EU 2016/679

EU GDPR: a complete guide to Regulation (EU) 2016/679

GDPR (Regulation (EU) 2016/679) is the EU law that sets what any organisation may and may not do with personal data about people in Europe. This guide covers the core principles, when you're allowed to use data at all, people's rights over their data, who must comply, sending data abroad, and fines up to €20M or 4% of worldwide turnover — every fact sourced to EUR-Lex, the EDPB and the European Commission.

The EU General Data Protection Regulation (GDPR) is the law that defines, across all 27 Member States plus the three EEA states, what an organisation is and is not allowed to do with personal data about people in Europe. It replaced the patchwork of national rules that grew out of the 1995 Data Protection Directive and harmonised — to the extent that 30 jurisdictions can be harmonised — the rights of data subjects, the obligations of controllers and processors (the organisation that decides why and how data is used, and any supplier that handles it on that organisation’s instructions), the powers of supervisory authorities, and the rules on transferring personal data outside the EEA.

If you process personal data about anyone in the EU/EEA — customer email addresses, employee files, IP logs, CCTV footage, health records, anything that can be linked to an identified or identifiable person — this Regulation applies to you. It applied from 25 May 2018, has been in force ever since, and has produced enforcement actions running into the billion-euro range: Ireland’s Data Protection Commission fined Meta €1.2 billion in May 2023 over EU–US data transfers, and another €530 million was imposed on TikTok in May 2025 for the same category of breach.

This page is the canonical klarproof guide — every key claim is sourced directly to EUR-Lex, the European Data Protection Board (EDPB), the European Commission, or named national supervisors.

Quick facts

  • Full name: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation)
  • Adopted: 27 April 2016
  • Published in OJ: 4 May 2016 (OJ L 119/1)
  • Entered into force: 24 May 2016 (twentieth day after publication, per Article 99)
  • Started to apply: 25 May 2018 (after a two-year transition period)
  • Penalties: up to €10M or 2% of total worldwide annual turnover (lower tier — Article 83(4)); up to €20M or 4% of total worldwide annual turnover (higher tier — Article 83(5)/(6)); whichever is higher in each case
  • Coordinating EU body: the European Data Protection Board (EDPB) — independent body composed of the heads of every national supervisory authority + the European Data Protection Supervisor (EDPS)
  • EU institutions’ supervisor: the European Data Protection Supervisor (EDPS) — supervises personal data processing by EU institutions, bodies, offices and agencies; current Supervisor: Wojciech Wiewiórowski (took office 6 December 2019 for the 2019–2024 term; remains in post on an interim basis as of June 2026, pending appointment of a successor)
  • EDPB Chair: Anu Talus (Finland, Data Protection Ombudsman); Deputy Chairs: Jelena Virant Burnik (Slovenia, Information Commissioner — elected December 2025) and Zdravko Vukić (Croatia)
  • National enforcement: by the supervisory authority (DPA) in each Member State — CNIL in France, BfDI/Länder DPAs in Germany, AKI in Estonia, the Office of the Data Protection Ombudsman in Finland, Garante in Italy, AEPD in Spain, the Data Protection Commission in Ireland, etc.

What GDPR actually does

GDPR regulates the processing of personal data — meaning anything you do with information that can be linked to an identified or identifiable person: collecting it, storing it, looking at it, sharing it, deleting it, even pseudonymising it. The Regulation sets the baseline rules; sector-specific laws (ePrivacy, AML, employment, health) add layers on top.

Three things it does at the same time:

  1. Imposes obligations on the organisations that decide what to do with personal data (controllers) and on the organisations that handle data on their behalf (processors) — principles of processing, lawful bases, security, accountability, transparency.
  2. Grants enforceable rights to the people the data is about (data subjects) — access, rectification, erasure, restriction, portability, objection, the right not to be subject to fully automated decisions.
  3. Restricts data flows outside the EEA unless the destination country has been granted an “adequacy decision” or the transfer is protected by an instrument like Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs).

GDPR does not replace other EU privacy rules. The ePrivacy Directive (the “cookie law”) still governs cookies, electronic marketing and the confidentiality of communications. The EU AI Act governs how AI systems are built and supervised, while GDPR governs the personal data flowing through those systems — the two regulate the same product from different angles. See our AI Act pillar for the AI side.

What counts as “personal data”

The definition (Article 4(1)) is broader than most non-lawyers expect:

“Personal data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

In practice, this includes everything that can reasonably be tied back to an individual: name, email, phone number, postal address, ID numbers, IP addresses (case law treats them as personal data when the controller has the legal means to identify the user), cookie identifiers, device fingerprints, photos and CCTV footage, biometric data, genetic data, location, health data, behavioural data, advertising IDs, and so on. Pseudonymised data is still personal data under GDPR — only truly anonymised data (irreversibly stripped of any link back to a person) falls out of scope.

A separate, stricter regime applies to special categories of personal data (Article 9) — see below.

Material and territorial scope

GDPR applies only to processing in the course of activities that engage with the EU/EEA market in some way.

Material scope (Article 2)

The Regulation covers the processing of personal data wholly or partly by automated means and the processing other than by automated means of personal data which form part of a filing system (paper records organised in a structured way). It does not apply to:

  • Processing by a natural person in the course of a purely personal or household activity (your contact list, your family photos)
  • Processing for the purposes of the prevention, investigation, detection or prosecution of criminal offences — that’s covered by the Law Enforcement Directive (Directive (EU) 2016/680) instead
  • Processing by EU institutions, bodies, offices and agencies — that’s covered by Regulation (EU) 2018/1725, enforced by the EDPS

Territorial scope (Article 3)

GDPR is extraterritorial. It applies to:

  1. Processing of personal data in the context of the activities of an establishment of a controller or processor in the Union — regardless of whether the processing itself takes place inside or outside the EU. A US-based subsidiary of an EU company, doing processing on a Frankfurt server, is in scope. So is an EU branch of a non-EU company processing on a server in Singapore.
  2. Processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing relates to:
    • The offering of goods or services to those data subjects in the Union (paid or free), or
    • The monitoring of their behaviour as far as their behaviour takes place within the Union.

The second branch is what brings non-EU companies into scope without any physical presence in Europe. A US SaaS company that lets European users sign up and pay in euros is offering services to EU data subjects. An ad-tech company outside the EU that profiles EU users via cookies is monitoring their behaviour. Both must comply.

The seven principles (Article 5)

GDPR is built on seven principles. Every other rule in the Regulation either implements or refines one of these:

PrincipleWhat it means in practice
Lawfulness, fairness, transparencyEvery processing operation needs a lawful basis; people must know what’s being done with their data
Purpose limitationYou collect data for a specific declared purpose; you can’t quietly repurpose it for something incompatible
Data minimisationCollect only what’s adequate, relevant and limited to what’s necessary for the purpose
AccuracyKeep personal data accurate and up to date; correct or delete inaccurate data without delay
Storage limitationKeep personal data in identifiable form only as long as the purpose requires; then anonymise or delete
Integrity and confidentialityProtect personal data with appropriate technical and organisational measures (encryption, access controls, pseudonymisation, etc.)
AccountabilityThe controller must not just comply but be able to demonstrate compliance — through records, policies, DPIAs, training, audits

The accountability principle is the one that produced most of the procedural plumbing in the rest of the Regulation: records of processing (Article 30), DPIAs (Article 35), DPO appointments (Articles 37–39), data protection by design and by default (Article 25). If you’re ever audited, the supervisory authority will ask you to show your records, not just describe your intentions.

The six lawful bases (Article 6)

You cannot process personal data unless at least one of the six lawful bases applies. They are:

BasisArticle 6(1)Typical use
Consent(a)Marketing emails, optional cookies, profiling, voluntary surveys
Contract(b)Performing a contract the data subject is party to (account creation, order fulfilment)
Legal obligation(c)Tax records, AML/KYC checks, employment law records
Vital interests(d)Emergency situations to protect someone’s life
Public task(e)Processing by public authorities or in the exercise of official authority
Legitimate interests(f)Fraud prevention, internal administration, network security — only after a documented balancing test that confirms the controller’s interest does not override the data subject’s rights

A few traps practitioners hit repeatedly:

  • Consent has to meet the GDPR standard: freely given, specific, informed, unambiguous, by clear affirmative action. Pre-ticked boxes don’t count. Consent that bundles many purposes into one click does not count. People must be able to withdraw consent as easily as they gave it.
  • “Legitimate interests” is not a free pass. It requires a documented balancing test. The Irish Data Protection Commission’s €390 million fine on Meta in January 2023 turned on Meta’s attempt to use “contract” (Article 6(1)(b)) — and later “legitimate interests” — as the basis for behavioural advertising on Facebook and Instagram, where the EDPB ruled the only valid basis was consent.
  • Public-sector controllers cannot use “legitimate interests” — Article 6(1)(f) is unavailable to public authorities acting in their public-interest tasks.

Special categories of personal data (Article 9)

A subset of personal data carries higher risk and is prohibited from processing by default, unless one of ten specific exceptions in Article 9(2) applies. The special categories are:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade-union membership
  • Genetic data
  • Biometric data for the purpose of uniquely identifying a natural person (face recognition, fingerprint matching — but ordinary photos are not automatically biometric)
  • Data concerning health
  • Data concerning a person’s sex life or sexual orientation

The most commonly used Article 9(2) gateways are explicit consent ((a)), processing necessary in the field of employment, social security and social protection ((b)), processing for medical and public-health purposes ((h) and (i)), and processing for scientific research ((j)) — each subject to additional safeguards in Member State law.

A separate provision, Article 10, restricts the processing of personal data relating to criminal convictions and offences to either an authority’s official capacity or where authorised by Member State law.

Controller and processor — the two key roles

GDPR distinguishes two regulatory statuses for organisations that handle personal data:

  • Controller (Article 4(7)) — the natural or legal person who determines the purposes and means of the processing. The bank that decides what data to collect from customers and why is the controller. The hospital that runs medical records for its patients is the controller. Generally, the controller is the entity in the customer-facing position.
  • Processor (Article 4(8)) — the natural or legal person who processes personal data on behalf of the controller. The cloud provider that hosts the bank’s customer database is a processor. The payroll company that runs the hospital’s employee records is a processor. The processor acts on documented instructions from the controller.

Two or more controllers can be joint controllers (Article 26) when they jointly determine the purposes and means of processing — frequent in advertising ecosystems and in employer/works-council relationships. The CJEU in Fashion ID (C-40/17, 29 July 2019) held that a website operator who embeds a Facebook “Like” button is a joint controller with Facebook for the data collection that happens through that button.

The split matters because:

  • The controller carries most of the substantive obligations (lawful basis, transparency, data subject rights, breach notification to the DPA, DPIAs).
  • The processor is bound by Article 28 contracts with the controller, must process only on documented instructions, must implement security measures, must assist the controller, and must notify the controller of breaches without undue delay. A processor who oversteps and starts deciding the purposes of processing becomes a controller for that processing and inherits the controller’s obligations.

Data subject rights (Articles 12–22)

People in the EU/EEA have a set of enforceable rights against any organisation processing their personal data. The full list:

RightArticleWhat it does
To information13–14Be told, at the time data is collected, who is processing it, why, on what legal basis, for how long, and what rights you have
To access15Get confirmation that your data is being processed, plus a copy of it and the essential metadata about the processing
To rectification16Have inaccurate data corrected and incomplete data completed
To erasure (“to be forgotten”)17Have your data deleted in defined circumstances (no longer needed, consent withdrawn, unlawful processing, etc.)
To restriction of processing18Block further processing while a dispute is resolved
To data portability20Receive the data you provided to a controller in a structured, commonly used, machine-readable format and transmit it to another controller
To object21Object to processing based on legitimate interests or public task; absolute right to object to direct marketing
Not to be subject to automated decision-making22Avoid being subject to a fully automated decision (including profiling) that produces legal or similarly significant effects, unless one of three exceptions applies

The controller must respond to a request without undue delay and at the latest within one month (Article 12(3)), extendable by two further months for complex cases. Responses are free of charge unless the request is manifestly unfounded or excessive.

A right that is often overlooked: under Article 22, a fully automated decision with legal or similarly significant effects (refusing a loan, declining an insurance claim, denying access to a service) is in principle prohibited unless it is necessary for a contract, authorised by law, or based on explicit consent — and even then, the data subject has the right to obtain human intervention, express their point of view and contest the decision. This provision overlaps materially with the EU AI Act’s rules on high-risk AI systems used for the same kinds of decisions.

Data Protection Officer (DPO) — Articles 37–39

Three categories of organisation are required to designate a DPO:

  1. Public authorities and bodies (other than courts in their judicial capacity).
  2. Controllers or processors whose core activities consist of processing operations that, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale — typical examples: ad-tech, large platforms, telecoms, customer-facing surveillance systems.
  3. Controllers or processors whose core activities consist of processing special categories of data on a large scale — typical examples: hospitals, health-tech, biometric services.

The DPO must have expert knowledge of data-protection law and practice, must be involved in all data-protection issues, must report to the highest level of management, must be granted adequate resources, and cannot be dismissed or penalised for performing the role. The DPO is not personally liable for the organisation’s compliance — that liability sits on the controller — but the DPO’s independence is a structural protection that EU law treats seriously.

A DPO can be an employee or an external contractor. Many groups appoint a single DPO for multiple legal entities, provided the DPO is “easily accessible from each establishment” (Article 37(2)).

Records, DPIAs, breach notification

Three procedural obligations that produce most of the day-to-day documentation in a compliance programme:

Records of processing activities (Article 30)

Every controller (and every processor on the controller’s side) must maintain a written record of the processing activities under its responsibility. The record lists what data is processed, for what purpose, on what legal basis, who it’s shared with, retention periods, and security measures. The exemption for organisations under 250 employees is narrower than it looks — it does not apply if the processing is likely to result in a risk, is not occasional, or includes special categories.

Data Protection Impact Assessment (DPIA) — Article 35

A DPIA is required where processing is likely to result in a high risk to the rights and freedoms of natural persons — in particular for systematic and extensive automated decision-making, large-scale processing of special categories, or large-scale systematic monitoring of public areas. National DPAs publish their own lists of processing operations that always trigger a DPIA. If the DPIA shows residual high risk that the controller cannot mitigate, the controller must consult the DPA before starting (Article 36).

Personal data breach notification — Articles 33–34

Where a personal data breach occurs, the controller must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it (Article 33), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk, the controller must also notify the affected data subjects “without undue delay” (Article 34). Processors must notify their controller without undue delay.

The 72-hour clock is the most operationally pressured deadline in the Regulation. Most major DPAs publish online breach-notification forms; what they expect from the first notification is a description of the breach, the categories and approximate number of data subjects, the likely consequences, and the measures taken or proposed.

International transfers — Chapter V

Personal data may be transferred from the EEA to a third country only on one of the routes set out in Articles 44–49:

1. Adequacy decision (Article 45)

The European Commission has, by formal decision, recognised the third country as providing a level of data protection essentially equivalent to that in the EU. Once an adequacy decision is in force, transfers to that country can flow freely without further authorisation. As of 2026, the Commission has issued adequacy decisions covering:

  • United Kingdom (28 June 2021; renewed December 2025) — covers both GDPR and the Law Enforcement Directive
  • United States — under the EU–US Data Privacy Framework (10 July 2023), for commercial entities self-certified to the framework
  • Republic of Korea (17 December 2021)
  • Japan (2019), Canada (2002, commercial organisations only), Israel (2011), New Zealand (2013), Argentina (2003), Uruguay (2012), Switzerland (2000), Andorra (2010), Faroe Islands (2010), Guernsey (2003), Isle of Man (2004), Jersey (2008)
  • Brazil (26 January 2026 — most recent addition)
  • European Patent Organisation (15 July 2025) — for the international organisation rather than a country

2. Appropriate safeguards (Article 46)

Where there is no adequacy decision, the transfer is permitted if the exporter has put appropriate safeguards in place. The two most-used safeguards in practice:

  • Standard Contractual Clauses (SCCs) — model contractual terms approved by the Commission. The current SCCs are set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, entered into force on 27 June 2021 and used by the vast majority of EEA-to-third-country transfers today. They are modular, covering controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers.
  • Binding Corporate Rules (BCRs) — internal codes of conduct for intra-group transfers within multinational organisations, approved by a lead DPA after a long, detailed approval process. Used by groups like Airbus, IBM, Salesforce.

3. Derogations (Article 49)

A short, narrowly-drafted list of exceptions for non-routine transfers: explicit consent of the data subject, contract performance with the data subject, important reasons of public interest, legal claims, vital interests. These cannot be used as a workaround for routine business transfers — they are reserved for genuinely occasional, non-systematic situations.

Schrems II and what changed

The Court of Justice of the European Union in Data Protection Commissioner v. Facebook Ireland Ltd and Maximilian Schrems (C-311/18), judgment of 16 July 2020 invalidated the prior EU–US Privacy Shield because US surveillance law (FISA Section 702, EO 12333) provided neither the substantive limitations nor the actionable redress mechanisms required by EU fundamental-rights standards. The same judgment upheld the validity of SCCs in principle but ruled that the data exporter and the data importer must, before transferring, assess on a case-by-case basis whether the law of the third country provides the level of protection required by EU law, and if not, put supplementary measures in place (encryption, pseudonymisation, contractual additions) — or stop the transfer.

This case-by-case assessment is now embedded in the SCCs themselves and in the EDPB Recommendations 01/2020 on supplementary measures. Three years later, the Commission’s EU–US Data Privacy Framework (10 July 2023) re-established a no-questions-asked transfer route to certified US companies — but the framework relies on the President’s Executive Order 14086 of 7 October 2022 and remains exposed to a Schrems III challenge that is widely expected.

Governance: who supervises and who enforces

GDPR uses a three-level governance model.

EU level

  • European Data Protection Board (EDPB) — independent body composed of the heads of every national supervisory authority (one per Member State) plus the EDPS. The EDPB issues guidelines that harmonise the interpretation of GDPR across the EU, resolves cross-border disputes between national DPAs through binding decisions under Article 65, and approves codes of conduct, certification schemes and BCR applications. Chair: Anu Talus (Finland, Office of the Data Protection Ombudsman). Deputy Chairs: Jelena Virant Burnik (Slovenia, Information Commissioner — elected at the December 2025 plenary, replacing Irene Loizidou Nikolaidou) and Zdravko Vukić (Croatia).
  • European Data Protection Supervisor (EDPS) — independent EU institution that supervises the processing of personal data by EU institutions, bodies, offices and agencies under Regulation (EU) 2018/1725. The EDPS sits as an additional member of the EDPB. Current Supervisor: Wojciech Wiewiórowski (took office 6 December 2019 for the 2019–2024 term; remains in post on an interim basis as of June 2026, pending appointment of a successor).

National level

Each Member State has at least one independent supervisory authority (DPA) that handles complaints, conducts investigations, issues fines, and authorises certain processing operations. The most-cited DPAs in cross-border cases:

  • 🇮🇪 Ireland — Data Protection Commission (DPC) — lead supervisor for most US tech companies established in Ireland (Meta, Google, TikTok, Microsoft, X). Has issued the largest GDPR fines on record.
  • 🇫🇷 France — CNIL — one of the oldest data protection authorities in the world (created by the Loi Informatique et Libertés of 6 January 1978) and among the most active EU enforcers, especially on ad-tech, cookies and consent-banner compliance.
  • 🇩🇪 Germany — federal-level BfDI plus 17 Länder DPAs (one per federal state, plus separate ones for the public and private sectors in some Länder). Most cross-border cases are split between Hamburg, Berlin, Bavaria and Rhineland-Palatinate.
  • 🇮🇹 Italy — Garante per la protezione dei dati personali — most active in AI-related enforcement (OpenAI, Replika).
  • 🇪🇸 Spain — AEPD — issues by far the highest number of fines per year, but typically smaller individual amounts.
  • 🇪🇪 Estonia — Andmekaitse Inspektsioon (AKI) — see our profile of AKI.
  • 🇫🇮 Finland — Office of the Data Protection Ombudsman (Tietosuojavaltuutettu) — currently led by Anu Talus, who is also EDPB Chair.

One-stop-shop and the lead supervisory authority

For cross-border processing — processing that takes place in more than one Member State, or that substantially affects data subjects in more than one Member State — Article 56 designates a lead supervisory authority (the DPA of the controller’s main EU establishment) to take primary responsibility for the case. Other concerned DPAs participate, can object, and can trigger an EDPB Article 65 decision if they cannot agree.

The mechanism has two consequences in practice:

  1. Cross-border tech investigations channel through Ireland (where most US tech HQs sit) and Luxembourg (Amazon), even when most affected data subjects live elsewhere. This has caused recurrent friction between the DPC and other national DPAs.
  2. EDPB Article 65 binding decisions have become the actual decisive event in several of the largest cases — the Meta €1.2 billion transfer fine and the 2023 TikTok €345 million children’s-data fine were both shaped by binding EDPB decisions after the DPC’s draft decision was disputed by other DPAs. By contrast, the later TikTok €530 million transfer fine (May 2025) was a clean DPC one-stop-shop decision: no objections were raised by other DPAs and it did not go to Article 65 dispute resolution — a reminder that the lead-authority model still produces most outcomes without an EDPB override.

Penalties (Article 83)

Administrative fines under GDPR are graduated between two tiers. The structure:

TierArticleTypical breachesMaximum fine
Lower83(4)Articles 8, 11, 25–39, 42, 43 — controller/processor obligations, DPO, records, security, certification body obligations€10,000,000 or 2% of total worldwide annual turnover, whichever is higher
Higher83(5)Articles 5, 6, 7, 9 (basic principles, lawful bases, conditions for consent, special categories), 12–22 (data subject rights), 44–49 (international transfers)€20,000,000 or 4% of total worldwide annual turnover, whichever is higher
Higher83(6)Non-compliance with an order from a supervisory authority (e.g., refusing to halt processing as ordered)€20,000,000 or 4% of total worldwide annual turnover, whichever is higher

Article 83(2) lists the factors the supervisory authority must weigh in setting the actual fine: nature, gravity and duration of the infringement; intentional vs negligent character; previous infringements; cooperation with the authority; categories of personal data affected; the manner the breach was discovered; etc. Member States may set additional national rules on the criminal sanctions for certain infringements (Article 84) on top of the administrative fines.

In practice the supervisory authority will calculate the fine using the EDPB Guidelines 04/2022 on the calculation of administrative fines, which provides a structured methodology adopted by every DPA.

Notable enforcement

The biggest GDPR fines on record (verified via enforcementtracker.com, CMS Law’s editorially-curated registry):

YearCompanyFineDPACause
2023Meta Platforms Ireland€1.2 billion (12 May 2023)DPC IrelandContinuing US transfers of EU user data after Schrems II without an adequate basis
2025TikTok Technology€530 million (2 May 2025)DPC IrelandTransfers of EEA user data to China without an adequate basis
2022Meta Platforms (Instagram)€405 million (2 September 2022)DPC IrelandChildren’s data — public exposure of teenage users’ contact details by default
2023Meta Platforms€390 million (4 January 2023)DPC IrelandReliance on “contract” as the legal basis for behavioural advertising on Facebook and Instagram
2023TikTok€345 million (1 September 2023)DPC IrelandChildren’s data — default settings, profile visibility, parental controls

A separate, very visible case — the €746 million fine issued by Luxembourg’s CNPD against Amazon Europe Core on 15 July 2021 over targeted advertising consent — has had a remarkable appellate history. The Luxembourg Administrative Tribunal upheld it on 18 March 2025; the Luxembourg Administrative Court (the higher court) annulled the decision on 12 March 2026 and sent the case back to the CNPD for fresh analysis on the criteria of fault and intentional violation. As of May 2026 the case is pending reconsideration.

Below the headline figures sit thousands of smaller enforcement actions: Spain’s AEPD has led the EU on the number of fines for six consecutive years (per CMS GDPR Enforcement Tracker, 2024/2025 report), followed by Italy and Romania. Most are in the four- to six-figure range, often for cookie-banner non-compliance, weak security or breach-notification failures.

How GDPR overlaps with other EU regimes

  • ePrivacy Directive (2002/58/EC, as amended) — the “cookie law”. Governs the storage of and access to information on a user’s device (cookies, local storage, fingerprinting) and the confidentiality of electronic communications. Applies on top of GDPR; consent for non-essential cookies is governed by ePrivacy first, GDPR second. The long-promised ePrivacy Regulation has not been adopted.
  • EU AI Act (Regulation 2024/1689) — applies in parallel. The AI Act regulates the AI system itself (risk classification, technical documentation, conformity assessment, market surveillance); GDPR continues to apply to the personal data flowing through the system. See our AI Act pillar.
  • MiCA (Regulation 2023/1114) — CASPs hold KYC and transaction data. GDPR applies to that data on top of MiCA. See our MiCA pillar.
  • DORA (Regulation 2022/2554) — operational resilience for financial entities, including incident notification regimes that overlap operationally with GDPR’s Article 33 breach-notification regime. See our DORA pillar.
  • NIS 2 Directive (Directive (EU) 2022/2555) — cybersecurity obligations for “essential” and “important” entities. Article 33 GDPR breach notification and NIS 2 incident notification are separate but commonly trigger together.
  • Digital Services Act (Regulation (EU) 2022/2065) and Digital Markets Act (Regulation (EU) 2022/1925) — content moderation and platform-competition obligations on very large online platforms; both refer back to GDPR for personal-data aspects.

What this means for you

If you’re a controller (you decide what to do with personal data — most companies are controllers for their customer and employee data):

  • Build a record of processing activities (Article 30) before you do anything else. Without it, you cannot answer a DPA’s first question.
  • For each processing operation: identify the lawful basis (Article 6), check whether special categories (Article 9) are involved, document the retention period, and write a privacy notice that gives the Article 13/14 information to data subjects in a clear, concise form.
  • Set up a process for handling data subject requests (Articles 15–22) within one month, with internal escalation and a tracker that survives staff turnover.
  • For high-risk processing, run a DPIA (Article 35) before the processing starts. Don’t retro-fit it after a complaint.
  • Set up breach detection and notification infrastructure — the 72-hour clock starts from awareness of the breach, not from internal escalation.
  • For transfers outside the EEA, check the adequacy decision map; otherwise put SCCs (or BCRs) in place and run the Schrems II transfer impact assessment.

If you’re a processor (you handle personal data on a controller’s instructions — typical for SaaS, cloud hosts, payroll providers, marketing-automation tools):

  • Every relationship with a controller needs an Article 28 contract (sometimes called a “DPA” — data-processing agreement). The contract must include Article 28(3) mandatory clauses — purposes, duration, types of data, data-subject categories, controller’s instructions, processor obligations, sub-processor rules, security measures.
  • You may only act on documented instructions from the controller. Going beyond instructions makes you a controller for that processing.
  • You must assist the controller in responding to data subject requests, breach notification, DPIAs, prior consultation. Build the operational playbooks.
  • Sub-processors require either specific or general written authorisation; either way, your contract with the sub-processor must impose the same data-protection obligations.

If you’re a data subject (everyone is):

  • Your rights are listed in Articles 15–22; you exercise them by writing to the controller (most have a privacy email or web form).
  • If you don’t get a response within one month, or you’re not satisfied with the response, you can complain to your national DPA — the EDPB list of DPA contacts is the authoritative directory.
  • For cross-border issues, you can complain to the DPA of your habitual residence, your place of work, or the place of the alleged infringement; the lead supervisory authority is then identified and the case is routed to it.

TL;DR

GDPR is the EU’s general law on the processing of personal data, applied since 25 May 2018 across all 27 Member States plus the three EEA states. It is extraterritorial: any non-EU organisation that offers goods or services to people in the EU, or that monitors their behaviour, is in scope. Seven principles, six lawful bases (with stricter rules for special categories under Article 9), eight enforceable rights for data subjects (Articles 15–22), and procedural plumbing — records of processing, DPIAs, breach notification within 72 hours — make up the day-to-day compliance work. Cross-border data transfers go through adequacy decisions (UK, US-DPF, Korea, Japan, Canada commercial, Switzerland and others), Standard Contractual Clauses (Commission Decision 2021/914), or Binding Corporate Rules; Schrems II invalidated the prior US Privacy Shield in 2020 and forced exporters to do a transfer-impact assessment. Enforcement is by national DPAs coordinated by the EDPB (Chair: Anu Talus, Finland) and, for EU institutions, by the EDPS (Wojciech Wiewiórowski). Penalties tier at €10M or 2% worldwide turnover for procedural failures and €20M or 4% worldwide turnover for the most serious breaches; the largest fine on record is €1.2 billion against Meta in 2023 over EU–US transfers.

Sources

EU 2016/679

Regulators

National authorities responsible for enforcement

Estonia

Who is AKI: Estonia's data protection authority

AKI is Andmekaitse Inspektsioon, Estonia's GDPR supervisory authority. What it does, who runs it, how to file a complaint, and how it went from issuing €280 fines to a €3,000,000 fine in 2025.

EU-wide

Who is the EDPB: the EU's data protection coordinator

The European Data Protection Board is the EU-wide body that coordinates national data-protection regulators (DPAs) and resolves cross-border GDPR disputes. What it does, how the one-stop-shop mechanism works, who leads it, and what binding decisions look like.

EU-wide

Who is the EDPS: the EU institutions' own data protection supervisor

The European Data Protection Supervisor (EDPS) is the independent authority that watches how the EU's own institutions — the Commission, Parliament, Council, Europol and the rest — handle personal data. What it does, how it differs from the EDPB it is constantly confused with, and who runs it. Every fact sourced.

Finland

Who is Tietosuojavaltuutettu: Finland's Data Protection Ombudsman

Tietosuojavaltuutetun toimisto is Finland's GDPR supervisory authority — one of the oldest in Europe (1987). What it does, how the collegial Sanctions Board works, why its head also chairs the EU's data-protection board (EDPB), and the €2.4M Posti fine that the Helsinki Administrative Court later annulled.

France

Who is the CNIL: France's data protection authority, created decades before the GDPR

The CNIL is France's GDPR supervisory authority — born from the 1974 SAFARI scandal and created by the 1978 Loi Informatique et Libertés, decades before the GDPR. This guide covers what it does, its 18-member college and sanctions chamber, the landmark fines from Google's first €50M to a record €325M, who runs it, and its 2024 figures — every fact sourced.

Germany

Who is the BfDI: Germany's federal data protection commissioner

The BfDI is Germany's federal data-protection regulator — but it supervises only federal bodies and the telecom and postal sector. The rest is handled by 16 state authorities. What the BfDI does, how Germany's two-tier system works, and who runs it. Every fact sourced.

Ireland

Who is the DPC: Ireland's data regulator that polices most of Big Tech

The Data Protection Commission is Ireland's GDPR supervisory authority — and, because Meta, Google, Apple, TikTok, X and LinkedIn run their EU operations from Ireland, the lead regulator for most of Big Tech across the whole EU under the one-stop-shop. What it does, why one national authority carries EU-wide weight, and who runs it after the move from one Commissioner to a three-person Commission — every fact sourced.

Italy

Who is the Garante: Italy's data protection authority that took on ChatGPT

The Garante per la protezione dei dati personali is Italy's GDPR supervisory authority — and the regulator that made global headlines by temporarily blocking ChatGPT. What it does, how its four-member Collegio is structured, why the first big AI fines in Europe are Italian, and who runs it after the January 2026 mandate change — every fact sourced.

Luxembourg

Who is the CNPD: Luxembourg's data regulator behind the €746M Amazon fine

The CNPD is Luxembourg's GDPR supervisory authority — a small national regulator that issued the second-largest GDPR fine in history, €746 million against Amazon, because so many global companies base their EU operations in the Grand Duchy. What it is, how its collège is composed after the 2025 change, and why a tiny country's regulator carries outsized weight. Every fact sourced.

Netherlands

Who is the AP: the Netherlands' data protection authority and algorithm watchdog

The Autoriteit Persoonsgegevens is the Netherlands' GDPR supervisory authority — the regulator that fined Uber €290 million and Clearview AI €30.5 million, and, unusually, also the country's coordinating supervisor for algorithms and AI. What it does, how it is run, and who chairs it through the 2026 leadership change — every fact sourced.

Poland

Who is the UODO: Poland's data regulator and one of the EU's busiest enforcers

The UODO is Poland's GDPR supervisory authority — the Personal Data Protection Office created in 2018 to replace the old GIODO inspectorate, and one of the most active fining regulators in the EU. What it does, who leads it after the 2024 change at the top, and the security-failure cases (Morele.net, Virgin Mobile) that define its enforcement. Every fact sourced.

Romania

Who is the ANSPDCP: Romania's data regulator that fines often but small

The ANSPDCP is Romania's GDPR supervisory authority — one of the top three EU countries by number of fines, yet with some of the smallest amounts. What it is, who leads it, and the security-breach cases (Raiffeisen, UniCredit, and the famous hotel breakfast-list fine) that define a high-volume, low-value enforcement style. Every fact sourced.

Spain

Who is the AEPD: Spain's data protection authority — the EU's busiest fining regulator

The Agencia Española de Protección de Datos is Spain's GDPR supervisory authority — and, by number of fines, the most prolific data-protection enforcer in the EU. What it does, why it is not the same body as Spain's AI authority AESIA, the 2025 leadership change under a new selection model, and who runs it — every fact sourced.

Sweden

Who is the IMY: Sweden's data protection authority, heir to the world's first privacy law

IMY (Integritetsskyddsmyndigheten) is Sweden's GDPR supervisory authority — the modern name of Datainspektionen, founded in 1973 to enforce what is widely regarded as the world's first national data protection law. This guide covers what it does, the mandate that runs beyond the GDPR, who runs it after the 2024 leadership change, and the Google, Spotify and Klarna fines — every fact sourced.

Fine registries

Real cases, amounts, articles violated, court status

Jun 2026

Big Tech GDPR fines: the largest data-protection penalties in EU history

A registry of the biggest GDPR fines ever issued — Meta €1.2 billion, Amazon €746 million, TikTok €530 million, Uber €290 million and more. Who was fined, how much, for what, why almost all of them come out of Ireland, and which ones courts have already overturned — every amount sourced to the regulator or the binding EU decision behind it.

Spain Jun 2026

AEPD fines: inside the EU's busiest data-protection enforcer

A registry of the largest fines from Spain's AEPD — Google €10M, Vodafone €8.15M, CaixaBank €6M, BBVA €5M and more — and why Spain matters less for the size of any single fine than for sheer volume: it issues a larger share of the EU's GDPR fines than any other country. Who was fined, for what, and why banks and telcos dominate the list. Every amount sourced.

France Jun 2026

CNIL fines: the EU's cookie-enforcement powerhouse, case by case

A registry of the biggest fines issued by France's CNIL — Google €150M and €100M, Facebook €60M, Microsoft €60M, Orange €50M, Criteo €40M and more. Why most of them are about cookies rather than the GDPR, why the CNIL can fine Big Tech directly when Ireland normally would, and which fines France's top court has upheld — every amount sourced to the regulator.

Ireland Jun 2026

DPC fines: Europe's most powerful — and most criticised — data regulator

A registry of fines from Ireland's DPC — the lead regulator for most of Big Tech, which imposed over €652 million in a single year, yet is accused of going easy on the platforms and being forced higher by the EU. The Big Tech mega-fines, the modest domestic Irish cases (Tusla, Bank of Ireland), and the bottleneck criticism — every fact sourced.

Italy Jun 2026

Garante fines: Italy's war on telemarketing — and on management by algorithm

A registry of the largest GDPR fines from Italy's Garante — Enel Energia €79.1M and €26.5M, TIM €27.8M, Wind Tre €16.7M, Vodafone €12.25M — plus the pioneering gig-economy cases against Foodinho and Deliveroo. Why Italy's enforcement is dominated by unsolicited marketing calls and worker-management algorithms, and what each company did. Every amount sourced to the regulator.

Italy May 2026

Garante AI fines: Italy's GDPR enforcement against generative AI

A registry of the Italian data protection authority's enforcement against generative-AI services: €15M on OpenAI for ChatGPT (later annulled by a Rome court) and €5M on Luka for Replika. What was violated, the exact articles, and the fate of each decision — every fact sourced to the regulator, the court record and editorial press.

May 2026

Clearview AI fines: how four EU regulators hit one US facial-recognition firm

A registry of the GDPR fines imposed on Clearview AI by EU data protection authorities — Italy, Greece, France and the Netherlands — for scraping billions of faces without a legal basis. The exact amounts, articles and orders, why the company has paid none of them, and how the UK route diverged. Every fact sourced to the regulator.

Estonia May 2026

AKI fines: every known enforcement case of Estonia's Data Protection Inspectorate

A complete public registry of fines issued by the Estonian Data Protection Inspectorate — from token misdemeanour fines of a few dozen euros on individuals up to €3 million against the Apotheka pharmacy chain. What was violated, which decisions were overturned in court, and why Estonia is the EU's most lenient GDPR jurisdiction — and is right now ceasing to be one.