note: This article is provided for informational purposes only and does not constitute legal advice. 

Photo of author
About the Author
Hans Skillrud

Hans is the Vice President of Termageddon, an auto-updating website policies generator. With Termageddon, you can generate a comprehensive set of policies for your website, and then receive automatic updates to your policies when the laws change.  When not working on Termageddon, you can find Hans gardening, beekeeping, fishing or taking care of his chickens.

Search the Site
Popular Articles
Browse by Category

Comparing Policy Generators

Cookie Consent Banner

Cookie Policy

Culture

Disclaimer

EULA

How To's

Privacy Policy

Terms of Service

Subscribe for Updates