🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
EEA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing39 sources retrieved model claude-sonnet-5 · 2026-08-05

European Economic Area (Bloc)

EEA schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 54 claims · 43 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
54Claimsbaseline..claims[]
41Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 9 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The EEA data protection picture this cycle is shaped by a genuine liberalisation on cross-border data flows set against a persistent gap in AI governance incorporation. Brazil's ANPD Resolution CD/ANPD No. 32/2026 recognises the EU as adequate for LGPD purposes and extends that recognition to Iceland, Liechtenstein and Norway as EEA-EFTA states, matched by a corresponding EU adequacy decision for Brazil. This is a new mutual adequacy arrangement that explicitly names the EEA-EFTA states rather than treating adequacy as an EU-only matter, which is itself a notable drafting choice this cycle.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, harmonised, directly-applicable omnibus regime with an active coordinating body and imminent procedural strengthening; no material derogation identified across EEA EFTA states.

Primary frameworkRegulation (EU) 2016/679 (GDPR), incorporated into the EEA Agreement (Annex XI)
Traffic-light rationale — GreenMature, harmonised, directly-applicable omnibus regime with an active coordinating body and imminent procedural strengthening; no material derogation identified across EEA EFTA states.

Sub-modules (5)

Regulator And AuthorityGreen

Primary enforcement rests with each Member/EEA State's national DPA (e.g. Irish DPC as lead authority for many multinational platforms, CNIL in France, Datatilsynet in Norway); the EDPB coordinates consistency and can issue binding decisions under Article 65 GDPR overriding a lead authority's proposed measures.

Claims (2):

  • National data protection authorities of the EU Member States and the EEA EFTA states (Iceland, Liechtenstein, Norway) are the primary enforcement bodies for the GDPR, cooperating through the EDPB's consistency and cooperation framework.
  • The EDPB may issue binding decisions under Article 65 GDPR that direct a lead supervisory authority to alter proposed measures, including materially increasing proposed fines, as occurred in the Meta Ireland Facebook/Instagram inquiries where the EDPB directed the fine be raised from a proposed maximum of €59 million to €390 million.

Act And InstrumentsGreen

The GDPR repealed Directive 95/46/EC and is the central instrument; it is supplemented by the ePrivacy Directive 2002/58/EC and, from 2 April 2027, by a new procedural regulation on cross-border enforcement.

Claims (2):

  • Regulation (EU) 2016/679 (GDPR) repealed and replaced Directive 95/46/EC as the EU's general data protection framework.
  • Regulation (EU) 2025/2518, laying down additional procedural rules for GDPR cross-border enforcement (harmonising complaint admissibility, lead/concerned-authority cooperation and party rights), was adopted on 26 November 2025, published in the Official Journal on 12 December 2025, and applies from 2 April 2027.

Material ScopeGreen

GDPR applies to the processing of personal data wholly or partly by automated means, and to non-automated processing forming part of a filing system, covering both controllers and processors established in the EEA.

Claims (1):

  • GDPR Article 2 material scope covers processing of personal data by automated means and manual processing forming part of a filing system, as reflected in EDPB and CNIL guidance defining personal data broadly (any information relating to an identified or identifiable natural person).

Territorial ScopeAmber

Article 3 GDPR extends application extraterritorially to non-EEA controllers/processors offering goods or services to, or monitoring the behaviour of, EEA data subjects, though DPAs' investigative powers outside EEA territory remain subject to third-state consent.

Claims (2):

  • Since 25 May 2018, GDPR applies to processing in the context of an EU/EEA establishment's activities and to processing by non-established controllers/processors targeting EEA data subjects through the offering of goods or services or the monitoring of their behaviour within the Union.
  • An EDPB report on extraterritorial enforcement notes that any exercise of a DPA's investigative powers outside EU/EEA territory requires the consent of the foreign state, limiting practical extraterritorial reach notwithstanding Article 3's broad scope.

Regulator Registration And FilingAmber

The GDPR replaced the prior notification/registration regime of Directive 95/46/EC with an accountability-based model; no general filing duty with the DPA was confirmed by direct source in this research pass beyond structural inference from the repeal of the prior directive.

Claims (1):

  • The GDPR is generally understood to have abolished the ex-ante notification/registration regime that existed under Directive 95/46/EC, substituting an accountability-based compliance model (Article 5(2), Article 24).
Category narrative75 words

The EEA (EU-27 plus Iceland, Liechtenstein and Norway) is governed by Regulation (EU) 2016/679 (GDPR) as the comprehensive omnibus instrument, incorporated into Annex XI of the EEA Agreement and applicable in the EFTA EEA states since 20 July 2018. Enforcement is decentralised to national supervisory authorities (e.g. Irish DPC, CNIL, Datatilsynet) coordinated by the EDPB through the one-stop-shop and Article 65 binding dispute-resolution mechanisms, with a new procedural regulation streamlining cross-border cooperation from April 2027.

no periodic updates on record for this sub-brief

Sources and claims (8)
  1. ConfirmedEDPS — National data protection authorities of the EU Member States and the EEA EFTA states (Iceland, Liechtenstein, Norway) are the primary enforcement bodies for the GDPR, cooperating through the EDPB's consistency and cooperation framework.observed
  2. ConfirmedIAPP — The EDPB may issue binding decisions under Article 65 GDPR that direct a lead supervisory authority to alter proposed measures, including materially increasing proposed fines, as occurred in the Meta Ireland Facebook/Instagram inquiries where the EDPB directed the fine be raised from a proposed maximum of €59 million to €390 million.observed
  3. ConfirmedCNIL — Regulation (EU) 2016/679 (GDPR) repealed and replaced Directive 95/46/EC as the EU's general data protection framework.observed
  4. ConfirmedPublications Office of the EU — Regulation (EU) 2025/2518, laying down additional procedural rules for GDPR cross-border enforcement (harmonising complaint admissibility, lead/concerned-authority cooperation and party rights), was adopted on 26 November 2025, published in the Official Journal on 12 December 2025, and applies from 2 April 2027.observed
  5. ConfirmedCNIL — GDPR Article 2 material scope covers processing of personal data by automated means and manual processing forming part of a filing system, as reflected in EDPB and CNIL guidance defining personal data broadly (any information relating to an identified or identifiable natural person).observed
  6. ConfirmedIAPP — Since 25 May 2018, GDPR applies to processing in the context of an EU/EEA establishment's activities and to processing by non-established controllers/processors targeting EEA data subjects through the offering of goods or services or the monitoring of their behaviour within the Union.observed
  7. ConfirmedEDPB — An EDPB report on extraterritorial enforcement notes that any exercise of a DPA's investigative powers outside EU/EEA territory requires the consent of the foreign state, limiting practical extraterritorial reach notwithstanding Article 3's broad scope.observed
  8. UncertainCNIL — The GDPR is generally understood to have abolished the ex-ante notification/registration regime that existed under Directive 95/46/EC, substituting an accountability-based compliance model (Article 5(2), Article 24).observed

#

Core provisions are stable and enforced, but the Digital Omnibus proposal (still in trilogue as of mid-2026) creates near-term uncertainty over consent-signal mechanics and the sensitive-data/AI derogation.

Primary frameworkGDPR Articles 4-11 (Regulation (EU) 2016/679); proposed amendments under the Digital Omnibus (COM(2025) 836 final)
Traffic-light rationale — AmberCore provisions are stable and enforced, but the Digital Omnibus proposal (still in trilogue as of mid-2026) creates near-term uncertainty over consent-signal mechanics and the sensitive-data/AI derogation.

Sub-modules (4)

Lawful BasesAmber

The EDPB's binding decisions confirmed Meta could not rely on the 'contract' basis (Art. 6(1)(b)) for behavioural advertising, materially narrowing available lawful bases for ad-targeting business models.

Claims (1):

  • The Irish DPC, implementing EDPB binding decisions, fined Meta Ireland a combined €390 million (€210m Facebook, €180m Instagram) after finding that Meta could not rely on the contractual-necessity legal basis under Article 6 GDPR for behavioural-advertising processing.

Special CategoriesAmber

The Digital Omnibus proposes a new derogation to the Article 9 prohibition on processing special-category data, covering incidental and residual processing in the context of developing and operating AI systems, subject to conditions the EDPB/EDPS say need lifecycle safeguards.

Claims (1):

  • The EDPB and EDPS welcomed the Digital Omnibus's proposed derogation permitting incidental and residual processing of special-category (Article 9) data in the context of developing and operating AI systems, while recommending improvements to scope and lifecycle safeguards.

Pseudonymisation And AnonymisationGreen

The EDPB adopted Guidelines 01/2025 on Pseudonymisation (finalisation ongoing) and published draft Guidelines 02/2026 on Anonymisation in July 2026 responding to the CJEU's EDPS v SRB ruling that pseudonymised data is not automatically personal data for every recipient.

Claims (2):

  • EDPB Guidelines 01/2025 clarify that pseudonymised data, when attributable to an individual via additional information, remains personal data, and detail how pseudonymisation supports Articles 5, 25 and 32 compliance.
  • Following the CJEU's September 2025 EDPS v SRB ruling that the same dataset can be personal data for one recipient and anonymous for another, the EDPB published draft Guidelines 02/2026 on Anonymisation (7 July 2026, consultation to 30 October 2026) setting out a two-question, three-criteria (no isolation, no linkage, no inference) test for anonymisation.
Category narrative57 words

GDPR Article 6 lawful bases remain unchanged, but their practical application is contested and evolving through enforcement (e.g. the Meta 'contract' basis for behavioural advertising being invalidated) and through the pending Digital Omnibus, which would add a targeted derogation permitting incidental/residual processing of special-category data in AI development and modify consent/transparency mechanics (Art. 88b automated choice signals).

no periodic updates on record for this sub-brief

Sources and claims (6)
  1. ConfirmedIAPP — The Irish DPC, implementing EDPB binding decisions, fined Meta Ireland a combined €390 million (€210m Facebook, €180m Instagram) after finding that Meta could not rely on the contractual-necessity legal basis under Article 6 GDPR for behavioural-advertising processing.observed
  2. ProbableIAPP — The Digital Omnibus proposal introduces a new GDPR Article 88b that would allow individuals to express privacy choices automatically through technical means such as browser settings, rather than manual cookie-banner interaction.observed
  3. ProbableIAPP — In June 2026 the Council of the EU removed the proposed Article 88b automated-consent-signal provision from its negotiating position following lobbying from media and advertising industry groups, creating legislative uncertainty over the final mechanism.observed
  4. ConfirmedEDPB — The EDPB and EDPS welcomed the Digital Omnibus's proposed derogation permitting incidental and residual processing of special-category (Article 9) data in the context of developing and operating AI systems, while recommending improvements to scope and lifecycle safeguards.observed
  5. ConfirmedEDPB — EDPB Guidelines 01/2025 clarify that pseudonymised data, when attributable to an individual via additional information, remains personal data, and detail how pseudonymisation supports Articles 5, 25 and 32 compliance.observed
  6. ConfirmedIAPP — Following the CJEU's September 2025 EDPS v SRB ruling that the same dataset can be personal data for one recipient and anonymous for another, the EDPB published draft Guidelines 02/2026 on Anonymisation (7 July 2026, consultation to 30 October 2026) setting out a two-question, three-criteria (no isolation, no linkage, no inference) test for anonymisation.observed

#

Rights are robustly enforced and subject to active coordinated supervisory scrutiny, but a pending legislative change (abuse-of-access-rights clarification) could alter practical scope.

Primary frameworkGDPR Articles 12-23 (Regulation (EU) 2016/679)
Traffic-light rationale — AmberRights are robustly enforced and subject to active coordinated supervisory scrutiny, but a pending legislative change (abuse-of-access-rights clarification) could alter practical scope.

Sub-modules (5)

Access RightAmber

CJEU case law confirms data subjects may exercise the right of access for purposes beyond verifying lawfulness of processing, without needing to state a motivation; the Digital Omnibus proposes clarifying when repeated/motiveless access requests constitute an abuse of rights, a framing the EDPB/EDPS partly contest.

Claims (2):

  • The CJEU has confirmed (Case C-307/22) that data subjects may legitimately exercise the Article 15 right of access for objectives other than becoming aware of processing or verifying its lawfulness, without needing to provide particular motivation.
  • The Digital Omnibus proposes to give controllers legal clarity for cases of abuse of rights by data subjects, but the EDPB and EDPS consider that exercising the access right for purposes other than data protection should not itself be treated as an element defining abuse.

Rectification And ErasureGreen

The EDPB's 2025 Coordinated Enforcement Framework action assessed compliance with the Article 17 right to erasure across participating DPAs, with a report adopted in 2026.

Claims (1):

  • The EDPB ran a year-long 2025 Coordinated Enforcement Framework action on the Article 17 right to erasure/right to be forgotten, adopting a report on the action's findings in 2026.

Restriction And ObjectionAmber

No dedicated 2026 enforcement or guidance action specific to Articles 18/21 restriction and objection rights was identified in this research pass distinct from the broader transparency and erasure actions.

Data PortabilityGreen

Article 20 portability continues to be governed by the WP29 Guidelines on the right to data portability, as endorsed by the EDPB; no material 2026 revision was identified.

Claims (1):

  • The right to data portability under Article 20 GDPR continues to be interpreted per the WP29 Guidelines on the right to data portability, as endorsed by the EDPB.

Deadlines And Response WindowsAmber

The EDPB's 2026 CEF action specifically targets controllers' compliance with the Article 12-14 transparency and information obligations that underpin data subjects' ability to exercise their rights within statutory response windows.

Claims (1):

  • During 2026, 25 DPAs across Europe are participating in the EDPB's Coordinated Enforcement Framework action assessing controller compliance with Article 12-14 transparency and information obligations that condition the effective exercise of data subject rights.
Category narrative55 words

GDPR Chapter III rights (access, rectification, erasure, restriction, objection, portability) remain fully in force EEA-wide. The EDPB's 2025 Coordinated Enforcement Framework focused on the right to erasure (Art. 17) and its 2026 CEF action targets transparency/information obligations (Arts. 12-14); the Digital Omnibus separately proposes an 'abuse of rights' clarification affecting how access requests are handled.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedEDPB — The CJEU has confirmed (Case C-307/22) that data subjects may legitimately exercise the Article 15 right of access for objectives other than becoming aware of processing or verifying its lawfulness, without needing to provide particular motivation.observed
  2. ConfirmedEDPB — The Digital Omnibus proposes to give controllers legal clarity for cases of abuse of rights by data subjects, but the EDPB and EDPS consider that exercising the access right for purposes other than data protection should not itself be treated as an element defining abuse.observed
  3. ConfirmedEDPB — The EDPB ran a year-long 2025 Coordinated Enforcement Framework action on the Article 17 right to erasure/right to be forgotten, adopting a report on the action's findings in 2026.observed
  4. ConfirmedEDPB — The right to data portability under Article 20 GDPR continues to be interpreted per the WP29 Guidelines on the right to data portability, as endorsed by the EDPB.observed
  5. ConfirmedEDPB — During 2026, 25 DPAs across Europe are participating in the EDPB's Coordinated Enforcement Framework action assessing controller compliance with Article 12-14 transparency and information obligations that condition the effective exercise of data subject rights.observed

#

Baseline obligations are stable and well-enforced, but simplification proposals (still in trilogue) will materially change SME/SMC recordkeeping and breach-notification thresholds once adopted.

Primary frameworkGDPR Articles 24-39 (Regulation (EU) 2016/679); Digital Omnibus (COM(2025) 836 final)
Traffic-light rationale — AmberBaseline obligations are stable and well-enforced, but simplification proposals (still in trilogue) will materially change SME/SMC recordkeeping and breach-notification thresholds once adopted.

Sub-modules (7)

Accountability And DpiaGreen

Articles 5, 24, 25 and 35 remain the accountability/DPIA backbone; the Digital Omnibus proposes common EU templates for DPIAs and legitimate-interest assessments to ease compliance.

Claims (1):

  • As part of its 2026-2027 work programme, the EDPB is developing ready-to-use EU templates for legitimate interest assessments, records of processing, privacy notices, data breach notifications and data protection impact assessments to facilitate compliance.

Dpo RequirementsAmber

No 2026-specific development on DPO appointment thresholds (Articles 37-39) was identified in this research pass; core designation triggers (public authorities, large-scale monitoring, large-scale special-category processing) remain unchanged.

Ropa RequirementsAmber

The Digital Omnibus (part of the fourth simplification package) proposes raising the Article 30(5) recordkeeping-exemption threshold from under-250-employee to under-750-employee enterprises/organisations, unless processing is high-risk.

Claims (1):

  • The Commission's Digital Omnibus proposal would amend Article 30(5) GDPR to raise the records-of-processing exemption threshold from enterprises/organisations under 250 employees to those under 750 employees, unless the processing is likely to result in high risk to individuals.

Joint Controller ArrangementsAmber

Article 26 joint-controller allocation-of-responsibility rules remain unchanged; no material 2026 development was identified in this research pass.

Security MeasuresGreen

Pseudonymisation is confirmed by EDPB guidance as a key technical safeguard supporting Article 32 security-of-processing obligations, alongside encryption.

Claims (1):

  • EDPB guidance explains how pseudonymisation, alongside encryption, functions as a technical safeguard supporting Article 32 security-of-processing obligations and Article 25 data protection by design.

Breach NotificationAmber

The EDPB and EDPS support the Digital Omnibus's proposal to raise the risk threshold triggering the Article 33 duty to notify the DPA of a breach, and to extend the notification deadline, alongside common EU breach-notification templates.

Claims (1):

  • The EDPB and EDPS support the Digital Omnibus proposal to increase the risk threshold that triggers the Article 33 duty to notify a personal data breach to the competent DPA, and to extend the notification deadline, alongside introducing common breach-notification and DPIA templates.

Retention And DisposalAmber

No dedicated 2026 guidance or enforcement action on Article 5(1)(e) storage-limitation/retention specifics was identified in this research pass distinct from general accountability duties.

Category narrative51 words

Core GDPR accountability duties (DPIA, DPO, ROPA, security, breach notification, retention) remain in force. The Digital Omnibus proposes targeted relief: raising the Article 30(5) ROPA-exemption employee threshold from 250 to 750, common EU templates for DPIAs/breach notifications, and a higher risk threshold plus longer deadline for breach notification to supervisory authorities.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedEDPB — As part of its 2026-2027 work programme, the EDPB is developing ready-to-use EU templates for legitimate interest assessments, records of processing, privacy notices, data breach notifications and data protection impact assessments to facilitate compliance.observed
  2. ConfirmedEDPB — The Commission's Digital Omnibus proposal would amend Article 30(5) GDPR to raise the records-of-processing exemption threshold from enterprises/organisations under 250 employees to those under 750 employees, unless the processing is likely to result in high risk to individuals.observed
  3. ConfirmedEDPB — EDPB guidance explains how pseudonymisation, alongside encryption, functions as a technical safeguard supporting Article 32 security-of-processing obligations and Article 25 data protection by design.observed
  4. ConfirmedEDPB — The EDPB and EDPS support the Digital Omnibus proposal to increase the risk threshold that triggers the Article 33 duty to notify a personal data breach to the competent DPA, and to extend the notification deadline, alongside introducing common breach-notification and DPIA templates.observed

#

Transfer mechanisms are mature and well-documented, but the EU-US DPF faces continuing legal challenge risk and the EDPB has flagged concerns (e.g. over US entry-condition changes for EEA citizens and a US Supreme Court ruling) that could affect adequacy stability.

Primary frameworkGDPR Chapter V, Articles 44-50 (Regulation (EU) 2016/679)
Traffic-light rationale — AmberTransfer mechanisms are mature and well-documented, but the EU-US DPF faces continuing legal challenge risk and the EDPB has flagged concerns (e.g. over US entry-condition changes for EEA citizens and a US Supreme Court ruling) that could affect adequacy stability.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Article 46 appropriate-safeguards tools (SCCs, BCRs) and Article 49 derogations remain the default routes absent adequacy; TIAs must precede reliance on Article 46 tools per CNIL/EDPB methodology.

Claims (1):

  • Article 46 GDPR lists appropriate-safeguards transfer tools (including SCCs and BCRs), and Article 49 provides derogations for specific situations, both usable absent an adequacy decision, subject to the exporter maintaining Article 5 GDPR compliance.

Adequacy ReceivedGreen

As the standard-setting jurisdiction, the EEA is structurally an adequacy-GRANTING regime rather than a recipient of adequacy decisions from third countries; the concept of 'adequacy received' does not apply to the EEA in the way it applies to third countries such as the UK receiving EU adequacy.

Claims (1):

  • The GDPR framework positions the European Commission as the body issuing adequacy decisions under Article 45 to third countries (e.g. the UK, renewed 19 December 2025 to run until 27 December 2031); the EEA itself is not a recipient of inbound adequacy findings under this mechanism.

Adequacy GrantedGreen

The European Commission has granted adequacy to Andorra, Argentina, Canada (private sector), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and the United States (via the EU-US DPF, private-sector participants only).

Claims (2):

  • The European Commission has recognised adequate third countries/territories including Andorra, Argentina, Canada, the Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay and the United States.
  • The EU-US Data Privacy Framework adequacy decision, adopted 10 July 2023, allows personal data to flow to certified US organisations without additional transfer safeguards; as of early 2026 more than 3,500 US companies had self-certified, though the framework remains subject to potential CJEU review and EDPB monitoring including a first-review report.

Sccs And BcrsGreen

The Commission's 2021 modernised SCCs (Implementing Decision (EU) 2021/914) remain the principal contractual transfer tool; the EDPB continues to issue Article 64 opinions approving national DPAs' draft BCR decisions for both controllers and processors.

Claims (1):

  • The European Commission adopted modernised Standard Contractual Clauses via Implementing Decision (EU) 2021/914 in June 2021, and since 27 September 2021 only the current SCCs may be used for new transfer contracts; the EDPB continues to issue opinions approving Member State DPAs' draft BCR authorisations (e.g. multiple 2026 opinions on Dutch SA BCR decisions).

Transfer Impact AssessmentGreen

A Transfer Impact Assessment is required before relying on an Article 46 tool for transfers to non-adequate third countries, assessing whether the importer's jurisdiction offers protection essentially equivalent to the EEA; TIAs are not required where an adequacy decision or Article 49 derogation applies.

Claims (1):

  • A Transfer Impact Assessment must be carried out by an exporter relying on an Article 46 GDPR transfer tool prior to transferring data to a third country, unless the destination is covered by an adequacy decision or an Article 49 derogation applies.

Data LocalisationAmber

GDPR does not impose a general data-localisation mandate, but the EU's parallel Digital Omnibus/sovereign-cloud legislative track (COM(2026)502) introduces sovereignty-oriented safeguards for personal data processed via cloud infrastructure, without altering GDPR's transfer rules directly.

Claims (1):

  • A separate EU legislative proposal for sovereign cloud computing services (impact assessment submitted to the Regulatory Scrutiny Board, positive opinion 8 May 2026) introduces safeguards for EU-citizen personal data processed via cloud infrastructure and is framed as complementary to, not a replacement for, the GDPR and EU-US DPF transfer regime.
Category narrative67 words

The EEA operates the full GDPR Chapter V transfer toolkit (adequacy, SCCs, BCRs, Article 49 derogations, TIAs). It currently grants adequacy to 15 third countries/territories (including the US via the EU-US DPF, and the UK, renewed to 27 December 2031), while itself functioning as the adequacy-granting jurisdiction rather than a recipient. The EU-US Data Privacy Framework remains under EDPB monitoring amid ongoing litigation risk and periodic review.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

The EEA's adequacy landscape gained a notable new arrangement this cycle. Brazil's data protection authority, the ANPD, issued Resolution CD/ANPD No. 32/2026 recognising the EU as adequate for LGPD purposes, and that recognition explicitly extends to Iceland, Liechtenstein and Norway as EEA-EFTA states. This is matched by a corresponding European Commission adequacy decision for Brazil, making the arrangement genuinely mutual rather than a one-directional recognition. The explicit naming of the EEA-EFTA states in the Brazilian resolution is analytically significant: it treats the EEA as the relevant unit for adequacy purposes rather than defaulting to an EU-only framing, which is not guaranteed in every third-country adequacy instrument and is worth noting as a positive drafting choice for EEA-EFTA data flows specifically.

This sits alongside the standing structural fact that the European Data Protection Board's membership already includes the heads of the EEA-EFTA states' national supervisory authorities, one per EU Member State plus Iceland, Liechtenstein and Norway, reflecting the EEA-EFTA states' established integration into the EU's core data protection institutional architecture even where specific instruments, such as adequacy decisions, require separate treatment.

The practical effect for organisations moving personal data between the EEA and Brazil is a genuine liberalisation: data flows in both directions can now rely on the mutual adequacy finding rather than requiring supplementary transfer mechanisms such as standard contractual clauses, for the EEA-EFTA states as well as the EU Member States.

Outlook

No further adequacy developments are flagged for this cycle beyond the Brazil arrangement. The mutual adequacy finding is now in force; the marker to watch is whether other third-country adequacy arrangements adopt the same practice of explicitly naming the EEA-EFTA states rather than treating adequacy as an EU-only question.

Sources and claims (7)
  1. ConfirmedEDPB — Article 46 GDPR lists appropriate-safeguards transfer tools (including SCCs and BCRs), and Article 49 provides derogations for specific situations, both usable absent an adequacy decision, subject to the exporter maintaining Article 5 GDPR compliance.observed
  2. ConfirmedICO — The GDPR framework positions the European Commission as the body issuing adequacy decisions under Article 45 to third countries (e.g. the UK, renewed 19 December 2025 to run until 27 December 2031); the EEA itself is not a recipient of inbound adequacy findings under this mechanism.observed
  3. ConfirmedEDPB — The European Commission has recognised adequate third countries/territories including Andorra, Argentina, Canada, the Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay and the United States.observed
  4. ConfirmedIAPP — The EU-US Data Privacy Framework adequacy decision, adopted 10 July 2023, allows personal data to flow to certified US organisations without additional transfer safeguards; as of early 2026 more than 3,500 US companies had self-certified, though the framework remains subject to potential CJEU review and EDPB monitoring including a first-review report.observed
  5. ConfirmedBfDI — The European Commission adopted modernised Standard Contractual Clauses via Implementing Decision (EU) 2021/914 in June 2021, and since 27 September 2021 only the current SCCs may be used for new transfer contracts; the EDPB continues to issue opinions approving Member State DPAs' draft BCR authorisations (e.g. multiple 2026 opinions on Dutch SA BCR decisions).observed
  6. ConfirmedCNIL — A Transfer Impact Assessment must be carried out by an exporter relying on an Article 46 GDPR transfer tool prior to transferring data to a third country, unless the destination is covered by an adequacy decision or an Article 49 derogation applies.observed
  7. ProbableEuropean Commission — A separate EU legislative proposal for sovereign cloud computing services (impact assessment submitted to the Regulatory Scrutiny Board, positive opinion 8 May 2026) introduces safeguards for EU-citizen personal data processed via cloud infrastructure and is framed as complementary to, not a replacement for, the GDPR and EU-US DPF transfer regime.observed

#

Health and telecoms/eprivacy overlays are actively evidenced; other sectoral overlays (financial, employment, education, insurance) lack direct 2026 sourcing in this pass and are flagged as gaps.

Primary frameworkGDPR (Regulation (EU) 2016/679) with sector-specific overlays (ePrivacy Directive 2002/58/EC)
Traffic-light rationale — AmberHealth and telecoms/eprivacy overlays are actively evidenced; other sectoral overlays (financial, employment, education, insurance) lack direct 2026 sourcing in this pass and are flagged as gaps.

Sub-modules (7)

Financial Sector OverlayRed

No direct 2026 source evidencing a specific financial-sector GDPR overlay (e.g. interplay with PSD2/AML frameworks) was retrieved in this research pass.

Health Sector OverlayAmber

CNIL imposed a €5 million fine against IQVIA for health-data violations, evidencing active health-sector GDPR enforcement.

Claims (1):

  • CNIL imposed a €5 million fine against IQVIA in connection with health-data processing, evidencing active French enforcement in the health sector.

Telecoms And EprivacyAmber

The Digital Omnibus proposes targeted amendments to the ePrivacy Directive (cookie/tracking consent rules), including a new automated-consent-signal mechanism and additional narrow derogations to the prohibition on accessing terminal-equipment data.

Claims (1):

  • The Digital Omnibus proposes amendments to the ePrivacy Directive including limited additional derogations to the general prohibition on storing or accessing data in terminal equipment, which the EDPB/EDPS urge be balanced by incentivising contextual over behavioural advertising.

Employment DataRed

No dedicated 2026 EEA employment-data overlay source was retrieved in this research pass beyond generic Article 88 GDPR employment-context processing rules, which were not directly evidenced.

Credit And ScoringAmber

The CJEU's December 2023 SCHUFA ruling (C-634/21) provided the first interpretation of the Article 22 right not to be subject to solely automated decision-making in the context of automated credit scoring.

Claims (1):

  • In December 2023, the CJEU issued its first interpretation of Article 22 GDPR (right not to be subject to solely automated decision-making) in the context of automated credit scoring (Case C-634/21, SCHUFA).

EducationRed

No dedicated 2026 EEA education-sector data protection source was retrieved in this research pass.

InsuranceRed

No dedicated 2026 EEA insurance-sector data protection source was retrieved in this research pass.

Category narrative42 words

GDPR applies horizontally with sector overlays; identified 2026 activity centres on health data (CNIL's €5m fine against IQVIA) and telecoms/eprivacy (Digital Omnibus proposed ePrivacy Directive amendments on cookies/tracking). Financial-sector, employment, education and insurance overlays were not directly evidenced in this research pass.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedCNIL — CNIL imposed a €5 million fine against IQVIA in connection with health-data processing, evidencing active French enforcement in the health sector.observed
  2. ConfirmedEDPB — The Digital Omnibus proposes amendments to the ePrivacy Directive including limited additional derogations to the general prohibition on storing or accessing data in terminal equipment, which the EDPB/EDPS urge be balanced by incentivising contextual over behavioural advertising.observed
  3. ConfirmedMedical Law Review / NCBI PMC — In December 2023, the CJEU issued its first interpretation of Article 22 GDPR (right not to be subject to solely automated decision-making) in the context of automated credit scoring (Case C-634/21, SCHUFA).observed

#

Cookie-consent fatigue is a recognised, unresolved policy problem; the principal legislative fix (Art. 88b) is currently stalled in the Council, leaving practical mechanics unsettled.

Primary frameworkePrivacy Directive 2002/58/EC read with GDPR consent standards (Regulation (EU) 2016/679)
Traffic-light rationale — AmberCookie-consent fatigue is a recognised, unresolved policy problem; the principal legislative fix (Art. 88b) is currently stalled in the Council, leaving practical mechanics unsettled.

Sub-modules (6)

Cookies And TrackersAmber

The proposed Article 88b would let individuals express privacy choices via automated technical means (e.g. browser settings) rather than manual cookie-banner clicks, with oversight entrusted to DPAs; the Council removed this provision from its June 2026 negotiating position.

Claims (1):

  • The Digital Omnibus's proposed Article 88b GDPR would allow automated, machine-readable expression of individuals' data-processing choices, with oversight of such mechanisms entrusted to DPAs; in June 2026 the Council of the EU removed this provision from its position paper after industry lobbying.

Dark PatternsAmber

Commentary identifies persistent cookie-banner 'consent fatigue' and dark-pattern-style nudging toward data sharing as an unresolved problem the Digital Omnibus aims, but has not yet succeeded, to fix.

Claims (1):

  • Cookie banners are widely characterised as causing consent fatigue and facilitating data exploitation rather than achieving the meaningful, effective data protection the ePrivacy Directive and GDPR were intended to deliver.

Opt Out SignalsAmber

Global Privacy Control, already implemented on at least 385,000 websites and recognised under several US state privacy laws, is discussed as a potential model for the EU's automated consent-signal mechanism, though the GPC specification (opt-out only) does not natively support giving affirmative consent.

Claims (1):

  • Global Privacy Control is implemented on at least 385,000 websites and recognised under California, Colorado, Connecticut and other US state privacy laws, and is discussed as a candidate technical standard for the EU's proposed automated consent-signal mechanism, though as an opt-out-only specification it cannot natively express affirmative consent.

Clean Rooms And DcrRed

No dedicated 2026 EEA source on data clean rooms/data-collaboration-room rules was retrieved in this research pass.

Cross Context AdvertisingAmber

The EDPB and EDPS invite co-legislators to incentivise contextual advertising over behavioural advertising within the Digital Omnibus's ePrivacy amendments, via a specific exception surrounded by safeguards.

Claims (1):

  • The EDPB and EDPS welcome limited additional ePrivacy derogations proposed in the Digital Omnibus and invite co-legislators to incentivise contextual advertising over behavioural advertising through a specific, safeguarded exception.

Direct MarketingRed

No dedicated 2026 EEA source specific to direct-marketing consent/suppression rules distinct from general ePrivacy Article 13 rules was retrieved in this research pass.

Category narrative44 words

Cookie/tracker consent is governed by the ePrivacy Directive read with GDPR consent standards; 2026 developments centre on the contested Digital Omnibus Article 88b automated-consent-signal mechanism (removed by the Council in June 2026) and continuing debate over Global Privacy Control-style opt-out signals and contextual-versus-behavioural advertising.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedIAPP — The Digital Omnibus's proposed Article 88b GDPR would allow automated, machine-readable expression of individuals' data-processing choices, with oversight of such mechanisms entrusted to DPAs; in June 2026 the Council of the EU removed this provision from its position paper after industry lobbying.observed
  2. ProbableIAPP — Cookie banners are widely characterised as causing consent fatigue and facilitating data exploitation rather than achieving the meaningful, effective data protection the ePrivacy Directive and GDPR were intended to deliver.observed
  3. ConfirmedIAPP — Global Privacy Control is implemented on at least 385,000 websites and recognised under California, Colorado, Connecticut and other US state privacy laws, and is discussed as a candidate technical standard for the EU's proposed automated consent-signal mechanism, though as an opt-out-only specification it cannot natively express affirmative consent.observed
  4. ConfirmedEDPB — The EDPB and EDPS welcome limited additional ePrivacy derogations proposed in the Digital Omnibus and invite co-legislators to incentivise contextual advertising over behavioural advertising through a specific, safeguarded exception.observed

#

Article 22 is settled law with recent CJEU interpretation, but the practical GDPR/AI Act interface remains in active development pending joint EDPB-Commission guidelines and AI Act simplification.

Primary frameworkGDPR Article 22 (Regulation (EU) 2016/679); interplay with Regulation (EU) 2024/1689 (AI Act)
Traffic-light rationale — AmberArticle 22 is settled law with recent CJEU interpretation, but the practical GDPR/AI Act interface remains in active development pending joint EDPB-Commission guidelines and AI Act simplification.

Sub-modules (6)

Profiling RestrictionsGreen

Article 22 GDPR provides data subjects a right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects.

Claims (1):

  • Article 22 GDPR provides data subjects with the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them.

Automated Decision Making TransparencyAmber

The EDPB and European Commission are jointly developing guidelines on the GDPR/AI Act interplay covering transparency, risk assessments, bias detection and accountability, with a draft expected soon and possible final adoption by end of 2026.

Claims (1):

  • The EDPB and the European Commission are jointly preparing guidelines on the interplay between the GDPR and the AI Act, addressing transparency, risk assessments, bias detection and accountability, with a first draft potentially available soon and final adoption possible by end of 2026.

Ai Risk AssessmentsAmber

The Digital Omnibus on AI proposes to extend the AI Act's high-risk-system compliance timeline (originally August 2026) by up to six months once implementing standards are confirmed, capped at December 2027, alongside SME/SMC documentation simplifications.

Claims (1):

  • The EU's AI Act high-risk system compliance timeline, originally set for August 2026, is being extended via the Digital Omnibus on AI, with organisations to receive six months to comply once implementing standards and support tools are confirmed, capped at December 2027.

Biometric RegimeRed

No dedicated 2026 EEA-specific biometric-regime source (facial recognition, fingerprint, gait) distinct from general Article 9 special-category rules was retrieved in this research pass.

Genetic DataAmber

Genetic data is treated as an Article 9 special category; the Digital Omnibus's proposed AI-context sensitive-data derogation would potentially cover incidental genetic-data processing in AI development, subject to EDPB/EDPS-recommended safeguards.

Claims (1):

  • Genetic data falls within the Article 9 special-category regime; the Digital Omnibus's proposed derogation for incidental/residual sensitive-data processing in AI development would potentially extend to genetic data, subject to EDPB/EDPS-recommended lifecycle safeguards.

State Surveillance CarveoutsAmber

The EDPB has formally engaged the European Commission on privacy implications of proposed US legislative changes to entry conditions for EEA citizens, and separately on a US Supreme Court judgment (Trump v. Slaughter), reflecting active EDPB scrutiny of law-enforcement/surveillance-adjacent international-cooperation issues.

Claims (1):

  • The EDPB has issued formal correspondence to the European Commission addressing the privacy implications of proposed US legislative changes to entry conditions for EEA citizens, and separately regarding a US Supreme Court judgment, reflecting ongoing EDPB engagement with law-enforcement and surveillance-adjacent international-cooperation matters.
Category narrative69 words

Article 22 GDPR remains the core EEA safeguard against solely automated decision-making, interpreted by the CJEU in SCHUFA (2023). The EDPB and European Commission are jointly drafting guidelines on the GDPR/AI Act interplay (transparency, risk assessments, bias, accountability), expected in draft form soon with final adoption possibly by end of 2026, against the backdrop of the AI Act's own Digital Omnibus-driven timeline extension (high-risk obligations capped to December 2027).

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

The EU AI Act's status within the EEA Agreement remains unresolved this cycle, and this is a genuine EEA-bloc-specific gap rather than a restatement of the AI Act's EU applicability. The AI Act is understood to have been marked by EFTA as a proposed act with possible EEA relevance, and remains under EEA-EFTA scrutiny, with a draft Joint Committee Decision under consideration but not yet adopted. Reports suggest incorporation, if it proceeds, may not occur before 2027, though no primary EEA Joint Committee or EFTA scrutiny document has been directly retrieved confirming a firm timeline this cycle.

The practical consequence is that the algorithmic risk-assessment, biometric-system, and AI-governance obligations that already bind providers and deployers operating within the EU are not yet extended, as a matter of EEA law, to Iceland, Liechtenstein and Norway. Organisations operating AI systems across both EU and EEA-EFTA markets should not assume uniform applicability of AI Act obligations across the full EEA footprint while this incorporation gap persists; the EEA-EFTA states currently rely on their existing data protection and general regulatory law rather than a dedicated AI-governance framework equivalent to the AI Act.

This incorporation gap echoes a broader pattern visible elsewhere in the EEA-EFTA bloc this cycle, where major EU instruments require a distinct EEA Joint Committee incorporation step that can proceed on a materially different timeline from the instrument's EU application date.

Outlook

The marker to watch is any movement on the draft EEA Joint Committee Decision addressing AI Act incorporation; current reporting points to no earlier than 2027 for any resolution, though this figure carries meaningful uncertainty given the absence of a directly retrieved primary source this cycle.

Sources and claims (5)
  1. ConfirmedIAPP — Article 22 GDPR provides data subjects with the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them.observed
  2. ProbableIAPP — The EDPB and the European Commission are jointly preparing guidelines on the interplay between the GDPR and the AI Act, addressing transparency, risk assessments, bias detection and accountability, with a first draft potentially available soon and final adoption possible by end of 2026.observed
  3. ConfirmedIAPP — The EU's AI Act high-risk system compliance timeline, originally set for August 2026, is being extended via the Digital Omnibus on AI, with organisations to receive six months to comply once implementing standards and support tools are confirmed, capped at December 2027.observed
  4. ProbableEDPB — Genetic data falls within the Article 9 special-category regime; the Digital Omnibus's proposed derogation for incidental/residual sensitive-data processing in AI development would potentially extend to genetic data, subject to EDPB/EDPS-recommended lifecycle safeguards.observed
  5. ConfirmedEDPB — The EDPB has issued formal correspondence to the European Commission addressing the privacy implications of proposed US legislative changes to entry conditions for EEA citizens, and separately regarding a US Supreme Court judgment, reflecting ongoing EDPB engagement with law-enforcement and surveillance-adjacent international-cooperation matters.observed

#

Core Article 8 mechanism is well-established law, but dedicated children's-data guidelines remain in development and several sub-areas (age verification specifics, education settings, dependent adults) lack direct 2026 sourcing in this pass.

Primary frameworkGDPR Article 8 (Regulation (EU) 2016/679)
Traffic-light rationale — AmberCore Article 8 mechanism is well-established law, but dedicated children's-data guidelines remain in development and several sub-areas (age verification specifics, education settings, dependent adults) lack direct 2026 sourcing in this pass.

Sub-modules (5)

Age VerificationAmber

Article 8 GDPR sets a default age of 16 for a child's own consent to information-society-service processing, with Member States able to lower this to no less than 13; a direct 2026 source confirming current Member-State-by-Member-State variance was not retrieved in this pass.

Claims (1):

  • Article 8 GDPR sets a default minimum age of 16 for a child to consent to processing in relation to information-society services, permitting Member States to lower this threshold by law to no less than 13 years, with parental-responsibility-holder consent required below the applicable age.

Minor Profiling BansAmber

The EDPB is developing dedicated Guidelines on children's data as part of its 2026-2027 work programme, which is expected to address profiling and other processing risks specific to minors, though the guidelines were not yet finalised as of this research pass.

Claims (1):

  • The EDPB's 2026-2027 work programme includes the development of dedicated Guidelines on children's data as one of its Pillar I harmonisation priorities.

Education SettingsRed

No dedicated 2026 EEA education-settings-specific children's-data source was retrieved in this research pass.

Dependent AdultsRed

No dedicated 2026 EEA dependent-adults (elderly, mentally incapacitated) data protection source was retrieved in this research pass.

Category narrative60 words

GDPR Article 8 establishes the default digital-consent age of 16 (Member States may lower to no less than 13); the EDPB is actively developing dedicated Guidelines on children's data as part of its 2026-2027 work programme, but this research pass did not surface a source directly confirming per-Member-State age-of-consent variance or minor-profiling-ban specifics for 2026, which are flagged as gaps.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainCNIL — Article 8 GDPR sets a default minimum age of 16 for a child to consent to processing in relation to information-society services, permitting Member States to lower this threshold by law to no less than 13 years, with parental-responsibility-holder consent required below the applicable age.observed
  2. ConfirmedEDPB — The EDPB's 2026-2027 work programme includes the development of dedicated Guidelines on children's data as one of its Pillar I harmonisation priorities.observed

#

Enforcement powers are broad, actively used at scale (billion-euro-class fines), collective redress mechanisms are in force, and a further procedural-harmonisation regulation is already adopted (pending 2027 application).

Primary frameworkGDPR Articles 77-84, 58, 83 (Regulation (EU) 2016/679); Regulation (EU) 2025/2518; Directive (EU) 2020/1828
Traffic-light rationale — GreenEnforcement powers are broad, actively used at scale (billion-euro-class fines), collective redress mechanisms are in force, and a further procedural-harmonisation regulation is already adopted (pending 2027 application).

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Article 83 GDPR authorises administrative fines of up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, alongside corrective powers (bans, suspensions) under Article 58.

Claims (1):

  • GDPR Article 83 authorises fines for certain violations of up to 4% of an undertaking's total global annual turnover of the preceding financial year or €20 million, whichever is greater.

Enforcement Activity IndexGreen

Ireland's DPC imposed a record €1.2 billion fine on Meta (May 2023) for unlawful US data transfers, plus a combined €390 million fine for unlawful ad-targeting legal basis and a €5.5 million WhatsApp transparency fine; the Czech SA confirmed a €13.9 million fine on appeal, and CNIL fined IQVIA €5 million over health data, evidencing sustained large-scale enforcement into 2026.

Claims (3):

  • Ireland's Data Protection Commission imposed a record €1.2 billion fine on Meta Ireland in May 2023 over unlawful EU-US data transfers, the largest GDPR fine to date, alongside orders to suspend future transfers and cease unlawful US processing of EEA users' data.
  • The Czech supervisory authority's appellate decision confirmed a first-instance fine of approximately €13.9 million against a controller for infringing Articles 6 and 13(1) GDPR over the transfer of antivirus-software users' browsing data to a sister company.
  • CNIL fined IQVIA €5 million over health-data violations, and Ireland's DPC separately fined WhatsApp Ireland €5.5 million for transparency and consent failures in its Terms of Service, illustrating continued multi-jurisdictional enforcement momentum.

Regulator Funding And CapacityAmber

No dedicated 2026 source quantifying EEA DPA funding or headcount levels was retrieved in this research pass; the European Commission has separately noted limited DPA resourcing as a factor hindering cross-border enforcement effectiveness, motivating the new procedural regulation.

Claims (1):

  • The European Commission identified fragmented national procedures and limited DPA resourcing as factors hindering effective cross-border GDPR enforcement, a key motivation for the new procedural regulation (EU) 2025/2518.

Collective Redress And Class ActionsGreen

Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers, in force since 25 June 2023, enables qualified entities to bring injunctive and redress collective actions covering, among other sectors, data protection infringements.

Claims (1):

  • Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers, applicable in Member States since 25 June 2023, empowers qualified entities to bring both injunctive and redress collective actions against traders for infringements including, where available under national or EU law, data protection.

Private Right Of ActionGreen

Articles 77-79 and 82 GDPR give data subjects the right to lodge a complaint with a DPA, an effective judicial remedy against a controller/processor and a DPA, and compensation for material or non-material damage; advocacy group NOYB's 2018 complaints underpinned the Meta enforcement chain and NOYB has signalled intent to challenge the EU-US DPF adequacy decision.

Claims (1):

  • Complaints filed in May 2018 by advocacy group NOYB under Articles 77-79/82 GDPR underpinned the enforcement chain leading to the Irish DPC's Meta Facebook, Instagram and WhatsApp fines, and NOYB has indicated it intends to challenge the EU-US Data Privacy Framework adequacy decision before the CJEU.

Recent Developments 180DAmber

Within the last 180 days (Feb-Aug 2026): the EDPB/EDPS adopted Joint Opinion 2/2026 on the Digital Omnibus (Feb 2026); the Council removed the proposed Art.88b automated-consent-signal provision (Jun 2026); the EDPB published draft Guidelines 02/2026 on Anonymisation (Jul 2026, consultation to Oct 2026); the EDPB launched its 2026 Coordinated Enforcement Framework action on transparency (19 Mar 2026); and the EDPB corresponded with the Commission on US Supreme Court and US entry-condition developments (2026).

Claims (3):

  • On 11 February 2026, the EDPB and EDPS adopted Joint Opinion 2/2026 on the Digital Omnibus Regulation proposal, supporting simplification aims while urging co-legislators not to adopt the proposed narrowing of the GDPR's personal-data definition.
  • On 7 July 2026, the EDPB published draft Guidelines 02/2026 on Anonymisation for public consultation (open until 30 October 2026), responding to the CJEU's September 2025 EDPS v SRB ruling.
  • On 19 March 2026, the EDPB launched its 2026 Coordinated Enforcement Framework action, with 25 participating DPAs assessing controller compliance with GDPR transparency and information obligations (Articles 12-14).
Category narrative103 words

GDPR Article 83 empowers DPAs to impose fines up to €20 million or 4% of global annual turnover, whichever is greater. 2026 enforcement activity remains vigorous, evidenced by the Czech SA's €13.9m appellate-confirmed fine, CNIL's €5m IQVIA fine, and the historical record €1.2 billion Meta transfer fine and €390m/€5.5m Meta ad-targeting/WhatsApp fines implemented via EDPB Article 65 binding decisions. A new procedural regulation (EU) 2025/2518 will streamline cross-border cooperation from April 2027, and the EU's Representative Actions Directive (2020/1828, in force since June 2023) enables qualified-entity collective redress covering data protection, alongside individual rights of judicial remedy and compensation under Articles 79/82 GDPR.

no periodic updates on record for this sub-brief

Sources and claims (10)
  1. ConfirmedSEC — GDPR Article 83 authorises fines for certain violations of up to 4% of an undertaking's total global annual turnover of the preceding financial year or €20 million, whichever is greater.observed
  2. ConfirmedIAPP — Ireland's Data Protection Commission imposed a record €1.2 billion fine on Meta Ireland in May 2023 over unlawful EU-US data transfers, the largest GDPR fine to date, alongside orders to suspend future transfers and cease unlawful US processing of EEA users' data.observed
  3. ConfirmedEDPB — The Czech supervisory authority's appellate decision confirmed a first-instance fine of approximately €13.9 million against a controller for infringing Articles 6 and 13(1) GDPR over the transfer of antivirus-software users' browsing data to a sister company.observed
  4. ConfirmedIAPP — CNIL fined IQVIA €5 million over health-data violations, and Ireland's DPC separately fined WhatsApp Ireland €5.5 million for transparency and consent failures in its Terms of Service, illustrating continued multi-jurisdictional enforcement momentum.observed
  5. ProbableIAPP — The European Commission identified fragmented national procedures and limited DPA resourcing as factors hindering effective cross-border GDPR enforcement, a key motivation for the new procedural regulation (EU) 2025/2518.observed
  6. ConfirmedPublications Office of the EU — Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers, applicable in Member States since 25 June 2023, empowers qualified entities to bring both injunctive and redress collective actions against traders for infringements including, where available under national or EU law, data protection.observed
  7. ConfirmedIAPP — Complaints filed in May 2018 by advocacy group NOYB under Articles 77-79/82 GDPR underpinned the enforcement chain leading to the Irish DPC's Meta Facebook, Instagram and WhatsApp fines, and NOYB has indicated it intends to challenge the EU-US Data Privacy Framework adequacy decision before the CJEU.observed
  8. ConfirmedEDPB — On 11 February 2026, the EDPB and EDPS adopted Joint Opinion 2/2026 on the Digital Omnibus Regulation proposal, supporting simplification aims while urging co-legislators not to adopt the proposed narrowing of the GDPR's personal-data definition.observed
  9. ConfirmedEDPB — On 7 July 2026, the EDPB published draft Guidelines 02/2026 on Anonymisation for public consultation (open until 30 October 2026), responding to the CJEU's September 2025 EDPS v SRB ruling.observed
  10. ConfirmedEDPB — On 19 March 2026, the EDPB launched its 2026 Coordinated Enforcement Framework action, with 25 participating DPAs assessing controller compliance with GDPR transparency and information obligations (Articles 12-14).observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct61.54
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for European Economic Area (Bloc)
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 54 claim(s) (54 category placement(s)), 43 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with T1 (EDPB/EDPS/EUR-Lex/CNIL/national-DPA official sources) as the backbone for regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy and enforcement_and_redress. Sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely more heavily on T3 (IAPP journalism) supplementing T1 anchors, reflecting the fast-moving Digital Omnibus/AI Act interplay news cycle. Several sub-modules (financial_sector_overlay, employment_data, education, insurance, biometric_regime, education_settings, dependent_adults, clean_rooms_and_dcr, direct_marketing, regulator_funding_and_capacity granular figures, DPO threshold specifics, restriction_and_objection dedicated 2026 action) carry no populating claims in this pass and are marked red/amber with explicit absent_field_provenance or narrative rationale rather than fabricated content.

Unresolved questions (6):

  • What is the final text of Digital Omnibus Article 88b (automated consent signals) and the ePrivacy amendments following the Council's June 2026 removal of that provision, once trilogues conclude?
  • Will the CJEU rule on a NOYB challenge to the EU-US Data Privacy Framework adequacy decision, and what would that mean for the adequacy_granted sub-module?
  • What are current, quantified EEA national DPA funding/headcount figures for 2026 (regulator_funding_and_capacity gap)?
  • What is the current Member-State-by-Member-State variance in the Article 8 digital-consent age (13-16) across all 30 EEA jurisdictions?
  • What is the content and adoption timeline of the EDPB's dedicated Guidelines on children's data referenced in the 2026-2027 work programme?
  • Is there a distinct EEA financial-sector GDPR overlay (AML/PSD2 interplay) analogous to the health-sector and telecoms/eprivacy overlays evidenced in this pass?

Escalate to primary-source review: yes