GDPR position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Current view on GDPR after eight years of enforcement (2018-2026). What it does well, what it does poorly, where the regulation sits as a global privacy benchmark and as operational reality. Dated, revisable, diff-tracked.

State of the view as of 2026-05-12

What GDPR does well

  • Comprehensive scope. All personal data processing in or affecting the EU is covered. No major gaps.
  • Brussels effect achieved. GDPR has become the global benchmark for privacy regulation. California (CCPA/CPRA), Brazil (LGPD), India (DPDP Act 2023), China (PIPL), Japan, Korea, multiple US states have adopted GDPR-influenced laws.
  • Rights-based framing. Data protection treated as fundamental right; principles + lawful bases + rights structure is internally coherent.
  • Substantial enforcement. Eight years of enforcement has produced meaningful case law, accumulated fines (billions in total), and clear expectation that violations cost real money.
  • DPA capacity has scaled. National DPAs have grown staff and capability. EDPB coordinates effectively (with member-state variance).
  • Industry compliance maturity. Most large organizations have functional GDPR programs. Consultancies, tooling vendors, training infrastructure all mature.
  • Privacy as design discipline. Article 25 privacy by design and by default has shifted engineering practice meaningfully.
  • Cross-border transfer mechanisms work (with effort). Adequacy decisions, SCCs, BCRs provide functional paths despite Schrems II disruption.
  • Notable fines have teeth. €1.2B Meta fine (2023), €746M Amazon fine (2021), €345M TikTok fine (2023), €290M Uber fine (2024). Enforcement is not toothless.
  • AI Act co-applies. GDPR continues to apply alongside the AI Act, providing privacy protection for AI-mediated processing.

What GDPR does poorly

  • One-stop-shop friction. Cross-border cases handled by lead DPA produce delays and forum-shopping concerns. Reform proposals discussed but no major restructuring yet.
  • Enforcement is uneven across member states. Ireland (lead DPA for many large US tech companies) faces sustained criticism for slow enforcement; other DPAs more aggressive. Two-tier enforcement landscape.
  • Compliance cost gates smaller orgs. Significant compliance overhead for SMEs. GDPR doesn't formally exempt small orgs (records-of-processing exemption is narrow); de facto enforcement focus on larger violators softens the practical burden somewhat.
  • Consent fatigue. Cookie consent banners and similar consent UI have produced consent fatigue. Many consents are pro-forma. Quality of "informed" consent questionable.
  • Schrems II ongoing complexity. International data transfers face ongoing legal complexity. Each subsequent CJEU decision adjusts the landscape. Meta €1.2B fine (May 2023) underlines that getting it wrong is expensive.
  • Article 22 automated decision-making is partial. The rights apply only when decision is "solely" automated and has "legal or similarly significant effects." Both criteria are contested; AI-assisted decision-making typically falls outside.
  • DPIA quality varies. DPIAs (Art 35) are common but quality varies; many are ceremonial.
  • DPO role inconsistent. DPO appointment criteria are interpreted variably. Some orgs appoint nominally without empowerment.
  • GDPR vs AI Act interaction unclear in places. Where the regimes overlap (automated decision-making, AI processing of personal data) the interaction has not been fully clarified by guidance or case law.
  • Legitimate interests balancing test is hard. Article 6(1)(f) legitimate interests is the most flexible but also most contested basis. Balancing test against data subject's interests is subjective.

Where the evidence currently sits

  • Mature enforcement landscape. Enforcement patterns clear. Major DPAs publish enforcement strategies.
  • Schrems II + EU-US Data Privacy Framework: the 2023 adequacy decision provides safe harbor for transfers to certified US organizations. Holds at the moment; potential Schrems III challenge if EU surveillance concerns escalate.
  • EDPB guidelines publication ongoing. Comprehensive guidance corpus on most contested provisions.
  • CJEU jurisprudence continues to develop. Each major decision shifts the operational landscape.
  • National DPA cooperation improving over time. Cross-border enforcement coordination tighter than in early years.
  • Privacy-enhancing technologies (PETs) maturing — differential privacy, federated learning, homomorphic encryption, secure multi-party computation, synthetic data. Adoption growing slowly.
  • AI Act co-existence: AI Act and GDPR both apply. EDPB and AI Office expected to coordinate; how clear has yet to emerge fully.
  • Reform proposals: Commission has proposed minor procedural reforms (cross-border enforcement, one-stop-shop). No major substantive reform on table.

Personal calibration

  • Working assumption for any work touching personal data of EU residents: GDPR applies. Don't assume otherwise.
  • Working assumption for AI features processing personal data: DPIA likely required; AI Act + GDPR co-apply.
  • Working assumption for model provider relationships: cross-border transfer assessment required. EU-US Data Privacy Framework participation is a viable path for US providers; alternative is SCCs with supplementary measures per Schrems II requirements.
  • Working assumption for consent: prefer alternative lawful bases where possible. Consent is the most fragile basis; contract, legitimate interests often more durable.
  • Working assumption for data subject rights: build the response capability before requests arrive. Right of access (Art 15), erasure (Art 17), portability (Art 20) all need operational paths.
  • Working assumption for breach response: 72-hour notification clock starts on awareness. Pre-built notification workflow shortens response time.

What would shift this view

  • Schrems III: another CJEU challenge to EU-US Data Privacy Framework. Would disrupt transfer landscape again. EU surveillance / FISA developments are watch points.
  • GDPR reform: Commission has signaled willingness to consider reforms. Major procedural simplification (one-stop-shop reform, SME relief) plausibly 2026-2028.
  • AI Act + GDPR coordination guidance: EDPB/AI Office joint guidance on automated decision-making, AI training data, etc. Would clarify the overlap.
  • Major enforcement against AI-system data handling: would establish precedents for AI-specific GDPR application.
  • State-of-the-art on PETs: if differential privacy, federated learning, or similar techniques become operationally practical at scale, would shift the privacy-utility frontier.

See also