#
Mature, harmonised, directly-applicable omnibus regime with an active coordinating body and imminent procedural strengthening; no material derogation identified across EEA EFTA states.
Sub-modules (5)
Regulator And AuthorityGreen
Primary enforcement rests with each Member/EEA State's national DPA (e.g. Irish DPC as lead authority for many multinational platforms, CNIL in France, Datatilsynet in Norway); the EDPB coordinates consistency and can issue binding decisions under Article 65 GDPR overriding a lead authority's proposed measures.
Claims (2):
- National data protection authorities of the EU Member States and the EEA EFTA states (Iceland, Liechtenstein, Norway) are the primary enforcement bodies for the GDPR, cooperating through the EDPB's consistency and cooperation framework.
- The EDPB may issue binding decisions under Article 65 GDPR that direct a lead supervisory authority to alter proposed measures, including materially increasing proposed fines, as occurred in the Meta Ireland Facebook/Instagram inquiries where the EDPB directed the fine be raised from a proposed maximum of €59 million to €390 million.
Act And InstrumentsGreen
The GDPR repealed Directive 95/46/EC and is the central instrument; it is supplemented by the ePrivacy Directive 2002/58/EC and, from 2 April 2027, by a new procedural regulation on cross-border enforcement.
Claims (2):
- Regulation (EU) 2016/679 (GDPR) repealed and replaced Directive 95/46/EC as the EU's general data protection framework.
- Regulation (EU) 2025/2518, laying down additional procedural rules for GDPR cross-border enforcement (harmonising complaint admissibility, lead/concerned-authority cooperation and party rights), was adopted on 26 November 2025, published in the Official Journal on 12 December 2025, and applies from 2 April 2027.
Material ScopeGreen
GDPR applies to the processing of personal data wholly or partly by automated means, and to non-automated processing forming part of a filing system, covering both controllers and processors established in the EEA.
Claims (1):
- GDPR Article 2 material scope covers processing of personal data by automated means and manual processing forming part of a filing system, as reflected in EDPB and CNIL guidance defining personal data broadly (any information relating to an identified or identifiable natural person).
Territorial ScopeAmber
Article 3 GDPR extends application extraterritorially to non-EEA controllers/processors offering goods or services to, or monitoring the behaviour of, EEA data subjects, though DPAs' investigative powers outside EEA territory remain subject to third-state consent.
Claims (2):
- Since 25 May 2018, GDPR applies to processing in the context of an EU/EEA establishment's activities and to processing by non-established controllers/processors targeting EEA data subjects through the offering of goods or services or the monitoring of their behaviour within the Union.
- An EDPB report on extraterritorial enforcement notes that any exercise of a DPA's investigative powers outside EU/EEA territory requires the consent of the foreign state, limiting practical extraterritorial reach notwithstanding Article 3's broad scope.
Regulator Registration And FilingAmber
The GDPR replaced the prior notification/registration regime of Directive 95/46/EC with an accountability-based model; no general filing duty with the DPA was confirmed by direct source in this research pass beyond structural inference from the repeal of the prior directive.
Claims (1):
- The GDPR is generally understood to have abolished the ex-ante notification/registration regime that existed under Directive 95/46/EC, substituting an accountability-based compliance model (Article 5(2), Article 24).
no periodic updates on record for this sub-brief
Sources and claims (8)
- ConfirmedEDPS — National data protection authorities of the EU Member States and the EEA EFTA states (Iceland, Liechtenstein, Norway) are the primary enforcement bodies for the GDPR, cooperating through the EDPB's consistency and cooperation framework.observed
- ConfirmedIAPP — The EDPB may issue binding decisions under Article 65 GDPR that direct a lead supervisory authority to alter proposed measures, including materially increasing proposed fines, as occurred in the Meta Ireland Facebook/Instagram inquiries where the EDPB directed the fine be raised from a proposed maximum of €59 million to €390 million.observed
- ConfirmedCNIL — Regulation (EU) 2016/679 (GDPR) repealed and replaced Directive 95/46/EC as the EU's general data protection framework.observed
- ConfirmedPublications Office of the EU — Regulation (EU) 2025/2518, laying down additional procedural rules for GDPR cross-border enforcement (harmonising complaint admissibility, lead/concerned-authority cooperation and party rights), was adopted on 26 November 2025, published in the Official Journal on 12 December 2025, and applies from 2 April 2027.observed
- ConfirmedCNIL — GDPR Article 2 material scope covers processing of personal data by automated means and manual processing forming part of a filing system, as reflected in EDPB and CNIL guidance defining personal data broadly (any information relating to an identified or identifiable natural person).observed
- ConfirmedIAPP — Since 25 May 2018, GDPR applies to processing in the context of an EU/EEA establishment's activities and to processing by non-established controllers/processors targeting EEA data subjects through the offering of goods or services or the monitoring of their behaviour within the Union.observed
- ConfirmedEDPB — An EDPB report on extraterritorial enforcement notes that any exercise of a DPA's investigative powers outside EU/EEA territory requires the consent of the foreign state, limiting practical extraterritorial reach notwithstanding Article 3's broad scope.observed
- UncertainCNIL — The GDPR is generally understood to have abolished the ex-ante notification/registration regime that existed under Directive 95/46/EC, substituting an accountability-based compliance model (Article 5(2), Article 24).observed