EU Data Privacy Laws: GDPR, AI Act & the 2025-2026 Digital Reforms

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 26 primary sources cited on this page. How we verify our legal content

EU Data Privacy Laws: GDPR, AI Act & the 2025-2026 Digital Reforms

Frequently Asked Questions

Does the GDPR apply to companies outside the European Union?

Yes. The GDPR applies to any organization worldwide that offers goods or services to individuals in the EU or monitors the behavior of people located in the EU. A company does not need a physical presence in Europe to fall under the GDPR. Article 3 establishes this broad territorial scope, and the EDPB's Guidelines 3/2018 on Territorial Scope clarify how it applies to non-EU organizations.

What is the maximum fine under the GDPR?

The maximum fine is EUR 20 million or 4% of the organization's total worldwide annual turnover from the preceding financial year, whichever is higher. This upper-tier penalty applies to violations of core processing principles, data subject rights, and international transfer rules. The largest individual fine to date is EUR 1.2 billion, issued to Meta in 2023 by Ireland's Data Protection Commission for unlawful transfers of EU user data to the United States. That fine is under appeal, and a DPC fine cannot be collected while an appeal is pending.

Is the ePrivacy Regulation still coming?

No. The European Commission announced the withdrawal in its 2025 Work Programme of 11 February 2025, approved it on 16 July 2025, and the withdrawal was published in the Official Journal on 6 October 2025 (OJ C, C/2025/5423). The proposal had been stalled since 2017. The existing ePrivacy Directive (2002/58/EC) and its national transpositions remain in force. Some ePrivacy issues are being addressed through the November 2025 Digital Omnibus proposal, which proposes moving cookie consent rules into the GDPR framework.

What is the GDPR Procedural Regulation?

Regulation (EU) 2025/2518 is a new EU regulation that streamlines cross-border GDPR enforcement under the one-stop-shop mechanism. It came into force on 1 January 2026 and will apply from 2 April 2027. It introduces binding 15-month investigation deadlines, unified admissibility standards for complaints across all member states, an early resolution mechanism, and enhanced procedural rights for parties and complainants.

What is the EU Digital Omnibus and how does it affect the GDPR?

The Digital Omnibus is a European Commission proposal published on 19 November 2025 as part of a Digital Package. For the GDPR, key proposals include moving cookie consent rules from the ePrivacy Directive into the GDPR, harmonizing DPIA requirement lists at EU level, and creating a single reporting point for data breaches and cybersecurity incidents. The AI Act half of the Omnibus was adopted separately as Regulation (EU) 2026/1744 and has been in force since 27 July 2026; it moved the high-risk compliance deadlines to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and left the 2 August 2026 transparency date alone. The GDPR half, COM(2025) 837, is still in first reading as of 10 September 2026: Parliament has not adopted a position, the Council has not agreed a general approach, and trilogues have not opened.

What countries can receive EU personal data without additional safeguards?

As of 10 September 2026, the European Commission has granted adequacy decisions to the following destinations: Andorra, Argentina, Brazil, Canada (commercial organizations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom, United States (for organizations certified under the EU-US Data Privacy Framework), Uruguay, and the European Patent Organisation. Personal data can flow to these destinations without Standard Contractual Clauses or other additional mechanisms.

How does the EU AI Act interact with the GDPR?

The EU AI Act and the GDPR apply simultaneously to AI systems that process personal data. The AI Act imposes risk classification, transparency, logging, and conformity assessment obligations on AI providers and deployers. Where an AI system processes personal data, GDPR requirements including legal basis, data minimization, purpose limitation, and DPIAs for high-risk processing also apply. Joint guidelines on the interplay between the AI Act and the GDPR are listed in the EDPB work programme for 2026-2027, adopted on 12 February 2026. No adoption date for them has been published.

Updates

Corrected who the GDPR actually binds outside the EU (the Article 3 offering-goods-or-services and behaviour-monitoring test, not any organization holding an EU resident data), the status of the November 2025 Digital Omnibus (two proposals, still in first reading, with the GDPR half proposing to repeal the Data Governance Act), the EU-wide fine total (about EUR 6.3 billion across more than 3,200 actions), the ePrivacy Regulation withdrawal date (6 October 2025), and the Meta EUR 1.2 billion case, where the EDPB directed a fine the Irish DPC had proposed not to impose and which is still under appeal.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 (Annex III) and 2 August 2028 (Annex I), and the 2 August 2026 transparency date is unchanged, with only a 2 December 2026 grace period for marking synthetic content on systems already on the market.

Major expansion: added EU AI Act phased timeline, ePrivacy Directive and withdrawn ePrivacy Regulation, [GDPR](/world-laws/world-data-privacy-laws) Procedural Regulation (EU) 2025/2518, November 2025 Digital Omnibus proposal, AI Act political agreement of May 2026, wider EU digital rulebook (Data Act, DGA, DSA, DMA), member-state and sub-page directory, updated enforcement data.

Reviewed and approved by an editor

Sources and References

  1. GDPR Full Text - Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  2. European Commission - Data Protection in the EU(commission.europa.eu).gov
  3. EDPB Guidelines 3/2018 on Territorial Scope (Article 3)(edpb.europa.eu).gov
  4. EDPB Guidelines 1/2024 on Legitimate Interest(edpb.europa.eu).gov
  5. European Commission - Adequacy Decisions for International Data Transfers(commission.europa.eu).gov
  6. EU-US Data Privacy Framework Adequacy Decision (July 2023)(ec.europa.eu).gov
  7. European Data Protection Board (EDPB)(edpb.europa.eu).gov
  8. EDPB Binding Decision 1/2023 of 13 April 2023 on the Irish SA dispute concerning Meta transfers(edpb.europa.eu).gov
  9. EDPB CEF 2026 - Coordinated Enforcement on Transparency(edpb.europa.eu).gov
  10. GDPR Enforcement Tracker - Fines and Penalties Database(enforcementtracker.com)
  11. ePrivacy Directive 2002/58/EC - Full Text(eur-lex.europa.eu).gov
  12. EU AI Act - Regulation (EU) 2024/1689 Full Text(eur-lex.europa.eu).gov
  13. EU AI Act - European Commission Digital Strategy(digital-strategy.ec.europa.eu).gov
  14. Council of the EU - AI Act Simplification Political Agreement (May 2026)(consilium.europa.eu).gov
  15. EU Digital Package - Commission Overview(digital-strategy.ec.europa.eu).gov
  16. EU Data Act - Regulation (EU) 2023/2854(digital-strategy.ec.europa.eu).gov
  17. Data Governance Act - Regulation (EU) 2022/868(digital-strategy.ec.europa.eu).gov
  18. Digital Services Act - European Commission(commission.europa.eu).gov
  19. Digital Markets Act - European Commission (DMA portal)(digital-markets-act.ec.europa.eu).gov
  20. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  21. European Parliament Legislative Train - Digital Omnibus Regulation, 2025/0360(COD), status Tabled (updated 1 August 2026)(europarl.europa.eu).gov
  22. COM(2025) 837 final, 19 November 2025 - Digital Omnibus Regulation proposal (amendments and repeals, proposed GDPR Article 88a)(eur-lex.europa.eu).gov
  23. Withdrawal of Commission proposals (C/2025/5423), OJ C, 6.10.2025 - includes COM(2017) 10 final, the ePrivacy Regulation proposal(eur-lex.europa.eu).gov
  24. Irish Data Protection Commission - fines imposed since 25 May 2018 (updated 10 August 2026)(dataprotection.ie).gov
  25. Irish DPC press release - conclusion of the Meta Ireland transfers inquiry (EUR 1.2 billion, 22 May 2023)(dataprotection.ie).gov
  26. European Commission - DMA designated gatekeepers and core platform services(digital-markets-act.ec.europa.eu).gov
  27. EDPB work programme 2026-2027, adopted 12 February 2026 (includes joint AI Act and GDPR guidelines)(edpb.europa.eu).gov
Share: