Home › Law library › EU GDPR
EU
EU GDPR
Regulation (EU) 2016/679 (General Data Protection Regulation)
Sourced. Last verified 9 October 2026
European Union (EEA) Privacy
- Status
- In force since 25 May 2018. Digital Omnibus amendments proposed Nov 2025, not adopted as of Oct 2026.
- Who it applies to
- Any organisation processing personal data in the context of an EU establishment, plus non-EU organisations that offer goods/services to people in the EU or monitor their behaviour there.
- Size thresholds
- None — applies regardless of size.
- Regulator
- National data protection authorities (DPAs), coordinated by the European Data Protection Board (EDPB)
- Breach or incident reporting
- Notify the lead DPA without undue delay and within 72 hours of becoming aware, if the breach is likely to risk individuals' rights. Tell affected individuals without undue delay if the risk is high.
- Deadline to answer personal data requests
- 1 month from receipt; extendable by 2 further months for complex requests if the person is told within the first month. Free of charge unless manifestly unfounded or excessive.
- Data protection officer
- DPO mandatory for public bodies, and where core activities involve large-scale regular and systematic monitoring, or large-scale processing of special-category or criminal-offence data.
- Local representative
- Non-EU controllers/processors caught by Art 3(2) must appoint an EU representative in writing, unless processing is occasional, low-risk and excludes large-scale sensitive data, or they are a public body.
- Sending data abroad
- Transfers outside the EEA need an adequacy decision (e.g. UK, Switzerland, EU-US Data Privacy Framework), or safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Art 49 derogation.
- Cookies and consent
- Cookie/tracker consent is governed by the ePrivacy Directive Art 5(3); where consent is the GDPR legal basis it must be freely given, specific, informed, unambiguous and as easy to withdraw as to give.
- Maximum penalty
- Up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher (lower tier: EUR 10 million or 2%).
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Identify a lawful basis for every processing purpose and record it.
- Publish a clear privacy notice covering purposes, recipients, retention and rights.
- Keep a record of processing activities and sign Art 28 contracts with processors.
- Run a DPIA before high-risk processing such as large-scale profiling or sensitive data.
- Report qualifying breaches to the DPA within 72 hours and log all breaches.
- Answer access, erasure and other rights requests within one month.
- Put SCCs or another valid mechanism in place before sending data outside the EEA.
Recent changes
Commission's Digital Omnibus (COM(2025) 837, 19 Nov 2025) would raise the breach threshold to high risk, extend the deadline to 96 hours via a single EU portal, refine the personal-data definition and move cookie rules. Council took a position June 2026; still in negotiation.
Sources
- Primary source: https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/obligations/what-data-breach-and-what-do-we-have-do-case-data-breach_en
- Second source: https://eaccny.com/news/nautadutilh-the-digital-omnibus-what-changed-what-survived-and-what-remains-open/
- Regulator: National data protection authorities (DPAs), coordinated by the European Data Protection Board (EDPB)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].