Skip to content
GlanceDeskJurisdiction

Home › Law library › EU GDPR

EU

EU GDPR

Regulation (EU) 2016/679 (General Data Protection Regulation)

Sourced. Last verified 9 October 2026

European Union (EEA) Privacy

Status
In force since 25 May 2018. Digital Omnibus amendments proposed Nov 2025, not adopted as of Oct 2026.
Who it applies to
Any organisation processing personal data in the context of an EU establishment, plus non-EU organisations that offer goods/services to people in the EU or monitor their behaviour there.
Size thresholds
None — applies regardless of size.
Regulator
National data protection authorities (DPAs), coordinated by the European Data Protection Board (EDPB)
Breach or incident reporting
Notify the lead DPA without undue delay and within 72 hours of becoming aware, if the breach is likely to risk individuals' rights. Tell affected individuals without undue delay if the risk is high.
Deadline to answer personal data requests
1 month from receipt; extendable by 2 further months for complex requests if the person is told within the first month. Free of charge unless manifestly unfounded or excessive.
Data protection officer
DPO mandatory for public bodies, and where core activities involve large-scale regular and systematic monitoring, or large-scale processing of special-category or criminal-offence data.
Local representative
Non-EU controllers/processors caught by Art 3(2) must appoint an EU representative in writing, unless processing is occasional, low-risk and excludes large-scale sensitive data, or they are a public body.
Sending data abroad
Transfers outside the EEA need an adequacy decision (e.g. UK, Switzerland, EU-US Data Privacy Framework), or safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow Art 49 derogation.
Cookies and consent
Cookie/tracker consent is governed by the ePrivacy Directive Art 5(3); where consent is the GDPR legal basis it must be freely given, specific, informed, unambiguous and as easy to withdraw as to give.
Maximum penalty
Up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher (lower tier: EUR 10 million or 2%).

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

Commission's Digital Omnibus (COM(2025) 837, 19 Nov 2025) would raise the breach threshold to high risk, extend the deadline to 96 hours via a single EU portal, refine the personal-data definition and move cookie rules. Council took a position June 2026; still in negotiation.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].