{
 "jurisdiction_id": "EEA",
 "jurisdiction": "European Economic Area",
 "url": "https://dataprotection.gi/jurisdictions/european-economic-area/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 54,
  "sub_modules": 57,
  "source_register": 39
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Mature, harmonised, directly-applicable omnibus regime with an active coordinating body and imminent procedural strengthening; no material derogation identified across EEA EFTA states.",
   "claims": [
    {
     "statement": "National data protection authorities of the EU Member States and the EEA EFTA states (Iceland, Liechtenstein, Norway) are the primary enforcement bodies for the GDPR, cooperating through the EDPB's consistency and cooperation framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/data-protection/our-work/cooperation-eu-dpas/cooperation-european-economic-area-eea-and-european-free-trade-association-efta_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB may issue binding decisions under Article 65 GDPR that direct a lead supervisory authority to alter proposed measures, including materially increasing proposed fines, as occurred in the Meta Ireland Facebook/Instagram inquiries where the EDPB directed the fine be raised from a proposed maximum of €59 million to €390 million.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/irelands-meta-decisions-raise-complex-fundamental-questions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Regulation (EU) 2016/679 (GDPR) repealed and replaced Directive 95/46/EC as the EU's general data protection framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/sites/cnil/files/2025-01/guide_tia.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Regulation (EU) 2025/2518, laying down additional procedural rules for GDPR cross-border enforcement (harmonising complaint admissibility, lead/concerned-authority cooperation and party rights), was adopted on 26 November 2025, published in the Official Journal on 12 December 2025, and applies from 2 April 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=LEGISSUM%3A310401_2",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 2 material scope covers processing of personal data by automated means and manual processing forming part of a filing system, as reflected in EDPB and CNIL guidance defining personal data broadly (any information relating to an identified or identifiable natural person).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/sites/cnil/files/2025-01/guide_tia.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Since 25 May 2018, GDPR applies to processing in the context of an EU/EEA establishment's activities and to processing by non-established controllers/processors targeting EEA data subjects through the offering of goods or services or the monitoring of their behaviour within the Union.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/european-commission-adopts-eu-u-s-adequacy-decision",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "An EDPB report on extraterritorial enforcement notes that any exercise of a DPA's investigative powers outside EU/EEA territory requires the consent of the foreign state, limiting practical extraterritorial reach notwithstanding Article 3's broad scope.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2024-10/edpb_20240417_report_extraterritorial_enforcement_gdpr_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GDPR is generally understood to have abolished the ex-ante notification/registration regime that existed under Directive 95/46/EC, substituting an accountability-based compliance model (Article 5(2), Article 24).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/sites/cnil/files/2025-01/guide_tia.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core provisions are stable and enforced, but the Digital Omnibus proposal (still in trilogue as of mid-2026) creates near-term uncertainty over consent-signal mechanics and the sensitive-data/AI derogation.",
   "claims": [
    {
     "statement": "The Irish DPC, implementing EDPB binding decisions, fined Meta Ireland a combined €390 million (€210m Facebook, €180m Instagram) after finding that Meta could not rely on the contractual-necessity legal basis under Article 6 GDPR for behavioural-advertising processing.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/irish-dpc-fines-meta-390m-euros-over-legal-basis-for-personalized-ads",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Digital Omnibus proposal introduces a new GDPR Article 88b that would allow individuals to express privacy choices automatically through technical means such as browser settings, rather than manual cookie-banner interaction.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/can-we-solve-the-cookie-banner-problem-in-the-eu-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In June 2026 the Council of the EU removed the proposed Article 88b automated-consent-signal provision from its negotiating position following lobbying from media and advertising industry groups, creating legislative uncertainty over the final mechanism.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/can-we-solve-the-cookie-banner-problem-in-the-eu-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and EDPS welcomed the Digital Omnibus's proposed derogation permitting incidental and residual processing of special-category (Article 9) data in the context of developing and operating AI systems, while recommending improvements to scope and lifecycle safeguards.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EDPB Guidelines 01/2025 clarify that pseudonymised data, when attributable to an individual via additional information, remains personal data, and detail how pseudonymisation supports Articles 5, 25 and 32 compliance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2025/edpb-adopts-pseudonymisation-guidelines-and-paves-way-improve-cooperation_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following the CJEU's September 2025 EDPS v SRB ruling that the same dataset can be personal data for one recipient and anonymous for another, the EDPB published draft Guidelines 02/2026 on Anonymisation (7 July 2026, consultation to 30 October 2026) setting out a two-question, three-criteria (no isolation, no linkage, no inference) test for anonymisation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/the-edpb-s-draft-anonymization-guidelines-what-they-mean-for-your-data-strategy",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights are robustly enforced and subject to active coordinated supervisory scrutiny, but a pending legislative change (abuse-of-access-rights clarification) could alter practical scope.",
   "claims": [
    {
     "statement": "The CJEU has confirmed (Case C-307/22) that data subjects may legitimately exercise the Article 15 right of access for objectives other than becoming aware of processing or verifying its lawfulness, without needing to provide particular motivation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2026-02/edpb_edps_jointopinion_202602_digitalomnibus_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Digital Omnibus proposes to give controllers legal clarity for cases of abuse of rights by data subjects, but the EDPB and EDPS consider that exercising the access right for purposes other than data protection should not itself be treated as an element defining abuse.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB ran a year-long 2025 Coordinated Enforcement Framework action on the Article 17 right to erasure/right to be forgotten, adopting a report on the action's findings in 2026.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/cef-2026-edpb-launches-coordinated-enforcement-action-on-transparency-and-information_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The right to data portability under Article 20 GDPR continues to be interpreted per the WP29 Guidelines on the right to data portability, as endorsed by the EDPB.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-01/edpb_guidelines_202501_pseudonymisation_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "During 2026, 25 DPAs across Europe are participating in the EDPB's Coordinated Enforcement Framework action assessing controller compliance with Article 12-14 transparency and information obligations that condition the effective exercise of data subject rights.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/cef-2026-edpb-launches-coordinated-enforcement-action-on-transparency-and-information_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Baseline obligations are stable and well-enforced, but simplification proposals (still in trilogue) will materially change SME/SMC recordkeeping and breach-notification thresholds once adopted.",
   "claims": [
    {
     "statement": "As part of its 2026-2027 work programme, the EDPB is developing ready-to-use EU templates for legitimate interest assessments, records of processing, privacy notices, data breach notifications and data protection impact assessments to facilitate compliance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2026-02/edpb_work-programme_2026-2027_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commission's Digital Omnibus proposal would amend Article 30(5) GDPR to raise the records-of-processing exemption threshold from enterprises/organisations under 250 employees to those under 750 employees, unless the processing is likely to result in high risk to individuals.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2025/targeted-modifications-gdpr-edpb-edps-welcome-simplification-record-keeping_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EDPB guidance explains how pseudonymisation, alongside encryption, functions as a technical safeguard supporting Article 32 security-of-processing obligations and Article 25 data protection by design.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2025/edpb-adopts-pseudonymisation-guidelines-and-paves-way-improve-cooperation_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and EDPS support the Digital Omnibus proposal to increase the risk threshold that triggers the Article 33 duty to notify a personal data breach to the competent DPA, and to extend the notification deadline, alongside introducing common breach-notification and DPIA templates.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms are mature and well-documented, but the EU-US DPF faces continuing legal challenge risk and the EDPB has flagged concerns (e.g. over US entry-condition changes for EEA citizens and a US Supreme Court ruling) that could affect adequacy stability.",
   "claims": [
    {
     "statement": "Article 46 GDPR lists appropriate-safeguards transfer tools (including SCCs and BCRs), and Article 49 provides derogations for specific situations, both usable absent an adequacy decision, subject to the exporter maintaining Article 5 GDPR compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme-data-protection-guide/international-data-transfers_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GDPR framework positions the European Commission as the body issuing adequacy decisions under Article 45 to third countries (e.g. the UK, renewed 19 December 2025 to run until 27 December 2031); the EEA itself is not a recipient of inbound adequacy findings under this mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "ICO",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/receiving-personal-information-from-the-eea/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Commission has recognised adequate third countries/territories including Andorra, Argentina, Canada, the Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay and the United States.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/edpb-meets-adequate-countries_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU-US Data Privacy Framework adequacy decision, adopted 10 July 2023, allows personal data to flow to certified US organisations without additional transfer safeguards; as of early 2026 more than 3,500 US companies had self-certified, though the framework remains subject to potential CJEU review and EDPB monitoring including a first-review report.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/iapp-global-summit-2026-on-the-state-of-the-trans-atlantic-data-transfer-agreement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Commission adopted modernised Standard Contractual Clauses via Implementing Decision (EU) 2021/914 in June 2021, and since 27 September 2021 only the current SCCs may be used for new transfer contracts; the EDPB continues to issue opinions approving Member State DPAs' draft BCR authorisations (e.g. multiple 2026 opinions on Dutch SA BCR decisions).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "BfDI",
     "source_url": "https://www.bfdi.bund.de/EN/Fachthemen/Inhalte/Europa-Internationales/Internationaler_Datentransfer.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A Transfer Impact Assessment must be carried out by an exporter relying on an Article 46 GDPR transfer tool prior to transferring data to a third country, unless the destination is covered by an adequacy decision or an Article 49 derogation applies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/sites/cnil/files/2025-01/guide_tia.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A separate EU legislative proposal for sovereign cloud computing services (impact assessment submitted to the Regulatory Scrutiny Board, positive opinion 8 May 2026) introduces safeguards for EU-citizen personal data processed via cloud infrastructure and is framed as complementary to, not a replacement for, the GDPR and EU-US DPF transfer regime.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "European Commission",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52026PC0502",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Health and telecoms/eprivacy overlays are actively evidenced; other sectoral overlays (financial, employment, education, insurance) lack direct 2026 sourcing in this pass and are flagged as gaps.",
   "claims": [
    {
     "statement": "CNIL imposed a €5 million fine against IQVIA in connection with health-data processing, evidencing active French enforcement in the health sector.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/en/investigation-powers-cnil/sanctions-issued-cnil",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Digital Omnibus proposes amendments to the ePrivacy Directive including limited additional derogations to the general prohibition on storing or accessing data in terminal equipment, which the EDPB/EDPS urge be balanced by incentivising contextual over behavioural advertising.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In December 2023, the CJEU issued its first interpretation of Article 22 GDPR (right not to be subject to solely automated decision-making) in the context of automated credit scoring (Case C-634/21, SCHUFA).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Medical Law Review / NCBI PMC",
     "source_url": "https://www.ncbi.nlm.nih.gov/pmc/articles/PMC11347939/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie-consent fatigue is a recognised, unresolved policy problem; the principal legislative fix (Art. 88b) is currently stalled in the Council, leaving practical mechanics unsettled.",
   "claims": [
    {
     "statement": "The Digital Omnibus's proposed Article 88b GDPR would allow automated, machine-readable expression of individuals' data-processing choices, with oversight of such mechanisms entrusted to DPAs; in June 2026 the Council of the EU removed this provision from its position paper after industry lobbying.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/can-we-solve-the-cookie-banner-problem-in-the-eu-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Cookie banners are widely characterised as causing consent fatigue and facilitating data exploitation rather than achieving the meaningful, effective data protection the ePrivacy Directive and GDPR were intended to deliver.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/can-we-solve-the-cookie-banner-problem-in-the-eu-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Global Privacy Control is implemented on at least 385,000 websites and recognised under California, Colorado, Connecticut and other US state privacy laws, and is discussed as a candidate technical standard for the EU's proposed automated consent-signal mechanism, though as an opt-out-only specification it cannot natively express affirmative consent.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/can-we-solve-the-cookie-banner-problem-in-the-eu-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and EDPS welcome limited additional ePrivacy derogations proposed in the Digital Omnibus and invite co-legislators to incentivise contextual advertising over behavioural advertising through a specific, safeguarded exception.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Article 22 is settled law with recent CJEU interpretation, but the practical GDPR/AI Act interface remains in active development pending joint EDPB-Commission guidelines and AI Act simplification.",
   "claims": [
    {
     "statement": "Article 22 GDPR provides data subjects with the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/mapping-interplays-gdpr-eu-ai-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB and the European Commission are jointly preparing guidelines on the interplay between the GDPR and the AI Act, addressing transparency, risk assessments, bias detection and accountability, with a first draft potentially available soon and final adoption possible by end of 2026.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-view-from-brussels-a-sneak-peek-into-upcoming-guidelines-on-gdpr-ai-act-interplay",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU's AI Act high-risk system compliance timeline, originally set for August 2026, is being extended via the Digital Omnibus on AI, with organisations to receive six months to comply once implementing standards and support tools are confirmed, capped at December 2027.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/european-commission-proposes-significant-reforms-to-gdpr-ai-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Genetic data falls within the Article 9 special-category regime; the Digital Omnibus's proposed derogation for incidental/residual sensitive-data processing in AI development would potentially extend to genetic data, subject to EDPB/EDPS-recommended lifecycle safeguards.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB has issued formal correspondence to the European Commission addressing the privacy implications of proposed US legislative changes to entry conditions for EEA citizens, and separately regarding a US Supreme Court judgment, reflecting ongoing EDPB engagement with law-enforcement and surveillance-adjacent international-cooperation matters.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/home_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core Article 8 mechanism is well-established law, but dedicated children's-data guidelines remain in development and several sub-areas (age verification specifics, education settings, dependent adults) lack direct 2026 sourcing in this pass.",
   "claims": [
    {
     "statement": "Article 8 GDPR sets a default minimum age of 16 for a child to consent to processing in relation to information-society services, permitting Member States to lower this threshold by law to no less than 13 years, with parental-responsibility-holder consent required below the applicable age.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "CNIL",
     "source_url": "https://www.cnil.fr/sites/cnil/files/2025-01/guide_tia.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB's 2026-2027 work programme includes the development of dedicated Guidelines on children's data as one of its Pillar I harmonisation priorities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2026-02/edpb_work-programme_2026-2027_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/european-economic-area/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers are broad, actively used at scale (billion-euro-class fines), collective redress mechanisms are in force, and a further procedural-harmonisation regulation is already adopted (pending 2027 application).",
   "claims": [
    {
     "statement": "GDPR Article 83 authorises fines for certain violations of up to 4% of an undertaking's total global annual turnover of the preceding financial year or €20 million, whichever is greater.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "SEC",
     "source_url": "https://www.sec.gov/Archives/edgar/data/1830081/000121390026042803/ea0270012-02.htm",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ireland's Data Protection Commission imposed a record €1.2 billion fine on Meta Ireland in May 2023 over unlawful EU-US data transfers, the largest GDPR fine to date, alongside orders to suspend future transfers and cease unlawful US processing of EEA users' data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ireland-dpcs-data-transfers-decision-pragmatic-punch-or-knockout-blow",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Czech supervisory authority's appellate decision confirmed a first-instance fine of approximately €13.9 million against a controller for infringing Articles 6 and 13(1) GDPR over the transfer of antivirus-software users' browsing data to a sister company.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/czech-sa-imposed-fine-of-139-million-eur-for-infringement-of-art-6-and-art-13-of-gdpr_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CNIL fined IQVIA €5 million over health-data violations, and Ireland's DPC separately fined WhatsApp Ireland €5.5 million for transparency and consent failures in its Terms of Service, illustrating continued multi-jurisdictional enforcement momentum.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/irish-dpcs-whatsapp-fine-deepens-fissure-with-edpb-over-enforcement-jurisdictions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Commission identified fragmented national procedures and limited DPA resourcing as factors hindering effective cross-border GDPR enforcement, a key motivation for the new procedural regulation (EU) 2025/2518.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/eu-lawmakers-announce-deal-on-cross-border-gdpr-enforcement-procedures",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers, applicable in Member States since 25 June 2023, empowers qualified entities to bring both injunctive and redress collective actions against traders for infringements including, where available under national or EU law, data protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Publications Office of the EU",
     "source_url": "https://eur-lex.europa.eu/EN/legal-content/summary/consumer-protection-representative-actions.html",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Complaints filed in May 2018 by advocacy group NOYB under Articles 77-79/82 GDPR underpinned the enforcement chain leading to the Irish DPC's Meta Facebook, Instagram and WhatsApp fines, and NOYB has indicated it intends to challenge the EU-US Data Privacy Framework adequacy decision before the CJEU.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/european-commission-adopts-eu-u-s-adequacy-decision",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 11 February 2026, the EDPB and EDPS adopted Joint Opinion 2/2026 on the Digital Omnibus Regulation proposal, supporting simplification aims while urging co-legislators not to adopt the proposed narrowing of the GDPR's personal-data definition.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 7 July 2026, the EDPB published draft Guidelines 02/2026 on Anonymisation for public consultation (open until 30 October 2026), responding to the CJEU's September 2025 EDPS v SRB ruling.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/public-consultations/guidelines-022026-on-anonymisation_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 19 March 2026, the EDPB launched its 2026 Coordinated Enforcement Framework action, with 25 participating DPAs assessing controller compliance with GDPR transparency and information obligations (Articles 12-14).",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/cef-2026-edpb-launches-coordinated-enforcement-action-on-transparency-and-information_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}