Skip to content

GDPR

Amended European Union · In force May 24, 2016 · next deadline Apr 2, 2027 (in 6 months)

Deadlines

DateWhat happens
May 24, 2016GDPR enters into force10.3 years ago
May 25, 2018GDPR applies8.3 years ago
Nov 26, 2025GDPR Procedural Regulation adopted10 months ago
Jan 1, 2026GDPR Procedural Regulation enters into force9 months ago
Apr 2, 2027GDPR Procedural Regulation appliesin 6 months

Summaries for reference, not legal advice. Check the official text.

What it does

The EU's core data protection law: any processing of personal data needs a lawful basis, must follow principles such as purpose limitation and data minimisation, and gives individuals rights of access, erasure, portability and objection. Controllers must notify breaches to the supervisory authority within 72 hours and restrict transfers outside the EEA to adequate countries or safeguarded mechanisms. Regulation (EU) 2025/2518 adds harmonised procedural rules for cross-border enforcement from 2 April 2027.

Who it applies to
Controllers and processors established in the EU, and non-EU controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in the EU. No revenue or volume threshold; some record-keeping relief below 250 employees.
Penalties
Up to EUR 20M or 4% of total worldwide annual turnover of the preceding year, whichever is higher (Art 83(5)); up to EUR 10M or 2% for other infringements (Art 83(4)).
Enforced by
National data protection supervisory authorities (DPAs), coordinated by the European Data Protection Board (EDPB) via the one-stop-shop mechanism
Official name
Regulation (EU) 2016/679 (General Data Protection Regulation)
Citation
OJ L 119, 4.5.2016, p. 1
Topics
privacy, breach-notification, data-access, children, biometrics, health
Research notes

Digital Omnibus proposal COM(2025) 837 (19 Nov 2025, procedure 2025/0360(COD)) would amend the GDPR: clarify the definition of personal data, move cookie/terminal-equipment consent from the ePrivacy Directive into a new GDPR Art 88a, add machine-readable preference signals (Art 88b), and require breach notification to DPAs only for high-risk breaches within 96 hours via a single-entry point. As of the Parliament Legislative Train update of 1 Aug 2026 it is still 'tabled': ITRE/LIBE draft report 22 June 2026, 1,750+ amendments, no plenary vote, a planned Council mandate vote on 26 June 2026 was cancelled, and no trilogues. None of these changes are law. The procedural regulation's 12- and 15-month investigation timelines are reported by the Council; check the regulation text for exact extensions.

Related

Questions about GDPR
What are the GDPR compliance deadlines?
May 24, 2016: GDPR enters into force. May 25, 2018: GDPR applies. Nov 26, 2025: GDPR Procedural Regulation adopted. Jan 1, 2026: GDPR Procedural Regulation enters into force. Apr 2, 2027: GDPR Procedural Regulation applies.
When does GDPR take effect?
GDPR took effect on May 24, 2016. The next milestone is Apr 2, 2027: GDPR Procedural Regulation applies.
Who does GDPR apply to?
Controllers and processors established in the EU, and non-EU controllers/processors that offer goods or services to, or monitor the behaviour of, individuals in the EU. No revenue or volume threshold; some record-keeping relief below 250 employees.
What are the penalties under GDPR?
Up to EUR 20M or 4% of total worldwide annual turnover of the preceding year, whichever is higher (Art 83(5)); up to EUR 10M or 2% for other infringements (Art 83(4)).

When the rules change: new data, privacy and AI laws and deadlines, the next morning.