Every statement this site makes about GDPR, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.
Primary lawlaw
The GDPR rests on Article 16 TFEU, the Union's data-protection competence, not on Article 114.
Primary lawlaw
The GDPR applies to controllers and processors not established in the Union when they process personal data of data subjects who are in the Union in connection with offering them goods or services or monitoring their behaviour there.
Primary lawlaw
GDPR Article 56 gives the supervisory authority of the controller's main establishment the lead role in cross-border cases, with Article 60 cooperation and Article 65 EDPB dispute resolution behind it.
Primary lawlaw
Regulation (EU) 2025/2518, which harmonises the admissibility of complaints, the parties' procedural rights and the time limits for draft decisions in cross-border GDPR cases, entered into force on 1 January 2026 and applies from 2 April 2027, its investigation rules to complaints lodged after that date.
Primary lawfact
The EUR 746 million fine against Amazon Europe Core was annulled by the Luxembourg courts in March 2026 on procedural grounds — the authority had not adequately assessed intent, negligence and proportionality — and referred back for reassessment, though the underlying violations were upheld.
Tier 1 · primary lawstates this
Cour administrative, arrêt du 12 mars 2026, n° 52757C du rôle, ECLI:LU:CADM:2026:52757 — Cour administrative du Grand-Duché de Luxembourg 12 March 2026 dispositif, p. 89: "par réformation du jugement entrepris du 18 mars 2025, annule la décision de la Commission nationale pour la protection des données du 15 juillet 2021 en tous ses volets et renvoie le dossier devant ladite Commission"; grounds pp. 85–88 (fault not examined; fine the only option considered); merits §§ 5.1–5.2 (Art. 6(1)(f), Arts 12–14 and 15–17 confirmed)
Primary lawlaw
The CJEU held in EDPS v SRB (C-413/23 P) that pseudonymised data is not necessarily personal data for every entity: identifiability must be assessed relative to the means reasonably likely to be used by the entity in question.
Tier 1 · primary lawstates this
Judgment in Case C-413/23 P, EDPS v SRB — Court of Justice of the European Union 4 September 2025 Judgment of 4 September 2025, paras 80 and 82: pseudonymised data is not to be regarded "in all cases and for every person" as personal data
Tier 2 · regulatorstates this
Press release on Case C-413/23 P — Court of Justice of the European Union 4 September 2025 Press Release No 107/25, page 1, paragraph beginning 'In the second place': pseudonymised data 'must not be regarded as constituting, in all cases and for every person, personal data'
Primary lawlaw
GDPR Article 22 is the pre-existing European law of automated decision-making: it did not wait for the AI Act and applies to systems the AI Act classifies as minimal risk.
Primary lawlaw
Article 5 GDPR sets six principles for processing — lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality — and makes the controller responsible for, and able to demonstrate, compliance with them (accountability).
Primary lawlaw
Article 6(1) GDPR makes processing lawful only where at least one of six bases applies: consent, contract, legal obligation, vital interests, public task or legitimate interests.
Primary lawlaw
Article 9 GDPR prohibits processing of special categories of personal data unless one of the exceptions it lists applies.
Primary lawlaw
Chapter III GDPR (Articles 12 to 23) sets out the data subject's rights: information, access, rectification, erasure, restriction, portability, objection, and the Article 22 right not to be subject to a decision based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects them.
Primary lawlaw
Chapter IV GDPR includes data protection by design and by default (Article 25), records of processing activities (Article 30), personal data breach notification and communication (Articles 33 and 34), data protection impact assessment (Article 35) and the data protection officer (Articles 37 to 39).
Primary lawlaw
Chapter V GDPR governs transfers of personal data to third countries and international organisations.
Primary lawlaw
Article 83 GDPR sets two tiers of fine ceilings: up to EUR 10 million or 2% of total worldwide annual turnover, and up to EUR 20 million or 4%, whichever is higher in each case.
Primary lawlaw
The Commission's four principal proposed GDPR reforms were: an entity-relative test for personal data in Art. 4(1); a new Art. 41a empowering the Commission to set, by implementing acts, the means and criteria for determining when pseudonymised data ceases to be personal; relocation of cookie consent into a new Art. 88a; and a new Art. 88c providing an explicit legitimate-interest basis for AI model training. None is law.
Tier 1 · primary lawstates this
COM(2025) 837 final — Digital Omnibus Regulation — European Commission 19 November 2025 Art. 3 (amendments to Regulation (EU) 2016/679): point 1(a) (Art. 4(1), added sentences), point 10 (new Art. 41a), point 15 (new Arts 88a and 88c)
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VIII
Official sourcefact
The Irish DPC accounts for about EUR 4.04 billion of cumulative GDPR fine value.
Tier 2 · regulatorstates this
Fines — Data Protection Commission (Ireland) "Total Fines (last updated 10/08/2026) €4,038,832,000"
Official sourcefact
On 21 August 2026 the Dutch data protection authority fined Uber EUR 824,990,000 under the GDPR for fully automated deactivation of drivers; Uber has appealed.
Official sourcefact
In August 2024 the Dutch data protection authority fined Uber EUR 290 million under the GDPR for transferring European drivers' data to the US without appropriate safeguards.
Official sourcefact
Of more than EUR 4 billion levied through DPC inquiries, only on the order of EUR 20 million has been collected, because fines generally do not become payable until confirmed by a court.
Tier 2 · regulatorstates this
Fines — Data Protection Commission (Ireland) "over €4 billion in fines have been levied … To date, approximately €20 million in fines has been collected"; "Collection of Fines": fines "do not become payable until they are confirmed in Court"
Official sourcefact
The DPC has grown to nearly 300 staff by 2026 and moved to a three-Commissioner structure.
Tier 2 · regulatorstates this
Data Protection Commission — Annual Report 2025 — Data Protection Commission (Ireland) 30 June 2026 p. 5 (Commissioners' foreword: 'completing the move from a one to three-person Commission'; staff 'increased to 295 by year end') and p. 115 ('By year-end 2025, the DPC had reached a total headcount of 295')
Unverified · the brief itselfcontext only
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Official sourcefact
The EDPB made transparency and information obligations under GDPR Articles 12 to 14 the subject of its 2026 coordinated enforcement action, with twenty-five data protection authorities taking part.
Official sourcefact
Meta's binary pay-or-consent model was found not to provide the genuinely equivalent, less data-intensive alternative DMA Article 5(2) requires.
Tier 2 · regulatorstates this
Commission finds Apple and Meta in breach of the Digital Markets Act — European Commission 23 April 2025 IP/25/1085, section 'Non-compliance decision on Meta's “consent or pay” model': the model 'did not give users the required specific choice to opt for a service that uses less of their personal data but is otherwise equivalent'
Secondary onlyfact
Cumulative GDPR fines have passed roughly EUR 7.1 billion since 2018.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Secondary onlyfact
Spain leads by number of GDPR decisions, with over a thousand.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Secondary onlyfact
Regulators are processing an average of 443 breach notifications per day, a 22% year-on-year increase.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Secondary onlyfact
On 27 September 2026 the CMS GDPR Enforcement Tracker recorded total fines of EUR 7,159,322,834 across 3,275 cases.
Secondary onlyfact
On 27 September 2026 the CMS GDPR Enforcement Tracker recorded fines totalling EUR 3,124,976,242 for insufficient legal basis for data processing.
Secondary onlyfact
On 27 September 2026 the CMS GDPR Enforcement Tracker recorded fines totalling EUR 2,649,889,997 for non-compliance with general data processing principles.
Secondary onlyfact
On 27 September 2026 the CMS GDPR Enforcement Tracker recorded fines totalling EUR 971,797,663 for insufficient technical and organisational measures to ensure information security.
Secondary onlyfact
The Italian Garante's EUR 15 million ChatGPT decision was voided by a Rome tribunal in March 2026 on a pure jurisdiction point: once OpenAI established an Irish subsidiary, the DPC became lead authority.
Derived by this sitederived
The Irish DPC's share of cumulative GDPR fine value is roughly 57%.
Derived by this sitederived
What the DPC has collected is roughly half a percent of what it has levied.
Tier 2 · regulatorsupports in part
Fines — Data Protection Commission (Ireland)
Derived by this sitederived
Three violation categories account for roughly 94% of all GDPR fine value recorded in the CMS Enforcement Tracker: insufficient legal basis, non-compliance with the general processing principles, and insufficient security measures.
Attributed viewattributed
In 2021 the Irish Council for Civil Liberties called Ireland the GDPR's worst bottleneck, documenting failure to transmit draft decisions to peer authorities in the great majority of major cross-border cases.
Tier 4 · press / advocacystates this
Europe's enforcement paralysis: ICCL's 2021 GDPR report — Irish Council for Civil Liberties 13 September 2021 "Key insights": "The Irish Data Protection Commission is the bottleneck of GDPR enforcement against Big Tech across the EU. Almost all (98%) major GDPR cases referred to Ireland remain unresolved"
Attributed viewattributed
The International Center for Law & Economics argues, borrowing Nadezhda Purtova's phrase, that the GDPR has been interpreted into a 'law of everything', and that the EDPB's proportionality analysis tests limitations on data protection without asking whether the scope of data protection remains proportionate to the burdens it imposes.
Attributed viewattributed
The EDPB and EDPS adopted Joint Opinion 1/2026 on the AI Omnibus and Joint Opinion 2/2026 on the Data Omnibus, holding in the second that the personal-data definition change goes far beyond a targeted modification and would significantly narrow the concept, that the Art. 41a implementing-act power should not be entrusted to the Commission, and that Art. 88c is unnecessary.
Tier 2 · regulatorstates this
EDPB–EDPS Joint Opinion 2/2026 on the Digital Omnibus proposal — European Data Protection Board February 2026 Paras 17 ('significantly narrowing the concept of personal data') and 21 ('goes far beyond a targeted modification of the GDPR'); paras 23 and 25 (applying the definitions is for supervisory authorities; 'suggest deleting proposed Article 41a GDPR'); para 39 ('it is not necessary to add a specific provision to the GDPR on this point')
Attributed viewattributed
noyb concluded that the Digital Omnibus's GDPR and ePrivacy amendments would produce multiple conflicts with the Charter and a clear departure from the GDPR's logic and CJEU case law.
Attributed viewattributed
ICLE argues that the Digital Omnibus's greatest weakness is its silence on enforcement architecture: without institutional reform, the authorities that read the GDPR expansively will read the new exemptions narrowly.
Tier 4 · press / advocacystates this
EU Digital Omnibus Hands the Wheel to the Referee — International Center for Law & Economics 11 June 2026 Opening section: 'Finally, the package’s greatest weakness was its silence on enforcement architecture. Without institutional reform, we argued, the same authorities that had interpreted the GDPR into a “law of everything” would read the new exemptions just as narrowly.'
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VIII
Interpretationinterpretationunverified
Almost the entire EU digital rulebook rests on Article 114 TFEU (internal-market harmonisation) rather than on a speech, safety or morality competence, and that choice shapes each instrument's form.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I
Interpretationinterpretation
The instruments following the GDPR reproduce the same institutional shape — a specialised vocabulary, principles, case-specific rights and a supervisory apparatus — a pattern described as act-ification and GDPR mimesis.
Interpretationcritique
The recurring objection across every instrument is a capacity-ambition gap: broad obligations assigned either to a single Commission directorate with a few hundred staff or to twenty-seven national authorities of radically unequal resource.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part I, Part IX
Interpretationinterpretationunverified
A single recommender system can engage the GDPR, the DSA, the AI Act and, for a gatekeeper, the DMA at once, so the rational compliance strategy is one control set mapped to several regimes.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX
Interpretationinterpretationunverified
2016-2024 was the accumulation phase of EU digital regulation and 2025-2027 is a consolidation phase, but consolidation is contested from within: simplification and expansion are happening in the same instruments.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part IX
Interpretationinterpretationunverified
The GDPR is the instrument every other one either builds on, carves an exception from, or must be reconciled with.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Interpretationinterpretationunverified
Announced enforcement and delivered enforcement are different quantities: headline GDPR fine totals overstate what has been finally imposed and collected.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II, Part IX
Interpretationinterpretationunverified
GDPR Art. 35 DPIAs, DSA Art. 34 systemic risk assessment and AI Act Art. 27 fundamental rights impact assessment are three overlapping assessment duties; an organisation running all three separately duplicates work regulators themselves acknowledge is duplicated.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Interpretationinterpretationunverified
The DSA–GDPR interface is unresolved: the DSA tells platforms to be transparent while the GDPR tells them to minimise, and EDPB guidance mediates the conflict without dissolving it.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part III
Interpretationcritique
The AI Act is one instrument in a system that already regulated most of its subject matter: automated decision-making by GDPR Art. 22 since 2018, algorithmic recommender risk by DSA Arts. 34–35, product liability by the revised PLD — while the proposed AI Liability Directive was abandoned, leaving a gap in the fault-based route.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part V
Interpretationcritiqueunverified
This body of law restrains corporate power far more effectively than it restrains state power, and the enforcement asymmetry between corporate and state addressees is not seriously disputable.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part XI
Unresolvedfact
Eight of the ten largest GDPR fines still standing were imposed by the Irish DPC; the other two are the Dutch authority's, both on Uber.
Tier 2 · regulatorsupports in part
Fines — Data Protection Commission (Ireland) Fines table: EUR 1.2bn (Meta, 12/05/2023), 530m (TikTok), 405m (Instagram), 390m (Meta), 345m (TikTok), 310m (LinkedIn), 265m (Meta), 251m (Meta), 225m (WhatsApp) — nine DPC fines of EUR 225m or more
Tier 4 · press / advocacysupports in part
GDPR Enforcement Tracker — case database — CMS Case list sorted by fine: no other GDPR fine above EUR 251 million (ETid-3232 Uber 824.99m; ETid-2447 Uber 290m)
Unverified · the brief itselfcontext only
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part II
Unresolvedattributed
An analysis by the insurance brokerage Alliance Risk found that roughly 40% of the EUR 7.1 billion in announced GDPR fines — about EUR 2.8 billion — is either annulled or actively contested in court.
Unresolvedfact
Two large September 2025 French decisions (Google EUR 325m, Shein EUR 150m) are frequently miscounted as GDPR fines when they were issued under the French ePrivacy regime rather than through the one-stop-shop.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Annex B
Unresolvedlaw
Where the GDPR governs personal data, the Data Act governs product and service data as such — personal or not, though predominantly non-personal, industrial and machine-generated, with the GDPR prevailing wherever personal data is involved — and reallocates control over it by default.
Unverified · the brief itselfstates this
Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VI