1. Digital Policy
  2. Instruments
  3. GDPR

Regulation · directly applicable · CELEX 32016R0679

GDPR

Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data

Known as the General Data Protection Regulation. Official text: Regulation (EU) 2016/679 (General Data Protection Regulation)Tier 1 · primary law

Status
Applicable as of 19 August 2026
Competent authority
National DPAsand 3 more — see below
Sanction ceiling
4% of global turnover / EUR 20m

What it does

Protection of natural persons with regard to the processing of personal data, and free movement of such data within the Union.

How it allocates obligations

Risk to the rights and freedoms of natural persons.

Regulated actor
Controller · Processor
Protected party
Data subject
Territorial reach
Established in the EU · Outside the EU, serving EU users
Implementation model
Directly applicable
Enforcement mechanism
National supervisory authorities with the one-stop-shop for cross-border cases; EDPB consistency and dispute resolution.

Key dates

Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.

  1. 27 April 2016AdoptionAdoption
  2. 4 May 2016Publication in the Official JournalPublication in the Official Journal
  3. 24 May 2016Entry into forceEntry into force
  4. 25 May 2018Application dateThe full GDPR obligation set becomes applicable.

The whole compliance calendar, filterable →

Who it applies to

5 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.

Yes

activity Processing personal dataterritory Established in the EU

Any processing of personal data by a controller or processor established in the Union falls within the GDPR, whatever the sector and whatever the size of the organisation. There is no de minimis exemption from the Regulation as a whole.

Exemptions: Purely personal or household activity is outside scope. · Article 30(5) narrows the records obligation for organisations under 250 employees, but does not remove it where processing is not occasional or involves special categories.

Last verified 27 August 2026

Potentially applicable

activity Processing personal dataterritory Outside the EU, serving EU users

Article 3(2) reaches a controller not established in the Union where the processing relates to offering goods or services to data subjects in the Union, or to monitoring their behaviour. Whether either limb is met is a question of fact about targeting that this questionnaire does not establish — merely being accessible from the Union is not enough.

Last verified 27 August 2026

Yes

actor Public authorityactivity Processing personal data

A public authority processing personal data owes the full obligation set, and must designate a data protection officer under Article 37 irrespective of the scale of processing.

Exemptions: Processing by competent authorities for law-enforcement purposes falls under the Law Enforcement Directive rather than the GDPR — an instrument outside this dataset.

Last verified 27 August 2026

Potentially applicable

actor AI provider or AI deployeractivity Deploying AI systems or Processing personal data

Article 22 has governed decisions based solely on automated processing since 2018 and applies to systems the AI Act classifies as minimal risk. An AI system that produces legal or similarly significant effects for individuals engages it regardless of the AI Act tier the system falls into.

Last verified 27 August 2026

Yes

actor Very large online platform or Online platformactivity Operating recommender systems or Operating an online platform

The DSA and the GDPR both reach the same conduct here and pull in different directions: the DSA requires transparency about recommender parameters and an advertisement repository, while the GDPR requires minimisation. EDPB guidance mediates the conflict without dissolving it. Compliance with one is not compliance with the other.

Last verified 27 August 2026

Run these against your situation →

Key provisions

16 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.

ArticleHeadingBindsApplies
Art. 3Territorial scopeApplies to processing by a controller or processor established in the Union, and to processing of data subjects in the Union by a controller not established in the Union where it relates to offering goods or services to them or monitoring their behaviour.Controller · ProcessorApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 5load-bearingPrinciples relating to processing of personal dataSix processing principles plus accountability: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality.ControllerApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 6load-bearingLawfulness of processingExhaustive list of lawful bases: consent, contract, legal obligation, vital interests, public task, legitimate interests.ControllerApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 9Processing of special categories of personal dataProhibits processing of special categories absent a narrow derogation.ControllerApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 22Automated individual decision-making, including profilingProtection against decisions based solely on automated processing producing legal or similarly significant effects. In force since 2018, and therefore the pre-existing European law of automated decision-making.ControllerApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 25load-bearingData protection by design and by defaultControllerApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 30load-bearingRecords of processing activitiesController · ProcessorApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 33Notification of a personal data breach to the supervisory authority72-hour notification decision.ControllerApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 35load-bearingData protection impact assessmentThe conceptual ancestor of the DSA's Art. 34 systemic risk assessment and the AI Act's Art. 27 fundamental rights impact assessment.ControllerApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 37Designation of the data protection officerMandatory where processing is carried out by a public authority or body, and in the other cases the Article specifies.Controller · Processor · Public authorityApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 51Supervisory authorityEach Member State provides for one or more independent supervisory authorities.Member StateApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 56Competence of the lead supervisory authorityThe one-stop-shop: the authority of the controller's main establishment leads cross-border cases.not recordedApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 58Powers of supervisory authoritiesnot recordedApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 60Cooperation between the lead authority and other concerned authoritiesnot recordedApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 65Dispute resolution by the Boardnot recordedApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded
Art. 83General conditions for imposing administrative finesTwo-tier penalty ceilings.not recordedApplies from 25 May 2018the instrument’s general date; nothing specific to this article is recorded

Enforcement

EUR 3.61bnannounced across 6 records
unknowndemonstrably collected

3 of 6 records cannot settle whether money moved. That is not zero, and the announced figure is not a total of anything that has been paid.

Uber Technologies Inc.

Imposed
EUR 825mannounced
Unknownpayment
21 August 2026decision
Authority
AP
Issue
Administrative fine for fully automated deactivation of drivers (Art. 22 GDPR) and insufficient information about it
Legal basis
Art. 22 · Art. 83
Full record and derivation →Last verified 27 September 2026

TikTok Technology Limited

Under appeal
EUR 530mannounced
Not yet payablepayment
30 April 2025decision
Authority
Irish DPC
Issue
Administrative fines and order to bring China transfers into compliance within six months (Arts. 46(1) and 13(1)(f) GDPR infringed)
Legal basis
Art. 83

High Court of Ireland (Commercial), Mulcahy J, 3 June 2026. Main judgment of 3 June 2026: every ground against the two infringement findings (Art. 46(1), 29 July 2020 to 17 May 2023; Art. 13(1)(f), 29 July 2020 to 1 December 2022) and against the decision to impose fines to be dismissed; the DPC made no error of law in holding that a controller must verify, and be able to demonstrate, essentially equivalent protection for data transferred. The court found errors in the DPC's assessment of material relevant to the suspension order (an unconsidered expert opinion on Chinese law; no reasons given for rejecting TikTok's Project Clover measures) and proposed to vacate the corrective orders and remit them to the DPC, subject to hearing the parties on the final form of order. The amount of the fines was left over: by a second judgment of 30 June 2026 ([2026] IEHC 419) the court held the DPC entitled, subject to the CJEU's answers, to use ByteDance's turnover and 2024 as the preceding financial year, and proposed four questions for a preliminary reference on Art. 83.

Full record and derivation →Last verified 27 September 2026

OpenAI

Annulled
EUR 15mannounced
Not yet payablepayment
2 November 2024decision
Authority
Garante
Issue
Administrative fine
Legal basis
Art. 83

Tribunale di Roma, 18 March 2026. Annulled on a preliminary, jurisdictional ground (as analysed by the European Law Blog; the judgment's text has not been read here): once OpenAI Ireland was recognised by the Irish DPC as OpenAI's single EEA establishment (15 February 2024), the DPC became lead authority under the one-stop-shop. Some twenty months of investigation, from March 2023 to the November 2024 decision, ended with no court ruling on whether the conduct was lawful.

Full record and derivation →Last verified 27 September 2026

Uber Technologies Inc. and Uber B.V.

Imposed
EUR 290mannounced
Unknownpayment
26 August 2024decision
Authority
AP
Issue
Administrative fine for transferring European drivers' data to the US without appropriate safeguards (Chapter V GDPR)
Legal basis
Art. 83
Full record and derivation →Last verified 27 September 2026

Meta Platforms Ireland Limited

Imposed
EUR 1.2bnannounced
Unknownpayment
12 May 2023decision
Authority
Irish DPC
Issue
Administrative fine and order to suspend EU-US transfers (Art. 46(1) GDPR infringed)
Legal basis
Art. 83
Full record and derivation →Last verified 27 September 2026

Amazon Europe Core S.à r.l.

Annulled
EUR 746mannounced
Not yet payablepayment
15 July 2021decision
Authority
CNPD
Issue
Administrative fine
Legal basis
Art. 6 · Art. 83

Cour administrative (Luxembourg), 12 March 2026. The CNPD's decision was annulled in all its parts and the file remitted to the CNPD: it had not examined fault (intent or at least negligence), which the CJEU requires (C-807/21 Deutsche Wohnen and C-683/21 Nacionalinis: the GDPR sets no strict liability), and it had treated a fine as the only option, without weighing the other measures available under Art. 58. On the merits the Court confirmed, for the practices at the start of the investigation, that Art. 6(1)(f) was not a sufficient legal basis and that Arts 12–14 were breached, and confirmed Arts 15–17 subject to the reservation that rectification and erasure were at risk rather than shown to be infringed; it held that the investigation's scope did not cover Arts 16 and 21. The CNPD itself declared its injunctions moot, the last changes it asked for having been made. Judgment of 12 March 2026 (ECLI:LU:CADM:2026:52757), published 13 March 2026.

Full record and derivation →Last verified 27 September 2026

Evidence and sources

Every statement this site makes about GDPR, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.

The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.

15 Primary law7 Official source8 Secondary only3 Derived by this site5 Attributed view11 Interpretation4 Unresolved
Primary lawlaw

The GDPR rests on Article 16 TFEU, the Union's data-protection competence, not on Article 114.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Citation: 'Having regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof'

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The GDPR applies to controllers and processors not established in the Union when they process personal data of data subjects who are in the Union in connection with offering them goods or services or monitoring their behaviour there.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 3(2)(a)–(b)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

GDPR Article 56 gives the supervisory authority of the controller's main establishment the lead role in cross-border cases, with Article 60 cooperation and Article 65 EDPB dispute resolution behind it.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Arts. 56, 60, 65

Read it in the brief →Last verified 27 August 2026
Primary lawlaw

Regulation (EU) 2025/2518, which harmonises the admissibility of complaints, the parties' procedural rights and the time limits for draft decisions in cross-border GDPR cases, entered into force on 1 January 2026 and applies from 2 April 2027, its investigation rules to complaints lodged after that date.

Tier 1 · primary lawstates this

Regulation (EU) 2025/2518 of 26 November 2025 laying down additional procedural rules on the enforcement of Regulation (EU) 2016/679 — Publications Office of the European Union (Cellar) 12 December 2025 Art. 4(1) (admissibility), Arts 19, 22 and 24 (right to be heard, administrative file), Art. 12(1) and (6) (draft decision within 15 months, 12 under the simple cooperation procedure), Art. 36 (transitional provisions), Art. 37 (entry into force and application)

Tier 3 · researchstates this

New Regulation Speeds Up Handling of Cross-Border GDPR Complaints — eucrim (Max Planck Institute for the Study of Crime, Security and Law) 16 January 2026 "Regulation 2025/2518 entered into force on 1 January 2026 and it will apply from 2 April 2027"

Read it in the brief →Last verified 27 September 2026
Primary lawfact

The EUR 746 million fine against Amazon Europe Core was annulled by the Luxembourg courts in March 2026 on procedural grounds — the authority had not adequately assessed intent, negligence and proportionality — and referred back for reassessment, though the underlying violations were upheld.

Tier 1 · primary lawstates this

Cour administrative, arrêt du 12 mars 2026, n° 52757C du rôle, ECLI:LU:CADM:2026:52757 — Cour administrative du Grand-Duché de Luxembourg 12 March 2026 dispositif, p. 89: "par réformation du jugement entrepris du 18 mars 2025, annule la décision de la Commission nationale pour la protection des données du 15 juillet 2021 en tous ses volets et renvoie le dossier devant ladite Commission"; grounds pp. 85–88 (fault not examined; fine the only option considered); merits §§ 5.1–5.2 (Art. 6(1)(f), Arts 12–14 and 15–17 confirmed)

Tier 2 · regulatorstates this

Arrêt de la Cour administrative en relation avec un des grands acteurs mondiaux au niveau du commerce en ligne — Justice Luxembourg (justice.public.lu) 13 March 2026 "Dans son arrêt du 12 mars 2026, la Cour …"

Tier 4 · press / advocacystates this

Amazon sees Luxembourg appeals court annul EUR 746 million GDPR fine — MLex March 2026 "upheld the … findings that Amazon breached the GDPR, but referred the case back … for a new analysis of whether Amazon had engaged in deliberate conduct or negligence"

Tier 4 · press / advocacystates this

Luxembourg court of appeal cancels EUR 746 million CNPD fine against Amazon — Linari Law Firm March 2026 Title: "Luxembourg court of appeal cancels EUR 746 million CNPD fine against Amazon"

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The CJEU held in EDPS v SRB (C-413/23 P) that pseudonymised data is not necessarily personal data for every entity: identifiability must be assessed relative to the means reasonably likely to be used by the entity in question.

Tier 1 · primary lawstates this

Judgment in Case C-413/23 P, EDPS v SRB — Court of Justice of the European Union 4 September 2025 Judgment of 4 September 2025, paras 80 and 82: pseudonymised data is not to be regarded "in all cases and for every person" as personal data

Tier 2 · regulatorstates this

Press release on Case C-413/23 P — Court of Justice of the European Union 4 September 2025 Press Release No 107/25, page 1, paragraph beginning 'In the second place': pseudonymised data 'must not be regarded as constituting, in all cases and for every person, personal data'

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

GDPR Article 22 is the pre-existing European law of automated decision-making: it did not wait for the AI Act and applies to systems the AI Act classifies as minimal risk.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 22

Tier 1 · primary lawsupports in part

Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex 12 July 2024 Art. 6

Read it in the brief →Last verified 27 August 2026
Primary lawlaw

Article 5 GDPR sets six principles for processing — lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality — and makes the controller responsible for, and able to demonstrate, compliance with them (accountability).

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 5(1)(a)–(f); Art. 5(2)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 6(1) GDPR makes processing lawful only where at least one of six bases applies: consent, contract, legal obligation, vital interests, public task or legitimate interests.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 6(1)(a)–(f)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 9 GDPR prohibits processing of special categories of personal data unless one of the exceptions it lists applies.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 9(1)–(2)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Chapter III GDPR (Articles 12 to 23) sets out the data subject's rights: information, access, rectification, erasure, restriction, portability, objection, and the Article 22 right not to be subject to a decision based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects them.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Arts. 12–22 (Chapter III); Art. 22(1)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Chapter IV GDPR includes data protection by design and by default (Article 25), records of processing activities (Article 30), personal data breach notification and communication (Articles 33 and 34), data protection impact assessment (Article 35) and the data protection officer (Articles 37 to 39).

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Arts. 25, 30, 33–35, 37–39 (Chapter IV)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Chapter V GDPR governs transfers of personal data to third countries and international organisations.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Chapter V, Arts. 44–50

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 83 GDPR sets two tiers of fine ceilings: up to EUR 10 million or 2% of total worldwide annual turnover, and up to EUR 20 million or 4%, whichever is higher in each case.

Tier 1 · primary lawstates this

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 83(4) and (5)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

The Commission's four principal proposed GDPR reforms were: an entity-relative test for personal data in Art. 4(1); a new Art. 41a empowering the Commission to set, by implementing acts, the means and criteria for determining when pseudonymised data ceases to be personal; relocation of cookie consent into a new Art. 88a; and a new Art. 88c providing an explicit legitimate-interest basis for AI model training. None is law.

Tier 1 · primary lawstates this

COM(2025) 837 final — Digital Omnibus Regulation — European Commission 19 November 2025 Art. 3 (amendments to Regulation (EU) 2016/679): point 1(a) (Art. 4(1), added sentences), point 10 (new Art. 41a), point 15 (new Arts 88a and 88c)

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VIII

Read it in the brief →Last verified 27 September 2026
Official sourcefact

The Irish DPC accounts for about EUR 4.04 billion of cumulative GDPR fine value.

Tier 4 · press / advocacystates this

GDPR Fines and Data Breach Survey: January 2026 (eighth edition) — DLA Piper 21 January 2026 EUR 4.04bn, Irish Data Protection Commission

Tier 2 · regulatorstates this

Fines — Data Protection Commission (Ireland) "Total Fines (last updated 10/08/2026) €4,038,832,000"

Tier 4 · press / advocacysupports in part

Data Protection Commission owed over EUR 4 billion in fines — RTÉ 12 January 2026

Tier 2 · regulatorcontext only

Data Protection Commission publishes Annual Report for 2025 and results of 'Sharenting' survey — Data Protection Commission (Ireland) 30 June 2026

Read it in the brief →Last verified 27 September 2026
Official sourcefact

On 21 August 2026 the Dutch data protection authority fined Uber EUR 824,990,000 under the GDPR for fully automated deactivation of drivers; Uber has appealed.

Tier 2 · regulatorstates this

Uber fined nearly 825 million euros for automated driver blocking — Autoriteit Persoonsgegevens (Dutch Data Protection Authority) 21 August 2026 First paragraph ('a fine of 824,990,000 euros on Uber'); section 'Amount of the fine for Uber' ('Uber has filed an appeal against the fine')

Read it in the brief →Last verified 27 September 2026
Official sourcefact

In August 2024 the Dutch data protection authority fined Uber EUR 290 million under the GDPR for transferring European drivers' data to the US without appropriate safeguards.

Tier 2 · regulatorstates this

Dutch DPA imposes a fine of 290 million euro on Uber because of transfers of drivers' data to the US — Autoriteit Persoonsgegevens (Dutch Data Protection Authority) 26 August 2024 First paragraph ('a fine of 290 million euros on Uber'), 26 August 2024

Read it in the brief →Last verified 27 September 2026
Official sourcefact

Of more than EUR 4 billion levied through DPC inquiries, only on the order of EUR 20 million has been collected, because fines generally do not become payable until confirmed by a court.

Tier 2 · regulatorstates this

Fines — Data Protection Commission (Ireland) "over €4 billion in fines have been levied … To date, approximately €20 million in fines has been collected"; "Collection of Fines": fines "do not become payable until they are confirmed in Court"

Tier 4 · press / advocacystates this

Billions in data protection fines imposed, just EUR 20 million collected — TheStory.ie 13 January 2026 "€4.02 billion of it remains uncollected and just €20 million has been paid in fines so far"

Tier 4 · press / advocacystates this

Data Protection Commission owed over EUR 4 billion in fines — RTÉ 12 January 2026 "€4.02 billion of it remains uncollected and just €20m has been paid in fines so far"

Read it in the brief →Last verified 27 September 2026
Official sourcefact

The DPC has grown to nearly 300 staff by 2026 and moved to a three-Commissioner structure.

Tier 2 · regulatorstates this

Data Protection Commission — Annual Report 2025 — Data Protection Commission (Ireland) 30 June 2026 p. 5 (Commissioners' foreword: 'completing the move from a one to three-person Commission'; staff 'increased to 295 by year end') and p. 115 ('By year-end 2025, the DPC had reached a total headcount of 295')

Tier 4 · press / advocacystates this

New Irish Data Protection Commissioner Niamh Sweeney addresses scrutiny over her appointment, shares agency priorities — IAPP 1 April 2026 'With nearly 300 staff, up from 27 in 2014'

Tier 2 · regulatorsupports in part

Data Protection Commission publishes Annual Report for 2025 and results of 'Sharenting' survey — Data Protection Commission (Ireland) 30 June 2026 three Commissioners named

Unverified · the brief itselfcontext only

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 27 September 2026
Official sourcefact

The EDPB made transparency and information obligations under GDPR Articles 12 to 14 the subject of its 2026 coordinated enforcement action, with twenty-five data protection authorities taking part.

Tier 2 · regulatorstates this

CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPR — European Data Protection Board 19 March 2026 "Next steps": "During 2026, 25 Data Protection Authorities (DPAs) across Europe will take part in this initiative"

Read it in the brief →Last verified 27 September 2026
Official sourcefact

Meta's binary pay-or-consent model was found not to provide the genuinely equivalent, less data-intensive alternative DMA Article 5(2) requires.

Tier 2 · regulatorstates this

Commission finds Apple and Meta in breach of the Digital Markets Act — European Commission 23 April 2025 IP/25/1085, section 'Non-compliance decision on Meta's “consent or pay” model': the model 'did not give users the required specific choice to opt for a service that uses less of their personal data but is otherwise equivalent'

Read it in the brief →Last verified 27 September 2026
Secondary onlyfact

Cumulative GDPR fines have passed roughly EUR 7.1 billion since 2018.

Tier 4 · press / advocacystates this

GDPR Fines and Data Breach Survey: January 2026 (eighth edition) — DLA Piper 21 January 2026 Aggregate total to 10 January 2026

Tier 4 · press / advocacysupports in part

GDPR Enforcement Tracker Report 2025/2026 (7th edition) — CMS 1 March 2026

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 28 August 2026
Secondary onlyfact

Spain leads by number of GDPR decisions, with over a thousand.

Tier 4 · press / advocacystates this

GDPR Enforcement Tracker Report 2025/2026 (7th edition) — CMS 1 March 2026 Numbers and figures: 1,048 published fines, most active authority

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 28 August 2026
Secondary onlyfact

Regulators are processing an average of 443 breach notifications per day, a 22% year-on-year increase.

Tier 4 · press / advocacystates this

GDPR Fines and Data Breach Survey: January 2026 (eighth edition) — DLA Piper 21 January 2026 443 per day, up 22% from 363 (28 Jan 2025 – 27 Jan 2026)

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 28 August 2026
Secondary onlyfact

On 27 September 2026 the CMS GDPR Enforcement Tracker recorded total fines of EUR 7,159,322,834 across 3,275 cases.

Tier 4 · press / advocacystates this

GDPR Enforcement Tracker — Insights (data refreshed 27 September 2026) — CMS 27 September 2026 Headline: "Total fines €7.16B €7,159,322,834"; "Total cases 3,275"; "data shown was last refreshed 2026-09-27 13:01 UTC"

Read it in the brief →Last verified 27 September 2026
Secondary onlyfact

On 27 September 2026 the CMS GDPR Enforcement Tracker recorded fines totalling EUR 3,124,976,242 for insufficient legal basis for data processing.

Tier 4 · press / advocacystates this

GDPR Enforcement Tracker — Insights (data refreshed 27 September 2026) — CMS 27 September 2026 "Top violation types", by penalty total: "Insufficient legal basis for data processing", sum 3124976242, count 992 (the page's embedded chart data)

Read it in the brief →Last verified 27 September 2026
Secondary onlyfact

On 27 September 2026 the CMS GDPR Enforcement Tracker recorded fines totalling EUR 2,649,889,997 for non-compliance with general data processing principles.

Tier 4 · press / advocacystates this

GDPR Enforcement Tracker — Insights (data refreshed 27 September 2026) — CMS 27 September 2026 "Top violation types", by penalty total: "Non-compliance with general data processing principles", sum 2649889997, count 814

Read it in the brief →Last verified 27 September 2026
Secondary onlyfact

On 27 September 2026 the CMS GDPR Enforcement Tracker recorded fines totalling EUR 971,797,663 for insufficient technical and organisational measures to ensure information security.

Tier 4 · press / advocacystates this

GDPR Enforcement Tracker — Insights (data refreshed 27 September 2026) — CMS 27 September 2026 "Top violation types", by penalty total: "Insufficient technical and organisational measures to ensure information security", sum 971797663, count 616

Read it in the brief →Last verified 27 September 2026
Secondary onlyfact

The Italian Garante's EUR 15 million ChatGPT decision was voided by a Rome tribunal in March 2026 on a pure jurisdiction point: once OpenAI established an Irish subsidiary, the DPC became lead authority.

Tier 3 · researchstates this

Establish, Then Escape? How the Court of Rome, the One-Stop-Shop and a Single Word Opened an AI Enforcement Gap — European Law Blog 4 June 2026 "annulled Decision No. 755 in its entirety on a purely preliminary, jurisdictional ground"; notes [i]–[ii]: R.G. 4785/2025, decided 18 March 2026; OpenAI Ireland recognised by the DPC as single EEA establishment on 15 February 2024

Tier 2 · regulatorsupports in part

ChatGPT, il Garante privacy chiude l’istruttoria. OpenAI dovrà realizzare una campagna informativa di sei mesi e pagare una sanzione di 15 milioni di euro — Garante per la protezione dei dati personali (Italy) 20 December 2024 notice at the head of the release: "Il provvedimento n. 755 del 2 novembre 2024 è stato temporaneamente rimosso ... a seguito della sentenza del Tribunale di Roma n. 4153/2026, pubbl. il 18/03/2026, con la quale è stata accolta l'opposizione" — the Garante's own record that the decision fell in March 2026; it does not state the ground

Read it in the brief →Last verified 27 September 2026
Derived by this sitederived

The Irish DPC's share of cumulative GDPR fine value is roughly 57%.

Tier 4 · press / advocacysupports in part

GDPR Fines and Data Breach Survey: January 2026 (eighth edition) — DLA Piper 21 January 2026 EUR 4.04bn, Irish Data Protection Commission; aggregate total to 10 January 2026

Read it in the brief →Last verified 26 September 2026
Derived by this sitederived

What the DPC has collected is roughly half a percent of what it has levied.

Tier 2 · regulatorsupports in part

Fines — Data Protection Commission (Ireland)

Read it in the brief →Last verified 27 September 2026
Derived by this sitederived

Three violation categories account for roughly 94% of all GDPR fine value recorded in the CMS Enforcement Tracker: insufficient legal basis, non-compliance with the general processing principles, and insufficient security measures.

Tier 4 · press / advocacysupports in part

GDPR Enforcement Tracker — Insights (data refreshed 27 September 2026) — CMS 27 September 2026 the three category totals and the headline total, read back through the input claims

Read it in the brief →Last verified 27 September 2026
Attributed viewattributed

In 2021 the Irish Council for Civil Liberties called Ireland the GDPR's worst bottleneck, documenting failure to transmit draft decisions to peer authorities in the great majority of major cross-border cases.

Tier 4 · press / advocacystates this

Europe's enforcement paralysis: ICCL's 2021 GDPR report — Irish Council for Civil Liberties 13 September 2021 "Key insights": "The Irish Data Protection Commission is the bottleneck of GDPR enforcement against Big Tech across the EU. Almost all (98%) major GDPR cases referred to Ireland remain unresolved"

Read it in the brief →Last verified 27 September 2026
Attributed viewattributed

The International Center for Law & Economics argues, borrowing Nadezhda Purtova's phrase, that the GDPR has been interpreted into a 'law of everything', and that the EDPB's proportionality analysis tests limitations on data protection without asking whether the scope of data protection remains proportionate to the burdens it imposes.

Tier 4 · press / advocacystates this

ICLE Comments to the European Commission on GDPR and ePrivacy in the Digital Omnibus — International Center for Law & Economics 13 March 2026 Section B and footnote 3

Tier 3 · researchcontext only

The law of everything. Broad concept of personal data and future of EU data protection law — Nadezhda Purtova 2 April 2018

Read it in the brief →Last verified 26 September 2026
Attributed viewattributed

The EDPB and EDPS adopted Joint Opinion 1/2026 on the AI Omnibus and Joint Opinion 2/2026 on the Data Omnibus, holding in the second that the personal-data definition change goes far beyond a targeted modification and would significantly narrow the concept, that the Art. 41a implementing-act power should not be entrusted to the Commission, and that Art. 88c is unnecessary.

Tier 2 · regulatorstates this

EDPB–EDPS Joint Opinion 2/2026 on the Digital Omnibus proposal — European Data Protection Board February 2026 Paras 17 ('significantly narrowing the concept of personal data') and 21 ('goes far beyond a targeted modification of the GDPR'); paras 23 and 25 (applying the definitions is for supervisory authorities; 'suggest deleting proposed Article 41a GDPR'); para 39 ('it is not necessary to add a specific provision to the GDPR on this point')

Tier 2 · regulatorsupports in part

EDPB–EDPS Joint Opinion 1/2026 on the AI Omnibus proposal — European Data Protection Board 20 January 2026 Title page: Joint Opinion 1/2026 on the Digital Omnibus on AI, adopted on 20 January 2026

Read it in the brief →Last verified 27 September 2026
Attributed viewattributed

noyb concluded that the Digital Omnibus's GDPR and ePrivacy amendments would produce multiple conflicts with the Charter and a clear departure from the GDPR's logic and CJEU case law.

Tier 4 · press / advocacystates this

Digital Omnibus Report V3: Analysis of Select GDPR and ePrivacy Proposals by the Commission — noyb 24 February 2026 "Our analysis reveals that the parts amending the GDPR and the ePrivacy Directive would lead to multiple conflicts with the EU's Charter of Fundamental Rights … and a clear departure from the current logic of the GDPR or CJEU case law"

Read it in the brief →Last verified 27 September 2026
Attributed viewattributed

ICLE argues that the Digital Omnibus's greatest weakness is its silence on enforcement architecture: without institutional reform, the authorities that read the GDPR expansively will read the new exemptions narrowly.

Tier 4 · press / advocacystates this

EU Digital Omnibus Hands the Wheel to the Referee — International Center for Law & Economics 11 June 2026 Opening section: 'Finally, the package’s greatest weakness was its silence on enforcement architecture. Without institutional reform, we argued, the same authorities that had interpreted the GDPR into a “law of everything” would read the new exemptions just as narrowly.'

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VIII

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretationunverified

Almost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretation

The instruments following the GDPR reproduce the same institutional shape — a specialised vocabulary, principles, case-specific rights and a supervisory apparatus — a pattern described as act-ification and GDPR mimesis.

Tier 3 · researchstates this

The Regulation of Digital Technologies in the EU: the law-making phenomena of “act-ification”, “GDPR mimesis” and “EU law brutality” — Papakonstantinou and De Hert 21 May 2022 Abstract: "three basic phenomena common to all, or most, EU new technology-relevant regulatory initiatives, namely (a) act-ification, (b) GDPR mimesis, and (c) regulatory brutality"

Read it in the brief →Last verified 27 September 2026
Interpretationcritique

The recurring objection across every instrument is a capacity-ambition gap: broad obligations assigned either to a single Commission directorate with a few hundred staff or to twenty-seven national authorities of radically unequal resource.

Tier 4 · press / advocacysupports in part

The case for a European Union digital enforcement authority — Bruegel 5 March 2026

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I, Part IX

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretationunverified

A single recommender system can engage the GDPR, the DSA, the AI Act and, for a gatekeeper, the DMA at once, so the rational compliance strategy is one control set mapped to several regimes.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX

Read it in the brief →no verification date recorded
Interpretationinterpretationunverified

2016-2024 was the accumulation phase of EU digital regulation and 2025-2027 is a consolidation phase, but consolidation is contested from within: simplification and expansion are happening in the same instruments.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX

Read it in the brief →no verification date recorded
Interpretationinterpretationunverified

The GDPR is the instrument every other one either builds on, carves an exception from, or must be reconciled with.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretationunverified

Announced enforcement and delivered enforcement are different quantities: headline GDPR fine totals overstate what has been finally imposed and collected.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II, Part IX

Read it in the brief →Last verified 26 September 2026
Interpretationinterpretationunverified

GDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties; an organisation running all three separately duplicates work regulators themselves acknowledge is duplicated.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 27 August 2026
Interpretationinterpretationunverified

The DSA–GDPR interface is unresolved: the DSA tells platforms to be transparent while the GDPR tells them to minimise, and EDPB guidance mediates the conflict without dissolving it.

Tier 2 · regulatorcontext only

EDPB Guidelines 3/2025 on the interplay between the DSA and the GDPR — European Data Protection Board 17 September 2026 Guidelines 3/2025 v2 (final, 17 September 2026) on the EDPB's site; v1 consulted 12 September – 31 October 2025

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III

Read it in the brief →Last verified 27 September 2026
Interpretationcritique

The AI Act is one instrument in a system that already regulated most of its subject matter: automated decision-making by GDPR Art. 22 since 2018, algorithmic recommender risk by DSA Arts. 34–35, product liability by the revised PLD — while the proposed AI Liability Directive was abandoned, leaving a gap in the fault-based route.

Tier 1 · primary lawsupports in part

Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex 4 May 2016 Art. 22

Tier 1 · primary lawsupports in part

Directive (EU) 2024/2853 on liability for defective products — EUR-Lex 18 November 2024

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V

Read it in the brief →Last verified 27 August 2026
Interpretationcritiqueunverified

This body of law restrains corporate power far more effectively than it restrains state power, and the enforcement asymmetry between corporate and state addressees is not seriously disputable.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part XI

Read it in the brief →Last verified 27 August 2026
Unresolvedfact

Eight of the ten largest GDPR fines still standing were imposed by the Irish DPC; the other two are the Dutch authority's, both on Uber.

Tier 2 · regulatorsupports in part

Fines — Data Protection Commission (Ireland) Fines table: EUR 1.2bn (Meta, 12/05/2023), 530m (TikTok), 405m (Instagram), 390m (Meta), 345m (TikTok), 310m (LinkedIn), 265m (Meta), 251m (Meta), 225m (WhatsApp) — nine DPC fines of EUR 225m or more

Tier 2 · regulatorsupports in part

Uber fined nearly 825 million euros for automated driver blocking — Autoriteit Persoonsgegevens (Dutch Data Protection Authority) 21 August 2026 First paragraph: 'imposes a fine of 824,990,000 euros on Uber' (21 August 2026)

Tier 2 · regulatorsupports in part

Dutch DPA imposes a fine of 290 million euro on Uber because of transfers of drivers' data to the US — Autoriteit Persoonsgegevens (Dutch Data Protection Authority) 26 August 2024 First paragraph: 'imposes a fine of 290 million euros on Uber' (26 August 2024)

Tier 4 · press / advocacysupports in part

GDPR Enforcement Tracker — case database — CMS Case list sorted by fine: no other GDPR fine above EUR 251 million (ETid-3232 Uber 824.99m; ETid-2447 Uber 290m)

Unverified · the brief itselfcontext only

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II

Read it in the brief →Last verified 27 September 2026
Unresolvedattributed

An analysis by the insurance brokerage Alliance Risk found that roughly 40% of the EUR 7.1 billion in announced GDPR fines — about EUR 2.8 billion — is either annulled or actively contested in court.

Tier 4 · press / advocacysupports in part

GDPR set the tone for regulatory action — and the AI fine pushback to come — CSO Online 29 May 2026

Read it in the brief →Last verified 26 September 2026
Unresolvedfact

Two large September 2025 French decisions (Google EUR 325m, Shein EUR 150m) are frequently miscounted as GDPR fines when they were issued under the French ePrivacy regime rather than through the one-stop-shop.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Annex B

Tier 2 · regulatorsupports in part

Cookies and advertisements inserted between emails: GOOGLE fined 325 million euros by the CNIL — Commission nationale de l'informatique et des libertés (CNIL) 3 September 2025 Section 'The jurisdiction of the CNIL'

Tier 2 · regulatorsupports in part

Cookies placed without consent: SHEIN fined 150 million euros by the CNIL — Commission nationale de l'informatique et des libertés (CNIL) 3 September 2025 Section 'The jurisdiction of the CNIL'

Read it in the brief →Last verified 27 September 2026
Unresolvedlaw

Where the GDPR governs personal data, the Data Act governs product and service data as such — personal or not, though predominantly non-personal, industrial and machine-generated, with the GDPR prevailing wherever personal data is involved — and reallocates control over it by default.

Tier 1 · primary lawsupports in part

Regulation (EU) 2023/2854 (Data Act) — EUR-Lex 22 December 2023 Art. 1(2), 1(5)

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VI

Read it in the brief →Last verified 27 September 2026

The full bibliography and the evidence method →

How it interacts

6 recorded interactions with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.

DSA In tension with GDPR

Content moderation is processing; ad repositories publish targeting data; Art. 40 access almost always entails personal data. The DSA tells platforms to be transparent while the GDPR tells them to minimise. EDPB guidance mediates the conflict but does not dissolve it.

Carried byDSA Art. 40DSA Art. 39
What the brief argues
  • InterpretationThe DSA–GDPR interface is unresolved: the DSA tells platforms to be transparent while the GDPR tells them to minimise, and EDPB guidance mediates the conflict without dissolving it.

Recorded as at August 27, 2026

AI Act Overlaps with GDPR

Both instruments reach the same conduct.

GDPR Art. 22 has governed solely-automated decision-making since 2018, including systems the AI Act classifies as minimal risk. The AI Act arrived into a field the GDPR already occupied.

Carried byGDPR Art. 22AI Act Art. 6
What the brief argues
  • Primary lawGDPR Article 22 is the pre-existing European law of automated decision-making: it did not wait for the AI Act and applies to systems the AI Act classifies as minimal risk.
  • InterpretationThe AI Act is one instrument in a system that already regulated most of its subject matter: automated decision-making by GDPR Art. 22 since 2018, algorithmic recommender risk by DSA Arts. 34–35, product liability by the revised PLD — while the proposed AI Liability Directive was abandoned, leaving a gap in the fault-based route.

Recorded as at August 27, 2026

AI Act Overlaps with GDPR

Both instruments reach the same conduct.

GDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties that regulators themselves acknowledge are duplicated.

Carried byGDPR Art. 35DSA Art. 34AI Act Art. 27
What the brief argues
  • InterpretationGDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties; an organisation running all three separately duplicates work regulators themselves acknowledge is duplicated.
Sources
  • The European Legal Framework for the Digital World (this brief)Unverified · the brief itself

Recorded as at August 27, 2026

DMA Overlaps with GDPR

Both instruments reach the same conduct.

DMA Art. 5(2)'s consent architecture is functionally a data protection provision enforced by a competition regulator.

Carried byDMA Art. 5
What the brief argues
  • Official sourceMeta's binary pay-or-consent model was found not to provide the genuinely equivalent, less data-intensive alternative DMA Article 5(2) requires.

Recorded as at August 27, 2026

Data Omnibus Amends GDPR

PROPOSED amendment only. The Digital Omnibus proposes changes to the personal-data definition, a new Art. 41a, relocation of cookie consent to Art. 88a and a new Art. 88c. None is law; the proposal is stalled in Council.

What the brief argues
  • Primary lawThe Commission's four principal proposed GDPR reforms were: an entity-relative test for personal data in Art. 4(1); a new Art. 41a empowering the Commission to set, by implementing acts, the means and criteria for determining when pseudonymised data ceases to be personal; relocation of cookie consent into a new Art. 88a; and a new Art. 88c providing an explicit legitimate-interest basis for AI model training. None is law.
  • Secondary onlyThe Data Omnibus has moved in both directions before the Council: by May 2026 successive Cypriot Presidency texts had deleted three of the Commission's four principal GDPR reforms, the Cypriot Presidency withdrew its text from COREPER in late June 2026 for lack of a qualified majority, and the Irish Presidency's revised compromise of 3 September 2026 then restored an AI legitimate-interest clause (as a new Article 88 bis, without the Commission's safeguards) and moved pseudonymised data into a new Article 25a. As of 25 September 2026 the Council has no agreed mandate and trilogues have not begun.

Recorded as at August 27, 2026

TFEU Is the legal basis for GDPR

Almost the entire digital rulebook rests on the internal-market harmonisation competence rather than on a speech, safety or morality competence. That choice shapes each instrument's form.

Carried byTFEU Art. 114
What the brief argues
  • InterpretationAlmost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.
Sources
  • The European Legal Framework for the Digital World (this brief)Unverified · the brief itself

Recorded as at August 27, 2026