ePrivacy Regulation Could Finally Be Adopted
The long-delayed ePrivacy Regulation — stalled since 2017 — faces further setbacks after EU Member States blocked the Commission's proposal to eliminate cookie banners in June 2026. The regulation would replace the Cookie Directive with stricter rules on electronic communications metadata, but disagreements over metadata retention and the cookie consent mechanism continue to delay progress.
AI Act Full Application Triggers GDPR Enforcement Wave
The EU AI Act reaches full application in August 2026, and regulators are expected to launch coordinated enforcement actions targeting AI systems that process personal data without adequate safeguards. Expect clarification on how GDPR rights — especially Article 22 on automated decisions — apply to high-risk AI systems, with stronger requirements for human review, transparency, and DPIAs before deployment.
DPA Cross-Border Enforcement Overhaul
The one-stop-shop mechanism has drawn sustained criticism — particularly the Irish DPC's handling of Big Tech cases. The European Commission published its GDPR evaluation in 2023, and a political agreement on additional procedural rules was reached in June 2025. The next phase is practical implementation, with likely follow-up guidance to accelerate cross-border enforcement and reduce bottlenecks at lead supervisory authorities.
Schrems III: EU–US Data Flows Under Threat Again
The EU–US Data Privacy Framework faces mounting pressure after the US Supreme Court ruled in June 2026 that the FTC may no longer operate independently. Since the DPF relies on the FTC as a key enforcement body, this ruling undermines a core assumption of the adequacy decision. Privacy advocates including NOYB have explicitly flagged this as a trigger for a formal CJEU challenge. A successful challenge would again disrupt cloud services and transatlantic business operations.
Stricter Age Verification Requirements EU-Wide
Following Ireland's major fine against Meta over children's data (Instagram, 2022), and broader DSA enforcement, expect new EU-wide standards for age verification and parental consent mechanisms. The EDPB has signalled children's data as a top enforcement priority for 2025–2026. Coordinated enforcement actions across multiple DPAs are expected, potentially targeting social media platforms and gaming companies.
First €2 Billion+ GDPR Fine
With Meta's €1.2B fine setting a record in 2023, and multiple open investigations into Big Tech advertising ecosystems, a fine crossing the €2 billion threshold is plausible before 2027. This would require a proven Article 83(5) violation — systematic and intentional processing in breach of fundamental GDPR principles — with a company large enough to support a fine of 4% of global annual turnover at this level.
"Pay or Okay" Consent Models Ruled Invalid
Following NOYB's complaints against Meta and Schibsted over "Pay or Okay" consent walls — where users must pay for an ad-free experience or consent to tracking — regulators are expected to issue binding guidance declaring these models incompatible with freely given consent under GDPR Article 7. The EDPB has already expressed scepticism, and a definitive ruling could force publishers and platforms to find alternative business models.