NIS2 & DORA in force. EU AI Act next — book a demo
GDPREDPB27 Apr 2026

Marking 10 years of the GDPR: the evolution of the European data protection landscape

General Data Protection Regulation. Sourced from EDPB, summarised by Matproof.

AI Analysis

What changed and what to do.

This publication from the European Data Protection Board marks the tenth anniversary of the GDPR by reflecting on its evolution and current enforcement priorities. While no new legal text or binding guidelines were issued, the EDPB uses this milestone to reaffirm key areas of focus: the increasing importance of data protection by design and default, the need for robust accountability measures, and the growing scrutiny of algorithmic decision-making and AI systems. The document signals that supervisory authorities are now more coordinated and aggressive in cross-border enforcement, particularly regarding large-scale data processing and the use of personal data for training AI models.

All organizations processing personal data of individuals in the EU remain affected, but the EDPB specifically highlights sectors heavily reliant on automated profiling and high-risk processing, such as technology companies, financial services, healthcare, and digital advertising. Small and medium enterprises are also reminded that the principle of accountability applies proportionally, meaning they cannot rely on limited resources as a blanket excuse for non-compliance.

Compliance teams should immediately review their data protection impact assessments, especially for any AI or machine learning projects, and ensure that records of processing activities are up to date. Teams should also verify that their data protection officer is adequately resourced and that internal procedures for handling data subject requests are efficient. Finally, organizations should prepare for more frequent and coordinated audits by national supervisory authorities, particularly around the transparency of automated decisions and the lawful basis for data use in emerging technologies.

View original at EDPB

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More GDPR updates

Latest in General Data Protection Regulation.

← Back to all updates
Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.

Book a DemoBrowse all updates