If you manage data protection, 2026 arrives with a lot of noise about the General Data Protection Regulation being "reformed" or "watered down." The reality is more precise: the GDPR that binds you today is the same text as last year, while a separate simplification proposal is still working its way through Brussels and has not become law.
A quick refresher on what GDPR requires
The GDPR (Regulation (EU) 2016/679) has applied directly across the EU since 25 May 2018. It rests on the processing principles in Article 5: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability, which requires you to be able to demonstrate compliance, not merely assert it.
Every act of processing needs a lawful basis under Article 6. There are six, and none ranks above the others: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, a task carried out in the public interest, and legitimate interests. Special-category data (health, biometrics, political opinions and so on) carries a higher bar under Article 9.
The regulation also gives individuals a set of enforceable rights. In summary:
| Right | GDPR article | What it means in practice |
|---|---|---|
| Information | Arts 13-14 | Be told who processes your data, why and on what basis |
| Access | Art 15 | Obtain a copy of your data and the processing details |
| Rectification | Art 16 | Have inaccurate or incomplete data corrected |
| Erasure ("right to be forgotten") | Art 17 | Have data deleted where grounds apply |
| Restriction | Art 18 | Freeze processing while a dispute is resolved |
| Portability | Art 20 | Receive your data in a machine-readable format |
| Object | Art 21 | Object to processing, including direct marketing |
| Automated decisions | Art 22 | Not be subject to solely automated decisions with significant effects |
Two operational duties sit alongside the rights. Personal-data breaches must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours (Article 33). And enforcement carries real weight: fines run to two tiers under Article 83, up to 10 million euros or 2 percent of total worldwide annual turnover for the lower tier, and up to 20 million euros or 4 percent of turnover for the higher tier, whichever figure is greater in each case.
None of the above has changed in 2026. If you take one thing from this article, take that.
What is genuinely new in 2025 and 2026: the Digital Omnibus
The source of the "GDPR is changing" headlines is the Digital Omnibus, a simplification package the European Commission presented on 19 November 2025. It is a competitiveness-driven effort to streamline several digital laws at once, and it does propose amendments that touch the GDPR. The critical point for compliance planning is status: the GDPR-related parts sit in the so-called Data Omnibus, which remains a proposal under negotiation between the Parliament and Council. It is not law, and nothing in it applies today.
Timelines are still soft. Most observers do not expect the Data Omnibus to be adopted before late 2026 at the earliest, with entry into force more realistically in the 2027 to 2028 window, and only after that will any transition periods start to run. A related but separate strand, the AI Omnibus, moved faster and was adopted by the Council in mid-2026, which is why AI Act deadlines have shifted. The GDPR changes have not followed on the same schedule.
What is actually on the table, and where it stands:
| Proposed change | Effect | Status |
|---|---|---|
| Simplified records of processing (ROPA) | Relief for organisations under 250 employees, unless processing is high-risk | Proposed, not in force |
| Cookie and consent rules | Move consent from the ePrivacy Directive into the GDPR; one-click consent valid for six months; browser-level machine-readable signals; wider exemptions | Proposed, not in force |
| Narrower "personal data" definition | Clarify when pseudonymised data falls outside the GDPR for a given controller | Proposed; strongly opposed by the EDPB and EDPS |
| AI processing bases | Clearer legitimate-interest footing for training AI on personal data; explicit basis for processing special-category data to detect and correct bias | Proposed, not in force |
| Breach notification | Extend and centralise the reporting workflow, easing the current 72-hour pressure | Proposed, not in force |
Two of these deserve a caution. The narrowing of the personal-data definition around pseudonymisation has drawn the sharpest objection from the European Data Protection Board and the European Data Protection Supervisor, who warn against treating pseudonymisation as a switch that turns the GDPR off. It is among the least likely elements to survive negotiation unchanged. The consent and cookie reforms are popular with businesses but technically ambitious, since a genuine browser-level signal depends on browsers, operating systems and app stores actually implementing it. Treat both as directional signals, not settled rules.
Enforcement trends
While the reform debate continues, enforcement has not paused. Cumulative GDPR fines since 2018 now exceed 7.1 billion euros, with roughly 1.2 billion euros issued in 2025 alone, so the pace is rising rather than cooling ahead of any simplification.
The headline cases show where regulators are looking. In May 2025 the Irish Data Protection Commission fined TikTok 530 million euros over unlawful EU-to-China data transfers, and in September 2025 the French CNIL issued a combined 325 million euros against Google. International transfers, and the transparency of consent flows, remain reliable triggers for large penalties.
The structural shift is toward transparency and algorithmic processing. In March 2026 the EDPB launched the fifth edition of its Coordinated Enforcement Framework, this time targeting the transparency and information duties under Articles 12 to 14, with national authorities running parallel investigations. The previous year's framework had already pointed at AI systems used in hiring, credit and insurance. The through-line is clear: regulators are scrutinising how organisations explain their processing and how they deploy automated decision-making, not just whether a privacy policy exists.
What to actually do
The practical posture for 2026 is steadiness, not disruption. Concretely:
Keep complying with the GDPR as written. The obligations, rights and fine exposure are unchanged, so a "wait for the reform" strategy simply accumulates risk. Nothing in the proposal reduces your duties today.
Do not dismantle controls in anticipation. It is tempting to scale back records of processing or consent banners because relief is proposed, but the proposal can change substantially in negotiation and may not take effect for years. Removing a control now to match a rule that does not yet exist is the wrong trade.
Prioritise transparency and consent hygiene. Given the EDPB's Article 12 to 14 focus, review your privacy notices, consent capture and the clarity of any automated decision-making disclosures. This is where coordinated enforcement is actively looking.
Map your AI and transfer exposure. The largest recent fines involved international transfers and, increasingly, algorithmic processing. Confirm your transfer mechanisms and document the lawful basis for any AI that touches personal data.
Track the Data Omnibus as a live file. Assign someone to watch its progress so that if and when it is adopted, you can act on real transition dates rather than on headlines. Re-baseline only against enacted text.