Yt post test

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Play video
This is the block title field

This is made with block

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Play video
Foobar
This is made with shortcode

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Test

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Play video
Foobar
This is made with shortcode

The state of GDPR: what to expect in 2026-2027

As organizations race to adopt AI, navigate evolving EU digital regulation, and respond to growing regulatory scrutiny, data protection is once again firmly in the spotlight. GDPR compliance remains a key EU requirement for organizations processing personal data, but the context around it is changing rapidly. In this article, our privacy experts look at where GDPR stands in 2026 and share insights on how to stay compliant in an increasingly complex regulatory landscape.

GDPR overview

Implemented in 2018, GDPR remains the most far-reaching regulation on information privacy.

It applies globally to any organization processing the personal data of individuals located within the EU. Its concepts are broadly defined and cover most data-related activities. GDPR distinguishes between two main roles:

  • Data controllers decide why and how personal data is processed
  • Data processors process personal data on a controller’s behalf

Controllers must maintain visibility over the full lifecycle of personal data, from collection to deletion. Under the principle of accountability, the data controller must also be able to demonstrate GDPR compliance to data protection authorities.

Non-compliance can lead to fines of up to €20M or 4% of global annual turnover, whichever is higher. Other risks include reputational damage, civil claims, and orders from regulators to change or stop processing altogether.

How GDPR assessments have changed

A major question for many organizations is whether earlier GDPR assessments still match today’s expectations.

Tiia Summe, who leads Reversec’s DPIA services, explains that when the GDPR entered into force, many organizations relied on best‑guess interpretations because there was little case law to draw on. EU-level guidance was limited, and national approaches varied.

The European Data Protection Board (EDPB) began building shared interpretation through guidelines, including endorsing a list of operations that require a data protection impact assessment (DPIA).

In many organizations, the last GDPR assessment was conducted when compliance still relied on reasonable assumptions and local practice.

Since then, guidance and supervisory practice have matured. In 2020, the EDPB clarified how to apply Article 25, which covers data protection by design and by default, in products and services. In 2023, it provided additional guidance on the right of access, including how to handle unfounded or excessive requests.

Case law from the Court of Justice of the European Union has also clarified how GDPR should be interpreted, including the scope of the right of access and what counts as a copy of personal data.

Furthermore, cooperation and enforcement have strengthened, and the EDPB has highlighted the need for guidance that is easier to use and better aligned with other digital regulation. In 2026, GDPR oversight is more structured and predictable than it was in 2018.

Organizations tend to notice this maturation when they revisit old GDPR assessments. Security Management Consultant Emilia Hjelm describes a common client situation where an assessment was last performed when GDPR compliance still relied on reasonable assumptions and local practice.

At the time, some organizations interpreted certain aspects of GDPR more narrowly than today’s guidance and case law would support. For example, the scope of right of access requests was often defined more restrictively than in current EDPB guidance and has since been further clarified by CJEU case law. As a result, many earlier assessments no longer align with current interpretation.

From clarity to efficiency

In recent years, the EU’s focus has moved from clarification toward making GDPR enforcement work better in practice.

Cross-border cases have been slowed by differences in national administrative procedures, and the Commission has proposed additional procedural rules to improve how these cases are handled. This can create uncertainty for organizations, because complaint handling, admissibility criteria, and timelines may change as the framework evolves.

In parallel, the Commission has proposed targeted adjustments that aim to reduce administrative burden for SMEs and SMCs. For example, record-keeping obligations would be reduced for enterprises or organizations with fewer than 750 people.

During 2026, proposals like this can raise questions about thresholds, scope, and how “high risk” should be interpreted when exemptions are considered.

AI Act and GDPR

Organizations also need to understand how GDPR fits with newer regulation in fast-moving technology areas. A key development is the EU AI Act, the world’s first comprehensive, risk-based framework for artificial intelligence. It sets harmonized rules for developing and using AI systems in the Union.

The regulation entered into force on August 1, 2024, and its requirements take effect in stages. The Commission has proposed adjustments aimed at simplifying parts of the implementation, and EU regulators have commented on those proposals. This means that timelines and details need to be tracked as implementation progresses.

The AI Act does not negate GDPR. If an AI use case involves personal data, GDPR still applies alongside AI Act obligations. The EDPB and the Commission regulators are working on joint guidance to clarify how the two frameworks should operate together.

For certain high-risk AI deployments, the AI Act introduces a fundamental rights impact assessment (FRIA), mainly for specific use cases and public sector actors. Where a GDPR DPIA already covers parts of that work, the AI Act’s FRIA should complement it.

Good AI governance starts with solid privacy and security foundations. AI relies on data, and the regulatory load is growing. It also introduces complexity and unpredictability that make risks harder to understand, control, and explain. These risks need to be handled without creating separate compliance tracks.

In practice, AI integration works best when roles and responsibilities are clear, output quality is actively monitored, and privacy and security are built into the risk management framework. Monitoring should continue after rollout, not just during the initial assessment. There should be a human in the loop for oversight and decision-making.

How the Digital Omnibus affects GDPR

The Commission is also working on a major effort to simplify the EU’s digital legislation and support competitiveness without weakening protections. Published in November 2025, the Digital Omnibus is framed as a first step toward a more streamlined rulebook.

It is a wide-ranging regulation covering AI, data, and security, and it explicitly includes the GDPR in its scope. Because the final text is still under negotiation, organizations should keep a close eye on what changes and when.

Several areas of the Digital Omnibus could affect GDPR requirements, including:

  • Redefining personal data. Pseudonymized data would not be considered personal data for entities that cannot re-identify individuals.
  • Clarifying AI processing. Companies could rely on “legitimate interest” to use personal data to train AI systems.

Beyond these GDPR amendments, the proposal describes moving cookie consent rules from the ePrivacy Directive into GDPR and streamlines data protection impact assessments and breach reporting requirements.

It is worth noting that the Digital Omnibus is positioned as the first step. The next stage is the Digital Fitness Check, an evaluation planned for Q1 2027, intended to stress-test the impact of the digital rulebook.

Organizations should communicate internally that nothing changes overnight. Over the next 12–24 months, processes may need to be adjusted, especially around consent tracking, AI processing expectations, and incident reporting.

Privacy work is increasingly about managing the whole picture, and it is becoming more strategic.

Managing the whole picture

The Digital Omnibus ties GDPR more tightly to other data-related regulations such as the Data Act, NIS2, and the AI Act. While these changes aim to reduce administrative burden, the rulebook itself is becoming more interconnected.

This increases the need to understand overlaps and build strong foundations, such as GDPR compliance, that extend into other requirements.

As a result, privacy work is increasingly about managing the whole picture, and it is becoming more strategic. Organizations need to keep up with change while still staying consistent in how they manage risk.

How we can help with GDPR compliance

As regulatory requirements become more interconnected, many organizations need additional expertise and capacity to keep pace. Purchasing privacy services is an investment that frees the organization to focus on its core business while ensuring changes are addressed in time and that solutions are fit for purpose.

Our Privacy team combines regulatory insight with technical expertise to deliver holistic guidance that goes beyond legal interpretation. We deliver privacy assessments that complement technical and AI governance assessments, giving you a clearer view of your security and privacy posture.

AI integration and AI Act compliance are much easier to achieve when the foundations for GDPR compliance are already in place. We can help you solidify those foundations and connect them to a technical assessment so AI governance stays aligned.

Our combined expertise can also help with:

  • Mapping cookie and tracking data flows alongside consent and transparency requirements
  • Running joint threat modeling that covers technical and data protection risks in the same exercise
  • Adding privacy input to security deliverables when findings raise questions about issues like logging or sensitive data handling
  • Targeted privacy reviews of systems that are already being tested, such as comparing what a mobile app does with what the privacy notice and internal processing records say.
  • Evaluating the current state of your organization against a chosen standard, framework, or regulation.

Alongside ongoing technical and privacy advice, we provide flexible ad-hoc support, pairing a privacy consultant with a technical expert when needed.

Trust is a competitive advantage

Digital business runs on trust. When customers share their data, they expect it to be handled securely, transparently, and lawfully. Technology is also moving faster than many organizations can update their policies and controls.

Generative AI, automation, large-scale data use, and new ecosystems introduce new risks and new responsibilities. In this environment, data protection is a foundation for competitiveness and one of the strongest ways to build trust.

If you’re looking to strengthen your privacy foundations and navigate evolving regulatory requirements with confidence, our experts are here to help.

Trusted Advisor

Trusted Advisor

Read more

Related content

Our thinking

The Cyber Resilience Act (CRA) is about to change European product security

September 2, 2026
The Cyber Resilience Act (CRA) is about to change European product security
Our thinking

NIS2 must-knows for Digital Service Providers

November 24, 2025
NIS2 must-knows for Digital Service Providers
Our thinking

DORA compliance: Testing that makes sense

February 23, 2026
DORA compliance: Testing that makes sense

AI Governance – Because Hype Is Not a Control

Related content

Our thinking

Generative AI security: Findings from our research

May 28, 2024
Generative AI security: Findings from our research
Webinars

Building secure LLM apps into your business

April 11, 2024
Building secure LLM apps into your business
Our thinking

Prompt injections could confuse AI-powered agents

May 17, 2024
Prompt injections could confuse AI-powered agents