DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Special · In force · Opt-in · Non-UN jurisdiction

🇪🇺 European Union Data Privacy Laws

The GDPR is the world's reference privacy law: one regulation binding 27 member states plus the EEA, exported globally through adequacy, contract clauses and imitation. For advertisers the operative pair is GDPR plus the ePrivacy Directive, which together make consent the price of tracking in Europe.

Updated September 28, 2026 · digitalprivacyregs.com
Listing
Supranational bloc (27 member states) · listed alongside the 193 UN member states
Status
In force
Consent model
Opt-in
Primary law
GDPR + ePrivacy Directive
Year
2018
Authority
EDPB coordination + national DPAs; European Commission for adequacy
Marketing consent
A lawful basis under Article 6 for all processing; freely given, specific, informed, unambiguous consent for cookies, tracking and most adtech via the ePrivacy Directive.
Transfers
Chapter V: adequacy decisions, SCCs, BCRs, derogations; the EU-US Data Privacy Framework covers certified US companies.
Penalties
Up to EUR 20M or 4% of global annual turnover, whichever is higher.

The framework

The GDPR took effect 25 May 2018 and applies to anyone processing the personal data of people in the EU in connection with offering them goods or services or monitoring their behavior, wherever the controller or processor is established. Six legal bases exist; for advertising, the CJEU and EDPB have progressively narrowed the field so that behavioral advertising effectively requires consent, a line cemented by the Meta cases and the EDPB's 2024 opinion on consent-or-pay models, which found that large platforms usually cannot offer only a binary choice between tracking and payment.

The ePrivacy Directive (2002, amended 2009) supplies the cookie rule: storing or reading anything on a user's device requires prior informed consent unless strictly necessary. The Commission moved to withdraw the planned ePrivacy Regulation in February 2025 after a decade of deadlock, which leaves 27 national implementations and national regulators (the CNIL above all) enforcing cookies outside the GDPR's one-stop-shop.

The live story in 2026 is the Digital Omnibus. Proposed in November 2025, it splits into an AI package (adopted by the Council in June 2026, delaying and adjusting parts of the AI Act) and a data package that would amend the GDPR and ePrivacy rules: moving cookie consent into the GDPR with new exceptions, machine-readable consent signals that browsers must honor, a single breach-reporting entry point, a narrowed personal-data definition, and relief for smaller companies. The data half remains in negotiation; the Council's June 2026 text dropped some of the boldest ideas (a single-click reject duty and a consent-banner moratorium), the EDPB and EDPS backed simplification while raising key concerns about lost protection, and adoption is not expected before late 2026 at the earliest. Plan against current law until the text is final.

Enforcement is mature and expensive. Cumulative GDPR fines reached EUR 7.1B by January 2026, according to DLA Piper's annual survey, led by Meta's EUR 1.2B transfer decision, Amazon's EUR 746M and TikTok's EUR 530M China-transfer fine, and 2026 added the Irish DPC's EUR 403M fine on Google over location data. In September 2026 the EDPB put out for consultation a common five-step method for deciding whether to fine at all, and its coordinated enforcement actions sweep a chosen topic across dozens of authorities each year.

Key instruments

General Data Protection Regulation (2016/679)

2016 · In force since 25 May 2018

The comprehensive framework: legal bases, special categories, data subject rights, controller and processor duties, DPOs, breach notification, transfers, fines to 4% of global turnover.

Official source →

ePrivacy Directive (2002/58/EC)

2002 · In force via national implementations; replacement regulation withdrawn Feb 2025

Confidentiality of communications, the cookie consent rule, and electronic marketing consent (opt-in with a soft opt-in for existing customers), enforced nationally outside the one-stop-shop.

Official source →

Digital Omnibus (data package)

2025 · Proposed Nov 2025; under negotiation, adoption not before late 2026

Would amend GDPR and ePrivacy: cookie rules folded into the GDPR with new exceptions, machine-readable consent signals, single breach entry point, narrowed personal-data definition, SME relief. Contested by the EDPB and EDPS.

Official source →

Marketing and advertising

A lawful basis under Article 6 for all processing; freely given, specific, informed, unambiguous consent for cookies, tracking and most adtech via the ePrivacy Directive. Most channel decisions here follow from that consent rule.

The planning rule for EU campaigns is unchanged in 2026: consent before tracking, one-click reject where the CNIL and its allies can see you, legitimate interests only for processing with low impact, and documented transfer mechanics for any US-based stack. Watch the Omnibus, but do not build against it.

Cross-border transfers

Chapter V: adequacy decisions, SCCs, BCRs, derogations; the EU-US Data Privacy Framework covers certified US companies.

Enforcement and penalties

The GDPR's ceiling applies, with fines up to EUR 20M or 4% of global annual turnover, whichever is higher, levied by the national supervisory authority, and the EDPB can force a harder line through the dispute mechanism. Member states share the ceiling and differ in enforcement appetite.

Primary sources

Cite this page: "European Union Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/european-union.html. Accessed [date].