Blog Post: GDPR Anniversary – 10 Key Developments
Summary
The General Data Protection Regulation (GDPR), eight years after its May 25, 2018 applicability, is undergoing significant evolution, marked by intensifying enforcement and legislative proposals. 2025 saw record fines exceeding €1.2 billion, contributing to €7.1 billion in cumulative sanctions, with major tech firms facing penalties over €200 million. The proposed Digital Omnibus, introduced November 2025, aims to streamline EU digital laws, proposing explicit legitimate interest as a legal basis for AI training and reforms to automated decision-making. It also seeks to harmonize cookie rules with new consent exemptions and align data breach notifications with other directives like NIS2 and DORA. The European Data Protection Board (EDPB) is actively issuing guidance on anonymization, scientific research, and the interplay with the Digital Markets Act (DMA) and Digital Services Act (DSA). International data transfer adequacy decisions were renewed for the UK (December 2025) and adopted for Brazil (January 2026) and the European Patent Organisation (July 2025).
Key takeaway
For privacy and compliance professionals navigating the evolving GDPR landscape, you must proactively adapt your programs to legislative changes and intensifying enforcement. Continuously monitor the Digital Omnibus's progress, especially regarding AI legal bases, automated decision-making, and data breach notifications, as these will directly impact your operational burden. Audit your consent mechanisms against new cookie rules and ensure your incident response plans account for overlapping requirements from GDPR, NIS2, and DORA. Seriously review appellate rights for any supervisory authority sanctions.
Key insights
GDPR is evolving through legislative reform, intensifying enforcement, and new regulatory guidance, demanding continuous compliance adaptation.
Principles
- EDPB guidelines directly inform enforcement actions.
- Adequacy decisions simplify international data transfers.
- Regulatory sanctions are appealable, not final.
Method
The EU Commission's structured process for adopting adequacy decisions involves a proposal, EDPB opinion, Member State approval, and formal adoption.
In practice
- Audit consent mechanisms against current and proposed cookie rules.
- Conduct rigorous Legitimate Interest Assessments for AI.
- Update incident response plans for overlapping notification duties.
Topics
- GDPR Compliance
- EU Digital Legislation
- Data Transfer Adequacy
- AI Governance
- Children's Data Privacy
- Data Breach Notification
Best for: CTO, VP of Engineering/Data, Director of AI/ML, Legal Professional, Consultant, Policy Maker
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by cyber/data/privacy insights.