GDPR in 2026: What's Changing and What Isn't

Add as a preferred source on Google

If you manage data protection, 2026 arrives with a lot of noise about the General Data Protection Regulation being "reformed" or "watered down." The reality is more precise: the GDPR that binds you today is the same text as last year, while a separate simplification proposal is still working its way through Brussels and has not become law.

A quick refresher on what GDPR requires

The GDPR (Regulation (EU) 2016/679) has applied directly across the EU since 25 May 2018. It rests on the processing principles in Article 5: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability, which requires you to be able to demonstrate compliance, not merely assert it.

Every act of processing needs a lawful basis under Article 6. There are six, and none ranks above the others: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, a task carried out in the public interest, and legitimate interests. Special-category data (health, biometrics, political opinions and so on) carries a higher bar under Article 9.

The regulation also gives individuals a set of enforceable rights. In summary:

Right GDPR article What it means in practice
Information Arts 13-14 Be told who processes your data, why and on what basis
Access Art 15 Obtain a copy of your data and the processing details
Rectification Art 16 Have inaccurate or incomplete data corrected
Erasure ("right to be forgotten") Art 17 Have data deleted where grounds apply
Restriction Art 18 Freeze processing while a dispute is resolved
Portability Art 20 Receive your data in a machine-readable format
Object Art 21 Object to processing, including direct marketing
Automated decisions Art 22 Not be subject to solely automated decisions with significant effects

Two operational duties sit alongside the rights. Personal-data breaches must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours (Article 33). And enforcement carries real weight: fines run to two tiers under Article 83, up to 10 million euros or 2 percent of total worldwide annual turnover for the lower tier, and up to 20 million euros or 4 percent of turnover for the higher tier, whichever figure is greater in each case.

None of the above has changed in 2026. If you take one thing from this article, take that.

What is genuinely new in 2025 and 2026: the Digital Omnibus

The source of the "GDPR is changing" headlines is the Digital Omnibus, a simplification package the European Commission presented on 19 November 2025. It is a competitiveness-driven effort to streamline several digital laws at once, and it does propose amendments that touch the GDPR. The critical point for compliance planning is status: the GDPR-related parts sit in the so-called Data Omnibus, which remains a proposal under negotiation between the Parliament and Council. It is not law, and nothing in it applies today.

Timelines are still soft. Most observers do not expect the Data Omnibus to be adopted before late 2026 at the earliest, with entry into force more realistically in the 2027 to 2028 window, and only after that will any transition periods start to run. A related but separate strand, the AI Omnibus, moved faster and was adopted by the Council in mid-2026, which is why AI Act deadlines have shifted. The GDPR changes have not followed on the same schedule.

What is actually on the table, and where it stands:

Proposed change Effect Status
Simplified records of processing (ROPA) Relief for organisations under 250 employees, unless processing is high-risk Proposed, not in force
Cookie and consent rules Move consent from the ePrivacy Directive into the GDPR; one-click consent valid for six months; browser-level machine-readable signals; wider exemptions Proposed, not in force
Narrower "personal data" definition Clarify when pseudonymised data falls outside the GDPR for a given controller Proposed; strongly opposed by the EDPB and EDPS
AI processing bases Clearer legitimate-interest footing for training AI on personal data; explicit basis for processing special-category data to detect and correct bias Proposed, not in force
Breach notification Extend and centralise the reporting workflow, easing the current 72-hour pressure Proposed, not in force

Two of these deserve a caution. The narrowing of the personal-data definition around pseudonymisation has drawn the sharpest objection from the European Data Protection Board and the European Data Protection Supervisor, who warn against treating pseudonymisation as a switch that turns the GDPR off. It is among the least likely elements to survive negotiation unchanged. The consent and cookie reforms are popular with businesses but technically ambitious, since a genuine browser-level signal depends on browsers, operating systems and app stores actually implementing it. Treat both as directional signals, not settled rules.

While the reform debate continues, enforcement has not paused. Cumulative GDPR fines since 2018 now exceed 7.1 billion euros, with roughly 1.2 billion euros issued in 2025 alone, so the pace is rising rather than cooling ahead of any simplification.

The headline cases show where regulators are looking. In May 2025 the Irish Data Protection Commission fined TikTok 530 million euros over unlawful EU-to-China data transfers, and in September 2025 the French CNIL issued a combined 325 million euros against Google. International transfers, and the transparency of consent flows, remain reliable triggers for large penalties.

The structural shift is toward transparency and algorithmic processing. In March 2026 the EDPB launched the fifth edition of its Coordinated Enforcement Framework, this time targeting the transparency and information duties under Articles 12 to 14, with national authorities running parallel investigations. The previous year's framework had already pointed at AI systems used in hiring, credit and insurance. The through-line is clear: regulators are scrutinising how organisations explain their processing and how they deploy automated decision-making, not just whether a privacy policy exists.

What to actually do

The practical posture for 2026 is steadiness, not disruption. Concretely:

Keep complying with the GDPR as written. The obligations, rights and fine exposure are unchanged, so a "wait for the reform" strategy simply accumulates risk. Nothing in the proposal reduces your duties today.

Do not dismantle controls in anticipation. It is tempting to scale back records of processing or consent banners because relief is proposed, but the proposal can change substantially in negotiation and may not take effect for years. Removing a control now to match a rule that does not yet exist is the wrong trade.

Prioritise transparency and consent hygiene. Given the EDPB's Article 12 to 14 focus, review your privacy notices, consent capture and the clarity of any automated decision-making disclosures. This is where coordinated enforcement is actively looking.

Map your AI and transfer exposure. The largest recent fines involved international transfers and, increasingly, algorithmic processing. Confirm your transfer mechanisms and document the lawful basis for any AI that touches personal data.

Track the Data Omnibus as a live file. Assign someone to watch its progress so that if and when it is adopted, you can act on real transition dates rather than on headlines. Re-baseline only against enacted text.

This article is general information, not legal advice. Always verify against the official text on EUR-Lex.