EU Data Privacy Laws: GDPR, AI Act & the 2025-2026 Digital Reforms
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 26 primary sources cited on this page. How we verify our legal content

Regulation (EU) 2016/679, the GDPR, sets a single data protection standard across all 27 EU member states. It binds organizations established in the EU, and organizations outside the EU that offer goods or services to people in the EU or that monitor their behavior in the EU (Article 3). Violations carry fines up to EUR 20 million or 4% of global annual turnover under Article 83.
The European Union has built the world's most comprehensive data protection framework. At its core sits the General Data Protection Regulation (GDPR), a single set of rules that applies in every EU country. Layered around it are sectoral laws covering electronic communications, artificial intelligence, data markets, online platforms, and algorithmic gatekeepers.
This page is the hub for EU data privacy law. It explains how the framework fits together, covers the major legal instruments and their current status, and links to detailed guides for each EU member state and each GDPR sub-topic.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified data protection attorney or privacy professional for guidance specific to your situation.
Quick Answer
The GDPR is EU law that protects personal data. It applies to organizations established in the EU, and to organizations anywhere else in the world that offer goods or services to people in the EU or that monitor their behavior in the EU. Article 3 sets that two-limb test, so merely holding data about someone who happens to be in the EU does not by itself bring a non-EU organization within the GDPR. Penalties reach up to EUR 20 million or 4% of global annual turnover. Every EU member state enforces it through its own data protection authority (DPA), coordinated by the European Data Protection Board (EDPB).
The GDPR is not the only EU data law. The ePrivacy Directive governs cookies and electronic communications. The EU AI Act governs artificial-intelligence systems. The Data Act, Data Governance Act, Digital Services Act, and Digital Markets Act together form a broader digital rulebook. The GDPR Procedural Regulation (EU) 2025/2518 will streamline cross-border enforcement when it starts to apply on 2 April 2027. The November 2025 Digital Omnibus is a pending proposal that would simplify several of these instruments, and it has not been adopted.
The GDPR: Core EU Data Protection Law
The General Data Protection Regulation -- Regulation (EU) 2016/679 -- was adopted on 27 April 2016, entered into force on 24 May 2016 and applied from 25 May 2018. It replaced the 1995 Data Protection Directive (Directive 95/46/EC), which had produced a patchwork of inconsistent national laws.
Because the GDPR is a regulation rather than a directive, it is directly applicable in all member states without requiring national transposition of its core provisions. Where the GDPR reserves discretion to member states -- on the age of consent for children's data, additional conditions for employment data, or specific exemptions -- national implementing laws fill those gaps.

Territorial Scope (Article 3)
The GDPR applies in three situations. First, to any organization with an establishment in the EU that processes personal data in the context of that establishment, regardless of where the processing physically occurs. Second, to any organization outside the EU that offers goods or services to individuals in the EU. Third, to any organization outside the EU that monitors the behavior of individuals in the EU.
This broad extraterritorial reach means a company in the United States, India, or Australia must comply with the GDPR if it targets EU customers or tracks their behavior online. The EDPB Guidelines 3/2018 on territorial scope interpret Article 3 in detail.
The Seven Principles (Article 5)
Every processing activity must comply with seven principles: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. The accountability principle requires organizations to demonstrate compliance, not merely assert it.
Six Legal Bases for Processing (Article 6)
Processing is lawful only if it rests on one of six legal bases: consent, contract performance, legal obligation, vital interests, public interest or official authority, or legitimate interests. Organizations must identify and document their legal basis before processing begins and cannot change it retroactively.
Consent must be freely given, specific, informed, and unambiguous. It must be as easy to withdraw as to give. Pre-ticked boxes and bundled consent do not satisfy the GDPR's consent standard.
Data Subject Rights (Articles 15-22)
Articles 15 to 22 grant individuals seven enforceable rights: access, rectification, erasure (the "right to be forgotten"), restriction of processing, data portability, objection, and rights related to automated decision-making including profiling. Article 19 adds a controller duty to pass rectification, erasure and restriction on to every recipient of the data, and Articles 13 and 14 give individuals the right to be informed. Organizations must respond within one calendar month, extendable by two months in complex cases.
Controller and Processor Obligations
Data controllers determine the purposes and means of processing. Data processors act on instructions from controllers. Written contracts must govern every controller-processor relationship. Controllers must appoint a Data Protection Officer (DPO) in prescribed circumstances, conduct Data Protection Impact Assessments (DPIAs) before high-risk processing, and maintain records of processing activities.
Breach Notification (Articles 33-34)
Controllers must notify their supervisory authority within 72 hours of becoming aware of a personal data breach. If the breach poses a high risk to individuals, the controller must also notify affected individuals without undue delay.
Penalties (Article 83)
The GDPR's two-tier penalty structure provides fines up to EUR 10 million or 2% of global annual turnover (lower tier) and up to EUR 20 million or 4% of global annual turnover (upper tier), whichever is higher in each case. Since May 2018, EU and EEA DPAs have issued approximately EUR 6.3 billion in fines across more than 3,200 publicly known enforcement actions (GDPR Enforcement Tracker, 10 September 2026). There is no official EU-wide aggregate, so any total counts publicly reported decisions only.
For detailed coverage of each topic, see the GDPR sub-pages listed below.
GDPR Across 27 Member States
The GDPR is the same law in every EU country, but national implementing legislation, national DPAs, and national court decisions shape how it operates in practice.

National implementing laws address the topics where the GDPR reserves discretion to member states. Germany's Federal Data Protection Act (BDSG) sets strict rules on employee monitoring and works councils. France's loi Informatique et Libertés has been in force since 1978 and was updated to harmonize with the GDPR. Ireland's Data Protection Act 2018 sets the minimum age for children's consent at 16. Our Ireland law hub covers Irish rules on data protection, employment, tenancies, and family matters. Every member state has its own supplementary rules.
National DPAs investigate complaints, conduct audits, and issue fines. The Irish Data Protection Commission (DPC) is the lead DPA for most major US technology companies because those companies have their EU headquarters in Ireland. If you want the DPC to examine how a company handled your data, see our guide to making a GDPR complaint to Ireland's Data Protection Commission. Ireland's DPC has imposed about EUR 4.04 billion in GDPR fines in total since May 2018, the largest national share by value. Most of that comes from cross-border cases where it acts as lead authority, but the total also includes purely domestic Irish decisions.
The one-stop-shop mechanism allows organizations with establishments across multiple member states to deal with a single lead DPA for cross-border processing. Concerned DPAs in other member states can raise objections, and disputes escalate to the EDPB for a binding decision. The GDPR Procedural Regulation (discussed below) strengthens this mechanism with binding deadlines from April 2027.
The member-state guide section below links to every EU country's implementing law and DPA page on this site.
ePrivacy Directive and the Withdrawn ePrivacy Regulation
The ePrivacy Directive (Directive 2002/58/EC) governs privacy in electronic communications. It is the source of EU cookie consent rules. Article 5(3) of the Directive requires consent before storing or accessing information on a user's device -- the rule behind the cookie banners on virtually every European website.
The ePrivacy Directive is a directive, not a regulation, so each member state has transposed it into national law differently. Germany, France, Spain, and others have reached different conclusions on what counts as valid cookie consent under their national transpositions.
The ePrivacy Regulation proposal was introduced in January 2017. It was intended to replace the ePrivacy Directive with a directly applicable regulation and to bring cookie and communications-privacy rules into closer alignment with the GDPR. The proposal stalled in the Council for years, unable to reach agreement on data retention and legitimate-interest processing.
The European Commission announced its intention to withdraw the ePrivacy Regulation proposal in Annex IV of its 2025 Work Programme, COM(2025) 45 final of 11 February 2025, citing lack of expected agreement from the co-legislators and obsolescence in light of subsequent legislation. The Commission approved the withdrawal at its meeting of 16 July 2025, and the withdrawal took effect when it was published in the Official Journal on 6 October 2025 (OJ C, C/2025/5423). The current ePrivacy Directive and national transpositions therefore remain in force indefinitely.
The November 2025 Digital Omnibus proposal picks up some of this unfinished business by proposing to move cookie consent rules from the ePrivacy Directive into the GDPR and expand the list of processing activities that can proceed without consent. For detailed coverage of the current rules, see our ePrivacy Directive explainer.
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the world's first comprehensive regulatory framework for artificial intelligence. It was published in the Official Journal of the EU on 12 July 2024 and entered into force on 1 August 2024.
The AI Act takes a risk-based approach, dividing AI systems into four tiers: unacceptable risk (prohibited outright), high risk (strict compliance obligations), limited risk (transparency requirements), and minimal risk (no mandatory obligations). AI systems that process personal data are often subject to both the AI Act and the GDPR simultaneously.

Phased Implementation Timeline
The AI Act applies in phases:
- 2 February 2025 -- Prohibited AI practices and AI literacy obligations became applicable. Systems using subliminal manipulation, social scoring by public authorities, and most real-time biometric identification in public spaces are banned from this date.
- 2 August 2025 -- Obligations for providers of general-purpose AI (GPAI) models became applicable. Member states must designate national competent authorities and adopt national penalty laws. EU-level governance (the AI Board, Scientific Panel, and Advisory Forum) is operational.
- 2 August 2026 -- Article 50 transparency obligations apply: chatbot disclosure, notice for emotion recognition and biometric categorisation, deepfake labelling, and machine-readable marking of synthetic content. The Digital Omnibus did not postpone this date.
- 2 December 2026 -- Systems generating synthetic content that were already on the market before 2 August 2026 must meet the Article 50(2) marking rules by this date, under the new Article 111(4). New prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material also apply from this date.
- 2 December 2027 -- Compliance deadline for stand-alone high-risk AI systems listed in Annex III, along with the Chapter III Section 1 to 3 obligations that attach to them, moved from 2 August 2026 by the July 2026 Digital Omnibus.
- 2 August 2028 -- Compliance deadline for high-risk AI embedded in regulated products listed in Annex I, moved from 2 August 2027. This is the last block to take effect, so the AI Act is not fully applicable until this date.
Digital Omnibus on AI (Regulation (EU) 2026/1744)
The Digital Omnibus amendment to the AI Act was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, and entered into force on 27 July 2026. In addition to the timeline changes above, it extends regulatory relief available to SMEs to small mid-caps, narrows certain high-risk categorizations, and reinforces the AI Office's supervisory powers. It did not move the 2 August 2026 transparency date.
GDPR Procedural Regulation (Regulation (EU) 2025/2518)
For years, the GDPR's one-stop-shop mechanism suffered from procedural inconsistency: DPAs applied different admissibility standards, investigations ran for years without binding deadlines, and complainants in smaller member states had limited visibility into their cross-border cases.
The GDPR Procedural Regulation -- Regulation (EU) 2025/2518 -- was adopted in 2025 to fix these problems. It came into force on 1 January 2026 and will apply from 2 April 2027.
Key provisions include:
- Unified admissibility standards: the same criteria apply when deciding whether a complaint is admissible, regardless of which member state it is filed in.
- Binding 15-month investigation deadline: the lead DPA must complete its investigation within 15 months, with a possible 12-month extension in particularly complex cases.
- Early resolution mechanism: lead DPAs can resolve complaints before formal cooperation procedures begin, reducing administrative burden and accelerating outcomes.
- Enhanced procedural rights: both investigated parties and complainants have the right to access and comment on preliminary findings before a final decision is issued.
The November 2025 Digital Omnibus Proposal
On 19 November 2025, the European Commission published the Digital Omnibus as part of a Digital Package alongside the Data Union Strategy and European Business Wallets. The Digital Omnibus is two parallel proposals of 19 November 2025, not one. COM(2025) 837 would amend the GDPR, the EU institutions' data protection Regulation (EU) 2018/1725, the Single Digital Gateway Regulation, the Data Act, the ePrivacy Directive, the NIS2 Directive and the CER Directive. COM(2025) 836 handles the AI Act separately. The Cybersecurity Act is not part of either proposal; its revision is a distinct file. COM(2025) 837 would also repeal the Data Governance Act, the Free Flow of Non-Personal Data Regulation, the Platform-to-Business Regulation and the Open Data Directive, folding parts of them into the Data Act.
Key GDPR-related proposals include:
- Cookie consent simplification: cookie consent rules would move from the ePrivacy Directive into the GDPR, with an expanded list of activities exempt from consent, a single-click way to refuse a consent request, a bar on the controller re-asking for the same purpose for at least six months after a refusal, and machine-readable browser or device-level signals of the user's choice.
- Harmonized DPIA lists: the EDPB would compile EU-wide lists of processing activities that do or do not require a DPIA. Commission-approved lists would supersede conflicting national lists.
- Single incident reporting point: a unified mechanism for reporting cybersecurity incidents and personal data breaches under the GDPR, NIS2 Directive, and other instruments.
COM(2025) 837 is still in first reading. Parliament's ITRE and LIBE committees published a joint draft report on 22 June 2026 and more than 1,750 amendments were tabled to it, the Council has not agreed a general approach, and no trilogues have opened, according to the European Parliament's Legislative Train entry updated 1 August 2026. Only the AI half, COM(2025) 836, has been adopted, as Regulation (EU) 2026/1744. If the GDPR amendments are adopted, they would formally update Regulation (EU) 2016/679.
The EDPB and the Consistency Mechanism
The European Data Protection Board (EDPB) is the independent EU body responsible for consistent application of the GDPR across all member states. It is composed of the heads of each national DPA and the European Data Protection Supervisor (EDPS).
Its main functions include issuing guidelines, recommendations, and best practices; issuing binding decisions in disputes under the one-stop-shop mechanism; and conducting coordinated enforcement actions under the Coordinated Enforcement Framework (CEF).
The EDPS supervises the EU's own institutions in their handling of personal data and advises on EU legislation with a data protection dimension.
Consistency mechanism: when a national DPA adopts a measure that could affect data subjects in other member states, it must submit a draft decision to the EDPB. If a concerned DPA raises a relevant and reasoned objection that the lead DPA declines to follow, the EDPB issues a binding decision. This mechanism produced the EUR 1.2 billion fine against Meta in 2023, still the largest GDPR fine to date. The Irish DPC's draft decision of 6 July 2022 proposed a suspension order and no administrative fine at all. Four concerned authorities objected, and the EDPB's Binding Decision 1/2023 of 13 April 2023 directed the DPC to impose a fine, which the DPC did in its final decision of 12 May 2023. The fine is under appeal, and a DPC fine cannot be collected while an appeal is pending.
2026 coordinated enforcement: the EDPB launched its 2026 CEF action on 19 March 2026 on GDPR transparency and information obligations. Twenty-five data protection authorities are taking part. Participation in a CEF action is voluntary, so it is never the full set of authorities. In 2025, the CEF focused on the right to erasure.
The Wider EU Digital Rulebook
The GDPR is the foundation, but EU data law extends well beyond it. Several complementary instruments address specific sectors or types of data activity.
Data Governance Act (DGA) -- Regulation (EU) 2022/868, applicable since September 2023, and proposed for repeal by the November 2025 Digital Omnibus, which would move its data-intermediation and data-altruism rules into the Data Act. The DGA establishes trust frameworks for voluntary data sharing between companies and between the public and private sectors. It creates recognized data intermediaries and authorizes data altruism organizations. Where it involves personal data, the GDPR applies alongside it.
Data Act -- Regulation (EU) 2023/2854, applicable since 12 September 2025. The Data Act gives users of connected products (smart devices, industrial machinery, vehicles) the right to access and share the data generated by their use of those products. It governs business-to-business and business-to-government data sharing. Where personal data is involved, the GDPR applies concurrently.
Digital Services Act (DSA) -- Regulation (EU) 2022/2065. The DSA governs online intermediaries and platforms, with obligations on content moderation, transparency, and researcher data access. Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) face additional obligations. On 2 July 2025, the Commission published a delegated act enabling qualified researchers to access VLOP internal data to study systemic risks.
Digital Markets Act (DMA) -- Regulation (EU) 2022/1925. The DMA targets designated "gatekeeper" platforms. Seven undertakings are designated: Alphabet, Amazon, Apple, ByteDance, Meta and Microsoft, all on 6 September 2023, plus Booking, designated on 13 May 2024 for Booking.com. They carry interoperability, data portability, and consent obligations across 23 designated core platform services. In April 2025, the Commission issued its first non-compliance decisions: Apple received EUR 500 million for App Store steering restrictions and Meta received EUR 200 million for failing to offer users a less data-intensive service.
NIS2 Directive -- Directive (EU) 2022/2555. NIS2 imposes cybersecurity and incident reporting obligations on operators of essential services and digital providers. Data breaches that are also cybersecurity incidents may trigger both GDPR and NIS2 notification duties -- a complexity the Digital Omnibus single-reporting-point proposal is designed to resolve.
Adequacy Decisions and International Transfers
Transfers of personal data from the EU to third countries are governed by Chapter V of the GDPR. An adequacy decision by the European Commission permits free data flows to a destination without additional safeguards.
As of 10 September 2026, adequacy decisions cover: Andorra, Argentina, Brazil (2026), Canada (commercial organizations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom, United States (for organizations certified under the EU-US Data Privacy Framework), Uruguay, and the European Patent Organisation (2025).
EU-US Data Privacy Framework (DPF): The Commission adopted the DPF adequacy decision on 10 July 2023, replacing the invalidated Privacy Shield. The framework relies on US executive commitments limiting intelligence-agency access and on the Data Protection Review Court (DPRC) as a redress mechanism. The decision covers only US organizations that self-certify to the framework and appear on the active participant list maintained by the US Department of Commerce. The EU General Court dismissed a legal challenge on September 3, 2025 (Case T-553/23), but a further appeal before the CJEU (Case C-703/25 P, filed October 31, 2025) remains pending.
Where no adequacy decision exists, transfers may use Standard Contractual Clauses (SCCs, updated June 2021), Binding Corporate Rules (BCRs), or specific derogations. Organizations using SCCs must also conduct a transfer impact assessment (TIA).
GDPR Sub-Pages on This Site
These pages cover each major GDPR topic in depth:
- What Is GDPR? Complete Guide to EU Data Protection
- GDPR Consent Requirements: What Counts as Valid Consent
- GDPR Data Subject Rights: Access, Erasure and Portability
- GDPR Breach Notification: The 72-Hour Rule Explained
- GDPR Fines and Penalties: Complete List and Guide
- GDPR Compliance Checklist for Businesses
- GDPR for Small Businesses: Simplified Compliance Guide
- EU Cookie Law (ePrivacy Directive) Explained
EU Member-State Guides
Every EU member state has its own national implementing law and independent DPA. These pages explain how the GDPR applies in each country, what the national law adds, and how the local DPA enforces it:
- Austria Data Privacy Laws (DSG)
- Belgium Data Privacy Laws
- Bulgaria Data Privacy Laws
- Croatia Data Privacy Laws
- Cyprus Data Privacy Laws
- Czech Republic Data Privacy Laws
- Denmark Data Privacy Laws
- Estonia Data Privacy Laws
- Finland Data Privacy Laws
- France Data Privacy Laws (CNIL)
- Germany Data Privacy Laws (BDSG)
- Greece Data Privacy Laws (HDPA)
- Hungary Data Privacy Laws (NAIH)
- Ireland Data Privacy Laws (DPC)
- Italy Data Privacy Laws (Garante)
- Latvia Data Privacy Laws
- Lithuania Data Privacy Laws (VDAI)
- Luxembourg Data Privacy Laws (CNPD)
- Malta Data Privacy Laws
- Netherlands Data Privacy Laws (AP)
- Poland Data Privacy Laws (UODO)
- Portugal Data Privacy Laws (CNPD)
- Romania Data Privacy Laws (ANSPDCP)
- Slovakia Data Privacy Laws
- Slovenia Data Privacy Laws
- Spain Data Privacy Laws (AEPD / LOPDGDD)
- Sweden Data Privacy Laws (IMY)
EEA non-EU members applying the GDPR via the EEA Agreement:
In-depth guides
Frequently Asked Questions
Does the GDPR apply to companies outside the European Union?
Yes. The GDPR applies to any organization worldwide that offers goods or services to individuals in the EU or monitors the behavior of people located in the EU. A company does not need a physical presence in Europe to fall under the GDPR. Article 3 establishes this broad territorial scope, and the EDPB's Guidelines 3/2018 on Territorial Scope clarify how it applies to non-EU organizations.
What is the maximum fine under the GDPR?
The maximum fine is EUR 20 million or 4% of the organization's total worldwide annual turnover from the preceding financial year, whichever is higher. This upper-tier penalty applies to violations of core processing principles, data subject rights, and international transfer rules. The largest individual fine to date is EUR 1.2 billion, issued to Meta in 2023 by Ireland's Data Protection Commission for unlawful transfers of EU user data to the United States. That fine is under appeal, and a DPC fine cannot be collected while an appeal is pending.
Is the ePrivacy Regulation still coming?
No. The European Commission announced the withdrawal in its 2025 Work Programme of 11 February 2025, approved it on 16 July 2025, and the withdrawal was published in the Official Journal on 6 October 2025 (OJ C, C/2025/5423). The proposal had been stalled since 2017. The existing ePrivacy Directive (2002/58/EC) and its national transpositions remain in force. Some ePrivacy issues are being addressed through the November 2025 Digital Omnibus proposal, which proposes moving cookie consent rules into the GDPR framework.
What is the GDPR Procedural Regulation?
Regulation (EU) 2025/2518 is a new EU regulation that streamlines cross-border GDPR enforcement under the one-stop-shop mechanism. It came into force on 1 January 2026 and will apply from 2 April 2027. It introduces binding 15-month investigation deadlines, unified admissibility standards for complaints across all member states, an early resolution mechanism, and enhanced procedural rights for parties and complainants.
What is the EU Digital Omnibus and how does it affect the GDPR?
The Digital Omnibus is a European Commission proposal published on 19 November 2025 as part of a Digital Package. For the GDPR, key proposals include moving cookie consent rules from the ePrivacy Directive into the GDPR, harmonizing DPIA requirement lists at EU level, and creating a single reporting point for data breaches and cybersecurity incidents. The AI Act half of the Omnibus was adopted separately as Regulation (EU) 2026/1744 and has been in force since 27 July 2026; it moved the high-risk compliance deadlines to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and left the 2 August 2026 transparency date alone. The GDPR half, COM(2025) 837, is still in first reading as of 10 September 2026: Parliament has not adopted a position, the Council has not agreed a general approach, and trilogues have not opened.
What countries can receive EU personal data without additional safeguards?
As of 10 September 2026, the European Commission has granted adequacy decisions to the following destinations: Andorra, Argentina, Brazil, Canada (commercial organizations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom, United States (for organizations certified under the EU-US Data Privacy Framework), Uruguay, and the European Patent Organisation. Personal data can flow to these destinations without Standard Contractual Clauses or other additional mechanisms.
How does the EU AI Act interact with the GDPR?
The EU AI Act and the GDPR apply simultaneously to AI systems that process personal data. The AI Act imposes risk classification, transparency, logging, and conformity assessment obligations on AI providers and deployers. Where an AI system processes personal data, GDPR requirements including legal basis, data minimization, purpose limitation, and DPIAs for high-risk processing also apply. Joint guidelines on the interplay between the AI Act and the GDPR are listed in the EDPB work programme for 2026-2027, adopted on 12 February 2026. No adoption date for them has been published.
Updates
Corrected who the GDPR actually binds outside the EU (the Article 3 offering-goods-or-services and behaviour-monitoring test, not any organization holding an EU resident data), the status of the November 2025 Digital Omnibus (two proposals, still in first reading, with the GDPR half proposing to repeal the Data Governance Act), the EU-wide fine total (about EUR 6.3 billion across more than 3,200 actions), the ePrivacy Regulation withdrawal date (6 October 2025), and the Meta EUR 1.2 billion case, where the EDPB directed a fine the Irish DPC had proposed not to impose and which is still under appeal.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 (Annex III) and 2 August 2028 (Annex I), and the 2 August 2026 transparency date is unchanged, with only a 2 December 2026 grace period for marking synthetic content on systems already on the market.
Major expansion: added EU AI Act phased timeline, ePrivacy Directive and withdrawn ePrivacy Regulation, [GDPR](/world-laws/world-data-privacy-laws) Procedural Regulation (EU) 2025/2518, November 2025 Digital Omnibus proposal, AI Act political agreement of May 2026, wider EU digital rulebook (Data Act, DGA, DSA, DMA), member-state and sub-page directory, updated enforcement data.
Reviewed and approved by an editor
Sources and References
- GDPR Full Text - Regulation (EU) 2016/679(eur-lex.europa.eu).gov
- European Commission - Data Protection in the EU(commission.europa.eu).gov
- EDPB Guidelines 3/2018 on Territorial Scope (Article 3)(edpb.europa.eu).gov
- EDPB Guidelines 1/2024 on Legitimate Interest(edpb.europa.eu).gov
- European Commission - Adequacy Decisions for International Data Transfers(commission.europa.eu).gov
- EU-US Data Privacy Framework Adequacy Decision (July 2023)(ec.europa.eu).gov
- European Data Protection Board (EDPB)(edpb.europa.eu).gov
- EDPB Binding Decision 1/2023 of 13 April 2023 on the Irish SA dispute concerning Meta transfers(edpb.europa.eu).gov
- EDPB CEF 2026 - Coordinated Enforcement on Transparency(edpb.europa.eu).gov
- GDPR Enforcement Tracker - Fines and Penalties Database(enforcementtracker.com)
- ePrivacy Directive 2002/58/EC - Full Text(eur-lex.europa.eu).gov
- EU AI Act - Regulation (EU) 2024/1689 Full Text(eur-lex.europa.eu).gov
- EU AI Act - European Commission Digital Strategy(digital-strategy.ec.europa.eu).gov
- Council of the EU - AI Act Simplification Political Agreement (May 2026)(consilium.europa.eu).gov
- EU Digital Package - Commission Overview(digital-strategy.ec.europa.eu).gov
- EU Data Act - Regulation (EU) 2023/2854(digital-strategy.ec.europa.eu).gov
- Data Governance Act - Regulation (EU) 2022/868(digital-strategy.ec.europa.eu).gov
- Digital Services Act - European Commission(commission.europa.eu).gov
- Digital Markets Act - European Commission (DMA portal)(digital-markets-act.ec.europa.eu).gov
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
- European Parliament Legislative Train - Digital Omnibus Regulation, 2025/0360(COD), status Tabled (updated 1 August 2026)(europarl.europa.eu).gov
- COM(2025) 837 final, 19 November 2025 - Digital Omnibus Regulation proposal (amendments and repeals, proposed GDPR Article 88a)(eur-lex.europa.eu).gov
- Withdrawal of Commission proposals (C/2025/5423), OJ C, 6.10.2025 - includes COM(2017) 10 final, the ePrivacy Regulation proposal(eur-lex.europa.eu).gov
- Irish Data Protection Commission - fines imposed since 25 May 2018 (updated 10 August 2026)(dataprotection.ie).gov
- Irish DPC press release - conclusion of the Meta Ireland transfers inquiry (EUR 1.2 billion, 22 May 2023)(dataprotection.ie).gov
- European Commission - DMA designated gatekeepers and core platform services(digital-markets-act.ec.europa.eu).gov
- EDPB work programme 2026-2027, adopted 12 February 2026 (includes joint AI Act and GDPR guidelines)(edpb.europa.eu).gov