Prefer to listen? Click play for AI narration

Two things are true about GDPR at the same time in 2026. Enforcement has never been heavier — regulators are issuing fines faster, wider, and further down the size of business than at any point since the law took effect in 2018. And the law itself is, for the first time, genuinely up for revision, with a Brussels reform package that could rewrite how cookie consent, breach notification, and data protection impact assessments work.

Neither of those things has finished happening. That combination — record enforcement against the rules as they stand today, layered under a reform that hasn't been finalised — is exactly the situation that catches unprepared businesses off guard. Here's what's actually changed this year, and what's still just a proposal.

Enforcement Has Become a High-Volume Machine

GDPR fines have crossed €7.1 billion cumulatively since 2018, with more than €600 million issued in the first half of 2026 alone. This isn't a story about a handful of headline-grabbing penalties against Big Tech anymore — it's a sustained, high-volume enforcement pattern that now reaches deep into small and mid-sized businesses.

€7.1B
Cumulative GDPR fines since 2018
€600M+
Issued in H1 2026 alone
443
Breach notifications filed per day, EU-wide
+22%
Year-over-year increase in daily notifications

That last figure is worth sitting with. Daily breach notifications across the EU have climbed to 443 per day — a 22% year-over-year jump, and the first time that number has topped 400 since GDPR came into force. Every one of those notifications is a business that just had a bad week, and a supervisory authority now deciding whether it was also a negligent one.

The geography of enforcement has shifted too. France overtook Luxembourg in 2025 to become the EU's second-largest enforcer by total fines issued, behind only Ireland — the only two countries to have crossed €1 billion in cumulative GDPR penalties. Spain's AEPD has also moved on from its old pattern of high-volume, low-value consumer complaints toward deliberate, high-value strategic cases.

One recent case is a useful reminder of how ordinary the trigger for a fine has become: Yoti Ltd was fined €950,000 in March 2026 for three distinct violations, including processing biometric data without a valid legal basis and inadequate transparency about how that data was used. No mega-breach, no dark pattern scandal — just biometric processing and a notice that didn't say enough. That's the kind of gap a routine audit catches.

The EDPB's 2026 Focus: Your Privacy Notice, Not Just Your Breach Response

Each year, the European Data Protection Board picks a shared theme for its Coordinated Enforcement Framework — a topic every national supervisory authority investigates in parallel. For 2026, that theme is transparency and information obligations under Articles 12–14: whether your privacy notices actually tell people, in plain language, what you do with their data.

That's a deliberately unglamorous target, and that's the point. Transparency notices are the GDPR document most businesses wrote once in 2018, never revisited, and now don't match what their site, their tools, or their AI features actually do. If your privacy notice was last updated for cookies and newsletters and hasn't caught up with your CRM, your analytics stack, or anything AI-related, this is the year a regulator is more likely than usual to notice.

The Digital Omnibus: GDPR's First Real Rewrite Since 2018

In November 2025, the European Commission proposed the "Digital Omnibus" — a package that would amend both GDPR and the ePrivacy Directive. It is not law yet. As of mid-2026, Council negotiations are still unresolved: the Cyprus Presidency withdrew its compromise text from formal approval at the end of June after it became clear the text didn't have the support of a qualified majority of member states. Expect this to keep moving through the rest of 2026 rather than landing all at once.

Five compliance areas are on the table: records of processing (RoPA), DPIAs, breach notification, the scope of when a DPO is required, and data subject rights. The proposals furthest along:

AreaTodayProposed under the Digital Omnibus
Cookie consentConsent required for essentially all non-essential cookiesAn estimated 60% of cookies would no longer require consent; a mandatory single-click "accept/reject all" button would be required wherever consent is still asked
Personal dataBroadly, any data that could identify a person, from anyone's perspectiveNarrowed to data a specific entity has "means reasonably likely to be used" to identify a person with — a relative, not absolute, test
Breach notification72-hour window to notify the supervisory authority for essentially any breachPossible changes to the 72-hour window plus new materiality thresholds, so minor breaches may no longer trigger formal notification
RoPA / DPIA / DPO scopeThresholds set in 2018, largely unchanged sinceUnder active renegotiation — expected to shift who is required to maintain formal records, run impact assessments, or appoint a DPO

None of this is in force. Redesigning your cookie banner or breach process around a proposal that could still change in Council negotiations is premature — but not tracking it at all means a real rule change could land on a compliance program still built for 2018.

📋
GDPRGard Toolkit
Whatever the RoPA threshold ends up being, have the register ready

Editable DPA pack, SAR response toolkit, and Article 30 RoPA register — the documents regulators actually ask for first. €39–€59 each or €99 for all three, instant download.

Get the Templates →

What to Actually Do Right Now

The two threads — heavier enforcement against today's rules, and reform still in motion for tomorrow's — point to the same practical response.

  1. Audit your privacy notice against Articles 12–14 this year, specifically. This is the EDPB's declared 2026 priority, and it's also the single easiest gap to have without knowing it — the notice is usually right, until you check it against what your site actually does now.
  2. Don't build ahead of the Digital Omnibus. If your cookie banner, breach process, or DPIA thresholds are compliant today, leave them as they are. React to the final text once Council and Parliament agree on one, not to a proposal that's already been through one failed compromise.
  3. Check any biometric, AI, or automated-decision processing for a documented legal basis and a plain-language explanation. The Yoti case is the pattern to watch for: not a catastrophic breach, but ordinary processing without the paperwork to back it up.
  4. If you don't already run a periodic GDPR self-check, start now rather than after a notification lands. Our free 30-second audit checks the ten most commonly missed requirements — the same categories showing up across 2026's enforcement actions.

The Bottom Line

Reform headlines can make GDPR feel like a moving target, but the enforcement data says the opposite: regulators are getting faster and more consistent at applying the rules exactly as written today. Compliance with the current GDPR, not a bet on what the Digital Omnibus will eventually say, is what protects you through 2026. Treat the reform as a thing to monitor, and treat this year's enforcement numbers as the thing to act on.

Book a free consultation with GDPRGard →

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.