GDPR
Amended European Union · In force May 24, 2016 · next deadline Apr 2, 2027 (in 6 months)
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
The EU's core data protection law: any processing of personal data needs a lawful basis, must follow principles such as purpose limitation and data minimisation, and gives individuals rights of access, erasure, portability and objection. Controllers must notify breaches to the supervisory authority within 72 hours and restrict transfers outside the EEA to adequate countries or safeguarded mechanisms. Regulation (EU) 2025/2518 adds harmonised procedural rules for cross-border enforcement from 2 April 2027.
- Who it applies to
- Controllers and processors established in the EU, and non-EU controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in the EU. No revenue or volume threshold; some record-keeping relief below 250 employees.
- Penalties
- Up to EUR 20M or 4% of total worldwide annual turnover of the preceding year, whichever is higher (Art 83(5)); up to EUR 10M or 2% for other infringements (Art 83(4)).
- Enforced by
- National data protection supervisory authorities (DPAs), coordinated by the European Data Protection Board (EDPB) via the one-stop-shop mechanism
- Official name
- Regulation (EU) 2016/679 (General Data Protection Regulation)
- Citation
- OJ L 119, 4.5.2016, p. 1
- Topics
- privacy, breach-notification, data-access, children, biometrics, health
Research notes
Digital Omnibus proposal COM(2025) 837 (19 Nov 2025, procedure 2025/0360(COD)) would amend the GDPR: clarify the definition of personal data, move cookie/terminal-equipment consent from the ePrivacy Directive into a new GDPR Art 88a, add machine-readable preference signals (Art 88b), and require breach notification to DPAs only for high-risk breaches within 96 hours via a single-entry point. As of the Parliament Legislative Train update of 1 Aug 2026 it is still 'tabled': ITRE/LIBE draft report 22 June 2026, 1,750+ amendments, no plenary vote, a planned Council mandate vote on 26 June 2026 was cancelled, and no trilogues. None of these changes are law. The procedural regulation's 12- and 15-month investigation timelines are reported by the Council; check the regulation text for exact extensions.
Related
Questions about GDPR
- What are the GDPR compliance deadlines?
- May 24, 2016: GDPR enters into force. May 25, 2018: GDPR applies. Nov 26, 2025: GDPR Procedural Regulation adopted. Jan 1, 2026: GDPR Procedural Regulation enters into force. Apr 2, 2027: GDPR Procedural Regulation applies.
- When does GDPR take effect?
- GDPR took effect on May 24, 2016. The next milestone is Apr 2, 2027: GDPR Procedural Regulation applies.
- Who does GDPR apply to?
- Controllers and processors established in the EU, and non-EU controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in the EU. No revenue or volume threshold; some record-keeping relief below 250 employees.
- What are the penalties under GDPR?
- Up to EUR 20M or 4% of total worldwide annual turnover of the preceding year, whichever is higher (Art 83(5)); up to EUR 10M or 2% for other infringements (Art 83(4)).