🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
EEA · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 39 sources retrieved model claude-sonnet-5 ·

European Economic Area

EEA schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 54 claims · 39 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
54Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Mature, harmonised, directly-applicable omnibus regime with an active coordinating body and imminent procedural strengthening; no material derogation identified across EEA EFTA states.

Primary frameworkRegulation (EU) 2016/679 (GDPR), incorporated into the EEA Agreement (Annex XI)
Traffic-light rationale — GreenMature, harmonised, directly-applicable omnibus regime with an active coordinating body and imminent procedural strengthening; no material derogation identified across EEA EFTA states.

Sub-modules (5)

Regulator And AuthorityGreen

Primary enforcement rests with each Member/EEA State's national DPA (e.g. Irish DPC as lead authority for many multinational platforms, CNIL in France, Datatilsynet in Norway); the EDPB coordinates consistency and can issue binding decisions under Article 65 GDPR overriding a lead authority's proposed measures.

Claims: CLM-EEA-1a2b3c01, CLM-EEA-1a2b3c02

Act And InstrumentsGreen

The GDPR repealed Directive 95/46/EC and is the central instrument; it is supplemented by the ePrivacy Directive 2002/58/EC and, from 2 April 2027, by a new procedural regulation on cross-border enforcement.

Claims: CLM-EEA-1a2b3c03, CLM-EEA-1a2b3c04

Material ScopeGreen

GDPR applies to the processing of personal data wholly or partly by automated means, and to non-automated processing forming part of a filing system, covering both controllers and processors established in the EEA.

Claims: CLM-EEA-1a2b3c05

Territorial ScopeAmber

Article 3 GDPR extends application extraterritorially to non-EEA controllers/processors offering goods or services to, or monitoring the behaviour of, EEA data subjects, though DPAs' investigative powers outside EEA territory remain subject to third-state consent.

Claims: CLM-EEA-1a2b3c06, CLM-EEA-1a2b3c07

Regulator Registration And FilingAmber

The GDPR replaced the prior notification/registration regime of Directive 95/46/EC with an accountability-based model; no general filing duty with the DPA was confirmed by direct source in this research pass beyond structural inference from the repeal of the prior directive.

Claims: CLM-EEA-1a2b3c08

Category narrative75 words

The EEA (EU-27 plus Iceland, Liechtenstein and Norway) is governed by Regulation (EU) 2016/679 (GDPR) as the comprehensive omnibus instrument, incorporated into Annex XI of the EEA Agreement and applicable in the EFTA EEA states since 20 July 2018. Enforcement is decentralised to national supervisory authorities (e.g. Irish DPC, CNIL, Datatilsynet) coordinated by the EDPB through the one-stop-shop and Article 65 binding dispute-resolution mechanisms, with a new procedural regulation streamlining cross-border cooperation from April 2027.

Sources and claims (8)
  1. ConfirmedEDPSNational data protection authorities of the EU Member States and the EEA EFTA states (Iceland, Liechtenstein, Norway) are the primary enforcement bodies for the GDPR, cooperating through the EDPB's consistency and cooperation framework.
  2. ConfirmedIAPPThe EDPB may issue binding decisions under Article 65 GDPR that direct a lead supervisory authority to alter proposed measures, including materially increasing proposed fines, as occurred in the Meta Ireland Facebook/Instagram inquiries where the EDPB directed the fine be raised from a proposed maximum of €59 million to €390 million.
  3. ConfirmedCNILRegulation (EU) 2016/679 (GDPR) repealed and replaced Directive 95/46/EC as the EU's general data protection framework.
  4. ConfirmedPublications Office of the EURegulation (EU) 2025/2518, laying down additional procedural rules for GDPR cross-border enforcement (harmonising complaint admissibility, lead/concerned-authority cooperation and party rights), was adopted on 26 November 2025, published in the Official Journal on 12 December 2025, and applies from 2 April 2027.
  5. ConfirmedCNILGDPR Article 2 material scope covers processing of personal data by automated means and manual processing forming part of a filing system, as reflected in EDPB and CNIL guidance defining personal data broadly (any information relating to an identified or identifiable natural person).
  6. ConfirmedIAPPSince 25 May 2018, GDPR applies to processing in the context of an EU/EEA establishment's activities and to processing by non-established controllers/processors targeting EEA data subjects through the offering of goods or services or the monitoring of their behaviour within the Union.
  7. ConfirmedEDPBAn EDPB report on extraterritorial enforcement notes that any exercise of a DPA's investigative powers outside EU/EEA territory requires the consent of the foreign state, limiting practical extraterritorial reach notwithstanding Article 3's broad scope.
  8. UncertainCNILThe GDPR is generally understood to have abolished the ex-ante notification/registration regime that existed under Directive 95/46/EC, substituting an accountability-based compliance model (Article 5(2), Article 24).

#

Core provisions are stable and enforced, but the Digital Omnibus proposal (still in trilogue as of mid-2026) creates near-term uncertainty over consent-signal mechanics and the sensitive-data/AI derogation.

Primary frameworkGDPR Articles 4-11 (Regulation (EU) 2016/679); proposed amendments under the Digital Omnibus (COM(2025) 836 final)
Traffic-light rationale — AmberCore provisions are stable and enforced, but the Digital Omnibus proposal (still in trilogue as of mid-2026) creates near-term uncertainty over consent-signal mechanics and the sensitive-data/AI derogation.

Sub-modules (4)

Lawful BasesAmber

The EDPB's binding decisions confirmed Meta could not rely on the 'contract' basis (Art. 6(1)(b)) for behavioural advertising, materially narrowing available lawful bases for ad-targeting business models.

Claims: CLM-EEA-2b3c4d01

Special CategoriesAmber

The Digital Omnibus proposes a new derogation to the Article 9 prohibition on processing special-category data, covering incidental and residual processing in the context of developing and operating AI systems, subject to conditions the EDPB/EDPS say need lifecycle safeguards.

Claims: CLM-EEA-2b3c4d04

Pseudonymisation And AnonymisationGreen

The EDPB adopted Guidelines 01/2025 on Pseudonymisation (finalisation ongoing) and published draft Guidelines 02/2026 on Anonymisation in July 2026 responding to the CJEU's EDPS v SRB ruling that pseudonymised data is not automatically personal data for every recipient.

Claims: CLM-EEA-2b3c4d05, CLM-EEA-2b3c4d06

Category narrative57 words

GDPR Article 6 lawful bases remain unchanged, but their practical application is contested and evolving through enforcement (e.g. the Meta 'contract' basis for behavioural advertising being invalidated) and through the pending Digital Omnibus, which would add a targeted derogation permitting incidental/residual processing of special-category data in AI development and modify consent/transparency mechanics (Art. 88b automated choice signals).

Sources and claims (6)
  1. ConfirmedIAPPThe Irish DPC, implementing EDPB binding decisions, fined Meta Ireland a combined €390 million (€210m Facebook, €180m Instagram) after finding that Meta could not rely on the contractual-necessity legal basis under Article 6 GDPR for behavioural-advertising processing.
  2. ProbableIAPPThe Digital Omnibus proposal introduces a new GDPR Article 88b that would allow individuals to express privacy choices automatically through technical means such as browser settings, rather than manual cookie-banner interaction.
  3. ProbableIAPPIn June 2026 the Council of the EU removed the proposed Article 88b automated-consent-signal provision from its negotiating position following lobbying from media and advertising industry groups, creating legislative uncertainty over the final mechanism.
  4. ConfirmedEDPBThe EDPB and EDPS welcomed the Digital Omnibus's proposed derogation permitting incidental and residual processing of special-category (Article 9) data in the context of developing and operating AI systems, while recommending improvements to scope and lifecycle safeguards.
  5. ConfirmedEDPBEDPB Guidelines 01/2025 clarify that pseudonymised data, when attributable to an individual via additional information, remains personal data, and detail how pseudonymisation supports Articles 5, 25 and 32 compliance.
  6. ConfirmedIAPPFollowing the CJEU's September 2025 EDPS v SRB ruling that the same dataset can be personal data for one recipient and anonymous for another, the EDPB published draft Guidelines 02/2026 on Anonymisation (7 July 2026, consultation to 30 October 2026) setting out a two-question, three-criteria (no isolation, no linkage, no inference) test for anonymisation.

#

Rights are robustly enforced and subject to active coordinated supervisory scrutiny, but a pending legislative change (abuse-of-access-rights clarification) could alter practical scope.

Primary frameworkGDPR Articles 12-23 (Regulation (EU) 2016/679)
Traffic-light rationale — AmberRights are robustly enforced and subject to active coordinated supervisory scrutiny, but a pending legislative change (abuse-of-access-rights clarification) could alter practical scope.

Sub-modules (5)

Access RightAmber

CJEU case law confirms data subjects may exercise the right of access for purposes beyond verifying lawfulness of processing, without needing to state a motivation; the Digital Omnibus proposes clarifying when repeated/motiveless access requests constitute an abuse of rights, a framing the EDPB/EDPS partly contest.

Claims: CLM-EEA-3c4d5e01, CLM-EEA-3c4d5e02

Rectification And ErasureGreen

The EDPB's 2025 Coordinated Enforcement Framework action assessed compliance with the Article 17 right to erasure across participating DPAs, with a report adopted in 2026.

Claims: CLM-EEA-3c4d5e03

Restriction And ObjectionAmber

No dedicated 2026 enforcement or guidance action specific to Articles 18/21 restriction and objection rights was identified in this research pass distinct from the broader transparency and erasure actions.

Data PortabilityGreen

Article 20 portability continues to be governed by the WP29 Guidelines on the right to data portability, as endorsed by the EDPB; no material 2026 revision was identified.

Claims: CLM-EEA-3c4d5e04

Deadlines And Response WindowsAmber

The EDPB's 2026 CEF action specifically targets controllers' compliance with the Article 12-14 transparency and information obligations that underpin data subjects' ability to exercise their rights within statutory response windows.

Claims: CLM-EEA-3c4d5e05

Category narrative55 words

GDPR Chapter III rights (access, rectification, erasure, restriction, objection, portability) remain fully in force EEA-wide. The EDPB's 2025 Coordinated Enforcement Framework focused on the right to erasure (Art. 17) and its 2026 CEF action targets transparency/information obligations (Arts. 12-14); the Digital Omnibus separately proposes an 'abuse of rights' clarification affecting how access requests are handled.

Sources and claims (5)
  1. ConfirmedEDPBThe CJEU has confirmed (Case C-307/22) that data subjects may legitimately exercise the Article 15 right of access for objectives other than becoming aware of processing or verifying its lawfulness, without needing to provide particular motivation.
  2. ConfirmedEDPBThe Digital Omnibus proposes to give controllers legal clarity for cases of abuse of rights by data subjects, but the EDPB and EDPS consider that exercising the access right for purposes other than data protection should not itself be treated as an element defining abuse.
  3. ConfirmedEDPBThe EDPB ran a year-long 2025 Coordinated Enforcement Framework action on the Article 17 right to erasure/right to be forgotten, adopting a report on the action's findings in 2026.
  4. ConfirmedEDPBThe right to data portability under Article 20 GDPR continues to be interpreted per the WP29 Guidelines on the right to data portability, as endorsed by the EDPB.
  5. ConfirmedEDPBDuring 2026, 25 DPAs across Europe are participating in the EDPB's Coordinated Enforcement Framework action assessing controller compliance with Article 12-14 transparency and information obligations that condition the effective exercise of data subject rights.

#

Baseline obligations are stable and well-enforced, but simplification proposals (still in trilogue) will materially change SME/SMC recordkeeping and breach-notification thresholds once adopted.

Primary frameworkGDPR Articles 24-39 (Regulation (EU) 2016/679); Digital Omnibus (COM(2025) 836 final)
Traffic-light rationale — AmberBaseline obligations are stable and well-enforced, but simplification proposals (still in trilogue) will materially change SME/SMC recordkeeping and breach-notification thresholds once adopted.

Sub-modules (7)

Accountability And DpiaGreen

Articles 5, 24, 25 and 35 remain the accountability/DPIA backbone; the Digital Omnibus proposes common EU templates for DPIAs and legitimate-interest assessments to ease compliance.

Claims: CLM-EEA-4d5e6f01

Dpo RequirementsAmber

No 2026-specific development on DPO appointment thresholds (Articles 37-39) was identified in this research pass; core designation triggers (public authorities, large-scale monitoring, large-scale special-category processing) remain unchanged.

Ropa RequirementsAmber

The Digital Omnibus (part of the fourth simplification package) proposes raising the Article 30(5) recordkeeping-exemption threshold from under-250-employee to under-750-employee enterprises/organisations, unless processing is high-risk.

Claims: CLM-EEA-4d5e6f02

Joint Controller ArrangementsAmber

Article 26 joint-controller allocation-of-responsibility rules remain unchanged; no material 2026 development was identified in this research pass.

Security MeasuresGreen

Pseudonymisation is confirmed by EDPB guidance as a key technical safeguard supporting Article 32 security-of-processing obligations, alongside encryption.

Claims: CLM-EEA-4d5e6f03

Breach NotificationAmber

The EDPB and EDPS support the Digital Omnibus's proposal to raise the risk threshold triggering the Article 33 duty to notify the DPA of a breach, and to extend the notification deadline, alongside common EU breach-notification templates.

Claims: CLM-EEA-4d5e6f04

Retention And DisposalAmber

No dedicated 2026 guidance or enforcement action on Article 5(1)(e) storage-limitation/retention specifics was identified in this research pass distinct from general accountability duties.

Category narrative51 words

Core GDPR accountability duties (DPIA, DPO, ROPA, security, breach notification, retention) remain in force. The Digital Omnibus proposes targeted relief: raising the Article 30(5) ROPA-exemption employee threshold from 250 to 750, common EU templates for DPIAs/breach notifications, and a higher risk threshold plus longer deadline for breach notification to supervisory authorities.

Sources and claims (4)
  1. ConfirmedEDPBAs part of its 2026-2027 work programme, the EDPB is developing ready-to-use EU templates for legitimate interest assessments, records of processing, privacy notices, data breach notifications and data protection impact assessments to facilitate compliance.
  2. ConfirmedEDPBThe Commission's Digital Omnibus proposal would amend Article 30(5) GDPR to raise the records-of-processing exemption threshold from enterprises/organisations under 250 employees to those under 750 employees, unless the processing is likely to result in high risk to individuals.
  3. ConfirmedEDPBEDPB guidance explains how pseudonymisation, alongside encryption, functions as a technical safeguard supporting Article 32 security-of-processing obligations and Article 25 data protection by design.
  4. ConfirmedEDPBThe EDPB and EDPS support the Digital Omnibus proposal to increase the risk threshold that triggers the Article 33 duty to notify a personal data breach to the competent DPA, and to extend the notification deadline, alongside introducing common breach-notification and DPIA templates.

#

Transfer mechanisms are mature and well-documented, but the EU-US DPF faces continuing legal challenge risk and the EDPB has flagged concerns (e.g. over US entry-condition changes for EEA citizens and a US Supreme Court ruling) that could affect adequacy stability.

Primary frameworkGDPR Chapter V, Articles 44-50 (Regulation (EU) 2016/679)
Traffic-light rationale — AmberTransfer mechanisms are mature and well-documented, but the EU-US DPF faces continuing legal challenge risk and the EDPB has flagged concerns (e.g. over US entry-condition changes for EEA citizens and a US Supreme Court ruling) that could affect adequacy stability.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Article 46 appropriate-safeguards tools (SCCs, BCRs) and Article 49 derogations remain the default routes absent adequacy; TIAs must precede reliance on Article 46 tools per CNIL/EDPB methodology.

Claims: CLM-EEA-5e6f7001

Adequacy ReceivedGreen

As the standard-setting jurisdiction, the EEA is structurally an adequacy-GRANTING regime rather than a recipient of adequacy decisions from third countries; the concept of 'adequacy received' does not apply to the EEA in the way it applies to third countries such as the UK receiving EU adequacy.

Claims: CLM-EEA-5e6f7002

Adequacy GrantedGreen

The European Commission has granted adequacy to Andorra, Argentina, Canada (private sector), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and the United States (via the EU-US DPF, private-sector participants only).

Claims: CLM-EEA-5e6f7003, CLM-EEA-5e6f7004

Sccs And BcrsGreen

The Commission's 2021 modernised SCCs (Implementing Decision (EU) 2021/914) remain the principal contractual transfer tool; the EDPB continues to issue Article 64 opinions approving national DPAs' draft BCR decisions for both controllers and processors.

Claims: CLM-EEA-5e6f7005

Transfer Impact AssessmentGreen

A Transfer Impact Assessment is required before relying on an Article 46 tool for transfers to non-adequate third countries, assessing whether the importer's jurisdiction offers protection essentially equivalent to the EEA; TIAs are not required where an adequacy decision or Article 49 derogation applies.

Claims: CLM-EEA-5e6f7006

Data LocalisationAmber

GDPR does not impose a general data-localisation mandate, but the EU's parallel Digital Omnibus/sovereign-cloud legislative track (COM(2026)502) introduces sovereignty-oriented safeguards for personal data processed via cloud infrastructure, without altering GDPR's transfer rules directly.

Claims: CLM-EEA-5e6f7007

Category narrative67 words

The EEA operates the full GDPR Chapter V transfer toolkit (adequacy, SCCs, BCRs, Article 49 derogations, TIAs). It currently grants adequacy to 15 third countries/territories (including the US via the EU-US DPF, and the UK, renewed to 27 December 2031), while itself functioning as the adequacy-granting jurisdiction rather than a recipient. The EU-US Data Privacy Framework remains under EDPB monitoring amid ongoing litigation risk and periodic review.

Sources and claims (7)
  1. ConfirmedEDPBArticle 46 GDPR lists appropriate-safeguards transfer tools (including SCCs and BCRs), and Article 49 provides derogations for specific situations, both usable absent an adequacy decision, subject to the exporter maintaining Article 5 GDPR compliance.
  2. ConfirmedICOThe GDPR framework positions the European Commission as the body issuing adequacy decisions under Article 45 to third countries (e.g. the UK, renewed 19 December 2025 to run until 27 December 2031); the EEA itself is not a recipient of inbound adequacy findings under this mechanism.
  3. ConfirmedEDPBThe European Commission has recognised adequate third countries/territories including Andorra, Argentina, Canada, the Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay and the United States.
  4. ConfirmedIAPPThe EU-US Data Privacy Framework adequacy decision, adopted 10 July 2023, allows personal data to flow to certified US organisations without additional transfer safeguards; as of early 2026 more than 3,500 US companies had self-certified, though the framework remains subject to potential CJEU review and EDPB monitoring including a first-review report.
  5. ConfirmedBfDIThe European Commission adopted modernised Standard Contractual Clauses via Implementing Decision (EU) 2021/914 in June 2021, and since 27 September 2021 only the current SCCs may be used for new transfer contracts; the EDPB continues to issue opinions approving Member State DPAs' draft BCR authorisations (e.g. multiple 2026 opinions on Dutch SA BCR decisions).
  6. ConfirmedCNILA Transfer Impact Assessment must be carried out by an exporter relying on an Article 46 GDPR transfer tool prior to transferring data to a third country, unless the destination is covered by an adequacy decision or an Article 49 derogation applies.
  7. ProbableEuropean CommissionA separate EU legislative proposal for sovereign cloud computing services (impact assessment submitted to the Regulatory Scrutiny Board, positive opinion 8 May 2026) introduces safeguards for EU-citizen personal data processed via cloud infrastructure and is framed as complementary to, not a replacement for, the GDPR and EU-US DPF transfer regime.

#

Health and telecoms/eprivacy overlays are actively evidenced; other sectoral overlays (financial, employment, education, insurance) lack direct 2026 sourcing in this pass and are flagged as gaps.

Primary frameworkGDPR (Regulation (EU) 2016/679) with sector-specific overlays (ePrivacy Directive 2002/58/EC)
Traffic-light rationale — AmberHealth and telecoms/eprivacy overlays are actively evidenced; other sectoral overlays (financial, employment, education, insurance) lack direct 2026 sourcing in this pass and are flagged as gaps.

Sub-modules (7)

Financial Sector OverlayRed

No direct 2026 source evidencing a specific financial-sector GDPR overlay (e.g. interplay with PSD2/AML frameworks) was retrieved in this research pass.

Health Sector OverlayAmber

CNIL imposed a €5 million fine against IQVIA for health-data violations, evidencing active health-sector GDPR enforcement.

Claims: CLM-EEA-6f708101

Telecoms And EprivacyAmber

The Digital Omnibus proposes targeted amendments to the ePrivacy Directive (cookie/tracking consent rules), including a new automated-consent-signal mechanism and additional narrow derogations to the prohibition on accessing terminal-equipment data.

Claims: CLM-EEA-6f708102

Employment DataRed

No dedicated 2026 EEA employment-data overlay source was retrieved in this research pass beyond generic Article 88 GDPR employment-context processing rules, which were not directly evidenced.

Credit And ScoringAmber

The CJEU's December 2023 SCHUFA ruling (C-634/21) provided the first interpretation of the Article 22 right not to be subject to solely automated decision-making in the context of automated credit scoring.

Claims: CLM-EEA-6f708103

EducationRed

No dedicated 2026 EEA education-sector data protection source was retrieved in this research pass.

InsuranceRed

No dedicated 2026 EEA insurance-sector data protection source was retrieved in this research pass.

Category narrative42 words

GDPR applies horizontally with sector overlays; identified 2026 activity centres on health data (CNIL's €5m fine against IQVIA) and telecoms/eprivacy (Digital Omnibus proposed ePrivacy Directive amendments on cookies/tracking). Financial-sector, employment, education and insurance overlays were not directly evidenced in this research pass.

Sources and claims (3)
  1. ConfirmedCNILCNIL imposed a €5 million fine against IQVIA in connection with health-data processing, evidencing active French enforcement in the health sector.
  2. ConfirmedEDPBThe Digital Omnibus proposes amendments to the ePrivacy Directive including limited additional derogations to the general prohibition on storing or accessing data in terminal equipment, which the EDPB/EDPS urge be balanced by incentivising contextual over behavioural advertising.
  3. ConfirmedMedical Law Review / NCBI PMCIn December 2023, the CJEU issued its first interpretation of Article 22 GDPR (right not to be subject to solely automated decision-making) in the context of automated credit scoring (Case C-634/21, SCHUFA).

#

Cookie-consent fatigue is a recognised, unresolved policy problem; the principal legislative fix (Art. 88b) is currently stalled in the Council, leaving practical mechanics unsettled.

Primary frameworkePrivacy Directive 2002/58/EC read with GDPR consent standards (Regulation (EU) 2016/679)
Traffic-light rationale — AmberCookie-consent fatigue is a recognised, unresolved policy problem; the principal legislative fix (Art. 88b) is currently stalled in the Council, leaving practical mechanics unsettled.

Sub-modules (6)

Cookies And TrackersAmber

The proposed Article 88b would let individuals express privacy choices via automated technical means (e.g. browser settings) rather than manual cookie-banner clicks, with oversight entrusted to DPAs; the Council removed this provision from its June 2026 negotiating position.

Claims: CLM-EEA-708192a1

Dark PatternsAmber

Commentary identifies persistent cookie-banner 'consent fatigue' and dark-pattern-style nudging toward data sharing as an unresolved problem the Digital Omnibus aims, but has not yet succeeded, to fix.

Claims: CLM-EEA-708192a2

Opt Out SignalsAmber

Global Privacy Control, already implemented on at least 385,000 websites and recognised under several US state privacy laws, is discussed as a potential model for the EU's automated consent-signal mechanism, though the GPC specification (opt-out only) does not natively support giving affirmative consent.

Claims: CLM-EEA-708192a3

Clean Rooms And DcrRed

No dedicated 2026 EEA source on data clean rooms/data-collaboration-room rules was retrieved in this research pass.

Cross Context AdvertisingAmber

The EDPB and EDPS invite co-legislators to incentivise contextual advertising over behavioural advertising within the Digital Omnibus's ePrivacy amendments, via a specific exception surrounded by safeguards.

Claims: CLM-EEA-708192a4

Direct MarketingRed

No dedicated 2026 EEA source specific to direct-marketing consent/suppression rules distinct from general ePrivacy Article 13 rules was retrieved in this research pass.

Category narrative44 words

Cookie/tracker consent is governed by the ePrivacy Directive read with GDPR consent standards; 2026 developments centre on the contested Digital Omnibus Article 88b automated-consent-signal mechanism (removed by the Council in June 2026) and continuing debate over Global Privacy Control-style opt-out signals and contextual-versus-behavioural advertising.

Sources and claims (4)
  1. ConfirmedIAPPThe Digital Omnibus's proposed Article 88b GDPR would allow automated, machine-readable expression of individuals' data-processing choices, with oversight of such mechanisms entrusted to DPAs; in June 2026 the Council of the EU removed this provision from its position paper after industry lobbying.
  2. ProbableIAPPCookie banners are widely characterised as causing consent fatigue and facilitating data exploitation rather than achieving the meaningful, effective data protection the ePrivacy Directive and GDPR were intended to deliver.
  3. ConfirmedIAPPGlobal Privacy Control is implemented on at least 385,000 websites and recognised under California, Colorado, Connecticut and other US state privacy laws, and is discussed as a candidate technical standard for the EU's proposed automated consent-signal mechanism, though as an opt-out-only specification it cannot natively express affirmative consent.
  4. ConfirmedEDPBThe EDPB and EDPS welcome limited additional ePrivacy derogations proposed in the Digital Omnibus and invite co-legislators to incentivise contextual advertising over behavioural advertising through a specific, safeguarded exception.

#

Article 22 is settled law with recent CJEU interpretation, but the practical GDPR/AI Act interface remains in active development pending joint EDPB-Commission guidelines and AI Act simplification.

Primary frameworkGDPR Article 22 (Regulation (EU) 2016/679); interplay with Regulation (EU) 2024/1689 (AI Act)
Traffic-light rationale — AmberArticle 22 is settled law with recent CJEU interpretation, but the practical GDPR/AI Act interface remains in active development pending joint EDPB-Commission guidelines and AI Act simplification.

Sub-modules (6)

Profiling RestrictionsGreen

Article 22 GDPR provides data subjects a right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects.

Claims: CLM-EEA-819a2b01

Automated Decision Making TransparencyAmber

The EDPB and European Commission are jointly developing guidelines on the GDPR/AI Act interplay covering transparency, risk assessments, bias detection and accountability, with a draft expected soon and possible final adoption by end of 2026.

Claims: CLM-EEA-819a2b02

Ai Risk AssessmentsAmber

The Digital Omnibus on AI proposes to extend the AI Act's high-risk-system compliance timeline (originally August 2026) by up to six months once implementing standards are confirmed, capped at December 2027, alongside SME/SMC documentation simplifications.

Claims: CLM-EEA-819a2b03

Biometric RegimeRed

No dedicated 2026 EEA-specific biometric-regime source (facial recognition, fingerprint, gait) distinct from general Article 9 special-category rules was retrieved in this research pass.

Genetic DataAmber

Genetic data is treated as an Article 9 special category; the Digital Omnibus's proposed AI-context sensitive-data derogation would potentially cover incidental genetic-data processing in AI development, subject to EDPB/EDPS-recommended safeguards.

Claims: CLM-EEA-819a2b04

State Surveillance CarveoutsAmber

The EDPB has formally engaged the European Commission on privacy implications of proposed US legislative changes to entry conditions for EEA citizens, and separately on a US Supreme Court judgment (Trump v. Slaughter), reflecting active EDPB scrutiny of law-enforcement/surveillance-adjacent international-cooperation issues.

Claims: CLM-EEA-819a2b05

Category narrative69 words

Article 22 GDPR remains the core EEA safeguard against solely automated decision-making, interpreted by the CJEU in SCHUFA (2023). The EDPB and European Commission are jointly drafting guidelines on the GDPR/AI Act interplay (transparency, risk assessments, bias, accountability), expected in draft form soon with final adoption possibly by end of 2026, against the backdrop of the AI Act's own Digital Omnibus-driven timeline extension (high-risk obligations capped to December 2027).

Sources and claims (5)
  1. ConfirmedIAPPArticle 22 GDPR provides data subjects with the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them.
  2. ProbableIAPPThe EDPB and the European Commission are jointly preparing guidelines on the interplay between the GDPR and the AI Act, addressing transparency, risk assessments, bias detection and accountability, with a first draft potentially available soon and final adoption possible by end of 2026.
  3. ConfirmedIAPPThe EU's AI Act high-risk system compliance timeline, originally set for August 2026, is being extended via the Digital Omnibus on AI, with organisations to receive six months to comply once implementing standards and support tools are confirmed, capped at December 2027.
  4. ProbableEDPBGenetic data falls within the Article 9 special-category regime; the Digital Omnibus's proposed derogation for incidental/residual sensitive-data processing in AI development would potentially extend to genetic data, subject to EDPB/EDPS-recommended lifecycle safeguards.
  5. ConfirmedEDPBThe EDPB has issued formal correspondence to the European Commission addressing the privacy implications of proposed US legislative changes to entry conditions for EEA citizens, and separately regarding a US Supreme Court judgment, reflecting ongoing EDPB engagement with law-enforcement and surveillance-adjacent international-cooperation matters.

#

Core Article 8 mechanism is well-established law, but dedicated children's-data guidelines remain in development and several sub-areas (age verification specifics, education settings, dependent adults) lack direct 2026 sourcing in this pass.

Primary frameworkGDPR Article 8 (Regulation (EU) 2016/679)
Traffic-light rationale — AmberCore Article 8 mechanism is well-established law, but dedicated children's-data guidelines remain in development and several sub-areas (age verification specifics, education settings, dependent adults) lack direct 2026 sourcing in this pass.

Sub-modules (5)

Age VerificationAmber

Article 8 GDPR sets a default age of 16 for a child's own consent to information-society-service processing, with Member States able to lower this to no less than 13; a direct 2026 source confirming current Member-State-by-Member-State variance was not retrieved in this pass.

Claims: CLM-EEA-92ab3c01

Minor Profiling BansAmber

The EDPB is developing dedicated Guidelines on children's data as part of its 2026-2027 work programme, which is expected to address profiling and other processing risks specific to minors, though the guidelines were not yet finalised as of this research pass.

Claims: CLM-EEA-92ab3c02

Education SettingsRed

No dedicated 2026 EEA education-settings-specific children's-data source was retrieved in this research pass.

Dependent AdultsRed

No dedicated 2026 EEA dependent-adults (elderly, mentally incapacitated) data protection source was retrieved in this research pass.

Category narrative60 words

GDPR Article 8 establishes the default digital-consent age of 16 (Member States may lower to no less than 13); the EDPB is actively developing dedicated Guidelines on children's data as part of its 2026-2027 work programme, but this research pass did not surface a source directly confirming per-Member-State age-of-consent variance or minor-profiling-ban specifics for 2026, which are flagged as gaps.

Sources and claims (2)
  1. UncertainCNILArticle 8 GDPR sets a default minimum age of 16 for a child to consent to processing in relation to information-society services, permitting Member States to lower this threshold by law to no less than 13 years, with parental-responsibility-holder consent required below the applicable age.
  2. ConfirmedEDPBThe EDPB's 2026-2027 work programme includes the development of dedicated Guidelines on children's data as one of its Pillar I harmonisation priorities.

#

Enforcement powers are broad, actively used at scale (billion-euro-class fines), collective redress mechanisms are in force, and a further procedural-harmonisation regulation is already adopted (pending 2027 application).

Primary frameworkGDPR Articles 77-84, 58, 83 (Regulation (EU) 2016/679); Regulation (EU) 2025/2518; Directive (EU) 2020/1828
Traffic-light rationale — GreenEnforcement powers are broad, actively used at scale (billion-euro-class fines), collective redress mechanisms are in force, and a further procedural-harmonisation regulation is already adopted (pending 2027 application).

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Article 83 GDPR authorises administrative fines of up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, alongside corrective powers (bans, suspensions) under Article 58.

Claims: CLM-EEA-a3b4c501

Enforcement Activity IndexGreen

Ireland's DPC imposed a record €1.2 billion fine on Meta (May 2023) for unlawful US data transfers, plus a combined €390 million fine for unlawful ad-targeting legal basis and a €5.5 million WhatsApp transparency fine; the Czech SA confirmed a €13.9 million fine on appeal, and CNIL fined IQVIA €5 million over health data, evidencing sustained large-scale enforcement into 2026.

Claims: CLM-EEA-a3b4c502, CLM-EEA-a3b4c503, CLM-EEA-a3b4c504

Regulator Funding And CapacityAmber

No dedicated 2026 source quantifying EEA DPA funding or headcount levels was retrieved in this research pass; the European Commission has separately noted limited DPA resourcing as a factor hindering cross-border enforcement effectiveness, motivating the new procedural regulation.

Claims: CLM-EEA-a3b4c505

Collective Redress And Class ActionsGreen

Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers, in force since 25 June 2023, enables qualified entities to bring injunctive and redress collective actions covering, among other sectors, data protection infringements.

Claims: CLM-EEA-a3b4c506

Private Right Of ActionGreen

Articles 77-79 and 82 GDPR give data subjects the right to lodge a complaint with a DPA, an effective judicial remedy against a controller/processor and a DPA, and compensation for material or non-material damage; advocacy group NOYB's 2018 complaints underpinned the Meta enforcement chain and NOYB has signalled intent to challenge the EU-US DPF adequacy decision.

Claims: CLM-EEA-a3b4c507

Recent Developments 180DAmber

Within the last 180 days (Feb-Aug 2026): the EDPB/EDPS adopted Joint Opinion 2/2026 on the Digital Omnibus (Feb 2026); the Council removed the proposed Art.88b automated-consent-signal provision (Jun 2026); the EDPB published draft Guidelines 02/2026 on Anonymisation (Jul 2026, consultation to Oct 2026); the EDPB launched its 2026 Coordinated Enforcement Framework action on transparency (19 Mar 2026); and the EDPB corresponded with the Commission on US Supreme Court and US entry-condition developments (2026).

Claims: CLM-EEA-a3b4c508, CLM-EEA-a3b4c509, CLM-EEA-a3b4c510

Category narrative103 words

GDPR Article 83 empowers DPAs to impose fines up to €20 million or 4% of global annual turnover, whichever is greater. 2026 enforcement activity remains vigorous, evidenced by the Czech SA's €13.9m appellate-confirmed fine, CNIL's €5m IQVIA fine, and the historical record €1.2 billion Meta transfer fine and €390m/€5.5m Meta ad-targeting/WhatsApp fines implemented via EDPB Article 65 binding decisions. A new procedural regulation (EU) 2025/2518 will streamline cross-border cooperation from April 2027, and the EU's Representative Actions Directive (2020/1828, in force since June 2023) enables qualified-entity collective redress covering data protection, alongside individual rights of judicial remedy and compensation under Articles 79/82 GDPR.

Sources and claims (10)
  1. ConfirmedSECGDPR Article 83 authorises fines for certain violations of up to 4% of an undertaking's total global annual turnover of the preceding financial year or €20 million, whichever is greater.
  2. ConfirmedIAPPIreland's Data Protection Commission imposed a record €1.2 billion fine on Meta Ireland in May 2023 over unlawful EU-US data transfers, the largest GDPR fine to date, alongside orders to suspend future transfers and cease unlawful US processing of EEA users' data.
  3. ConfirmedEDPBThe Czech supervisory authority's appellate decision confirmed a first-instance fine of approximately €13.9 million against a controller for infringing Articles 6 and 13(1) GDPR over the transfer of antivirus-software users' browsing data to a sister company.
  4. ConfirmedIAPPCNIL fined IQVIA €5 million over health-data violations, and Ireland's DPC separately fined WhatsApp Ireland €5.5 million for transparency and consent failures in its Terms of Service, illustrating continued multi-jurisdictional enforcement momentum.
  5. ProbableIAPPThe European Commission identified fragmented national procedures and limited DPA resourcing as factors hindering effective cross-border GDPR enforcement, a key motivation for the new procedural regulation (EU) 2025/2518.
  6. ConfirmedPublications Office of the EUDirective (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers, applicable in Member States since 25 June 2023, empowers qualified entities to bring both injunctive and redress collective actions against traders for infringements including, where available under national or EU law, data protection.
  7. ConfirmedIAPPComplaints filed in May 2018 by advocacy group NOYB under Articles 77-79/82 GDPR underpinned the enforcement chain leading to the Irish DPC's Meta Facebook, Instagram and WhatsApp fines, and NOYB has indicated it intends to challenge the EU-US Data Privacy Framework adequacy decision before the CJEU.
  8. ConfirmedEDPBOn 11 February 2026, the EDPB and EDPS adopted Joint Opinion 2/2026 on the Digital Omnibus Regulation proposal, supporting simplification aims while urging co-legislators not to adopt the proposed narrowing of the GDPR's personal-data definition.
  9. ConfirmedEDPBOn 7 July 2026, the EDPB published draft Guidelines 02/2026 on Anonymisation for public consultation (open until 30 October 2026), responding to the CJEU's September 2025 EDPS v SRB ruling.
  10. ConfirmedEDPBOn 19 March 2026, the EDPB launched its 2026 Coordinated Enforcement Framework action, with 25 participating DPAs assessing controller compliance with GDPR transparency and information obligations (Articles 12-14).
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for European Economic Area
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 54 claim(s), 39 source(s) in the cumulative register.