AI is moving fast. See how Whisperly helps you get control back and reduce risk.See how →
    Data Protection 18 min read

    Data Privacy Laws in 2026: A Practical Guide for Global Compliance

    A practical guide to global data privacy laws in 2026: GDPR, UK GDPR, US state laws, India DPDP Act, Brazil LGPD, and Canada PIPEDA.

    Jelena Djukanovic
    Jelena Djukanovic| Attorney at Law, Whisperly
    Published: · Last reviewed: · Reviewed by: Marija Veselinovic
    Last updated:
    Data privacy laws in 2026 explained: GDPR, UK DUA Act, US state laws, India DPDP, Brazil LGPD, and Canada PIPEDA, with enforcement data and checklists.

    Data privacy laws in 2026 are no longer a back-office compliance checkbox. They have become a boardroom priority, a customer trust signal, and (in an increasing number of jurisdictions) a matter of significant legal liability.

    Regulators across the globe have spent the last several years closing loopholes, increasing enforcement budgets, and handing out record fines. At the same time, new national privacy laws are entering into force at a pace that has stretched even the largest legal and compliance teams to their limits.

    Whether you are a data protection officer at a multinational enterprise, a privacy lead at a fast-growing SaaS company, or a compliance manager at an SME, this guide explains the data privacy laws in 2026 you actually need to operate against, and what your organisation must do to stay ahead of it.

    For a complete GDPR compliance framework, including RoPA templates, DPIA workflows, and a 2026 checklist, see our GDPR Compliance: A Practical Guide 2026.

    1. European Union: GDPR at Eight: Still the Global Benchmark

    TL;DRThe GDPR remains the world's most enforced data protection law. Aggregate fines across EU supervisory authorities since 2018 now exceed EUR 5 billion, and coordinated enforcement actions in 2026 focus on transparency and information obligations. High-risk AI systems that process personal data must satisfy GDPR and EU AI Act obligations simultaneously, making DPIAs effectively mandatory for any AI system in a high-risk category.

    The General Data Protection Regulation (GDPR) marked eight years of application in May 2026 and shows no sign of retreating. If anything, enforcement has accelerated: the aggregate fines imposed across EU supervisory authorities since 2018 now exceed €5 billion.

    Key Developments in 2026

    Coordinated enforcement actions. The EDPB's "coordinated enforcement framework" is now fully operational. For 2026, the coordinated action focuses on controllers' compliance with transparency and information obligations. Organisations using AI-driven or automated processing should therefore expect scrutiny not only of their lawful basis, but also of whether individuals receive clear, accessible and meaningful information about how their personal data is processed.

    AI Act intersection. The EU AI Act, which entered into application in stages from August 2024, now overlaps meaningfully with GDPR. High-risk AI systems that process personal data must satisfy obligations under both instruments simultaneously. Data protection impact assessments (DPIAs) are often required in practice for AI systems that fall into a high-risk category, and DPOs must be involved early in the development lifecycle, not as an afterthought.

    For a full breakdown of how GDPR and EU AI Act obligations overlap, see our EU AI Act and GDPR compliance guide.

    Data transfers post-adequacy reviews. The EU–US Data Privacy Framework (DPF), adopted in 2023, continues to be scrutinised by privacy advocates, and a legal challenge remains pending before the Court of Justice. Organisations relying on the DPF for US transfers should consider maintaining Standard Contractual Clauses (SCCs) as a backup mechanism.

    GDPR fines in 2026 to watch:

    • Consent management, cookie banner and transparency failures remain recurring enforcement themes, particularly for online services.
    • The highest individual fines continue to arise mainly from large-scale, systemic GDPR infringements, including international transfers, lawful basis, transparency and Big Tech processing practices. DPA enforcement remains particularly significant in Ireland for high-value Big Tech cases, while France, Luxembourg and several other member states continue to show high levels of published enforcement activity.

    The EU Digital Omnibus Package: Simplification on the Horizon, But Don't Relax Yet

    TL;DRThe EU Digital Omnibus Package, proposed in November 2025, proposes targeted amendments to several EU digital laws, including the GDPR, Data Act, AI Act and cybersecurity rules. Some of the more far-reaching GDPR proposals have reportedly been removed or narrowed in Council compromise discussions, but the package remains in the legislative process. As of May 2026, the package is still in legislative process. Continue meeting all current obligations in full.

    In November 2025, the European Commission proposed the EU Digital Omnibus Package, a sweeping legislative initiative aimed at reducing overlapping compliance burdens across several major EU digital laws. For privacy and GRC professionals, this is one of the most significant EU regulatory developments to watch in 2026.

    The package proposes targeted amendments to several laws, including:

    LawKey Proposed Change
    Data ActSimplified B2B data sharing obligations; streamlined smart contract requirements
    AI ActReduced obligations for certain general-purpose AI model providers
    Cyber Resilience ActStreamlined incident reporting and clarification of interaction with other cybersecurity regimes
    DORAStreamlined incident reporting and clarification of interaction with other cybersecurity regimes
    NIS2 DirectiveStreamlined incident reporting and clarification of interaction with other cybersecurity regimes

    What it means for data protection compliance specifically

    The Data Act amendments are the most relevant. The original Data Act created legal tension with GDPR (particularly around data minimisation and purpose limitation) by imposing obligations to share data with third parties in ways that could conflict with data protection principles. The Omnibus proposals aim to reduce that friction by simplifying B2B data sharing rules and automated data access requirements.

    While the GDPR's core structure remains in place, the proposal, if enacted, may affect areas such as DPIAs, transparency obligations, data subject rights procedures and AI-related processing rules. Some of the more far-reaching GDPR proposals have reportedly been removed or narrowed in Council compromise discussions, but the package remains in the legislative process.

    What's the current status?

    As of May 2026, the broader Digital Omnibus package remains in the EU legislative process. The AI-specific file is more advanced: on 7 May 2026, the Council Presidency and European Parliament negotiators reached a provisional political agreement on the Digital Omnibus on AI / AI Omnibus. This is not yet final law; it still requires formal adoption and legal-linguistic finalisation. Until then, the current AI Act remains fully applicable, and compliance teams should continue preparing against the existing legal requirements while monitoring the proposed AI Omnibus changes closely.

    The practical takeaway for compliance teams: The Omnibus signals that the Commission is listening to industry concerns about regulatory overload, but it is not a green light to deprioritise compliance programmes. Organisations that have built robust, documented data protection frameworks will be best placed to adapt quickly when changes do take effect.

    Whisperly's compliance mapping is updated as regulatory developments evolve, so your obligations view stays current without manual re-work.

    GDPR Compliance Checklist for 2026

    • Updated Records of Processing Activities (RoPA) reflecting any AI or automated decision-making tools adopted in 2025–2026. Whisperly automates RoPA population and maintenance: see how RoPA automation works.
    • Fresh DPIAs for high-risk processing, particularly anything involving biometrics, health data, or AI profiling. For a step-by-step DPIA methodology, see our guide to Data Protection Impact Assessments.
    • Lawful basis mapping reviewed, consent obtained under pre-2023 consent banners may no longer meet current standards.
    • Data retention schedules enforced programmatically, not just on paper.
    • Vendor/processor agreements updated to reflect the latest SCC modules. For GDPR Article 28 requirements and a DPA checklist, see GDPR vendor management.

    Managing these obligations manually, across multiple business units, vendors, and jurisdictions, is where compliance teams lose the most time. Whisperly's Data Protection Compliance module gives you a centralised RoPA builder, automated DPIA workflows, and a supplier due diligence hub, so nothing falls through the cracks.

    2. United Kingdom: A Diverging Path Post-Brexit

    TL;DRThe UK's Data (Use and Access) Act, which received Royal Assent in 2025, retains the core architecture of UK GDPR while introducing Recognised Legitimate Interests, broader SAR refusal grounds, and a more permissive automated decision-making regime. These divergences from EU law require careful legal analysis for organisations operating in both markets. The EU's adequacy decision for the UK remains subject to periodic review by the European Commission.

    Among the data privacy laws in 2026 that matter most for cross-border teams, the UK regime entered a new chapter in 2025 with the passage of the Data (Use and Access) Act (formerly known as the Data Protection and Digital Information Bill, or DPDI Bill), which received Royal Assent and is now largely in force.

    For a full comparison of UK GDPR and EU GDPR obligations, see our guide to UK GDPR compliance in 2026.

    What the Data (Use and Access) Act Changes

    The DUA Act retains the core architecture of the UK GDPR and the Data Protection Act 2018, but introduces several notable flexibilities and modernisations:

    Recognised Legitimate Interests (RLIs). The Act introduces a non-exhaustive list of processing purposes that are deemed to automatically pass the legitimate interests balancing test, removing the need for a case-by-case assessment in those scenarios. These include processing for certain public-interest purposes, national security, emergencies, crime prevention, and safeguarding vulnerable individuals. Organisations should map existing legitimate interests processing against the RLI categories to identify where documentation burdens are reduced.

    Reforms to Subject Access Requests (SARs). Controllers can now refuse or charge a fee for SARs deemed "vexatious or excessive", a slightly broader threshold than the previous "manifestly unfounded or excessive" standard. Practically, this gives organisations marginally more discretion, but the bar remains high, and the ICO has signalled it will scrutinise refusals carefully.

    Smart Data schemes. The Act creates a framework for sector-specific data portability schemes (following the model of Open Banking). Expect rollout across energy, telecoms, and financial services over the next 18 to 24 months, creating new data-sharing obligations for regulated firms in those sectors.

    Automated decision-making. The UK has replaced Article 22 GDPR's near-blanket prohibition on solely automated decisions with a more nuanced regime. Certain automated decisions are now permitted without explicit opt-in, provided appropriate safeguards are in place. This is a meaningful divergence from EU law and requires legal analysis for organisations operating in both markets.

    ICO Enforcement Posture in 2026

    The ICO's recent strategies indicate continued regulatory focus on:

    1. 1.Children's data, enforcement of the Children's Code (Age Appropriate Design Code) continues, with a focus on social media platforms and video sharing platforms.
    2. 2.AI and biometrics, the ICO's Generative AI guidance is now finalised, and enforcement activity is expected to follow.
    3. 3.Data brokers and adtech, a multi-year investigation into the real-time bidding ecosystem has begun producing enforcement outcomes.

    3. United States: A Patchwork Becomes a Quilt

    TL;DRAt least 11 US states now have comprehensive consumer privacy laws in force or entering into force in 2026, with more on the way. No federal omnibus law is expected in the near term. California's CPPA is among the most aggressive privacy enforcers, with finalised rules on automated decision-making, risk assessments, and cybersecurity audits. Maryland's MODPA is widely regarded as one of the strictest state laws currently in force, prohibiting the sale of sensitive data outright and imposing affirmative data minimisation obligations.

    The United States remains the most complex privacy jurisdiction for global businesses, with no single federal privacy law and a now-substantial body of state-level legislation that continues to grow.

    The Federal Privacy Landscape

    The American Privacy Rights Act (APRA), which came close to passing Congress in 2024, remains stalled as of early 2026. With divided legislative attention and significant lobbying from large technology companies, a comprehensive federal privacy law is not expected in the near term. Compliance teams should plan for continued state-level complexity.

    State Privacy Law Update: Where Things Stand in 2026

    At least 11 US states now have comprehensive consumer privacy laws in effect or entering into force in 2026. The key additions since 2025 include:

    StateLawEffective
    CaliforniaCCPA/CPRA (amended)In force
    VirginiaVCDPAIn force
    ColoradoCPAIn force
    TexasTDPSAIn force
    FloridaFDBRIn force
    DelawareDPDPAJanuary 2025
    NebraskaNDPAJanuary 2025
    New HampshireNH Privacy ActJanuary 2025
    New JerseyNJDPAJanuary 2025
    TennesseeTIPAJuly 2025
    MarylandMODPA (strictest to date)October 2025

    Maryland's Online Data Privacy Act (MODPA) deserves particular attention: it prohibits the sale of sensitive data altogether (rather than simply requiring opt-out), introduces data minimisation as an affirmative obligation, and applies to a broader range of entities than most other state laws. It is widely regarded as the most stringent US state privacy law currently in force.

    California: Still Setting the Pace

    For a full breakdown of CCPA/CPRA obligations for European-based businesses, see our CCPA Compliance Guidebook 2026.

    California's Privacy Protection Agency (CPPA) became fully operational in 2024 and has been aggressive. In 2025 to 2026, its focus areas include:

    • Automated decision-making technology (ADMT) regulations, which impose opt-out rights and transparency requirements for profiling and certain AI-powered decisions.
    • Risk assessments, the CPPA's risk assessment regulations require businesses conducting high-risk processing to complete and submit assessments.
    • Cybersecurity audits, requiring covered businesses whose processing presents significant security risk to complete annual cybersecurity audits.

    Sectoral Federal Laws Still Matter

    Even without a federal omnibus law, a range of sector-specific US federal laws remain fully in force and are seeing enhanced enforcement:

    • HIPAA: OCR enforcement of health data privacy remains vigorous. HHS/OCR proposed substantial updates to the HIPAA Security Rule in late 2024, with regulators aiming to finalise the amendments in 2026, imposing more prescriptive technical safeguards requirements.
    • COPPA: the FTC's revised COPPA Rule (effective 2025) significantly strengthens protections for children's data and broadens the definition of "operator".
    • GLBA: the FTC's updated Safeguards Rule for financial institutions is fully in force.
    • FTC Section 5: the FTC has been increasingly willing to bring unfair or deceptive practice actions against companies for privacy violations, even where no specific statute applies.

    4. India: DPDP Act Moves into Implementation

    TL;DRIndia's Digital Personal Data Protection Act 2023, covering 1.4 billion people, moved into implementation after the DPDP Rules, 2025. The Act has extraterritorial reach: it applies to processing outside India that relates to offering goods or services to Indian data principals. Penalties reach INR 250 crore for certain violations. Organisations operating in or serving the Indian market should begin compliance gap analyses now.

    India's Digital Personal Data Protection (DPDP) Act 2023 is one of the most significant privacy laws globally, covering a population of 1.4 billion. After a lengthy rules consultation process, the DPDP Rules, 2025 were notified in November 2025 and are being brought into force through phased compliance timelines.

    What Organisations Need to Know

    • Scope: The DPDP Act applies to processing of digital personal data within India, and to processing outside India if it relates to offering goods or services to data principals in India. Extraterritorial reach is significant.
    • Consent requirements: Consent must be free, specific, informed, unconditional, and unambiguous. A "consent manager" framework allows individuals to manage consents through registered intermediaries.
    • Data localisation: Certain categories of personal data may be subject to localisation requirements, with specific categories to be notified by the government. Cloud and SaaS providers serving Indian customers should monitor this closely.
    • Data Fiduciaries and Significant Data Fiduciaries: Larger organisations processing high volumes of data will be designated "Significant Data Fiduciaries" with additional obligations including data protection impact assessments, data protection officers, and periodic audits.
    • Penalties: Up to ₹250 crore for certain violations.

    India is a fast-growing digital economy and a major destination for outsourced services. Compliance with the DPDP Act is now a commercial necessity for any business operating in or serving the Indian market.

    5. Brazil: LGPD Enforcement Matures

    TL;DRBrazil's LGPD has been in force since 2020. The ANPD is now fully operational and actively enforcing, with its first LGPD fine issued in 2023 and enforcement activity continuing to mature through 2025 to 2026. Brazil's territorial reach mirrors GDPR: the law can apply regardless of where the organisation is based, including where processing relates to offering goods or services to individuals in Brazil or where the personal data was collected in Brazil. Legal bases closely mirror GDPR's structure, making compliance alignment relatively straightforward for organisations already GDPR-compliant.

    Brazil's Lei Geral de Proteção de Dados (LGPD) has been in force since 2020, and the Autoridade Nacional de Proteção de Dados (ANPD) (Brazil's data protection authority) is now fully operational and actively enforcing.

    The ANPD issued its first LGPD fine in 2023, and enforcement has continued to mature since. Brazil is Latin America's largest economy and the LGPD's territorial reach (broad and GDPR-like, including processing related to offering goods or services to individuals in Brazil or personal data collected in Brazil) means that many international companies are in scope.

    Key features relevant to 2026:

    • Legal bases closely mirror GDPR's structure, with ten lawful bases for processing.
    • Data subject rights are comprehensive and enforceable.
    • International transfers, the ANPD has published its adequacy recognition process and approved standard contractual clauses for international transfers.
    • SME exceptions, the ANPD has maintained simplified compliance pathways for smaller organisations, but these do not eliminate core obligations.

    6. Canada: PIPEDA's Replacement Still Pending

    TL;DRBill C-27, which would have replaced PIPEDA with the Consumer Privacy Protection Act, died on the Order Paper after Parliament was prorogued in January 2025 and has not been enacted as of early 2026. PIPEDA remains the operative federal private-sector privacy law in Canada, with the Office of the Privacy Commissioner continuing to investigate and report on breaches and complaints. Organisations should continue maintaining PIPEDA compliance while monitoring federal privacy reform.

    Canada's federal private-sector privacy law remains the Personal Information Protection and Electronic Documents Act (PIPEDA). Although Bill C-27 proposed replacing PIPEDA with the Consumer Privacy Protection Act, that reform stalled after Bill C-27 died on the Order Paper in January 2025. As of early 2026, no CPPA replacement has been enacted. PIPEDA continues to regulate private-sector organisations that collect, use or disclose personal information in the course of commercial activities. Key compliance points include:

    • Express consent requirements for sensitive data
    • Algorithmic transparency obligations for automated decision systems
    • Disposal obligations: personal information must be disposed once the purpose of collection has been served
    • A new Privacy Commissioner with order-making and penalty powers (up to 5% of global revenue or CAD $25 million)

    Canada is the second-largest trading partner for the United States and a major destination for cross-border data flows. Organisations with Canadian operations should continue maintaining PIPEDA compliance, while monitoring federal privacy reform and treating the former CPPA proposal as an indicator of possible future reform direction.

    7. Other Jurisdictions to Watch

    TL;DRSaudi Arabia's PDPL is fully in force with extraterritorial scope. The UAE's Federal Decree-Law No. 45 of 2021 remains the onshore federal privacy framework, but its full practical implementation depends on pending Executive Regulations; DIFC and ADGM continue to operate separate financial free-zone data protection regimes. South Korea's PIPA amendments expand mandatory data protection officer requirements. Australia is moving toward a substantially strengthened Privacy Act. Global compliance mapping must account for this expanding patchwork.

    The global privacy law map continues to expand. Notable 2026 additions and developments include:

    • Saudi Arabia: the Personal Data Protection Law (PDPL) is fully in force. Its extraterritorial scope captures processing of personal data relating to individuals in Saudi Arabia, including by organisations outside the Kingdom.
    • United Arab Emirates: the Federal Decree-Law No. 45 of 2021 on Personal Data Protection remains the onshore federal privacy framework, although full practical implementation depends on pending Executive Regulations. DIFC and ADGM maintain separate financial free-zone data protection regimes.
    • Japan: amendments to the Act on the Protection of Personal Information (APPI) that came into force in 2022 have prompted regulators to update their guidance on international transfers and sensitive data.
    • South Korea: PIPA amendments have introduced mandatory data protection officers for a wider range of organisations and the PIPC has issued AI-specific privacy guidance.
    • Australia: the Privacy Act Review is translating into legislative reform. A first tranche of Privacy Act amendments has already passed, with further reforms expected to substantially raise the bar from the current framework.

    8. The Common Threads: What the Data Privacy Laws in 2026 Share

    TL;DRFive themes run through major privacy law in 2026: data minimisation as a baseline obligation, not a best practice; more demanding consent standards across many jurisdictions; rising volumes of data subject rights requests with statutory deadlines; AI as a mainstream privacy risk requiring standard lawful basis, transparency, and DPIA analysis; and a shift from paper accountability to documented, evidenced compliance programmes that regulators can audit.

    Across every jurisdiction, five themes recur:

    1. Data Minimisation Is Now a Baseline, Not a Best Practice

    From GDPR to MODPA to the DPDP Act, modern privacy laws require organisations to collect only the data they actually need. Yet data inventories at most organisations remain incomplete. If you don't know what data you hold, you cannot defend what you process.

    Pre-ticked boxes, bundled consent, and vague privacy notices no longer meet the legal standard in most major privacy regimes. Consent management must be granular, documented, and revocable, with systems that can honour revocation in practice, not just on paper.

    3. Data Subject Rights Are Being Exercised and Enforced

    DSARs, deletion requests, opt-outs, and data portability requests are arriving in higher volumes. Organisations without automated or semi-automated workflows for handling them are struggling to meet statutory deadlines.

    4. AI Is the New Privacy Frontier

    Every major data protection authority published AI-specific guidance in 2025. In 2026, AI is not a special case; it is simply one more context in which lawful basis, transparency, DPIA, and data minimisation obligations apply. The organisations that built privacy-by-design processes for AI early are now ahead.

    Our guide to privacy by design under GDPR explains the Article 25 obligation and how to implement it in practice.

    5. Accountability Requires Evidence

    "We have a privacy policy" is not a compliance programme. Regulators expect documented evidence of processing activities, DPIAs, staff training, incident response plans, and vendor due diligence. The burden of proof rests with the controller.

    Our GDPR Guidebook 2026 covers the full accountability framework with practical templates and checklists.

    How Whisperly Helps You Stay on Top of All of It

    Managing compliance with GDPR, UK data protection law, a growing roster of US state laws, and emerging frameworks in India, Brazil, and beyond is simply not feasible with spreadsheets and shared drives.

    Whisperly is purpose-built for exactly this challenge. Our GRC platform includes a dedicated Data Protection Compliance module that gives you:

    • Centralised Records of Processing Activities (RoPA): maintained across your entire organisation, not scattered across departments.
    • DPIA Workflow Engine: guided assessments that meet GDPR, UK, and international standards, with version control and sign-off tracking.
    • Supplier & Processor Management: due diligence, contract tracking, and risk scoring for every third party that touches your data.
    • Data Subject Rights Tracker: log, assign, and meet statutory deadlines for SARs, deletion requests, and more.
    • Incident & Breach Management: structured workflows to assess, report, and document data breaches against applicable regulatory timelines.

    Final Thoughts

    The data privacy laws in 2026 make one thing clear: "we're working on it" has stopped being an acceptable answer to regulators. Enforcement budgets are up, cooperation between data protection authorities is increasing, and data subjects are more aware of their rights than ever. The question for most organisations is no longer whether to invest in privacy compliance, it is how to make that investment efficient and sustainable.

    The good news is that the underlying principles: data minimisation, transparency, accountability, and security are consistent across jurisdictions. A strong foundational compliance programme, supported by the right tooling, can be scaled and adapted rather than rebuilt from scratch for each new law.

    GDPRUK GDPRUS PrivacyDPDP ActLGPDPIPEDAComplianceData Protection

    Questions & Answers

    What is the difference between GDPR and UK GDPR in 2026?+

    UK GDPR is the UK version of the EU GDPR, retained in UK domestic law after Brexit and now amended by the Data (Use and Access) Act 2025. The core obligations are the same: lawful basis, data subject rights, DPIAs, and controller-processor agreements. Key divergences introduced by the DUA Act include Recognised Legitimate Interests, a broader SAR refusal threshold, and a more permissive automated decision-making regime. Organisations operating in both the EU and the UK must track both regimes separately.

    Which US state privacy law is the strictest in 2026?+

    Maryland's Online Data Privacy Act (MODPA), which entered into force in October 2025, is widely regarded as the most stringent US state privacy law currently in force. Unlike most other state laws, MODPA prohibits the sale of sensitive personal data outright rather than merely requiring opt-out consent, and imposes affirmative data minimisation obligations. California's CPRA remains the most actively enforced, with the CPPA pursuing rulemaking on automated decision-making, risk assessments, and cybersecurity audits.

    Does the EU Digital Omnibus Package change GDPR compliance obligations?+

    While the GDPR's core structure remains in place, the proposal, if enacted, may affect areas such as DPIAs, transparency obligations, data subject rights procedures, breach notification and GDPR-related rules for AI development and operation. Some of the more far-reaching GDPR proposals, including the proposed revision of the definition of personal data, have reportedly been removed or narrowed in Council compromise discussions, but the package remains in the legislative process. Continue meeting all current obligations in full.

    Do I need a DPIA for every AI system my organisation uses?+

    Not for every AI system, but for any AI system that is likely to result in high risk to data subjects. Under GDPR Article 35, DPIAs are mandatory for processing that involves systematic profiling with significant effects, large-scale processing of sensitive data, or systematic monitoring of publicly accessible areas. In practice, any AI system that falls into a high-risk category under the EU AI Act and processes personal data will require a DPIA. The EDPB has confirmed that the Article 35 DPIA obligation and the EU AI Act's fundamental rights impact assessment are complementary, not interchangeable.

    What records of processing activities must organisations maintain under GDPR?+

    GDPR Article 30 requires controllers to maintain a Record of Processing Activities (RoPA) covering: the name and contact details of the controller and DPO; the purposes of processing; categories of data subjects and personal data; recipients; international transfer details; retention periods; and a general description of technical and organisational security measures. Most organisations need a separate processor RoPA under Article 30(2). The record must be made available to supervisory authorities on request.

    What are the most common triggers for a GDPR enforcement action?+

    The most common triggers for GDPR enforcement action are recurring operational compliance failures rather than one-off mistakes. In practice, regulators most often target poor consent management and cookie banner practices, lack of transparency in privacy notices and online services, and failures to provide a valid legal basis for processing. Higher-value enforcement actions tend to arise from more systemic issues, including unlawful international transfers, large-scale or sensitive processing, Big Tech advertising and transparency practices, and serious data security or breach-related failures.

    Jelena Djukanovic

    Written by

    Jelena Djukanovic

    Attorney at Law, Whisperly

    Reviewed by: Marija Veselinovic

    Share
    Get Started

    Ready to make compliance
    feel effortless?

    Join 100+ companies automating GRC with Whisperly. Get audit-ready in weeks, not months.

    Stay ahead of compliance changes

    Practical compliance tips, delivered to your inbox every two weeks.