The European Data Protection Board has published its formal Opinion approving the updated Europrivacy certification criteria as a European Data Protection Seal. This approval is significant as it…
Marking 10 years of the GDPR: the evolution of the European data protection landscape
General Data Protection Regulation. Sourced from EDPB, summarised by Matproof.
AI Analysis
What changed and what to do.
This publication from the European Data Protection Board marks the tenth anniversary of the GDPR by reflecting on its evolution and current enforcement priorities. While no new legal text or binding guidelines were issued, the EDPB uses this milestone to reaffirm key areas of focus: the increasing importance of data protection by design and default, the need for robust accountability measures, and the growing scrutiny of algorithmic decision-making and AI systems. The document signals that supervisory authorities are now more coordinated and aggressive in cross-border enforcement, particularly regarding large-scale data processing and the use of personal data for training AI models.
All organizations processing personal data of individuals in the EU remain affected, but the EDPB specifically highlights sectors heavily reliant on automated profiling and high-risk processing, such as technology companies, financial services, healthcare, and digital advertising. Small and medium enterprises are also reminded that the principle of accountability applies proportionally, meaning they cannot rely on limited resources as a blanket excuse for non-compliance.
Compliance teams should immediately review their data protection impact assessments, especially for any AI or machine learning projects, and ensure that records of processing activities are up to date. Teams should also verify that their data protection officer is adequately resourced and that internal procedures for handling data subject requests are efficient. Finally, organizations should prepare for more frequent and coordinated audits by national supervisory authorities, particularly around the transparency of automated decisions and the lawful basis for data use in emerging technologies.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More GDPR updates
Latest in General Data Protection Regulation.
The European Data Protection Board has published its formal Opinion 14/2026, approving the updated Europrivacy certification criteria as a European Data Protection Seal under Article 42.5 of the…
The European Data Protection Board (EDPB) has launched its 2026 Coordinated Enforcement Framework (CEF) action, focusing on the practical application of GDPR transparency and information obligations.…
The European Data Protection Board (EDPB) has published its strategic work programme for 2026-2027, formally establishing a core objective of simplifying GDPR compliance. This represents a…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.