Two things are true about GDPR at the same time in 2026. Enforcement has never been heavier — regulators are issuing fines faster, wider, and further down the size of business than at any point since the law took effect in 2018. And the law itself is, for the first time, genuinely up for revision, with a Brussels reform package that could rewrite how cookie consent, breach notification, and data protection impact assessments work.
Neither of those things has finished happening. That combination — record enforcement against the rules as they stand today, layered under a reform that hasn't been finalised — is exactly the situation that catches unprepared businesses off guard. Here's what's actually changed this year, and what's still just a proposal.
Enforcement Has Become a High-Volume Machine
GDPR fines have crossed €7.1 billion cumulatively since 2018, with more than €600 million issued in the first half of 2026 alone. This isn't a story about a handful of headline-grabbing penalties against Big Tech anymore — it's a sustained, high-volume enforcement pattern that now reaches deep into small and mid-sized businesses.
That last figure is worth sitting with. Daily breach notifications across the EU have climbed to 443 per day — a 22% year-over-year jump, and the first time that number has topped 400 since GDPR came into force. Every one of those notifications is a business that just had a bad week, and a supervisory authority now deciding whether it was also a negligent one.
The geography of enforcement has shifted too. France overtook Luxembourg in 2025 to become the EU's second-largest enforcer by total fines issued, behind only Ireland — the only two countries to have crossed €1 billion in cumulative GDPR penalties. Spain's AEPD has also moved on from its old pattern of high-volume, low-value consumer complaints toward deliberate, high-value strategic cases.
One recent case is a useful reminder of how ordinary the trigger for a fine has become: Yoti Ltd was fined €950,000 in March 2026 for three distinct violations, including processing biometric data without a valid legal basis and inadequate transparency about how that data was used. No mega-breach, no dark pattern scandal — just biometric processing and a notice that didn't say enough. That's the kind of gap a routine audit catches.
The EDPB's 2026 Focus: Your Privacy Notice, Not Just Your Breach Response
Each year, the European Data Protection Board picks a shared theme for its Coordinated Enforcement Framework — a topic every national supervisory authority investigates in parallel. For 2026, that theme is transparency and information obligations under Articles 12–14: whether your privacy notices actually tell people, in plain language, what you do with their data.
That's a deliberately unglamorous target, and that's the point. Transparency notices are the GDPR document most businesses wrote once in 2018, never revisited, and now don't match what their site, their tools, or their AI features actually do. If your privacy notice was last updated for cookies and newsletters and hasn't caught up with your CRM, your analytics stack, or anything AI-related, this is the year a regulator is more likely than usual to notice.
The Digital Omnibus: GDPR's First Real Rewrite Since 2018
In November 2025, the European Commission proposed the "Digital Omnibus" — a package that would amend both GDPR and the ePrivacy Directive. It is not law yet. As of mid-2026, Council negotiations are still unresolved: the Cyprus Presidency withdrew its compromise text from formal approval at the end of June after it became clear the text didn't have the support of a qualified majority of member states. Expect this to keep moving through the rest of 2026 rather than landing all at once.
Five compliance areas are on the table: records of processing (RoPA), DPIAs, breach notification, the scope of when a DPO is required, and data subject rights. The proposals furthest along:
| Area | Today | Proposed under the Digital Omnibus |
|---|---|---|
| Cookie consent | Consent required for essentially all non-essential cookies | An estimated 60% of cookies would no longer require consent; a mandatory single-click "accept/reject all" button would be required wherever consent is still asked |
| Personal data | Broadly, any data that could identify a person, from anyone's perspective | Narrowed to data a specific entity has "means reasonably likely to be used" to identify a person with — a relative, not absolute, test |
| Breach notification | 72-hour window to notify the supervisory authority for essentially any breach | Possible changes to the 72-hour window plus new materiality thresholds, so minor breaches may no longer trigger formal notification |
| RoPA / DPIA / DPO scope | Thresholds set in 2018, largely unchanged since | Under active renegotiation — expected to shift who is required to maintain formal records, run impact assessments, or appoint a DPO |
None of this is in force. Redesigning your cookie banner or breach process around a proposal that could still change in Council negotiations is premature — but not tracking it at all means a real rule change could land on a compliance program still built for 2018.
Editable DPA pack, SAR response toolkit, and Article 30 RoPA register — the documents regulators actually ask for first. €39–€59 each or €99 for all three, instant download.
What to Actually Do Right Now
The two threads — heavier enforcement against today's rules, and reform still in motion for tomorrow's — point to the same practical response.
- Audit your privacy notice against Articles 12–14 this year, specifically. This is the EDPB's declared 2026 priority, and it's also the single easiest gap to have without knowing it — the notice is usually right, until you check it against what your site actually does now.
- Don't build ahead of the Digital Omnibus. If your cookie banner, breach process, or DPIA thresholds are compliant today, leave them as they are. React to the final text once Council and Parliament agree on one, not to a proposal that's already been through one failed compromise.
- Check any biometric, AI, or automated-decision processing for a documented legal basis and a plain-language explanation. The Yoti case is the pattern to watch for: not a catastrophic breach, but ordinary processing without the paperwork to back it up.
- If you don't already run a periodic GDPR self-check, start now rather than after a notification lands. Our free 30-second audit checks the ten most commonly missed requirements — the same categories showing up across 2026's enforcement actions.
The Bottom Line
Reform headlines can make GDPR feel like a moving target, but the enforcement data says the opposite: regulators are getting faster and more consistent at applying the rules exactly as written today. Compliance with the current GDPR, not a bet on what the Digital Omnibus will eventually say, is what protects you through 2026. Treat the reform as a thing to monitor, and treat this year's enforcement numbers as the thing to act on.
Book a free consultation with GDPRGard →
Sources
- CMS GDPR Enforcement Tracker
- European Data Protection Board — News & Coordinated Enforcement Framework
- Kiteworks — GDPR Fines Hit €7.1 Billion: Enforcement Trends in 2026
- Uniconsent — GDPR Enforcement and Fines 2026
- Privacy Next — Digital Omnibus Negotiations (GDPR), July 2026 Update
Also read:
- The AI Act just went live for high-risk systems — now you have two regulators
- The 5 most common cookie banner mistakes — and how to fix them
- Why every SaaS company needs a DPIA before launching AI features