For years, GDPR compliance meant cookie banners, data processing agreements, and breach-notification checklists. In 2026, it increasingly means something else: figuring out whether your AI models were trained legally, whether your chatbot has a lawful basis to process what users tell it, and whether "anonymised" training data actually is.

Regulators haven't rewritten GDPR's core principles, but they are actively reshaping how those principles apply to AI — and the numbers show enforcement hasn't slowed down while that rewrite happens.

The Enforcement Backdrop Hasn't Eased Up

Cumulative GDPR fines since 2018 now sit between €6.1 and €7.1 billion, depending on the tracker, with roughly €1.2 billion issued in just the last twelve months — enforcement pace is holding steady, not tapering off. Ireland still accounts for the largest share of fine value (around €4 billion, mostly from cases against large tech platforms over legal basis and international transfers), while Spain leads on sheer volume, publishing over a thousand fines for the seventh year running. That split matters: mega-fines against Big Tech make headlines, but the more common reality is mid-size and small organizations getting fined for basic lawfulness failures.

€6.1–7.1B
Cumulative GDPR fines since 2018
€1.2B
Issued in the last 12 months
443/day
Average EU breach notifications
+22%
Year-over-year rise in notifications

Breach notifications are also climbing. Reported breaches across Europe now average 443 per day, up 22% year-over-year — the first time that figure has crossed 400. And a growing share of penalties are for missing Data Protection Impact Assessments (DPIAs) treated as a standalone violation, not just a paperwork gap. Reddit was fined £14.47 million by the UK ICO in 2026 for exactly this combination: no lawful basis for processing under-13 users' data, and no DPIA in place before doing it. IQVIA Operations France picked up a €5 million fine for a subtler but increasingly common mistake — treating pseudonymised health data as if it were fully anonymised, and securing it accordingly (which is to say, inadequately).

Pseudonymised data is still personal data under GDPR — it can be re-identified with the right key. Anonymised data cannot be re-identified by anyone, by any means. Treating the first as the second is exactly the mistake that cost IQVIA €5 million, and it's the same mistake many AI teams are one "de-identified" training set away from making.

GDPR fine value by enforcer, 2018–2026 Ireland accounts for roughly €4 billion of the €6.1–7.1 billion issued EU-wide since 2018; the rest of the EU accounts for the remainder, while Spain leads separately on number of fines issued. FINE VALUE ISSUED, 2018–2026 (CUMULATIVE) Ireland ≈ €4.0B Rest of EU ≈ €2.1–3.1B Spain leads separately on volume — 1,000+ individual fines issued in 2026, the 7th straight year. Source: CMS GDPR Enforcement Tracker · figures rounded, midpoint of tracker range
Ireland's share reflects large cases against major tech platforms over legal basis and international transfers — but the broader enforcement pattern now reaches well beyond Big Tech.

The Digital Omnibus: GDPR's First Real AI-Era Rewrite

The headline regulatory story of 2026 is the European Commission's Digital Omnibus package, proposed in November 2025 and still being negotiated. It's the first structural change to GDPR since the regulation took effect in 2018, and much of it is aimed directly at AI development.

The most consequential proposal explicitly recognizes "legitimate interest" as a valid legal basis for processing personal data — including special-category data — to train AI models and test them for bias. That's a significant shift: it would give AI developers a clearer, more defensible legal footing for using personal data in training pipelines, something that has been a persistent gray area since GDPR was written years before generative AI existed.

AreaTodayProposed under the Digital Omnibus
AI training dataNo explicit legal basis named for training/bias-testing on personal data, including special-category data"Legitimate interest" formally recognized as a valid basis for training AI models and testing them for bias
Personal dataBroadly, any data anyone could use to identify a personNarrowed to exclude data a company has no reasonable means of identifying someone from
Breach notification72-hour window to notify the supervisory authorityExtended to 96 hours; threshold raised to "high risk" so fewer low-severity breaches trigger formal notification
Cookie consentConsent required for essentially all non-essential cookiesEqual-prominence accept/reject buttons, a 6-month moratorium on re-asking for declined consent, browser-level consent signals — though the Council's June 2026 text stripped out several of these provisions

On the AI Act side, high-risk obligation deadlines have been converted from Commission-decision-dependent dates to fixed calendar milestones.

EU AI Act high-risk obligation deadlines Timeline showing today in August 2026, standalone high-risk AI system obligations beginning December 2, 2027, and obligations for AI embedded in already-regulated products beginning August 2, 2028. AI ACT · HIGH-RISK OBLIGATION DEADLINES TODAY Aug 2026 STANDALONE HIGH-RISK SYSTEMS Dec 2, 2027 AI EMBEDDED IN REGULATED PRODUCTS Aug 2, 2028 Fixed calendar milestones, no longer dependent on a Commission decision · AI-Omnibus track adopted June 29, 2026
The GDPR-focused Data Omnibus track is still under negotiation, with adoption unlikely before late 2026 — track it, but don't build compliance around a text that could still change.
🧭
GDPRGard Tool
Is your AI's human oversight actually documented?

Self-assess whether your AI or automated decision-making meets the human oversight standard expected under Article 22 GDPR and EDPS guidance — free, 5 minutes.

Run the Checklist →

Why This Matters Now, Not Later

None of this is finalized, and that's precisely the point for compliance teams: the legal basis for AI training data is being actively renegotiated while enforcement against the current rules continues at full pace. Waiting for the Digital Omnibus to settle before auditing AI data pipelines means building on assumptions that could shift under you — and doing so while regulators are already fining companies for lawful-basis gaps and DPIA failures that look a lot like what many AI projects have today.

There's also a market signal worth noting. Cisco's 2026 privacy study found that consumers and companies are converging on the same conclusion from opposite ends: trust drives adoption, and privacy investment pays for itself.

95% OF CONSUMERS
say privacy is essential to trusting AI-powered services
99% OF COMPANIES
report measurable business benefit from privacy investment
Source: Cisco 2026 Data Privacy Benchmark Study. Regulatory pressure aside, treating AI data governance as a compliance afterthought is increasingly a competitive liability, not just a legal one.

What to Actually Do Right Now

The practical takeaway for 2026 doesn't depend on how the Digital Omnibus negotiations end. It comes down to three habits, applied consistently, starting with whatever AI system you shipped most recently:

  1. Document the legal basis for every dataset feeding an AI system, now. Don't wait for "legitimate interest" to become a formal option under the Digital Omnibus — write down what basis you're relying on today, for every training and fine-tuning set, and be ready to defend it.
  2. Run DPIAs before deployment, not after an incident. The Reddit fine shows exactly what happens when a DPIA is treated as optional paperwork rather than a gate before shipping a feature that touches children's data or other higher-risk processing.
  3. Don't assume pseudonymisation is a substitute for anonymisation. If your "de-identified" training data can be re-linked to a person by anyone holding the right key, it's still personal data — and it needs the security and legal basis that comes with that status, the way IQVIA's didn't.
  4. Track the Digital Omnibus without building around it. React to the final text once Council and Parliament actually agree on one — a proposal that's already lost provisions once in negotiation is not a foundation to compliance-plan on.

The Bottom Line

The rules around AI and GDPR are moving, but the enforcement record makes clear that "the rules aren't final yet" isn't a defense regulators are accepting in the meantime. Compliance with GDPR as it stands today — not a bet on where the Digital Omnibus lands — is what protects an AI project through the rest of 2026.

Book a free consultation with GDPRGard →

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.