For years, GDPR compliance meant cookie banners, data processing agreements, and breach-notification checklists. In 2026, it increasingly means something else: figuring out whether your AI models were trained legally, whether your chatbot has a lawful basis to process what users tell it, and whether "anonymised" training data actually is.
Regulators haven't rewritten GDPR's core principles, but they are actively reshaping how those principles apply to AI — and the numbers show enforcement hasn't slowed down while that rewrite happens.
The Enforcement Backdrop Hasn't Eased Up
Cumulative GDPR fines since 2018 now sit between €6.1 and €7.1 billion, depending on the tracker, with roughly €1.2 billion issued in just the last twelve months — enforcement pace is holding steady, not tapering off. Ireland still accounts for the largest share of fine value (around €4 billion, mostly from cases against large tech platforms over legal basis and international transfers), while Spain leads on sheer volume, publishing over a thousand fines for the seventh year running. That split matters: mega-fines against Big Tech make headlines, but the more common reality is mid-size and small organizations getting fined for basic lawfulness failures.
Breach notifications are also climbing. Reported breaches across Europe now average 443 per day, up 22% year-over-year — the first time that figure has crossed 400. And a growing share of penalties are for missing Data Protection Impact Assessments (DPIAs) treated as a standalone violation, not just a paperwork gap. Reddit was fined £14.47 million by the UK ICO in 2026 for exactly this combination: no lawful basis for processing under-13 users' data, and no DPIA in place before doing it. IQVIA Operations France picked up a €5 million fine for a subtler but increasingly common mistake — treating pseudonymised health data as if it were fully anonymised, and securing it accordingly (which is to say, inadequately).
Pseudonymised data is still personal data under GDPR — it can be re-identified with the right key. Anonymised data cannot be re-identified by anyone, by any means. Treating the first as the second is exactly the mistake that cost IQVIA €5 million, and it's the same mistake many AI teams are one "de-identified" training set away from making.
The Digital Omnibus: GDPR's First Real AI-Era Rewrite
The headline regulatory story of 2026 is the European Commission's Digital Omnibus package, proposed in November 2025 and still being negotiated. It's the first structural change to GDPR since the regulation took effect in 2018, and much of it is aimed directly at AI development.
The most consequential proposal explicitly recognizes "legitimate interest" as a valid legal basis for processing personal data — including special-category data — to train AI models and test them for bias. That's a significant shift: it would give AI developers a clearer, more defensible legal footing for using personal data in training pipelines, something that has been a persistent gray area since GDPR was written years before generative AI existed.
| Area | Today | Proposed under the Digital Omnibus |
|---|---|---|
| AI training data | No explicit legal basis named for training/bias-testing on personal data, including special-category data | "Legitimate interest" formally recognized as a valid basis for training AI models and testing them for bias |
| Personal data | Broadly, any data anyone could use to identify a person | Narrowed to exclude data a company has no reasonable means of identifying someone from |
| Breach notification | 72-hour window to notify the supervisory authority | Extended to 96 hours; threshold raised to "high risk" so fewer low-severity breaches trigger formal notification |
| Cookie consent | Consent required for essentially all non-essential cookies | Equal-prominence accept/reject buttons, a 6-month moratorium on re-asking for declined consent, browser-level consent signals — though the Council's June 2026 text stripped out several of these provisions |
On the AI Act side, high-risk obligation deadlines have been converted from Commission-decision-dependent dates to fixed calendar milestones.
Self-assess whether your AI or automated decision-making meets the human oversight standard expected under Article 22 GDPR and EDPS guidance — free, 5 minutes.
Why This Matters Now, Not Later
None of this is finalized, and that's precisely the point for compliance teams: the legal basis for AI training data is being actively renegotiated while enforcement against the current rules continues at full pace. Waiting for the Digital Omnibus to settle before auditing AI data pipelines means building on assumptions that could shift under you — and doing so while regulators are already fining companies for lawful-basis gaps and DPIA failures that look a lot like what many AI projects have today.
There's also a market signal worth noting. Cisco's 2026 privacy study found that consumers and companies are converging on the same conclusion from opposite ends: trust drives adoption, and privacy investment pays for itself.
What to Actually Do Right Now
The practical takeaway for 2026 doesn't depend on how the Digital Omnibus negotiations end. It comes down to three habits, applied consistently, starting with whatever AI system you shipped most recently:
- Document the legal basis for every dataset feeding an AI system, now. Don't wait for "legitimate interest" to become a formal option under the Digital Omnibus — write down what basis you're relying on today, for every training and fine-tuning set, and be ready to defend it.
- Run DPIAs before deployment, not after an incident. The Reddit fine shows exactly what happens when a DPIA is treated as optional paperwork rather than a gate before shipping a feature that touches children's data or other higher-risk processing.
- Don't assume pseudonymisation is a substitute for anonymisation. If your "de-identified" training data can be re-linked to a person by anyone holding the right key, it's still personal data — and it needs the security and legal basis that comes with that status, the way IQVIA's didn't.
- Track the Digital Omnibus without building around it. React to the final text once Council and Parliament actually agree on one — a proposal that's already lost provisions once in negotiation is not a foundation to compliance-plan on.
The Bottom Line
The rules around AI and GDPR are moving, but the enforcement record makes clear that "the rules aren't final yet" isn't a defense regulators are accepting in the meantime. Compliance with GDPR as it stands today — not a bet on where the Digital Omnibus lands — is what protects an AI project through the rest of 2026.
Book a free consultation with GDPRGard →
Sources
- CMS GDPR Enforcement Tracker
- European Data Protection Board — News
- UK ICO — Enforcement Action (Reddit fine)
- European Commission — Digital Omnibus
- Cisco — 2026 Data Privacy Benchmark Study
Also read:
- The "It Was Public" Excuse Is Over: GDPR Now Formally Covers AI Training Data
- Inside the EU's Digital Omnibus: what's actually changing for GDPR, and what just stalled
- Forget the AI Act — GDPR is already fining companies for AI mistakes